Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Document.doc.scr.exe

Overview

General Information

Sample name:Document.doc.scr.exe
Analysis ID:1431429
MD5:50e5dec57451005668704281688ca55d
SHA1:67dd4ac7eb8c193b39149b34d3a0d5bc21c3f200
SHA256:062683257386c9e41a1cd1493f029d817445c37f7c65386d54122fa466419ce1
Tags:exe
Infos:

Detection

LockBit ransomware, TrojanRansom
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found ransom note / readme
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Yara detected LockBit ransomware
Yara detected TrojanRansom
Changes the wallpaper picture
Contains functionality to detect hardware virtualization (CPUID execution measurement)
Deletes itself after installation
Found Tor onion address
Found potential ransomware demand text
Hides threads from debuggers
Initial sample is a PE file and has a suspicious name
Machine Learning detection for sample
Modifies existing user documents (likely ransomware behavior)
Overwrites Mozilla Firefox settings
Sample has a suspicious name (potential lure to open the executable)
Tries to harvest and steal browser information (history, passwords, etc)
Uses an obfuscated file name to hide its real file extension (double extension)
Writes many files with high entropy
Writes to foreign memory regions
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to clear windows event logs (to hide its activities)
Contains functionality to communicate with device drivers
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected potential crypto function
Enables debug privileges
Enables security privileges
PE file contains an invalid checksum
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Potentially Suspicious Desktop Background Change Via Registry
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • Document.doc.scr.exe (PID: 3720 cmdline: "C:\Users\user\Desktop\Document.doc.scr.exe" MD5: 50E5DEC57451005668704281688CA55D)
    • splwow64.exe (PID: 5996 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
    • 2172.tmp (PID: 3836 cmdline: "C:\ProgramData\2172.tmp" MD5: 294E9F64CB1642DD89229FFF0592856B)
      • cmd.exe (PID: 3092 cmdline: "C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 5604 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • ONENOTE.EXE (PID: 2284 cmdline: /insertdoc "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\{EA82EC72-B970-44A4-8C1B-42CD300B85FB}.xps" 133584884697420000 MD5: 0061760D72416BCF5F2D9FA6564F0BEA)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Document.doc.scr.exeJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
    Document.doc.scr.exeWindows_Ransomware_Lockbit_369e1e94unknownunknown
    • 0x1861d:$a2: 8B EC 53 56 57 33 C0 8B 5D 14 33 C9 33 D2 8B 75 0C 8B 7D 08 85 F6 74 33 55 8B 6D 10 8A 54 0D 00 02 D3 8A 5C 15 00 8A 54 1D 00
    • 0x4bc:$a3: 53 51 6A 01 58 0F A2 F7 C1 00 00 00 40 0F 95 C0 84 C0 74 09 0F C7 F0 0F C7 F2 59 5B C3 6A 07 58 33 C9 0F A2 F7 C3 00 00 04 00 0F 95 C0 84 C0 74 09 0F C7 F8 0F C7 FA 59 5B C3 0F 31 8B C8 C1 C9 ...
    SourceRuleDescriptionAuthorStrings
    00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
      00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmpWindows_Ransomware_Lockbit_369e1e94unknownunknown
      • 0x1841d:$a2: 8B EC 53 56 57 33 C0 8B 5D 14 33 C9 33 D2 8B 75 0C 8B 7D 08 85 F6 74 33 55 8B 6D 10 8A 54 0D 00 02 D3 8A 5C 15 00 8A 54 1D 00
      • 0xbc:$a3: 53 51 6A 01 58 0F A2 F7 C1 00 00 00 40 0F 95 C0 84 C0 74 09 0F C7 F0 0F C7 F2 59 5B C3 6A 07 58 33 C9 0F A2 F7 C3 00 00 04 00 0F 95 C0 84 C0 74 09 0F C7 F8 0F C7 FA 59 5B C3 0F 31 8B C8 C1 C9 ...
      00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
        00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
          00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
            Click to see the 7 entries
            SourceRuleDescriptionAuthorStrings
            0.2.Document.doc.scr.exe.930000.0.unpackJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
              0.2.Document.doc.scr.exe.930000.0.unpackWindows_Ransomware_Lockbit_369e1e94unknownunknown
              • 0x1861d:$a2: 8B EC 53 56 57 33 C0 8B 5D 14 33 C9 33 D2 8B 75 0C 8B 7D 08 85 F6 74 33 55 8B 6D 10 8A 54 0D 00 02 D3 8A 5C 15 00 8A 54 1D 00
              • 0x4bc:$a3: 53 51 6A 01 58 0F A2 F7 C1 00 00 00 40 0F 95 C0 84 C0 74 09 0F C7 F0 0F C7 F2 59 5B C3 6A 07 58 33 C9 0F A2 F7 C3 00 00 04 00 0F 95 C0 84 C0 74 09 0F C7 F8 0F C7 FA 59 5B C3 0F 31 8B C8 C1 C9 ...
              0.0.Document.doc.scr.exe.930000.0.unpackJoeSecurity_LockBit_ransomwareYara detected LockBit ransomwareJoe Security
                0.0.Document.doc.scr.exe.930000.0.unpackWindows_Ransomware_Lockbit_369e1e94unknownunknown
                • 0x1861d:$a2: 8B EC 53 56 57 33 C0 8B 5D 14 33 C9 33 D2 8B 75 0C 8B 7D 08 85 F6 74 33 55 8B 6D 10 8A 54 0D 00 02 D3 8A 5C 15 00 8A 54 1D 00
                • 0x4bc:$a3: 53 51 6A 01 58 0F A2 F7 C1 00 00 00 40 0F 95 C0 84 C0 74 09 0F C7 F0 0F C7 F2 59 5B C3 6A 07 58 33 C9 0F A2 F7 C3 00 00 04 00 0F 95 C0 84 C0 74 09 0F C7 F8 0F C7 FA 59 5B C3 0F 31 8B C8 C1 C9 ...

                System Summary

                barindex
                Source: Registry Key setAuthor: Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ): Data: Details: C:\ProgramData\Qs2QSInbk.bmp, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\Document.doc.scr.exe, ProcessId: 3720, TargetObject: HKEY_CURRENT_USER\Control Panel\Desktop\WallPaper
                No Snort rule has matched

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: Document.doc.scr.exeAvira: detected
                Source: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionAvira URL Cloud: Label: malware
                Source: http://lockbitapt.uzAvira URL Cloud: Label: malware
                Source: http://lockbitsupp.uzAvira URL Cloud: Label: malware
                Source: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionAvira URL Cloud: Label: malware
                Source: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionAvira URL Cloud: Label: malware
                Source: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionVirustotal: Detection: 12%Perma Link
                Source: http://lockbitapt.uzVirustotal: Detection: 11%Perma Link
                Source: http://lockbitsupp.uzVirustotal: Detection: 8%Perma Link
                Source: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionVirustotal: Detection: 8%Perma Link
                Source: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionVirustotal: Detection: 8%Perma Link
                Source: Document.doc.scr.exeVirustotal: Detection: 77%Perma Link
                Source: Document.doc.scr.exeJoe Sandbox ML: detected
                Source: Document.doc.scr.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Videos\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Searches\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Saved Games\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Recent\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Pictures\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Pictures\Saved Pictures\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Pictures\Camera Roll\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\OneDrive\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Music\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Links\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Favorites\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Favorites\Links\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Downloads\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\ZGGKNSUKOP\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\UNKRLCVOHV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\QFAPOWPAFG\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\NYMMPCEIMA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\NVWZAPQSQL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\LHEPQPGEWF\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\JDDHMPCDUJ\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\HMPPSXQPQV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\GRXZDKKVDB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\EOWRVPQCCS\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\EFOYFBOLXA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\BJZFPPWAPT\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\ZGGKNSUKOP\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\UNKRLCVOHV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\QFAPOWPAFG\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\NYMMPCEIMA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\NVWZAPQSQL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\LHEPQPGEWF\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\JDDHMPCDUJ\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\HMPPSXQPQV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\GRXZDKKVDB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\EOWRVPQCCS\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\EFOYFBOLXA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\BJZFPPWAPT\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Contacts\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yiaxs5ej.default\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\to-be-removed\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\temporary\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\security_state\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\minidumps\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\tmp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\db\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\bookmarkbackups\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Extensions\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\6d9d9777-7ded-4768-8191-9a707d72b009\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\61f56613-c62c-4b17-84dd-62b60d5776aa\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Sonar\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Sonar\SonarCC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\RTTransfer\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\LogTransport2CC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\LogTransport2\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Linguistics\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Headlights\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Flash Player\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\CRLogs\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\CRLogs\crashlogs\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\Preflight Acrobat Continuous\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\JSCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Forms\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Collab\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Linguistics\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cookie\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\VideoDecodeStats\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\dd432c4a-ba38-4070-9985-ed1b3bea85dc\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\assets\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\VirtualStore\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\msedge_url_fetcher_5172_761252224\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\msedge_url_fetcher_5172_1791500899\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\msedge_url_fetcher_2640_817343797\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\mozilla-temp-files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Low\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_995017740\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_778675694\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_736602331\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_649288342\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_339006160\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_27162369\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1988346647\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1959985254\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1807723660\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1693012001\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1635976352\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1619438387\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1485273224\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1421574262\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1318414972\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1289371347\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1234978473\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1191663050\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1090636871\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrocef_low\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\SolidDocuments\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\SolidDocuments\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\SettingsContainer\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Microsoft.WindowsAlarms\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Licenses\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Fonts\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\PlaceholderTileLogoFolder\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\PeerDistRepub\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\DiagOutputDir\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\BackgroundTransferApi\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\Flighting\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{99fff775-938d-4e2c-9c06-5d56107a5383}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2737c7bb-35fb-4b44-baf9-033ca587595d}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ea91a05a-d98f-4429-81a9-272df0335447}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{de0f148a-c476-467a-b7a3-14b0bb463140}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{c23bcd39-6fcf-4e41-add1-0231129b23be}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\CacheStorage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: Document.doc.scr.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*6 source: Document.doc.scr.exe, 00000000.00000003.2057742422.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2062343931.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2059377065.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058777627.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058937804.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb source: Document.doc.scr.exe, 00000000.00000003.2258783246.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2276164348.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2255923512.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2107881841.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2261471485.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2076076908.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2111760133.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103731468.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2105203218.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2106190276.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2092103152.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2116474466.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2119600876.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103049713.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090960096.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090386296.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2369872444.0000000001055000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\*WI source: Document.doc.scr.exe, 00000000.00000003.2076076908.0000000001055000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: Document.doc.scr.exe, 00000000.00000003.2057742422.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2062343931.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2059377065.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2073299919.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058777627.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2075467271.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2075677088.000000000107D000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058937804.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: WINLOA~1.PDBwinload_prod.pdb source: Document.doc.scr.exe, 00000000.00000003.2053393457.0000000001067000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.Qs2QSInbk source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \\?\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdbSt source: Document.doc.scr.exe, 00000000.00000003.2258783246.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2276164348.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2255923512.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2107881841.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2261471485.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2076076908.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2111760133.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103731468.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2105203218.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2106190276.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2092103152.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2116474466.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2119600876.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103049713.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090960096.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090386296.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2369872444.0000000001055000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.Qs2QSInbk source: Document.doc.scr.exe, 00000000.00000003.2066471035.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2068848310.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2053996337.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2069805491.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Qs2QSInbk.README.txtu source: Document.doc.scr.exe, 00000000.00000003.2053275478.000000000107E000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \Device\HarddiskVolume3\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ownload.errort source: Document.doc.scr.exe, 00000000.00000003.2053996337.0000000001076000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \\?\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: Document.doc.scr.exe, 00000000.00000003.2057742422.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2062343931.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2059377065.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058777627.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058937804.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.Qs2QSInbk> source: Document.doc.scr.exe, 00000000.00000003.2053338835.0000000001117000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.Qs2QSInbk~ source: Document.doc.scr.exe, 00000000.00000003.2053338835.0000000001117000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2068688836.0000000001137000.00000004.00000020.00020000.00000000.sdmp
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093A094 FindFirstFileExW,FindClose,0_2_0093A094
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009374BC FindFirstFileExW,FindNextFileW,0_2_009374BC
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00935C24 FindFirstFileW,FindClose,FindNextFileW,FindClose,0_2_00935C24
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00937590 FindFirstFileExW,FindClose,0_2_00937590
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093766C FindFirstFileExW,GetFileAttributesW,FindNextFileW,0_2_0093766C
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093F308 GetFileAttributesW,SetThreadPriority,FindFirstFileExW,FindNextFileW,FindClose,0_2_0093F308
                Source: C:\ProgramData\2172.tmpCode function: 8_2_0040227C FindFirstFileExW,8_2_0040227C
                Source: C:\ProgramData\2172.tmpCode function: 8_2_0040152C FindFirstFileExW,FindClose,FindNextFileW,FindClose,8_2_0040152C
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093A470 GetLogicalDriveStringsW,0_2_0093A470
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Jump to behavior

                Networking

                barindex
                Source: Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion]N
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion]
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion]p
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.oniong
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onional
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionic
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionin
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionic
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl2
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionedA
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionk
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionc~
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionin
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion0
                Source: Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: `https://www.facebook.com/ equals www.facebook.com (Facebook)
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: `https://www.youtube.com/ equals www.youtube.com (Youtube)
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001045000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt.uz
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion0
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionic
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl2
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionc~
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionedA
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionic
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionin
                Source: Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onional
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.oniong
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionin
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionk
                Source: Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://lockbitsupp.uz
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bugzilla.mo
                Source: Document.doc.scr.exe, 00000000.00000003.2244020288.0000000001163000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://content-signature-2.cdn.mozilla.net/chains/remote-settings.content-signature.mozilla.org-202
                Source: App1714014880372801600_29CC7398-2A01-4DC6-A22E-768619CAA88A.log.7.drString found in binary or memory: https://login.windows.net
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.0000000001105000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2027366204.00000000010FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.mozilla.org/products/firefoxgro.allizom.troppus.GVegJq3nFfBL
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tox.:
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tox.::
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056293087.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2061132357.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2065780379.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2111760133.0000000001049000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103731468.0000000001047000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2109489328.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2258114624.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2106881738.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2261471485.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2257598840.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2260455472.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2104352096.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2074831153.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2110837373.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103049713.0000000001012000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2107881841.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Qs2QSInbk.README.txt361.0.dr, Qs2QSInbk.README.txt180.0.dr, Qs2QSInbk.README.txt445.0.dr, Qs2QSInbk.README.txt409.0.drString found in binary or memory: https://tox.chat/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.amazon.com/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.baidu.com/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ctrip.com/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ebay.co.uk/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/complete/
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.0000000001105000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2027366204.00000000010FD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/about/gro.allizom.www.CDjelnmQJyZc
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/contribute/gro.allizom.www.b3lOZaxJcpF6
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/en-US/privacy/firefox/Firefox
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/firefox/?utm_medium=firefox-desktop&utm_source=bookmarks-toolbar&utm_campaig
                Source: Document.doc.scr.exe, 00000000.00000003.2244254218.0000000001163000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/media/img/logos/social/tiktok-white.599403de7ac0.svg
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/media/img/mozorg/mozilla-256.4720741d4108.jpg
                Source: Document.doc.scr.exe, 00000000.00000003.2244254218.0000000001163000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/media/js/sentry.2b64d2b46e8a.js
                Source: Document.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mozilla.org/privacy/firefox/gro.allizom.www.
                Source: Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: C:\Users\user\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtDropped file: !! ALL YOUR FILES ARE ENCRYPTED !!!You can't restore them without our decryptor.Don't try to use any public tools, you could damage the files and lose them forever.To make sure our decryptor works, contact us and decrypt one file for free.Download TOX messenger: https://tox.chat/Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6Jump to dropped file
                Source: Yara matchFile source: Document.doc.scr.exe, type: SAMPLE
                Source: Yara matchFile source: 0.2.Document.doc.scr.exe.930000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.0.Document.doc.scr.exe.930000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000000.2003658828.0000000000931000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000003.2457278883.000000000107B000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: Document.doc.scr.exe PID: 3720, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: Document.doc.scr.exe PID: 3720, type: MEMORYSTR
                Source: C:\Users\user\Desktop\Document.doc.scr.exeKey value created or modified: HKEY_CURRENT_USER\Control Panel\Desktop WallPaper C:\ProgramData\Qs2QSInbk.bmpJump to behavior
                Source: Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory : Your data are stolen and encrypted
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory : Your data are stolen and encrypted
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001055000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory : All your important files are stolen and encrypted!
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile moved: C:\Users\user\Desktop\NVWZAPQSQL\EFOYFBOLXA.xlsxJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile moved: C:\Users\user\Desktop\ZGGKNSUKOP.xlsxJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile moved: C:\Users\user\Desktop\NWCXBPIUYI.mp3Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile moved: C:\Users\user\Desktop\BJZFPPWAPT\KLIZUSIQEN.pdfJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile moved: C:\Users\user\Desktop\EFOYFBOLXA\EWZCVGNOWT.pngJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\appsglobals.txt.Qs2QSInbk entropy: 7.999530453Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ea91a05a-d98f-4429-81a9-272df0335447}\0.0.filtertrie.intermediate.txt.Qs2QSInbk entropy: 7.99470217834Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\settingsglobals.txt.Qs2QSInbk entropy: 7.99602959615Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\appssynonyms.txt.Qs2QSInbk entropy: 7.99929543556Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ea91a05a-d98f-4429-81a9-272df0335447}\Apps.ft.Qs2QSInbk entropy: 7.99603698648Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{c23bcd39-6fcf-4e41-add1-0231129b23be}\0.0.filtertrie.intermediate.txt.Qs2QSInbk entropy: 7.99555877498Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{de0f148a-c476-467a-b7a3-14b0bb463140}\Apps.ft.Qs2QSInbk entropy: 7.99650183294Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{de0f148a-c476-467a-b7a3-14b0bb463140}\0.0.filtertrie.intermediate.txt.Qs2QSInbk entropy: 7.9956212989Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\settingssynonyms.txt.Qs2QSInbk entropy: 7.99832291913Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\https___java_com_help.Qs2QSInbk entropy: 7.99539062709Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\https___java_com_.Qs2QSInbk entropy: 7.99499108204Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Chrome.Qs2QSInbk entropy: 7.99472100209Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\308046B0AF4A39CB;PrivateBrowsingAUMID.Qs2QSInbk entropy: 7.99485276516Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\308046B0AF4A39CB.Qs2QSInbk entropy: 7.99400724706Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\settingsconversions.txt.Qs2QSInbk entropy: 7.99744012982Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{c23bcd39-6fcf-4e41-add1-0231129b23be}\Apps.ft.Qs2QSInbk entropy: 7.99617501998Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1318414972\873489b1-33b2-480a-baa2-641b9e09edcd.Qs2QSInbk entropy: 7.99185952357Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1289371347\78549187-a875-4f1e-8dfa-9938ebc29c81.Qs2QSInbk entropy: 7.9955493004Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1234978473\1187695d-8276-4e31-8de1-9e57768989bd.Qs2QSInbk entropy: 7.99707376633Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1421574262\c50698d5-282c-4c8d-9fa6-c155f2d8d379.Qs2QSInbk entropy: 7.99953842152Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{E8B84CFB-B069-BC13-F88F-170904F645E5}.Qs2QSInbk entropy: 7.9954303523Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{DAA168DE-4306-C8BC-8C11-B596240BDDED}.Qs2QSInbk entropy: 7.99523194122Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{C804BBA7-FA5F-CBF7-8B55-2096E5F972CB}.Qs2QSInbk entropy: 7.99421838953Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{C1C6F8AC-40A3-0F5C-146F-65A9DC70BBB4}.Qs2QSInbk entropy: 7.99391612445Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{BD3F924E-55FB-A1BA-9DE6-B50F9F2460AC}.Qs2QSInbk entropy: 7.99555123884Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{BB044BFD-25B7-2FAA-22A8-6371A93E0456}.Qs2QSInbk entropy: 7.99520696149Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{923DD477-5846-686B-A659-0FCCD73851A8}.Qs2QSInbk entropy: 7.9944223541Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{8ABD94FB-E7D6-84A6-A997-C918EDDE0AE5}.Qs2QSInbk entropy: 7.99503490301Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1191663050\9e51170b-7adf-40ab-83b6-5f97b13bedcb.Qs2QSInbk entropy: 7.99905618588Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{8AA47365-B2B3-1961-69EB-F866E376B12F}.Qs2QSInbk entropy: 7.9955512613Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{16988324-21C9-05B2-CA60-9B4EC72739D8}.Qs2QSInbk entropy: 7.99478864523Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1696428505298658900_7B05BF2A-C74F-44F8-B674-AA3F9719008B.log.Qs2QSInbk entropy: 7.99106666429Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{116229A7-9A3B-2078-DB5F-B5A20811242C}.Qs2QSInbk entropy: 7.99544101448Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1696428527628431800_6CD9E3BB-4D03-46BD-8615-75A902267162.log.Qs2QSInbk entropy: 7.99891654605Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\App1696428537364279100_A2018481-B961-46B4-9328-34939DEAF293.log.Qs2QSInbk entropy: 7.99906688756Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_InternetExplorer_Default.Qs2QSInbk entropy: 7.99497560075Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt.Qs2QSInbk entropy: 7.99215658534Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{F1118828-A0CC-5FEB-85C9-DBFFDF98434A}.Qs2QSInbk entropy: 7.99543011954Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{E7A33582-E908-3379-5368-5999454DCD83}.Qs2QSInbk entropy: 7.99543396629Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_OUTLOOK_EXE_15.Qs2QSInbk entropy: 7.99598645533Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_ONENOTE_EXE_15.Qs2QSInbk entropy: 7.99491311144Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_OcPubMgr_exe_15.Qs2QSInbk entropy: 7.99510995942Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_MSPUB_EXE_15.Qs2QSInbk entropy: 7.99553812245Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_msoev_exe_15.Qs2QSInbk entropy: 7.99525657639Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_MSACCESS_EXE_15.Qs2QSInbk entropy: 7.99492277144Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_lync_exe_15.Qs2QSInbk entropy: 7.99450661874Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_EXCEL_EXE_15.Qs2QSInbk entropy: 7.99502618185Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_DATABASECOMPARE_EXE_15.Qs2QSInbk entropy: 7.99568317215Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsCalculator_8wekyb3d8bbwe!App.Qs2QSInbk entropy: 7.99482949928Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsAlarms_8wekyb3d8bbwe!App.Qs2QSInbk entropy: 7.99535120195Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_SkyDrive_Desktop.Qs2QSInbk entropy: 7.99479579026Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_WINWORD_EXE_15.Qs2QSInbk entropy: 7.99473051565Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_SETLANG_EXE_15.Qs2QSInbk entropy: 7.99555306367Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_SPREADSHEETCOMPARE_EXE_15.Qs2QSInbk entropy: 7.99549089696Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_POWERPNT_EXE_15.Qs2QSInbk entropy: 7.9946460316Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_MediaPlayer32.Qs2QSInbk entropy: 7.99513536266Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Explorer.Qs2QSInbk entropy: 7.99567966986Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_ControlPanel.Qs2QSInbk entropy: 7.99433428612Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Computer.Qs2QSInbk entropy: 7.99518365658Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_AdministrativeTools.Qs2QSInbk entropy: 7.995090363Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsSoundRecorder_8wekyb3d8bbwe!App.Qs2QSInbk entropy: 7.99525763885Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_RemoteDesktop.Qs2QSInbk entropy: 7.9949298655Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\MSEdge.Qs2QSInbk entropy: 7.9948720056Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Shell_RunDialog.Qs2QSInbk entropy: 7.99533739937Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Photos_8wekyb3d8bbwe!App.Qs2QSInbk entropy: 7.99424589779Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\content-prefs.sqlite.Qs2QSInbk entropy: 7.99926761851Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite.Qs2QSInbk entropy: 7.9980354342Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-shm.Qs2QSInbk entropy: 7.99416507223Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\extensions.json.Qs2QSInbk entropy: 7.99499811154Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-shm.Qs2QSInbk entropy: 7.99474400837Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.db.Qs2QSInbk entropy: 7.99937107839Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\permissions.sqlite.Qs2QSInbk entropy: 7.99802641596Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-shm.Qs2QSInbk entropy: 7.99429407194Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\protections.sqlite.Qs2QSInbk entropy: 7.99761979963Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite.Qs2QSInbk entropy: 7.99820906833Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-shm.Qs2QSInbk entropy: 7.99497759958Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\ls-archive.sqlite.Qs2QSInbk entropy: 7.99862267934Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm.Qs2QSInbk entropy: 7.99350111277Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.Qs2QSInbk entropy: 7.99590646082Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.Qs2QSInbk entropy: 7.99634599189Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm.Qs2QSInbk entropy: 7.9953289432Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite.Qs2QSInbk entropy: 7.99634893955Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm.Qs2QSInbk entropy: 7.99466243541Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.Qs2QSInbk entropy: 7.99621746015Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm.Qs2QSInbk entropy: 7.9946290405Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.Qs2QSInbk entropy: 7.99579574441Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm.Qs2QSInbk entropy: 7.99417435465Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\entries\62FC1E8DCE1991EEB55DE9EFADF47EA578A22AB5.Qs2QSInbk entropy: 7.99304075631Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm.Qs2QSInbk entropy: 7.99381508349Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\a83301c6-790b-49f3-adc7-55a855f7fe79.Qs2QSInbk entropy: 7.9972834818Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\entries\D0F48A0632B6C451791F4257697E861961F06A6F.Qs2QSInbk entropy: 7.9948305611Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\entries\C5FD1F724F49F95970FE8CD30C20519BF4582045.Qs2QSInbk entropy: 7.99842649706Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\entries\E557A7C6ADAC24EDE9B88CACC662B8A371C1931D.Qs2QSInbk entropy: 7.99634144795Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\entries\DED23BB33EA3C88FAD1C0A1CD53916E0D8C424D3.Qs2QSInbk entropy: 7.99086601599Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835649.b06d08be-79e8-4bfe-b6aa-988ea3d35cbd.first-shutdown.jsonlz4.Qs2QSInbk entropy: 7.99178472417Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\entries\E707EC8A256322E87908664A49F800B7B48E0961.Qs2QSInbk entropy: 7.99191929839Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\first_party_sets.db.Qs2QSInbk entropy: 7.99680483484Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cache2\doomed\14645.Qs2QSInbk entropy: 7.99451275548Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\data_1.Qs2QSInbk entropy: 7.99932840589Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\index.Qs2QSInbk entropy: 7.99930479681Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\GraphiteDawnCache\data_1.Qs2QSInbk entropy: 7.99922905492Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\data_1.Qs2QSInbk entropy: 7.99935997534Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\GrShaderCache\index.Qs2QSInbk entropy: 7.99918021754Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\GraphiteDawnCache\index.Qs2QSInbk entropy: 7.99934710748Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_mspaint_exe.Qs2QSInbk entropy: 7.99498073237Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_MdSched_exe.Qs2QSInbk entropy: 7.99591848937Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_magnify_exe.Qs2QSInbk entropy: 7.9950149436Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_iscsicpl_exe.Qs2QSInbk entropy: 7.99501552841Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_dfrgui_exe.Qs2QSInbk entropy: 7.99534024681Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_comexp_msc.Qs2QSInbk entropy: 7.99493620187Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_cmd_exe.Qs2QSInbk entropy: 7.99446232795Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_cleanmgr_exe.Qs2QSInbk entropy: 7.99511705607Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_charmap_exe.Qs2QSInbk entropy: 7.99514762776Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_msinfo32_exe.Qs2QSInbk entropy: 7.99519016039Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_msconfig_exe.Qs2QSInbk entropy: 7.99499143038Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WFS_exe.Qs2QSInbk entropy: 7.9940341658Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_SnippingTool_exe.Qs2QSInbk entropy: 7.99506270097Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_RecoveryDrive_exe.Qs2QSInbk entropy: 7.99510610784Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_quickassist_exe.Qs2QSInbk entropy: 7.99565767391Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_psr_exe.Qs2QSInbk entropy: 7.99515709484Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_printmanagement_msc.Qs2QSInbk entropy: 7.99466824149Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_osk_exe.Qs2QSInbk entropy: 7.99437631884Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_odbcad32_exe.Qs2QSInbk entropy: 7.99457822976Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_notepad_exe.Qs2QSInbk entropy: 7.99542619112Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_narrator_exe.Qs2QSInbk entropy: 7.99511801872Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_services_msc.Qs2QSInbk entropy: 7.99494840912Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Aut2Exe_Aut2exe_exe.Qs2QSInbk entropy: 7.99498348186Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Au3Info_x64_exe.Qs2QSInbk entropy: 7.9952200111Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Au3Info_exe.Qs2QSInbk entropy: 7.9949762494Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Windows NT_Accessories_wordpad_exe.Qs2QSInbk entropy: 7.99508378897Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Common Files_Microsoft Shared_Ink_mip_exe.Qs2QSInbk entropy: 7.99545669501Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Adobe_Acrobat DC_Acrobat_Acrobat_exe.Qs2QSInbk entropy: 7.99510217529Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_7-Zip_7zFM_exe.Qs2QSInbk entropy: 7.99487876848Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_7-Zip_7-zip_chm.Qs2QSInbk entropy: 7.99445087594Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WindowsPowerShell_v1_0_PowerShell_ISE_exe.Qs2QSInbk entropy: 7.99446717133Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WindowsPowerShell_v1_0_powershell_exe.Qs2QSInbk entropy: 7.99474669197Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WF_msc.Qs2QSInbk entropy: 7.99483833445Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_odbcad32_exe.Qs2QSInbk entropy: 7.99582756315Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Java_jre-1_8_bin_javacpl_exe.Qs2QSInbk entropy: 7.99515604123Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_SciTE_SciTE_exe.Qs2QSInbk entropy: 7.99535567429Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Extras.Qs2QSInbk entropy: 7.99520448852Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Examples.Qs2QSInbk entropy: 7.99514915323Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt_chm.Qs2QSInbk entropy: 7.99542213298Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoItX_AutoItX_chm.Qs2QSInbk entropy: 7.99580155571Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt3_x64_exe.Qs2QSInbk entropy: 7.99536168536Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt3_exe.Qs2QSInbk entropy: 7.99537567266Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt v3 Website_url.Qs2QSInbk entropy: 7.99421550914Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Aut2Exe_Aut2exe_x64_exe.Qs2QSInbk entropy: 7.99475701834Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edbres00002.jrs.Qs2QSInbk entropy: 7.99961877689Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edbres00001.jrs.Qs2QSInbk entropy: 7.99962880522Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edb.log.Qs2QSInbk entropy: 7.99961966706Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{F38BF404-1D43-42F2-9305-67DE0B28FC23}_regedit_exe.Qs2QSInbk entropy: 7.99538151287Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_WindowsPowerShell_v1_0_PowerShell_ISE_exe.Qs2QSInbk entropy: 7.99479879284Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_WindowsPowerShell_v1_0_powershell_exe.Qs2QSInbk entropy: 7.99494738957Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edbtmp.log.Qs2QSInbk entropy: 7.9996092098Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-shm.Qs2QSInbk entropy: 7.99435221768Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppTracing_startedInBGMode.etl.Qs2QSInbk entropy: 7.99719876836Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite-shm.Qs2QSInbk entropy: 7.99441359102Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei.Qs2QSInbk entropy: 7.99217197286Jump to dropped file
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.html.Qs2QSInbk entropy: 7.9981726133Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\Document.doc.scr.exe entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\AAAAAAAAAAAAAAAAAAAA (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\BBBBBBBBBBBBBBBBBBBB (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\CCCCCCCCCCCCCCCCCCCC (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\DDDDDDDDDDDDDDDDDDDD (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\EEEEEEEEEEEEEEEEEEEE (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\FFFFFFFFFFFFFFFFFFFF (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\GGGGGGGGGGGGGGGGGGGG (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\HHHHHHHHHHHHHHHHHHHH (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\IIIIIIIIIIIIIIIIIIII (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\JJJJJJJJJJJJJJJJJJJJ (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\KKKKKKKKKKKKKKKKKKKK (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\LLLLLLLLLLLLLLLLLLLL (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\MMMMMMMMMMMMMMMMMMMM (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\NNNNNNNNNNNNNNNNNNNN (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\OOOOOOOOOOOOOOOOOOOO (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\PPPPPPPPPPPPPPPPPPPP (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\QQQQQQQQQQQQQQQQQQQQ (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\RRRRRRRRRRRRRRRRRRRR (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\SSSSSSSSSSSSSSSSSSSS (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\TTTTTTTTTTTTTTTTTTTT (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\UUUUUUUUUUUUUUUUUUUU (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\VVVVVVVVVVVVVVVVVVVV (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\WWWWWWWWWWWWWWWWWWWW (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\XXXXXXXXXXXXXXXXXXXX (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\YYYYYYYYYYYYYYYYYYYY (copy) entropy: 7.99742508059Jump to dropped file
                Source: C:\ProgramData\2172.tmpFile created: C:\Users\user\Desktop\ZZZZZZZZZZZZZZZZZZZZ (copy) entropy: 7.99742508059Jump to dropped file

                System Summary

                barindex
                Source: Document.doc.scr.exe, type: SAMPLEMatched rule: Windows_Ransomware_Lockbit_369e1e94 Author: unknown
                Source: 0.2.Document.doc.scr.exe.930000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Lockbit_369e1e94 Author: unknown
                Source: 0.0.Document.doc.scr.exe.930000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Lockbit_369e1e94 Author: unknown
                Source: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Lockbit_369e1e94 Author: unknown
                Source: 00000000.00000000.2003658828.0000000000931000.00000020.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Lockbit_369e1e94 Author: unknown
                Source: initial sampleStatic PE information: Filename: Document.doc.scr.exe
                Source: Document.doc.scr.exeStatic file information: Suspicious name
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00936C98 NtQueryInformationToken,0_2_00936C98
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00939880 NtClose,0_2_00939880
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009404B4 GetTempFileNameW,CreateFileW,WriteFile,CreateProcessW,NtQueryInformationProcess,NtReadVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,CreateNamedPipeW,ResumeThread,ConnectNamedPipe,0_2_009404B4
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00947034 CreateThread,CreateThread,CreateThread,CreateThread,NtTerminateThread,CreateThread,CreateThread,0_2_00947034
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093B444 NtSetInformationThread,0_2_0093B444
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093B470 NtProtectVirtualMemory,0_2_0093B470
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093DC60 NtTerminateProcess,0_2_0093DC60
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093E1E8 CreateThread,NtClose,0_2_0093E1E8
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00937E58 NtQuerySystemInformation,Sleep,0_2_00937E58
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093B674 NtQueryInformationToken,0_2_0093B674
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093DE78 SetThreadPriority,ReadFile,WriteFile,WriteFile,NtClose,0_2_0093DE78
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00936668 CreateFileW,NtAllocateVirtualMemory,WriteFile,SetFilePointerEx,NtFreeVirtualMemory,NtClose,DeleteFileW,0_2_00936668
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009397D8 NtQuerySystemInformation,0_2_009397D8
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093B3C0 NtSetInformationThread,NtClose,0_2_0093B3C0
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093C3F8 CreateFileW,WriteFile,RegCreateKeyExW,RegSetValueExW,RegCreateKeyExW,RegSetValueExW,SHChangeNotify,NtClose,0_2_0093C3F8
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093B734 NtSetInformationProcess,NtSetInformationProcess,NtSetInformationProcess,0_2_0093B734
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00938F68 RtlAdjustPrivilege,NtSetInformationThread,0_2_00938F68
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00939811 NtQuerySystemInformation,0_2_00939811
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093982A NtQuerySystemInformation,0_2_0093982A
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00937E8A NtQuerySystemInformation,Sleep,0_2_00937E8A
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00937EA3 NtQuerySystemInformation,Sleep,0_2_00937EA3
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00938F66 RtlAdjustPrivilege,NtSetInformationThread,0_2_00938F66
                Source: C:\ProgramData\2172.tmpCode function: 8_2_00402760 CreateFileW,ReadFile,NtClose,8_2_00402760
                Source: C:\ProgramData\2172.tmpCode function: 8_2_0040286C NtSetInformationProcess,NtSetInformationProcess,NtSetInformationProcess,8_2_0040286C
                Source: C:\ProgramData\2172.tmpCode function: 8_2_00402F18 CreateFileW,NtAllocateVirtualMemory,WriteFile,SetFilePointerEx,SetFilePointerEx,NtFreeVirtualMemory,NtClose,DeleteFileW,8_2_00402F18
                Source: C:\ProgramData\2172.tmpCode function: 8_2_00401DC2 NtProtectVirtualMemory,8_2_00401DC2
                Source: C:\ProgramData\2172.tmpCode function: 8_2_00401D94 NtSetInformationThread,8_2_00401D94
                Source: C:\ProgramData\2172.tmpCode function: 8_2_004016B4 NtAllocateVirtualMemory,NtAllocateVirtualMemory,8_2_004016B4
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093A68C: GetVolumeNameForVolumeMountPointW,FindFirstVolumeW,GetVolumePathNamesForVolumeNameW,GetDriveTypeW,CreateFileW,DeviceIoControl,0_2_0093A68C
                Source: C:\Windows\splwow64.exeFile created: C:\Windows\system32\spool\PRINTERS\00002.SPL
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009380B80_2_009380B8
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009320AC0_2_009320AC
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00934D030_2_00934D03
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00934D080_2_00934D08
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009352180_2_00935218
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess token adjusted: Security
                Source: Document.doc.scr.exe, 00000000.00000003.2260960774.0000000001045000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesvchost.exe.muij% vs Document.doc.scr.exe
                Source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001045000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesvchost.exe.muij% vs Document.doc.scr.exe
                Source: Document.doc.scr.exe, 00000000.00000003.2369872444.0000000001045000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesvchost.exe.muij% vs Document.doc.scr.exe
                Source: Document.doc.scr.exe, 00000000.00000003.2276164348.0000000001045000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesvchost.exe.muij% vs Document.doc.scr.exe
                Source: Document.doc.scr.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: Document.doc.scr.exe, type: SAMPLEMatched rule: Windows_Ransomware_Lockbit_369e1e94 reference_sample = d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee, os = windows, severity = x86, creation_date = 2022-07-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Lockbit, fingerprint = 9cf4c112c0ee708ae64052926681e8351f1ccefeb558c41e875dbd9e4bdcb5f2, id = 369e1e94-3fbb-4828-bb78-89d26e008105, last_modified = 2022-07-18
                Source: 0.2.Document.doc.scr.exe.930000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Lockbit_369e1e94 reference_sample = d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee, os = windows, severity = x86, creation_date = 2022-07-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Lockbit, fingerprint = 9cf4c112c0ee708ae64052926681e8351f1ccefeb558c41e875dbd9e4bdcb5f2, id = 369e1e94-3fbb-4828-bb78-89d26e008105, last_modified = 2022-07-18
                Source: 0.0.Document.doc.scr.exe.930000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Ransomware_Lockbit_369e1e94 reference_sample = d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee, os = windows, severity = x86, creation_date = 2022-07-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Lockbit, fingerprint = 9cf4c112c0ee708ae64052926681e8351f1ccefeb558c41e875dbd9e4bdcb5f2, id = 369e1e94-3fbb-4828-bb78-89d26e008105, last_modified = 2022-07-18
                Source: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Lockbit_369e1e94 reference_sample = d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee, os = windows, severity = x86, creation_date = 2022-07-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Lockbit, fingerprint = 9cf4c112c0ee708ae64052926681e8351f1ccefeb558c41e875dbd9e4bdcb5f2, id = 369e1e94-3fbb-4828-bb78-89d26e008105, last_modified = 2022-07-18
                Source: 00000000.00000000.2003658828.0000000000931000.00000020.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Ransomware_Lockbit_369e1e94 reference_sample = d61af007f6c792b8fb6c677143b7d0e2533394e28c50737588e40da475c040ee, os = windows, severity = x86, creation_date = 2022-07-05, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Ransomware.Lockbit, fingerprint = 9cf4c112c0ee708ae64052926681e8351f1ccefeb558c41e875dbd9e4bdcb5f2, id = 369e1e94-3fbb-4828-bb78-89d26e008105, last_modified = 2022-07-18
                Source: classification engineClassification label: mal100.rans.phis.spyw.evad.winEXE@9/1690@0/0
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeMutant created: \Sessions\1\BaseNamedObjects\Global\059e209281ada150c0df4a044869e46c
                Source: C:\ProgramData\2172.tmpMutant created: \Sessions\1\BaseNamedObjects\Global\{649F4E29-16CB-DD42-8922-9FFF0592856B}
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5604:120:WilError_03
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: Document.doc.scr.exeVirustotal: Detection: 77%
                Source: unknownProcess created: C:\Users\user\Desktop\Document.doc.scr.exe "C:\Users\user\Desktop\Document.doc.scr.exe"
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
                Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE /insertdoc "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\{EA82EC72-B970-44A4-8C1B-42CD300B85FB}.xps" 133584884697420000
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess created: C:\ProgramData\2172.tmp "C:\ProgramData\2172.tmp"
                Source: C:\ProgramData\2172.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess created: C:\ProgramData\2172.tmp "C:\ProgramData\2172.tmp"Jump to behavior
                Source: C:\ProgramData\2172.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: wtsapi32.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: rstrtmgr.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: netapi32.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: wkscli.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: samcli.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: logoncli.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: activeds.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: adsldpc.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: wsock32.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: mpr.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: gpedit.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: dssec.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: dsuiext.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: framedynos.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: authz.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: dsrole.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: ntdsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: wbemcomn.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: ntmarta.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: adsldp.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: sxs.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: mscms.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: coloradapterclient.dllJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeSection loaded: textshaping.dllJump to behavior
                Source: C:\ProgramData\2172.tmpSection loaded: apphelp.dll
                Source: C:\ProgramData\2172.tmpSection loaded: rstrtmgr.dll
                Source: C:\ProgramData\2172.tmpSection loaded: ncrypt.dll
                Source: C:\ProgramData\2172.tmpSection loaded: ntasn1.dll
                Source: C:\ProgramData\2172.tmpSection loaded: windows.storage.dll
                Source: C:\ProgramData\2172.tmpSection loaded: wldp.dll
                Source: C:\ProgramData\2172.tmpSection loaded: kernel.appcore.dll
                Source: C:\ProgramData\2172.tmpSection loaded: uxtheme.dll
                Source: C:\ProgramData\2172.tmpSection loaded: propsys.dll
                Source: C:\ProgramData\2172.tmpSection loaded: profapi.dll
                Source: C:\ProgramData\2172.tmpSection loaded: edputil.dll
                Source: C:\ProgramData\2172.tmpSection loaded: urlmon.dll
                Source: C:\ProgramData\2172.tmpSection loaded: iertutil.dll
                Source: C:\ProgramData\2172.tmpSection loaded: srvcli.dll
                Source: C:\ProgramData\2172.tmpSection loaded: netutils.dll
                Source: C:\ProgramData\2172.tmpSection loaded: windows.staterepositoryps.dll
                Source: C:\ProgramData\2172.tmpSection loaded: sspicli.dll
                Source: C:\ProgramData\2172.tmpSection loaded: wintypes.dll
                Source: C:\ProgramData\2172.tmpSection loaded: appresolver.dll
                Source: C:\ProgramData\2172.tmpSection loaded: bcp47langs.dll
                Source: C:\ProgramData\2172.tmpSection loaded: slc.dll
                Source: C:\ProgramData\2172.tmpSection loaded: userenv.dll
                Source: C:\ProgramData\2172.tmpSection loaded: sppc.dll
                Source: C:\ProgramData\2172.tmpSection loaded: onecorecommonproxystub.dll
                Source: C:\ProgramData\2172.tmpSection loaded: onecoreuapcommonproxystub.dll
                Source: C:\Users\user\Desktop\Document.doc.scr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CB8555CC-9128-11D1-AD9B-00C04FD8FDFF}\InprocServer32Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.iniJump to behavior
                Source: Window RecorderWindow detected: More than 3 window changes detected
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common
                Source: Document.doc.scr.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: Document.doc.scr.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\*6 source: Document.doc.scr.exe, 00000000.00000003.2057742422.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2062343931.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2059377065.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058777627.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058937804.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb source: Document.doc.scr.exe, 00000000.00000003.2258783246.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2276164348.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2255923512.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2107881841.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2261471485.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2076076908.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2111760133.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103731468.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2105203218.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2106190276.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2092103152.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2116474466.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2119600876.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103049713.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090960096.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090386296.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2369872444.0000000001055000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\*WI source: Document.doc.scr.exe, 00000000.00000003.2076076908.0000000001055000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: Document.doc.scr.exe, 00000000.00000003.2057742422.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2062343931.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2059377065.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2073299919.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058777627.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2075467271.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2075677088.000000000107D000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058937804.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: WINLOA~1.PDBwinload_prod.pdb source: Document.doc.scr.exe, 00000000.00000003.2053393457.0000000001067000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.Qs2QSInbk source: Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \\?\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdbSt source: Document.doc.scr.exe, 00000000.00000003.2258783246.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2276164348.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2255923512.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2107881841.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2261471485.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2076076908.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2111760133.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103731468.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2105203218.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2106190276.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2092103152.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2116474466.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2119600876.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2465988864.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103049713.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090960096.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2090386296.0000000001055000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2369872444.0000000001055000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\download.error.Qs2QSInbk source: Document.doc.scr.exe, 00000000.00000003.2066471035.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2068848310.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2053996337.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2069805491.0000000001076000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Qs2QSInbk.README.txtu source: Document.doc.scr.exe, 00000000.00000003.2053275478.000000000107E000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \Device\HarddiskVolume3\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\ownload.errort source: Document.doc.scr.exe, 00000000.00000003.2053996337.0000000001076000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \\?\C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831 source: Document.doc.scr.exe, 00000000.00000003.2057742422.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2062343931.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2059377065.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058777627.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2057151278.000000000107E000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2058937804.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056689891.000000000107B000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.Qs2QSInbk> source: Document.doc.scr.exe, 00000000.00000003.2053338835.0000000001117000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: \??\C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\download.error.Qs2QSInbk~ source: Document.doc.scr.exe, 00000000.00000003.2053338835.0000000001117000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2068688836.0000000001137000.00000004.00000020.00020000.00000000.sdmp
                Source: Document.doc.scr.exeStatic PE information: real checksum: 0x2554d should be: 0x3ad8b
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009335D3 push 0000006Ah; retf 0_2_00933644
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009335D5 push 0000006Ah; retf 0_2_00933644
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009361EE push esp; retf 0_2_009361F6
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093356B push 0000006Ah; retf 0_2_00933644
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Videos\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Searches\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Saved Games\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Recent\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Pictures\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Pictures\Saved Pictures\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Pictures\Camera Roll\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\OneDrive\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Music\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Links\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Favorites\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Favorites\Links\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Downloads\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\ZGGKNSUKOP\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\UNKRLCVOHV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\QFAPOWPAFG\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\NYMMPCEIMA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\NVWZAPQSQL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\LHEPQPGEWF\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\JDDHMPCDUJ\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\HMPPSXQPQV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\GRXZDKKVDB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\EOWRVPQCCS\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\EFOYFBOLXA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Documents\BJZFPPWAPT\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\ZGGKNSUKOP\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\UNKRLCVOHV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\QFAPOWPAFG\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\NYMMPCEIMA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\NVWZAPQSQL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\LHEPQPGEWF\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\JDDHMPCDUJ\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\HMPPSXQPQV\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\GRXZDKKVDB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\EOWRVPQCCS\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\EFOYFBOLXA\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Desktop\BJZFPPWAPT\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\Contacts\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yiaxs5ej.default\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\to-be-removed\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\temporary\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\security_state\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\minidumps\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\tmp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\db\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\bookmarkbackups\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Mozilla\Extensions\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\6d9d9777-7ded-4768-8191-9a707d72b009\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\61f56613-c62c-4b17-84dd-62b60d5776aa\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Sonar\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Sonar\SonarCC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\RTTransfer\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\LogTransport2CC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\LogTransport2\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Linguistics\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Headlights\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Flash Player\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\CRLogs\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\CRLogs\crashlogs\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\Preflight Acrobat Continuous\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\JSCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Forms\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Collab\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Linguistics\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cookie\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\VideoDecodeStats\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\shared_proto_db\metadata\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\blob_storage\dd432c4a-ba38-4070-9985-ed1b3bea85dc\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\assets\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\Acrobat\DesktopNotification\NotificationsDB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\VirtualStore\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\winload_prod.pdb\01AB9056EA9380F71644C4339E3FA1AC2\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Symbols\ntkrnlmp.pdb\68A17FAF3012B7846079AEECDBE0A5831\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\msedge_url_fetcher_5172_761252224\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\msedge_url_fetcher_5172_1791500899\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\msedge_url_fetcher_2640_817343797\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\mozilla-temp-files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Low\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_995017740\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_778675694\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_736602331\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_649288342\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_339006160\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_27162369\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1988346647\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1959985254\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1807723660\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1693012001\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1635976352\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1619438387\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1485273224\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1421574262\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1318414972\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1289371347\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1234978473\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1191663050\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\edge_BITS_6440_1090636871\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrocef_low\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Acrobat\DC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\SolidDocuments\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\SolidDocuments\Acrobat\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\SettingsContainer\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Microsoft.WindowsAlarms\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Licenses\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Fonts\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\PlaceholderTileLogoFolder\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\PeerDistRepub\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\DiagOutputDir\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\AC\BackgroundTransferApi\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\SystemAppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\Settings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\RoamingState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\Flighting\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\DeviceSearchCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{99fff775-938d-4e2c-9c06-5d56107a5383}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2737c7bb-35fb-4b44-baf9-033ca587595d}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{4e763a36-90d3-4d6c-9949-dd01f7e5d23f}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ea91a05a-d98f-4429-81a9-272df0335447}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{de0f148a-c476-467a-b7a3-14b0bb463140}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{c23bcd39-6fcf-4e41-add1-0231129b23be}\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalCache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\CacheStorage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile created: C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Temp\Qs2QSInbk.README.txtJump to behavior

                Hooking and other Techniques for Hiding and Protection

                barindex
                Source: C:\ProgramData\2172.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL
                Source: C:\ProgramData\2172.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL
                Source: Possible double extension: doc.scrStatic PE information: Document.doc.scr.exe
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009391C8 RegCreateKeyExW,RegEnumKeyW,RegCreateKeyExW,RegSetValueExW,RegSetValueExW,OpenEventLogW,ClearEventLogW,RegCreateKeyExW,RegEnumKeyW,OpenEventLogW,ClearEventLogW,0_2_009391C8
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOXJump to behavior
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXEProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX
                Source: C:\ProgramData\2172.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX

                Malware Analysis System Evasion

                barindex
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009310BC 0_2_009310BC
                Source: C:\ProgramData\2172.tmpCode function: 8_2_00401E28 8_2_00401E28
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009310BC rdtsc 0_2_009310BC
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093A094 FindFirstFileExW,FindClose,0_2_0093A094
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009374BC FindFirstFileExW,FindNextFileW,0_2_009374BC
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00935C24 FindFirstFileW,FindClose,FindNextFileW,FindClose,0_2_00935C24
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00937590 FindFirstFileExW,FindClose,0_2_00937590
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093766C FindFirstFileExW,GetFileAttributesW,FindNextFileW,0_2_0093766C
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093F308 GetFileAttributesW,SetThreadPriority,FindFirstFileExW,FindNextFileW,FindClose,0_2_0093F308
                Source: C:\ProgramData\2172.tmpCode function: 8_2_0040227C FindFirstFileExW,8_2_0040227C
                Source: C:\ProgramData\2172.tmpCode function: 8_2_0040152C FindFirstFileExW,FindClose,FindNextFileW,FindClose,8_2_0040152C
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_0093A470 GetLogicalDriveStringsW,0_2_0093A470
                Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\Diagnostics\EXCEL\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Jump to behavior
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware workstation 15 player*|vmplayer6438
                Source: Document.doc.scr.exe, 00000000.00000003.2127207462.00000000010B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|turn windows features on or off*|hyper-v:wux:hyper-v4937
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware horizon client*|vm ware8394
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware vsphere client*|vspe6388
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware horizon client*|vdi3894
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|*|qemu10642
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware horizon client*|view5503
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware workstation 12 player*|vmpl5459
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|*|vmware6886
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware vsphere client*|vcenter5038
                Source: Document.doc.scr.exe, 00000000.00000003.2126886793.00000000010E2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *|vmware horizon client*|vmare7220
                Source: Document.doc.scr.exe, 00000000.00000003.2304586597.000000000106B000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess information queried: ProcessInformation

                Anti Debugging

                barindex
                Source: C:\Users\user\Desktop\Document.doc.scr.exeThread information set: HideFromDebuggerJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeThread information set: HideFromDebuggerJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeThread information set: HideFromDebuggerJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeThread information set: HideFromDebuggerJump to behavior
                Source: C:\ProgramData\2172.tmpThread information set: HideFromDebugger
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009310BC rdtsc 0_2_009310BC
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_00935A20 LdrLoadDll,0_2_00935A20
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess token adjusted: Debug
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess token adjusted: Debug
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess token adjusted: Debug

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: C:\Users\user\Desktop\Document.doc.scr.exeMemory written: C:\ProgramData\2172.tmp base: 401000Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeProcess created: C:\ProgramData\2172.tmp "C:\ProgramData\2172.tmp"Jump to behavior
                Source: C:\ProgramData\2172.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009310BC cpuid 0_2_009310BC
                Source: C:\ProgramData\2172.tmpCode function: EntryPoint,ExitProcess,GetModuleHandleW,GetCommandLineW,GetModuleHandleA,GetCommandLineW,GetLocaleInfoW,GetLastError,FreeLibrary,FreeLibrary,GetProcAddress,CreateWindowExW,DefWindowProcW,GetWindowTextW,LoadMenuW,LoadMenuW,DefWindowProcW,SetTextColor,GetTextCharset,TextOutW,SetTextColor,GetTextColor,CreateFontW,GetTextColor,CreateDIBitmap,SelectObject,GetTextColor,CreateFontW,8_2_00403983
                Source: C:\Users\user\Desktop\Document.doc.scr.exeCode function: 0_2_009404B4 GetTempFileNameW,CreateFileW,WriteFile,CreateProcessW,NtQueryInformationProcess,NtReadVirtualMemory,NtProtectVirtualMemory,NtWriteVirtualMemory,CreateNamedPipeW,ResumeThread,ConnectNamedPipe,0_2_009404B4

                Lowering of HIPS / PFW / Operating System Security Settings

                barindex
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yiaxs5ej.default\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\to-be-removed\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\temporary\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\security_state\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\minidumps\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\tmp\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\db\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\crashes\events\Qs2QSInbk.README.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile written: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\bookmarkbackups\Qs2QSInbk.README.txtJump to behavior

                Stealing of Sensitive Information

                barindex
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\search.json.mozlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cert9.dbJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835647.a83301c6-790b-49f3-adc7-55a855f7fe79.main.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\containers.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.db.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835635.a669692a-f9c9-42c0-a803-7b87d3ff5834.new-profile.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\a83301c6-790b-49f3-adc7-55a855f7fe79.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\b8f053a5-de16-4a2c-8120-1ab4aadd63e8Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\background-update.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addons.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\.metadata-v2.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835635.a669692a-f9c9-42c0-a803-7b87d3ff5834.new-profile.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840727.01c0ecdb-8e59-4210-95f1-0fd0406e84ad.event.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\search.json.mozlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\AlternateServices.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840708.3c7034d6-bc52-43bb-9a23-5da34ee205e0.health.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\previous.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\content-prefs.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840748.a8c1f564-c2e2-4ef8-a85f-52a56488f193.main.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\previous.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\protections.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\handlers.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835643.9a3c31ca-35e4-421e-91e1-5f7b9bd27492.event.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\3c7034d6-bc52-43bb-9a23-5da34ee205e0Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840727.01c0ecdb-8e59-4210-95f1-0fd0406e84ad.event.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835647.a83301c6-790b-49f3-adc7-55a855f7fe79.main.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\ls-archive.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\compatibility.ini.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\SiteSecurityServiceState.txt.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\content-prefs.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\eventsJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\targeting.snapshot.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\session-state.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yiaxs5ej.default\times.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\a83301c6-790b-49f3-adc7-55a855f7fe79Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cert9.db.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\.metadata-v2Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\43bb9a55-74a2-452e-8233-6899a7f737b0.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionCheckpoints.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addonStartup.json.lz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\ls-archive.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\permissions.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.jsJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\AlternateServices.txt.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\xulstore.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840727.86be03dd-6b03-42f5-89cd-4606f43d25ad.health.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\events.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\ae04dde8-69a1-49f8-95f1-d533ed587ff6.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\targeting.snapshot.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\containers.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.js.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\handlers.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\extension-preferences.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\7755ad51-2370-4623-9d21-15c89f2143db.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\pkcs11.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\times.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\43bb9a55-74a2-452e-8233-6899a7f737b0Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\extension-preferences.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835649.b06d08be-79e8-4bfe-b6aa-988ea3d35cbd.first-shutdown.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\compatibility.iniJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\state.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835649.b06d08be-79e8-4bfe-b6aa-988ea3d35cbd.first-shutdown.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\shield-preference-experiments.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840748.a8c1f564-c2e2-4ef8-a85f-52a56488f193.main.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\session-state.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\times.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\yiaxs5ej.default\times.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\7755ad51-2370-4623-9d21-15c89f2143dbJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426835643.9a3c31ca-35e4-421e-91e1-5f7b9bd27492.event.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840727.86be03dd-6b03-42f5-89cd-4606f43d25ad.health.jsonlz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\state.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\ae04dde8-69a1-49f8-95f1-d533ed587ff6Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\xulstore.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\pending_pings\b8f053a5-de16-4a2c-8120-1ab4aadd63e8.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addonStartup.json.lz4Jump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\addons.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionCheckpoints.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\permissions.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\protections.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\webappsstore.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\ExperimentStoreData.json.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\shield-preference-experiments.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\favicons.sqlite.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\archived\2023-10\1696426840708.3c7034d6-bc52-43bb-9a23-5da34ee205e0.health.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\pkcs11.txt.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqliteJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\datareporting\glean\events\background-updateJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\sessionstore.jsonlz4.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.dbJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\ExperimentStoreData.jsonJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm.Qs2QSInbkJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\SiteSecurityServiceState.txtJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shmJump to behavior
                Source: C:\Users\user\Desktop\Document.doc.scr.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\saved-telemetry-pings\3c7034d6-bc52-43bb-9a23-5da34ee205e0.Qs2QSInbkJump to behavior
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
                DLL Side-Loading
                112
                Process Injection
                111
                Masquerading
                1
                OS Credential Dumping
                211
                Security Software Discovery
                Remote Services1
                Archive Collected Data
                1
                Encrypted Channel
                Exfiltration Over Other Network Medium1
                Data Encrypted for Impact
                CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                DLL Side-Loading
                11
                Virtualization/Sandbox Evasion
                LSASS Memory1
                Process Discovery
                Remote Desktop Protocol1
                Browser Session Hijacking
                1
                Proxy
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)112
                Process Injection
                Security Account Manager11
                Virtualization/Sandbox Evasion
                SMB/Windows Admin Shares1
                Data from Local System
                SteganographyAutomated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
                Obfuscated Files or Information
                NTDS5
                File and Directory Discovery
                Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Indicator Removal
                LSA Secrets122
                System Information Discovery
                SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                DLL Side-Loading
                Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                File Deletion
                DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 signatures2 2 Behavior Graph ID: 1431429 Sample: Document.doc.scr.exe Startdate: 25/04/2024 Architecture: WINDOWS Score: 100 40 Multi AV Scanner detection for domain / URL 2->40 42 Malicious sample detected (through community Yara rule) 2->42 44 Antivirus detection for URL or domain 2->44 46 9 other signatures 2->46 8 Document.doc.scr.exe 32 1002 2->8         started        12 ONENOTE.EXE 2->12         started        process3 file4 24 Microsoft_Windows_...aPlayer32.Qs2QSInbk, COM 8->24 dropped 26 Microsoft_Internet...r_Default.Qs2QSInbk, COM 8->26 dropped 28 D0F48A0632B6C45179...961F06A6F.Qs2QSInbk, COM 8->28 dropped 30 223 other files (221 malicious) 8->30 dropped 48 Found potential ransomware demand text 8->48 50 Found Tor onion address 8->50 52 Contains functionality to detect hardware virtualization (CPUID execution measurement) 8->52 54 7 other signatures 8->54 14 2172.tmp 8->14         started        18 splwow64.exe 8->18         started        signatures5 process6 file7 32 C:\Users\user\...\ZZZZZZZZZZZZZZZZZZZZ (copy), data 14->32 dropped 34 C:\Users\user\...\YYYYYYYYYYYYYYYYYYYY (copy), data 14->34 dropped 36 C:\Users\user\...\XXXXXXXXXXXXXXXXXXXX (copy), data 14->36 dropped 38 24 other malicious files 14->38 dropped 56 Contains functionality to detect hardware virtualization (CPUID execution measurement) 14->56 58 Writes many files with high entropy 14->58 60 Hides threads from debuggers 14->60 62 Deletes itself after installation 14->62 20 cmd.exe 14->20         started        signatures8 process9 process10 22 conhost.exe 20->22         started       

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                Document.doc.scr.exe77%VirustotalBrowse
                Document.doc.scr.exe100%AviraBDS/ZeroAccess.Gen7
                Document.doc.scr.exe100%Joe Sandbox ML
                No Antivirus matches
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                https://www.ebay.co.uk/0%URL Reputationsafe
                https://bugzilla.mo0%URL Reputationsafe
                http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionk0%Avira URL Cloudsafe
                https://tox.chat/0%Avira URL Cloudsafe
                http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.oniong0%Avira URL Cloudsafe
                http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionic0%Avira URL Cloudsafe
                http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion100%Avira URL Cloudmalware
                http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionic0%Avira URL Cloudsafe
                http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onional0%Avira URL Cloudsafe
                http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl20%Avira URL Cloudsafe
                http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionin0%Avira URL Cloudsafe
                http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion13%VirustotalBrowse
                http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionin0%Avira URL Cloudsafe
                http://lockbitapt.uz100%Avira URL Cloudmalware
                http://lockbitsupp.uz100%Avira URL Cloudmalware
                http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion00%Avira URL Cloudsafe
                http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionc~0%Avira URL Cloudsafe
                https://tox.chat/0%VirustotalBrowse
                https://tox.::0%Avira URL Cloudsafe
                http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionedA0%Avira URL Cloudsafe
                http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion100%Avira URL Cloudmalware
                http://lockbitapt.uz12%VirustotalBrowse
                https://tox.:0%Avira URL Cloudsafe
                http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion100%Avira URL Cloudmalware
                http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl0%Avira URL Cloudsafe
                http://lockbitsupp.uz9%VirustotalBrowse
                http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion9%VirustotalBrowse
                http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion9%VirustotalBrowse
                No contacted domains info
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.ebay.co.uk/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                https://tox.chat/Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2056293087.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2061132357.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2065780379.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2111760133.0000000001049000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103731468.0000000001047000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2109489328.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2258114624.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2106881738.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2261471485.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2257598840.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2260455472.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2104352096.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2074831153.0000000001093000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2110837373.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2103049713.0000000001012000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2107881841.0000000001014000.00000004.00000020.00020000.00000000.sdmp, Qs2QSInbk.README.txt361.0.dr, Qs2QSInbk.README.txt180.0.dr, Qs2QSInbk.README.txt445.0.dr, Qs2QSInbk.README.txt409.0.drtrue
                • 0%, Virustotal, Browse
                • Avira URL Cloud: safe
                unknown
                https://login.windows.netApp1714014880372801600_29CC7398-2A01-4DC6-A22E-768619CAA88A.log.7.drfalse
                  high
                  http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionicDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: safe
                  unknown
                  http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionDocument.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmptrue
                  • 13%, Virustotal, Browse
                  • Avira URL Cloud: malware
                  unknown
                  http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionkDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: safe
                  unknown
                  http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.oniongDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: safe
                  unknown
                  https://www.amazon.com/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://www.ctrip.com/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionicDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: safe
                      unknown
                      http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionalDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: safe
                      unknown
                      http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionl2Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                      • Avira URL Cloud: safe
                      unknown
                      https://twitter.com/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onioninDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                        • Avira URL Cloud: safe
                        unknown
                        https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-brDocument.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpfalse
                          high
                          https://www.youtube.com/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onioninDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                            • Avira URL Cloud: safe
                            unknown
                            http://lockbitapt.uzDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000001045000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpfalse
                            • 12%, Virustotal, Browse
                            • Avira URL Cloud: malware
                            unknown
                            http://lockbitsupp.uzDocument.doc.scr.exe, 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmpfalse
                            • 9%, Virustotal, Browse
                            • Avira URL Cloud: malware
                            unknown
                            http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion0Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                            • Avira URL Cloud: safe
                            unknown
                            http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionc~Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                            • Avira URL Cloud: safe
                            low
                            https://bugzilla.moDocument.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            https://tox.::Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            low
                            http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionedADocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                            • Avira URL Cloud: safe
                            unknown
                            http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmptrue
                            • 9%, Virustotal, Browse
                            • Avira URL Cloud: malware
                            unknown
                            https://support.mozilla.org/products/firefoxgro.allizom.troppus.GVegJq3nFfBLDocument.doc.scr.exe, 00000000.00000003.2027366204.000000000110D000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://www.google.com/complete/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                https://support.mozilla.orgDocument.doc.scr.exe, 00000000.00000003.2027366204.0000000001105000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2027366204.00000000010FD000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://tox.:Document.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://www.google.com/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Document.doc.scr.exe, 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmptrue
                                    • 9%, Virustotal, Browse
                                    • Avira URL Cloud: malware
                                    unknown
                                    https://content-signature-2.cdn.mozilla.net/chains/remote-settings.content-signature.mozilla.org-202Document.doc.scr.exe, 00000000.00000003.2244020288.0000000001163000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionlDocument.doc.scr.exe, 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmptrue
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://www.baidu.com/Document.doc.scr.exe, 00000000.00000003.2031230612.00000000010D8000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        No contacted IP infos
                                        Joe Sandbox version:40.0.0 Tourmaline
                                        Analysis ID:1431429
                                        Start date and time:2024-04-25 05:13:06 +02:00
                                        Joe Sandbox product:CloudBasic
                                        Overall analysis duration:0h 7m 20s
                                        Hypervisor based Inspection enabled:false
                                        Report type:full
                                        Cookbook file name:default.jbs
                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                        Number of analysed new started processes analysed:18
                                        Number of new started drivers analysed:0
                                        Number of existing processes analysed:0
                                        Number of existing drivers analysed:0
                                        Number of injected processes analysed:0
                                        Technologies:
                                        • HCA enabled
                                        • EGA enabled
                                        • AMSI enabled
                                        Analysis Mode:default
                                        Analysis stop reason:Timeout
                                        Sample name:Document.doc.scr.exe
                                        Detection:MAL
                                        Classification:mal100.rans.phis.spyw.evad.winEXE@9/1690@0/0
                                        EGA Information:
                                        • Successful, ratio: 100%
                                        HCA Information:
                                        • Successful, ratio: 100%
                                        • Number of executed functions: 84
                                        • Number of non-executed functions: 6
                                        Cookbook Comments:
                                        • Found application associated with file extension: .exe
                                        • Exclude process from analysis (whitelisted): dllhost.exe, RuntimeBroker.exe, printfilterpipelinesvc.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                                        • Excluded IPs from analysis (whitelisted): 52.109.20.38, 52.113.194.132, 52.109.8.36, 52.182.143.214
                                        • Excluded domains from analysis (whitelisted): ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, slscr.update.microsoft.com, prod.configsvc1.live.com.akadns.net, scus-azsc-config.officeapps.live.com, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, cus-azsc-000.roaming.officeapps.live.com, fe3cr.delivery.mp.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, us1.roaming1.live.com.akadns.net, osiprod-cus-buff-azsc-000.centralus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, s-0005.s-msedge.net, config.officeapps.live.com, us.configsvc1.live.com.akadns.net, onedscolprdcus19.centralus.cloudapp.azure.com, officeclient.microsoft.com, ecs.office.trafficmanager.net
                                        • Not all processes where analyzed, report is missing behavior information
                                        • Report size exceeded maximum capacity and may have missing behavior information.
                                        • Report size getting too big, too many NtCreateFile calls found.
                                        • Report size getting too big, too many NtCreateKey calls found.
                                        • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                        • Report size getting too big, too many NtEnumerateKey calls found.
                                        • Report size getting too big, too many NtOpenFile calls found.
                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                        • Report size getting too big, too many NtQueryAttributesFile calls found.
                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                        • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                        • Report size getting too big, too many NtReadFile calls found.
                                        • Report size getting too big, too many NtSetInformationFile calls found.
                                        • Report size getting too big, too many NtWriteFile calls found.
                                        TimeTypeDescription
                                        05:14:29API Interceptor90x Sleep call for process: splwow64.exe modified
                                        No context
                                        No context
                                        No context
                                        No context
                                        No context
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Reputation:low
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.6215787088613025
                                        Encrypted:false
                                        SSDEEP:3:phSDZMXXXmVro1iBiMzKSCHWvg6oKpxjn:qDyXTnTSCHB30jn
                                        MD5:158516C11877B93342E380A45B6B6C3A
                                        SHA1:67A1D3B1D89D0A72FA31EA98419CC339892A882A
                                        SHA-256:9CD2407F08C8F612B49FDB2382B5D32267F1128ADDEA1DB30E3840B34C9258EA
                                        SHA-512:37278F7485D5D96935AAC7C9504C111081AEDD421E9AC14A6169EFDE364F0619A2B0CCA0391DA875BE4CDDA70844531CF44E23B22B3C4B5158F3233669CF50C5
                                        Malicious:false
                                        Preview:.2.$(@7-b.YOG.=.8.i..3.Ep.Go.U..z.......>...VKqu_.7......->...$.;V..V.{wk.x."........].3....<.d|..c..h....dG%...m.5..?...p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.485844018905282
                                        Encrypted:false
                                        SSDEEP:3:hqZb8Xua3ByoQ4JA4/gbVoaXcVnlJw3fRXpgRe:h8bc39Qq/LJcRZH
                                        MD5:C6B54478BA20D0E8CF77C993D38BD715
                                        SHA1:3B91C9B9355B61FFE18A892AD72FE21F72DC9534
                                        SHA-256:7BDCB63E72610C2E889D40C2017AC69457CD69A4B6BC83E748A074D17A80277A
                                        SHA-512:C5CE822355A09B36283128E4D40D85978C3E46269FF74CC2B447116378511B18C581FC466D2839CF8EE479590896C08174695A80BC402BE4E42FA6D01E28297D
                                        Malicious:false
                                        Preview:...C(.....^kI..;,....~.eL]C1.P^..#..s.Y....3u...$.....f4..'.2.........;...o})...w7.^.uF..}...;..0..YQ1u..z..4i..l..N.t(O...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.577118728291463
                                        Encrypted:false
                                        SSDEEP:3:Pf2kUz4xKM5VbddppqPWxfEbSSi/9Bs1+R5m:PfBBKuVE+xfshAssR5m
                                        MD5:73982F8CB32BF9B3EED6ED6B2B785317
                                        SHA1:368C668E23BACD03994DF3CF513032B2E08197B0
                                        SHA-256:7C16490123B9EC769BA48339D4B233C0B0A3AD31C235F53AA3973E728ABF003F
                                        SHA-512:C8F93E322E0528D7BA24E294C6F70498F1238AE5FC2959D462F5A7DF3B220A2917C07C06BBC2587097B98D5E4198A720123DC4674CFC9C321740453442EDA222
                                        Malicious:false
                                        Preview:....Rt*.,..rA..k7.]r.+....Qo.......T....Bh..}.uv..]x)pn....j0...O{`......pGt.+z.y..D..Ow..Q..asf......J${..P...Z..i.:....W*:<}
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):129
                                        Entropy (8bit):6.611926673994356
                                        Encrypted:false
                                        SSDEEP:3:F2nHw1ScYwanM3tY0KjTzogc0D1NXHjz8:wHws9waMdY0KP7c61NX8
                                        MD5:9C34831904C0570D903EDD926D9C2950
                                        SHA1:129DB2AA96A87BC14100B9EA569DB2B74DF3331A
                                        SHA-256:ED351338FB4422E14D5F134A7F5BC9EB7FE9729291F552E8874F506C58DEE70F
                                        SHA-512:700856911E676714FE241C9CCB878D4B143F0B6210DA0156140B7C16838D6F70CBC923F1F9F99A163AD3929BEF58EFD2882ADCD5E2A86516C7DDB5A2F69DC88E
                                        Malicious:false
                                        Preview:..N..7(.m..7....;.h...,.`..-.e_.....2.fp"......aV.A..J.k.......2%.-... l........../9........P..].....t.x.g[..&...{.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
                                        Category:dropped
                                        Size (bytes):15086
                                        Entropy (8bit):4.262047636092361
                                        Encrypted:false
                                        SSDEEP:192:jpBaAlHSa2vU9G/8MMBD7O1lXFMB8VMJP7:jpjmkMYD7IFMRx7
                                        MD5:88D9337C4C9CFE2D9AFF8A2C718EC76B
                                        SHA1:CE9F87183A1148816A1F777BA60A08EF5CA0D203
                                        SHA-256:95E059EF72686460884B9AEA5C292C22917F75D56FE737D43BE440F82034F438
                                        SHA-512:ABAFEA8CA4E85F47BEFB5AA3EFEE9EEE699EA87786FAFF39EE712AE498438D19A06BB31289643B620CB8203555EA4E2B546EF2F10D3F0087733BC0CEACCBEAFD
                                        Malicious:false
                                        Preview:......00.... ..%..6... .... ......%........ .h....6..(...0...`..... ......%............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):239
                                        Entropy (8bit):7.068929203224361
                                        Encrypted:false
                                        SSDEEP:6:XrOOhy3Z7tHneAWR7DVhTmBJp78frSJVgxGnFY22w20FCnBR:XrZyxNeH7JhTQp7aE6wKBR
                                        MD5:CAE47A96C62552102608291829690D73
                                        SHA1:4F2B4A1DAA431AF3796B42A4D443488E00BBCD9C
                                        SHA-256:FBAA87D50E512AF2BF23EB4E8B1EAF9127FBAFE5E4959BA0D649444B5CE776B7
                                        SHA-512:6302E61AAE2B75AC855146313219037ADC0DEC39553780ADB7F7E439DCD7B970EEABF3A689A4E184329F39B6C72AC336A2DA9DF793B4D210E8C141D73B67220E
                                        Malicious:false
                                        Preview:....0..R..l)....8.aG.......".bZ+..}....?......`.4W.....|.....;..t>...<.u0' ...M..6.V......l....P.a......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.173599636842755
                                        Encrypted:false
                                        SSDEEP:6:uiFceEcB2cTJW8s5n53cbgNTAp78frSJVgxGnFY22w20FCnBR:uiV1B2WWV5nGbgWp7aE6wKBR
                                        MD5:75E84F87DD14005531B292014DB0D63A
                                        SHA1:A5D6D9BD8B4718F62E91E620E1DEC271F9D50501
                                        SHA-256:A8B3F5F10FFE989AAE5511AC692962BA0AEB7C12DCF797E141BB484357CD078D
                                        SHA-512:DA1782B15DAA57C20A1612336F239B3022C3C87A63C3CF9A5AA4DCDCD26288789314AFB8EE815E4825F0AD9D74D80D74B60F5AB29D93E2B6C0BE97CF7B6C25D8
                                        Malicious:false
                                        Preview:...C.=O..!.M}..2g.Z). .m....G........".aY+..~..a.l3....e....Sh.\..'V..D..G...n..L.`.n.'..c...0K"^d...)..`.{8}.b......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):458
                                        Entropy (8bit):7.567478147321674
                                        Encrypted:false
                                        SSDEEP:12:lFDLqYKg608u4dCTDEFNwTvdsdU6c+U0Up7aE6wKBR:vHlKxCTDEcTv6ddUp7aOc
                                        MD5:17A338B048AC245D7F05E79FC33CF9AF
                                        SHA1:B0203F0C6C79F19D7EC8FFF1FFDD6A20A00644CB
                                        SHA-256:D21E4BF56E49DC1EBD85EBC95689E2A53B9F9BAB57E7328B8AA9D833A6560207
                                        SHA-512:7CA6BA4C0EF08015375B02270706088DEADB362F7EA1A04CD2A166875E2B66B1B5FD03233EBAA8F7E4A45B60A4BE4EAAD821AE2F59A16CEBDA19EFE6D11BA776
                                        Malicious:false
                                        Preview:Dc.S^R....j@.>k5g...|....r7..9H.....!m...g..$..$k.]..n+.^...,H....!tW....#&}..TG....gso..4f.G.i......Z.OmG.R-(.[7w...~.....F.G3..dq..{.f...F.r.....w....G.3.T..9....T<./..fc.F].....p.[...l..g.t.._...72..:).......].AcW.s.a.)..g*th....@%.~........d..@.h.."t.o..#.[E.>..6.(N.&.R.9K!.l.?...dm.loB..pL.R.. k}......-.s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):466
                                        Entropy (8bit):7.48523912971331
                                        Encrypted:false
                                        SSDEEP:12:hYo77YBwZRAlGtefbxiClGHnlOgJk8p7aE6wKBR:B7OKRVefbxJMs8p7aOc
                                        MD5:C569A270DA64466468B2F1EF222FEC51
                                        SHA1:C78258589748977332A8899C1A8D61E41F6F6135
                                        SHA-256:F8F574D036DF89EDE05BF293DBBDC5BF8FB13BAD8616A5143A0046E902DC173C
                                        SHA-512:5D8AFE15541A40031402C0EC12FE54C8AB6D8A535D33615E133B18D7693895063981217D47AD41F45BB59E9D1E430C453D1C96DE41CC15D8F0B423AB5E95B380
                                        Malicious:false
                                        Preview:v..W..p..%.+....u.k..w@O.._...$E.IE.j.._.`....."..^..u.7h.ra..b.7......._&<...9..v6.q.".l4.gvYo.hE.......G..a....#.b.cH$o..8~..e...s........9...B`.9.c...ce...p.&|....5)..:......FU|\S.cSE....uA..S*Y.F.t.S...Ux"...8)........`Y9......R..)..c..aw.,........d......G....8.gv.q;......... .{f../..f.u@b...6TPT..~..A...p......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):420
                                        Entropy (8bit):7.476853712123778
                                        Encrypted:false
                                        SSDEEP:6:AnBEA60fVpNV1zrMyUu2p/bvwwfGYhAFumZ6t6yp78frSJVgxGnFY22w20FCnBR:A360jNV5r5M/vmZ6Jp7aE6wKBR
                                        MD5:87CF21B8B13F962DF44D35E13EA03C98
                                        SHA1:97F981BD464C76A088A86E2AEF029DDD5E301588
                                        SHA-256:DE9A45D3915BE3DAC9DBCC169D326A2F232BDB8133720C23DECC30E0ED63F78E
                                        SHA-512:9188B9EFF868D1BE2EB3BDEBBF51C59517EF9335A702391B8290E0EDFF918700F40F566C935EA90E540F312D3A6E1FF101DC858DA0AA8ABC811CBAE2B7A9B605
                                        Malicious:false
                                        Preview:......5...B1&4....9.t.&.{.a$..P....'GTF.!....y...j3.....n.}...<Hc#`.2..$..I.s.h...hb........=.f...hU....j.b....i...;..i......K.U.....u..6ym...3. ]..}...wT.H..f...G..y.?X.E?....8).......b@2....... 4a@+../..a%.,.......l.k..yL.^..?....."L^qzn..jaPV...y..`...N.\........ .?sYyy..h.l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):498
                                        Entropy (8bit):7.625699656131821
                                        Encrypted:false
                                        SSDEEP:12:69magZbQktsakgr4OXglTah++Ap7aE6wKBR:emaY3/t4OsRhp7aOc
                                        MD5:6EA0F5762CCD8E4C511724CAE4320FD2
                                        SHA1:9EE76D964E69BED987E60E187D12651C0DE35E7E
                                        SHA-256:005C162019A798FB7FEFE0040D11A8FFB731BE8DAD6E4AE3DE464C8CF5E65554
                                        SHA-512:9BA91FDEA9F4ECB0A4250E26B470DEF86E8B3F0F169DF981994FD15CCC1047A8A3D30069AF2040A66E5E8193724271E00E86CBCCBD8018C5CD4D5C402E02DD28
                                        Malicious:false
                                        Preview:m..h.m..~.X.cw-YZ.._...E-........Rj.6Q..C.K.3...e.?....D.7.x..&>.s.]r(yHFX......O...m..$..rq.g.P..b..2M..Fc....h{_7F.F........#.w..U.@4.;..."O.H..O..pV=...,..'...<.......V...vB...C5.h....T..9.....).../1.y..,..~`..(?8...........t.j.....6....L...$..d.......Y.F....)a%..,........g..@..6..(m.s..^.R.WM).....2..8......7>.J]iFr.\.{.@.7..c 7.D......r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):445
                                        Entropy (8bit):7.524384603527172
                                        Encrypted:false
                                        SSDEEP:12:P6jCAc/ZCxQRBmuewB+o5nHAkp7aE6wKBR:j5/hfdtHAkp7aOc
                                        MD5:BAAD88B75920DEBD096258EAE4F5004D
                                        SHA1:89C057BE2B73B4E0EAFDFEA591B3BD282BC2A55A
                                        SHA-256:C10ACC0312EC25FEBBD4BECB29113340654DEEEBEEA1C453E5878DA86231F454
                                        SHA-512:656EE451F3F78A2A523E33BF1EED71181ED9E5753F487B6F17DD4A53401BBB6AC3578981D8D4F5E6C560558AE6548B6910CB97EBA7521D4D5CA9034D6E375CF6
                                        Malicious:false
                                        Preview:....a..T.S....J.=.........E..A.$......K\.t.k>...... p/b_...j. .x?9...26.6.K.$|....B......"..0.o......me..?q.N_.1}.2....}mH..?...Rc4%l@.z...%2...`.(Y.X.6........Dj...>....F.k.?.........GK...n)......d5.........'.>Wo..}..a%..,........d...Brz..6.@.I..q........e..q....Qh....mN..nS..e].u.....%..)..R.`q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):442
                                        Entropy (8bit):7.495284264394765
                                        Encrypted:false
                                        SSDEEP:6:cBlG0COBvdPqwjpHWuH1q1r6CiTQxniw05aEsui7g5p78frSJVgxGnFY22w20FCn:CCOZdPqwBe++nlYsuiE5p7aE6wKBR
                                        MD5:552F170F62614EF50DB510F6AB585D51
                                        SHA1:82717556BBCEE4BFA9C4C05C1CB9D8DD305DD841
                                        SHA-256:5864096BFD5349A33404134E5822CFC4FCB33F8D7B5E286D065FF08EEE659AFB
                                        SHA-512:A4EDF84B9E593F3975B76181C8AC4D7C560DBAD3F85BB47E3646FDEC20BD429A0219D5C3C1CEED990E906A14207A1585F05713129345BE734554AD1151F6F4AF
                                        Malicious:false
                                        Preview:...E....ile.....",0..W/9...]...f.T.).d...P...h.D%J...&....Gw.....0b.g3g..}#{...o.....P.vZ....8.Y.>.&K-FG.U/..F...&.e...I..a.50S....g.z..vN8..y..-..A.."c._.....W.{.m*.1...D I.t...v....g..(&..m(N..=....9&7.....G)..c..aw.,........d.6IK.OY.P..p9P!.$UU...o.L..s.W.].]au...#"p.../..qi.qN....n...p......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):461
                                        Entropy (8bit):7.560352999105107
                                        Encrypted:false
                                        SSDEEP:12:X1aqunDnKSfw2sgYW1+sCfWY7ikAuZGqsp7aE6wKBR:X1czXd0pcqsp7aOc
                                        MD5:28BA3679DCBA83B85807A11515CB4EB2
                                        SHA1:BB83F9729C974027747A6EAFB13FB97FE0703FF7
                                        SHA-256:7AA4298AF4D0A7E0384B649106218D4FBCE9B52CDF62B4C395B6B10F92C2474B
                                        SHA-512:C72F9869C4D830B292941C4031FAE981D4B259BBF0FDBD54987024ADC3F68540B1B96D18CB6BBA68C308DCA006EC734ED2F974F9993F77D470407532540178E5
                                        Malicious:false
                                        Preview:.4Y... .i...$.{W8...=i....lN...U.x.:.*...>..>L. {)........[]...`b.......i.^QKB.J+...}...?a..~...e..:..'.A...../...~...!u.s%.z..}...%..L.... .k...:8E.K...x..R.....4...[w7v..Y..\..8.......$.{V1.......e.-.f.t...i)....q..8Ye......3.W...S}..a%..,........d.....}f)(.....N,Sr.x....../...u.T.'......kH......3....)...]-...q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):467
                                        Entropy (8bit):7.54269116179455
                                        Encrypted:false
                                        SSDEEP:12:kyIVKh8Sdv27/eCCg3ldyHZd7Tp7aE6wKBR:ke8R7/edRZ5Tp7aOc
                                        MD5:90B8C1CAFD8492A6597E6C2D1F1F6A86
                                        SHA1:33A097F8D465CF2571DFABADED0D767583B3FA89
                                        SHA-256:757F054D49FB6C8E68CC8444062ADEF75242429DB7714005CC5A219F88C121D9
                                        SHA-512:A50A526F75ADD71C619125A88B2510E62FC767C58D55AB8628D178ACA53DFAA065681845B12E10B1B6C86600CC27887EAF51E5BA02394EDB5E2E391E3D60B193
                                        Malicious:false
                                        Preview:V.r`.....8.g........$T6a1.)..B...l.D]...........?.H.]...8...'..#.......&.........'k2b..eY..{"j....(..o..S.h.....![7ULTm/..3C..gn..|b.=._.(..J.C9..Mu:.Q.a...N.C.6.P..!.....;V...a...Usz..C_...._.e...a...r.........<).......[.v........R......}..a%..,........d....5u.cv..GF\..!....We....M....|.bk`.e..Rk.s?t.X^.u^Y.$.4.....Q..q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):461
                                        Entropy (8bit):7.564964055545611
                                        Encrypted:false
                                        SSDEEP:6:sr+dIjaiLK65kpbhzMy0uCTsdQOtJOAlBr8ptYOGXrVjzrwX+p78frSJVgxGnFYN:tCJK65YbhQuQsdECrVzwOp7aE6wKBR
                                        MD5:4595D7A017009D5DF7DF857C9C577325
                                        SHA1:7F8702DDBA2155605ADACD0463C042BBD702C104
                                        SHA-256:5FD41483042862257D26F868547D6750F96D09F9CE92F07D2F16F7C975F3B2F5
                                        SHA-512:B4EB9C8F55EBEEBF9A74322F88DA4AA67E018F84FEC5B050256D99946A31846716363883386CF1A0D715F347192C00BFDEA9FF9034D485DE5141E3C55282326A
                                        Malicious:false
                                        Preview:..?...d.1.xjei..q?..P.G(..........N.[.b..\......r.Z....t..1g...=...q.R4......[.0.T.t.:...x.*u......c.5.1.*u./......D.....;.'''...%,.yM...X.&N.....3 ..1.).vdH...._EO.^4.&.....]..B,.H.o....z..eV.u(~..SM..8).......J.'.......t....lt....)a%..,........g..@......`.....f.h...E..t.`..hY!....9!,h.....~.;......|...f...r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):469
                                        Entropy (8bit):7.543479341805252
                                        Encrypted:false
                                        SSDEEP:12:6G+9XzxePWd9+gIhq/QKZcEqBoYX6xmkp7aE6wKBR:z+9XNgWdFv/fZcXtKZp7aOc
                                        MD5:0DB1BDE23A421C2586416AA0C772067A
                                        SHA1:2E7DC0F250D5EE729D582ED181C7F0236C4DF00E
                                        SHA-256:7ED497B3F09204F2189EDB978BE7003227EBAA3C3BAA53B0C58F2F203B1B05C4
                                        SHA-512:BF9A29B0C1DE9E1344CD11C5E063D8BD73D78DF7122052E537C0755F807463D65378DAF5B7BB4087A429ED2FF75E265F0FE61E35F3DD0325B00DB266EE28C4E1
                                        Malicious:false
                                        Preview:..m >N..;;....S(....../.5.\@s..f......%.u*o.g.I..C.S..Y.M.b..h..6......v.X.......2...g{.V..C.[2.....k...... :.X:Q.`...}..N....EM.PL/.....Oo......|.cnF..F.d<...l.g.k.S..q....C.b.}....s/......aO,E.({..7.?......8)....:.4.......R....>..5...)a%..,........g..@V..7.)..C.....?..Zz..{.......)..F.&.....6'......t.ZdSm.^...p.r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):460
                                        Entropy (8bit):7.482603082704984
                                        Encrypted:false
                                        SSDEEP:12:ejxui+xW0E34666Csg5d8pEhsvmSIdkMyp/qp7aE6wKBR:e94Wd3ab5YvmSIOQp7aOc
                                        MD5:D694399A4627FBB631451BF5DE455180
                                        SHA1:AB67207DE38F00320634A1E3EED73E93755C733A
                                        SHA-256:EC3D48D9288829AE27E0BD348A376052E784F2C266420FCA892D13A7360605B7
                                        SHA-512:4E81B8745D11DC16D2F58D88D30A4A4EA85DF577FAE46BC417A23DB6EA7F69AEA263B5406FB59DD575C69FEFFAAF71527D1AC266D18FF87EF83F79A75751212B
                                        Malicious:false
                                        Preview:4...@.{.......]j 9..8.%....8.."..S'.[.4.y.6.....+....^.RS...m../. ........}+.MC......ge..wx.hfA.......>.%2J$B.M....dg.^(.. .L..t.v..n.NX..g+.Y..G..]..G..%.2.X.\7 .....`8N|+.%...."%"..%<.@.R.7(....D.C^...7).........e2.......'..j..S}..a%..,........d..........y_6^..I$..r........_.L.y.O.V/.....@..av......6..3..q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):432
                                        Entropy (8bit):7.41696341404842
                                        Encrypted:false
                                        SSDEEP:12:vyANqZ6a5e/zTPGy4XtNRsztYIZPp7aE6wKBR:9NK6a5OEnCyI5p7aOc
                                        MD5:740106B214599D1F206EDFF008EC4C46
                                        SHA1:8C7CBF3CFC05C316E6A624BE41D4FD20AF20B6A2
                                        SHA-256:FCE616A57DEDA19BBFF98E266B08A2120AC0A0614BAAD7C1A3945975D485467A
                                        SHA-512:262D14E7F59775F052EAB508878E5B74EAEE8C23B051AB08CDF88A1D87C22E80765F76CD6EB08FE37F01D7C81A42BAAC92181FCDC2A7BC7605412375FCA72C4D
                                        Malicious:false
                                        Preview:n-$:q`.P;...51jl......|\...F.s..o..\T.2^..JZ...d.T.,.1....c.lp......(.@..........o..gsV....z[.t.......I..z.Box..~......G..+...o.9.Z..K............^...+Ijx..}.y...%..'.9EXd.....n)..S$....0|E.U.g.s.f+.t.......@%.~........d..@.......01S..1...c....K...|g..J..V..Y=*...5.l;.$z:j..|..2.es......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):487
                                        Entropy (8bit):7.576736125292312
                                        Encrypted:false
                                        SSDEEP:12:nOMoSrzaPnSjXVD8xdtzRdyaf5BwBsp7aE6wKBR:pvoID87dyaf5BEsp7aOc
                                        MD5:5F8C078B5A9179B8DE7634378E981328
                                        SHA1:E74F14B319B38388C02D23661943EC1AC2D0317D
                                        SHA-256:ADB5C404BACD7CB2F624FF28390EA6272A09A71C88C8DC06B070CDEDD2A37A98
                                        SHA-512:C818EB46864C022F9E311262C1C41346FB4943611E506725A16E9B789565C432B60A00E303C7CFA57038085B739777525CB56B7F6D992390AEC1E616297592D2
                                        Malicious:false
                                        Preview:...........[..r..5pO.p.s<9fl.]kw.>.Vd1.f....xsM.c..w........FH;...`...Q.g.S.>.H....O..,..:R..<....V-.....8..........i.......p..K$x.sZ>@L.1MK%Q_.....[T6p..A....T...7.(~.7.........Lk..P..(|..F...?YJU$.:.qa!..">.....P..*.0...^xY..?.j..k(N..1.....}........./|...}..a%..,........d..W....Qx.zZ:O...H..L.zy$..B....Y.p.......c.M.w.UV.'..K...we]2..q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):469
                                        Entropy (8bit):7.563157593546904
                                        Encrypted:false
                                        SSDEEP:12:jNq7Rgco6MU1lfEOFAOoCqKZx5GkIp7aE6wKBR:jrLZUfEunoCXP5PIp7aOc
                                        MD5:87E937292C01617275ED97D230025BD3
                                        SHA1:58269D8050136B4E4137040965064054D3DDAE27
                                        SHA-256:FD97724ACB3790837EC97229AA96C8F975592B7046394196F9FFFDCA78E2EA81
                                        SHA-512:7D3E15274E2E140B2436F3979B7F7EE00AAE96C42B03434E65F57AC6A99B2C84384870D0F0D5925B825FDA0CA78BD806A6221FB22A6F13A718302F148D5E6FE5
                                        Malicious:false
                                        Preview:G........}...y...Q"'...n.....t}.zF..Ou#E...7......0...[..0....w.#.`.....<.C.:8~/G.Hk.u..`..Sw..<!b.=...>....,........{pn.#....O^fh.mI..<.!.f.D.q.I7Hnw.Y......}oQ....-..<..+....~2.#.Tnf..b...Yb....^e........>)......J.&.........Wot....)a%..,........g..@.&Kz.$.X.`a.h.!...|#.%2R`..|.S..'Gj.CuH.ooF..8.W..*0Z...C(...r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):479
                                        Entropy (8bit):7.528559881676155
                                        Encrypted:false
                                        SSDEEP:12:/FiGwD/i6itg6YjQBkdaEMhoJoscQTrp7aE6wKBR:diGK2tgR0SsliJxRPp7aOc
                                        MD5:6823B55B970BA79E49344635C3CBCD50
                                        SHA1:95AB6460B076144115C3846E6ED6208969549BF7
                                        SHA-256:80F758219D91CC1343162E2EA759B69E370F9CD90A2DBF911C3BED1670A9C88C
                                        SHA-512:D51D1D80B0405B1BB561A45558CE185623909E31651B317C0801E469AF219117E0EEC07B6944C088AA8B93618E4BD8D027CE47CF7FE594095F734383B0BD2E97
                                        Malicious:false
                                        Preview:...%...-LC...V....LE...f?c....QR..,.-...R.J|...w..D.o......3....h=..f..z(.2..o.!~.B.4`}...9_..rX.k....@i\...h.=z}..U6.....#.L.....l.L.gB..:..O.5..."....}.Z.Q..@*.^...%.jA..|.Q8..V$...iv.T.I...ff..!..[.$f..O...Z........O............<).........2X.....9.aZ0..}O.a%./.............l.\J./.O.b..N{.wc...s..jE.=..n..o.&.}.k*..~.?.u=.k...m......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):431
                                        Entropy (8bit):7.475573318287924
                                        Encrypted:false
                                        SSDEEP:12:E6aaRCRx3+p+DmLlwYMiq4787PANKnp7aE6wKBR:P7QRx3+p+D26YM74rWp7aOc
                                        MD5:59563DA13C1D797E16B3E3F9C96A7C73
                                        SHA1:32BF3BA7BBE333541D4D8D857B580195E1BAD32B
                                        SHA-256:16D12A76FAA253C96EB6578943B630ACF4F8789009A39420441FA757C72743BF
                                        SHA-512:82C3244A2866A512618C7B44DB68B57D5E3DE67269D7FF1C0B16E3F0DC6EAF113A544FD69F130ABD6B93304FD3B8FF5CA0D6B2D8D92F9BA9DC02B153DAA22490
                                        Malicious:false
                                        Preview:...3.(..p.....r...).mc...XV.<|V.....$/'.=.XD.L.....(dQz.z.>...L.F.iFW.7....o.n...n...6.J...P.r...5....U....p..".Ro.:.kGu..$...."oM.j.N\m.@.G6.tk..[vT....4.s...j......3...../..n)......~.4Y6....U..@.R*H..@..a..,B.......d..@...b..Dk.$.$R.....k.?..i @K..;...n...v.d,*.M...U..K.5.O"p..bt......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):462
                                        Entropy (8bit):7.458198313647888
                                        Encrypted:false
                                        SSDEEP:12:5STbfgeXNQ4KxTdsnqWyb7UikCRYaIGk+Rp7aE6wKBR:5S/jGTdsnqBfUfZ3G3Rp7aOc
                                        MD5:0E5FDF919E69F91A76983CCDE026AC7F
                                        SHA1:15B672B22D96FC05AAAEF4ABFF6C98EC010C8C15
                                        SHA-256:5EDC4906FAC20774684EF1A48CAEB305E760E318027428F15F80710031CEDF41
                                        SHA-512:12E24398868653FA7CB97AA9B4524BFF87CA0F2BDBC2DB210AB8FBAC406F7FBFE96D00044D4BAB7EDA7E65C2D5AE6BB5DE12CEC5F3A7DA9F4533FE6A25988989
                                        Malicious:false
                                        Preview:.....Z....:@'g..5...".,....@.....Y|...z..wG.-...Q.i..*.eF.c.Pk."..].Y?.4....'. ..........H?R.....}w.......5Y....g.D...6%.d.d..........s.e...l."..+[.p.7..R....6I-.{C.I....J...&....f......M{..3e..Q.S|HR......l)........}..... ....j..S}..a%..,........d....+.+.....M.j/...-.....%.....b+..f.U..=..)`...JR.^.:.l...;..q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):438
                                        Entropy (8bit):7.544175889930494
                                        Encrypted:false
                                        SSDEEP:12:U/6EhtQQVglu0ZmjzqWKwSFXHNFp7aE6wKBR:Q2joPjOWlEtFp7aOc
                                        MD5:35E3F4D9D20FF598F56D8EC96EF7BD1D
                                        SHA1:FBC742ED0D048EBDA1E5FCFC0E6C61EDE84F4831
                                        SHA-256:D729A9151EFE77990575EB12FD80F6450439BCD9D73F742D1F7CA945DE9C8B05
                                        SHA-512:6D1274B83654AE5A1223EBE6440BE55D0B82C9DD8C71304A966F21ED436C614100EB34FF79C3EC222124D7D72CB824F672064DA2FB09A599A149455D60E9F1D3
                                        Malicious:false
                                        Preview:N-.{.......F;,.Dy...I..a..m/.?.0n.7.....Vq..h..'.eA.)=....1....^X8jA.s..f.......\...@Z.&.l5ju...tYDYS.......8.-...uM.+.1.a..".*aB...o.[....C...P|q....C....&.y-..=-.N9.....:..6.......9).......d9.cv.k.....D.h.>k.}..a%..,........d...A.U.-.q.y..(_A.H...~.S.L ..Al ...G...A>.N...xd.J.Q......z.q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):497
                                        Entropy (8bit):7.595228344366498
                                        Encrypted:false
                                        SSDEEP:12:q4TTNb/pQKCgWNNISI6OsHDlQbW2GPuTw/p7aE6wKBR:qqhBQH3nHnpEecw/p7aOc
                                        MD5:76ED1A4ED8712B7BD34A5AFF404DA4DB
                                        SHA1:A6C4C40387129D5AAA4030A731A0D8EA4EC55B76
                                        SHA-256:26DBE976065E077F606A0407A7F192ED8DA9D3253112F9556D836879106F1E60
                                        SHA-512:BA0594E37F3FD9B10C9BE1385384A5B7F13717A53DE184902940C064BCEF01C7C33E27F2B62D3924EAE226B0E4D6C9AB2801C09918F7BEA3402DE4F0B8B2A9A0
                                        Malicious:false
                                        Preview:n...p..a..h.....i;....U.X.8.)...^...J.<N.....\Jp..8.....{Dr.D#.BF..f9....J$`.ZG=...-..r.^...(...|..Bv...9b.B!&o....t*-..].I.=....U......=H+O.c$}H5.2..gh.Z.......c.....)\..QE#^..&U..jWV..s'.c....G~.......H.....'....LF..x...........`z3.o.......9).......t.....<.......P...@%.~........d..@.{d{...~.je..V....K....8.(.....N..iB\F.}......;....]......k.s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):465
                                        Entropy (8bit):7.5516769341578085
                                        Encrypted:false
                                        SSDEEP:6:qrrUNE3UtG+SdPHUPaCoKAWmy/mEQon9Qe37h1uaYFf04dLYp78frSJVgxGnFY2Q:xAUstyPaCxaxodbYV0lp7aE6wKBR
                                        MD5:D36C3C2F5F186B65B9328AC658A6716E
                                        SHA1:79B947F1F3BD264C54B3C732AAB0AC88E1D8670D
                                        SHA-256:295512310427C61A745715348050F79095FC05E4B3AF5D23961041048D523853
                                        SHA-512:04183FA3E21A9D8410A1F6F41C24FF8134541EA33A9776D23408278D0CD89F9F73E04C015815979FBCC6AD13BFE38C7D1CF5178A4E05529A73477994BEFEEE29
                                        Malicious:false
                                        Preview:]...=Q.S.3rI.8..d..u[.176...T]4...j..=.Fq...7h...w...@.W.A..Ru.M1.S#.-....?.g.W....]...h5..2a.S.M............99?.$_U..". }.x......-.W}7#`Tq....:......p.....=...B............%....R...K......U..&G0+.."oM.?..S.mJ....=).7.8.".E8H......:.2c.+..}.[a%.,...........7..'jr..M..~.\."V.$;G..FPq...q..(.....N#..LJ7i..h[..T+w...n......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):462
                                        Entropy (8bit):7.538255983137911
                                        Encrypted:false
                                        SSDEEP:12:aElNL3Qy2HMHFWpL48lsOqq0bep7aE6wKBR:a2NL35FWIO30ip7aOc
                                        MD5:E6EE5A43C3433275767E551710C10DF3
                                        SHA1:3DD447D5DEB17238ADE56D20312AA748DF720786
                                        SHA-256:B1166D680FA81F12C4EB13D08B21B870FFDE5E35B007F9066441503459B8930B
                                        SHA-512:F265B227E2193E7705C6077F60DF848EB7F987C5CB131E514088F0E533A51126B4EDF96F2D03773DC0C985EC381BF73266FBE9FD320987B5DDE707D07348BFE3
                                        Malicious:false
                                        Preview:.Q:.[{.......-..GcN.e.....M.O....K...u....+...]a._.G;p.T^\...~..s.....[.+-VLx.......%..i.D;.*._.sLp5..t.3.C...:.C8.. ..p.....4#...'....YR....tA..nP.a.>G7..2VC9Uw)EB$m..'$Y._mB..r<.\...3GD3"...qU.@.5...e..G..;)......$........%?.}j...c..aw.,........d......q..6._...a.._.......1.K.3....I...^l k......V.).....=..w.p......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):477
                                        Entropy (8bit):7.569993278310116
                                        Encrypted:false
                                        SSDEEP:12:+nWJBn1du3p47aqkiBeh6fDemE7Fsm50Wru1p7aE6wKBR:+nWJhuyOQSm2FhDy1p7aOc
                                        MD5:8130EEF7F61D2888B9B276479BB2DAC3
                                        SHA1:6F4F52AFB5F4792E26C9D28DF9E8DF3FC474FEBF
                                        SHA-256:80B89087C31DBE2120BF5F9BE982FDD8145EEA2549EA581FF02055304DFC8525
                                        SHA-512:7AF827E116552A1D115327B3BC6E3617E6DE7D3531255D162A21C7C9DF6603F18B1509B3BE43F0FD501C929C1838AB2BB7AC93E10058F1DE399AC6946F6E215F
                                        Malicious:false
                                        Preview:.5[....D....{=..4....._...]..Kl..{uw]7...r.~.-...U..$.4.6.x.......|.o.E.'o.$.P.|..1c..?|.T.Ed_../....)..?G..0w{.d..,..`:.........?.t.0.uh.EQ......$...y.6..e.......{..66.... ...im.....\w.|.8.+N..O...Q.........:.7......:)......e.v.........+...&..}..a%..,........d..iJ.D.S.O..r..y....H?.Ua4[...VYe.o....U.7j...j.4.A...Y~.......q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):462
                                        Entropy (8bit):7.501528955192609
                                        Encrypted:false
                                        SSDEEP:12:tWr8uvynEVy7QxqUIbUknyzsQjYp7aE6wKBR:tWgnh+kyOp7aOc
                                        MD5:69A96ADBB7FC858864E8260031186632
                                        SHA1:CEC2A68A85B8B00BE715D0DC4FF3C0DE8291BBD1
                                        SHA-256:6A19786697C23564D011F9DF8D083BF78A39D0264AED81710190A0E1C7A52C63
                                        SHA-512:A261CC1D64639644290F677E728E6E63820750202E6B7F58D7CE211D1793D3F932930BFA28958C27DA60E617907EBB18FAC060573B5CD0F41254E5F99DD3C9C4
                                        Malicious:false
                                        Preview:..f..lt.{.y...TC6..J...l.%.G:.....;o.{...x......Z.O...H..>.G....n.4..7..X..G.........P....Ag..{Ti.'~9.....}...p.,.....9.V`...&..Y.%}....V...-...Ig."jf:.PF..D^...G..\B....n=..XVm.m].(..9.c[<.h.}nv.:......n)......H.|..U.I....+(E.7....)a%..,........g..@.......#../~<...q....2.k.....%fp}.......LD,...9*...........r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):456
                                        Entropy (8bit):7.5319307577647265
                                        Encrypted:false
                                        SSDEEP:12:G7xzNByIiriTtgjcmoZTwIvRCIa7p7aE6wKBR:OxzHiDjcmoZUIvo7p7aOc
                                        MD5:9966077890F50D38CC456B68F640E79D
                                        SHA1:5B07797C89AAF8ACFC6A338813F5ED99FA864A48
                                        SHA-256:F354BF748D4A21001BA7DA121E65D788E21106A1EDC7E39C2915675319A096BE
                                        SHA-512:626684A1C94973197A7E239B03642DB9ED3DADF4BC5DFBCFD7943E6D1BA32D0C7CE1898065E3C8AD78A384C401EEEAECE04E43EF5472221210827E618A781CFF
                                        Malicious:false
                                        Preview:P.N..R.+U+b....$.A.B...d.X.&.".".4..N.B...,....]p.wx<.6....WO..b..c.@...O.n.+..~..g.W.X.s..Z.v...>...~..\..Ym.:../...>...g..7.N...wm...h.V......s.........,...j..X.....!...._*..i..h.....@Z<.~...t...j).........p..g.]....|..}.)a%..,........g..@..8.....vD.3...M...(si...m.W..3.r.C"hM.....}?Acb.^../e.'>E.r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):463
                                        Entropy (8bit):7.5886832807576
                                        Encrypted:false
                                        SSDEEP:12:ZiKBq2/yYbECbkg1h1ACF+V8Nf037PbYp7aE6wKBR:ZiKBqJCQmVEC5A7jYp7aOc
                                        MD5:4455A5125CB60FA790ABC18F4170B34C
                                        SHA1:D223C1E66714DF8DBD38FFF67FA072ED7CE3E13C
                                        SHA-256:130BC756BE5B426BD6D0D82DBFD29CB054F35308C0737E374BD7FC0610F16A85
                                        SHA-512:AC67C4D63EF854543FEA096C53C69DE0CBB025BBFEA0607CAB296B34B21B4A5C0080C2CC5B2FD1DDAD533E7B16BFEC04D56EE516C609FD97E5504EE1A8F963BA
                                        Malicious:false
                                        Preview:".C6)......_..b.0..JM5).x.b.....L..'....^....P|..u....H..z..%.s.G(...~.p.....(;..C.Lo3y.F4..E.uu.PT.....F...}...S....rF}.a...i...a.;f..40.m....G..d....9.....'..Z.kj......6>7....WE.........h{]..E...."..Z..i)..S$...2LbW.s.......P\t.K..)a%..,........g..@VX.....3.y...... .......5@L......rJ....F.&.....\.......:)V.<.r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):455
                                        Entropy (8bit):7.546252317608634
                                        Encrypted:false
                                        SSDEEP:6:nH1z99tC4f63Igkax+jB6/Vd9fI2WWGFAvX2jLCL+be+XSbTyPW45p78frSJVgxr:na4C3Aa4VM9I2WivClZXgWXp7aE6wKBR
                                        MD5:0365ECD25A63230E6B9F992312257343
                                        SHA1:ADFF656A372A2289001DD77061802529A411B170
                                        SHA-256:90F9503090C3AD2C975966BECE992EB022304D3ED559F0ED0AEA7898164309B0
                                        SHA-512:05D2FD791718926BED4191728D45AD8ACAB6725FEC78314E34440DDA3442F5756587E5115D011CEDC3EBB255E7038495F1EEABFE113298E643388547B78B8378
                                        Malicious:false
                                        Preview:&P.X$..l.I.MAd.......'....{..6...?.W-..;...T....."..'2~....xD...Ox...uX.|C]....Z.1....?%s#.q*l....lz.F...L.~..V.w.[...)p.......x;.(x..X..\..S...wX....1.q,..p.v....f.>.T$/?...J3o+J.#..9.&.....y...>)......d4.cO.........?...h..@%.~........d..@..G.....vy]....o.P>Y..9.q/.,d..$...n...qfl..].N..|....D..x....s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):461
                                        Entropy (8bit):7.491371938237907
                                        Encrypted:false
                                        SSDEEP:6:GpdLFlrjvx9Ub/neLOtXDQ8erTI/Rw3piwSzdWl3KF65t39u2Fp78frSJVgxGnFO:Gz/PcVDQ8erTNlSzC2stNVFp7aE6wKBR
                                        MD5:640CA2DDD78DF8922904A1F7AE37CC3E
                                        SHA1:725786DA4ED2CE5FB2347F629CC052BB9FD0D108
                                        SHA-256:82E2AA60F9BDF1E37E30CB8221A54D38BDF293F1CA6281FE704E197A2E4194E6
                                        SHA-512:89BA63F06CFD1D2D3D486B9AE251FF371D5F830DE01B741F8D4FC19751D0F0C240855DA9748A8CF1AB3BB65936BD603A3199CFCD4C36891F24B75BD57F158231
                                        Malicious:false
                                        Preview:>@.h...m$....(.SS....RY.@.........$E.....+.o!....aK..F4.;Q0.....r.9..M...g..".{c.66..{|K.#.-y...vT...%..T..].I.q.E..Z?m.u.....~.2.MQ.}........L....5...9[K9..b2.."..........Ce*].AV...!* ...gr[...;...MX..>)....-...p..l.....R..j.c..aw.,........d.:U.lS....G..&...@..,.@..|....?.z#0....?.6.hXG$......A.m.."b..p......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:SysEx File -
                                        Category:dropped
                                        Size (bytes):478
                                        Entropy (8bit):7.541389286334622
                                        Encrypted:false
                                        SSDEEP:12:xEEdybZxv++EaZmdt2qQYdNPz4n/eIVQaN9X5p7aE6wKBR:EIjjbNPcnr5p7aOc
                                        MD5:9B1AC995AEC7CAE6822E41B54A761AAD
                                        SHA1:1F4587B0C7C896A903B178328A2D89B663B7A4CE
                                        SHA-256:AFA72268F05C81643536226E33AE750F375FA322277C99EC15EE8C18973B627A
                                        SHA-512:3B7E0878AA3C9537F4BCA4F73F5B13C61D4BF4F13C848BA7CB674E798B94D0000CC12162053C2AA58FA8CD87D3202B91911269107871993D30C3ADB9717C0D77
                                        Malicious:false
                                        Preview:.7...|8.O.$......"...%....Y........S|.\U...}'...g..k..?.w.E.....S......z.d..-...L._B..wI...$N_.;;~...kPvE`?t...L.*.{...E.h...W.(.#...\$......!.;p.y[j.1&.YP..G....kA........9iU..^.#...h.....y............s..)Y#...!..6..=)......I.s.........>].....)a%..,........g..@.f... .....H.+dhr..L..'.. F.#...O.?2.9.....\I.?*B..E2.OD....K|r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):465
                                        Entropy (8bit):7.537905691160156
                                        Encrypted:false
                                        SSDEEP:6:kyd6kJa900U+PCOrfaZd9wJAWVr+wZZQnWH8onDBxKp+SND85bI3yB6VAp78frSg:kylWsdSed9EtxzDBxUSbImHp7aE6wKBR
                                        MD5:0727268C50FB53C8C5319CDA9A3111AD
                                        SHA1:EDA87D0D5BBF9E0DCF2FB9A32D9764EF43EA733E
                                        SHA-256:0B55561C718EFF21A9FEC400F0A2C431473606478DB3E9FB2BF22AB147A62FF1
                                        SHA-512:F88C51D534F903D9266FAD59DE6348D0F3456612BB6407A5A31E656F3D91C4D0CB18BCCF5363D0365DF4AA19459BABFDE2D95036995CCFBADA741248FE50A258
                                        Malicious:false
                                        Preview:..+T..5m...Y..\4..I..,/{....;Q...!..y.N.F..A+u........}..`K.)."..qNL.5..1.8;{....!.Xs.......#k...J...H.S.......<d..{e...<...%.....gP......6....fI.c.>.Z.&..[.u<.4$.n....m.m....<.yz.......J_.~.<./K.?.*..[3..7)........t...).....R...[.K..)a%..,........g..@~....Y$/.6.\yb.W.I.....7...kz..r[..e...p#..bR.o..dRD.M.`K.z.r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):291
                                        Entropy (8bit):7.291567772408142
                                        Encrypted:false
                                        SSDEEP:6:TgxUWqloGsjF7y8q9T9fwsFM5p78frSJVgxGnFY22w20FCnBR:9W/Gsx7yH9Ovp7aE6wKBR
                                        MD5:5F866279BD64802BC4EB7B4024266824
                                        SHA1:1081D5F354E8ECD9FD9CDAD0C7D99EE6732A14E9
                                        SHA-256:A35E28FB1FA297554D6CC8095E1E40A7E0029D6D75C475BA83A1E2737D4DC6EB
                                        SHA-512:7F41C4CBD049BBE5071D20CEFBA3A54BB6F3ACEF6373E08451261BB3F63EFEA4A6037F8B0D1BCD168617D22F12A6A29CC705DD315503C9CBF9046A7775E4E021
                                        Malicious:false
                                        Preview:wsYA{io{.k..k.w.%.w.Ay.....-..p..:cv........w=.P.g)....-...)..U.g.]..9.aZ0..}O.a%./.........?.Hv.'eF....9....3h...........[o.;.:}.......ey....~....R..m......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):253
                                        Entropy (8bit):7.139663880821728
                                        Encrypted:false
                                        SSDEEP:6:zVEOGecym4EIscC3tz1hsrMOFODp78frSJVgxGnFY22w20FCnBR:z2y/Rpwtz1hsrmDp7aE6wKBR
                                        MD5:22369F0FF12BCB2D449CB229A952CDB7
                                        SHA1:FC8B41D2EBFEF54FA2FFE9568CA66732BA1645A1
                                        SHA-256:45895C3749CA67B7FB9F13C417585754D8D720AB37515A0CEC9BEDBC1B484C08
                                        SHA-512:DBBDE683499F41098CBBB60EFC4AB13CCD3D2BA6E3CF25CA2EB1ACF06C6A9994DF0604016E95A9102A6BA30F986674E22DA512C6A60C4BA9F9B50684BE981AA3
                                        Malicious:false
                                        Preview:.!"...Z.'..O..AT.Q..Ra..M.a).....R..H........!.aZ(..}.......n...g...J..S.%..qn.... ....s.E...A..5.ev...#...h. U.a.O_......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):519
                                        Entropy (8bit):7.627373515543098
                                        Encrypted:false
                                        SSDEEP:12:XxkgADTf6zzEaMwXGLzarSyyeCz9VLhp7aE6wKBR:B+j6zYa6ySydM99hp7aOc
                                        MD5:37DCE2183AD9180CC69BFD6C4C694BA6
                                        SHA1:8429B14B306AA7D770C3FE6380DC0E428F761766
                                        SHA-256:5EBB0212FDFD7EBC30A772DF41B1A8C2CA93DAC59105204CCFF84DBFB3F2C433
                                        SHA-512:F89DCEA10B59526F55F9EE9B3766678A63E99C10F98A308381EED15D02EA2283C11C37C4C30D5D2138DC029CF3B9B84BAB9584D5B70C75B875CD48961A8ED4CD
                                        Malicious:false
                                        Preview:..tCo..c\x.t.x.......Pi.5....I.;.+..-.I..3.`$...M.-{.=S..@hJ.#..D.3Wl.,:....w.&...;!..C.w.L.U"....E.l....1.......~^....O..c.Ct...J......s..h..../.dv...N.j.%X.......d@.._..S=:6Y.....{.0..^...}.Z.j....6E.tTI.P...g.....2....X![.w8/.o..?...f-.Sf]{..}..ZGx.H.$....../..a...:....@....h.@)...*.............!.aZ.>e..b6r..6,#H.ZRNwE|....\.Y.O*2...DlP.SD8u.`H..[.....y.5[[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):527
                                        Entropy (8bit):7.608924885135267
                                        Encrypted:false
                                        SSDEEP:12:jDD1/SLiyzFG1SzPVHWZ193OpiIG27Z6jqX+p7aE6wKBR:jDD1siTAPVHc93OpiIG26Vp7aOc
                                        MD5:47CB1C78B4CBEB6A0E41F18E77A9C84C
                                        SHA1:137EC8A5D3DB453BA7CB9BF6E7378BCBCBBB1FE9
                                        SHA-256:D256C646BA5604BA64F33E731F85AD5AB6EB38E3D7F35C58CABF0105FA707B55
                                        SHA-512:E36387F7DB6EB90905A52D7B3ABA44A890A6C78C21CAA424C0D13069DBEBE645E4E29F190D99F9C66B621B83150B991CCEBAFE284F470B737236D5B390C8CF6A
                                        Malicious:false
                                        Preview:.5T..u....Y.L........b1..Y...)..X=.*ZVe..R(g....V..6rE'......qZ...{.w.+...:...\u....l...e..F....(..5g...\[.....^.0.a...8..YhMv.......}....x..T.Vk.!w.7..'32.nQN;.N.....K..b.]......5..........y.....X..84..~`..\........sr"..5?...{b....?..x.8..i..U.......J....F........,......CYb..N.*h.@)......de..........".aZ(..}..a%\./jI....#..._Z1.~..87.56|.LOv...vy...../P..v.f.>.0rK.!z..c......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.0515647073811
                                        Encrypted:false
                                        SSDEEP:6:pHYKLlFwEcB2chVh8MOgoCLEFiWAp78frSJVgxGnFY22w20FCnBR:tE1B2kqohui5p7aE6wKBR
                                        MD5:5747922FB3F091C63645A02F7E02B903
                                        SHA1:F927555A02E43021F54923F6D07121D36A5F3836
                                        SHA-256:503E50177250FCEA0000E22414078DB3EC68CA5F66F39137F809F496720AABBD
                                        SHA-512:D7667B873926C440DDF6E73F06DD22335054BF4386DBB4D5CD85CC66FBEDC1CDC9989626B8FD7BFA21E86BB8AB76987B38E67C11F99523502F426048EE4F83DC
                                        Malicious:false
                                        Preview:.g.b9}.....?&v..g.Z). .m....G........".aY+..~..a...GL...swG..%+%0.<..5.;.~..~._h.....;Z&.S^n.,.&.....VV@D9.b......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):560
                                        Entropy (8bit):7.648570764784848
                                        Encrypted:false
                                        SSDEEP:12:hlQvln3hM1Iv3a0ZYdCxxGlvekoXVX9lKp7aE6wKBR:hlQtRq0JAlWke9wp7aOc
                                        MD5:7852D58A933D7C7090CC7EFA4727138A
                                        SHA1:8573300411AC1FAC6DFB062FC4F438C5F905B134
                                        SHA-256:F1C0C4995657C8CCBF96E57D649314B196501F36A428DAC2B2145D0EFF309811
                                        SHA-512:57239F73F749F56DDBB2452DC162C333AE8C627026AF460564DE38A8851439E9A3F84853CB57CF6C1974B76136EC3DEE4A8BEEFD6E1F0697CEF160FCABEA575A
                                        Malicious:false
                                        Preview:...+...g..gw1.j...D%h.g....t.L....P\.+...~A.igl..<|b.4........:....?qV..5y.L(.'.........mX...J`I$.U.|.^.(-T.s.q.3..^.. .A...BV..zN....Q.......KY'.~./.._....9..T..>..U^........ ...K...J...;.....;.qF...R_.....Z.D...T...6.nH..h.5s<.....U.'.=..E{.j.#..D....)a..#.!.g.t.b."dO.^p5..Q...(.}.J.....o.<*.N..n.B.'..cH...y...h.@)...*.............!.aZ7.+..+.HL.o..............H....2]...j..y..C)...[....8..\.0.7x..[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):568
                                        Entropy (8bit):7.596466900772093
                                        Encrypted:false
                                        SSDEEP:12:dfwaeY7bSendu6fVuM3zGBue3+McSJVMekfNfQTZFLETbJOpiIBtOFuc+p7aE6wc:dfVeY7bPVVLzGge3JZJVMemfQbkJOpix
                                        MD5:47810D4F31D04CB99B419B3DAE8DF939
                                        SHA1:72FDB130C4B82B157685E0BEF094B296D9891D9C
                                        SHA-256:7BDEC75B6B0F55E23512A110DC74FAB1DF369D6B9F894055CCD2A00875BF2D82
                                        SHA-512:3FE3BED5CB468FAC004E68B31EC112E72A1AA7BDCC1FA43A8E1E318F5E2EAC52DC3204F38E94EEC4328CF71472026F4D6284F3E3DA6DAC702200DFB3ACE3287C
                                        Malicious:false
                                        Preview:McGWi.....Fd.jqn....e:.f..).s..j'..Kw:"j.(47.JH{P..\"...i..7..#.....Q...2..Z.Wh.T..}..O.B....G..t.j.....L.%8....'Ya...<Z/..g+.^G.~+ ..G....N.4..s...pe.{HJ...zG-<r....$..mN.JM|;..o.G..=.!...{.l.)......4z.J.=.......]r.:..MHR&bg.grGr.6.....L+...[Q.Y....-d.!Dz.f..g...Z..7..Z#... ....p6[....."..Snf..7.&......"..f..'....%...F/..h.@)......de..........".aZ(..}..a%..H--...X.a3h.d`....,0...+.3..Qp.vx..MwK..V.....z+..!%...N..+.c......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Secret Key
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.240232437123238
                                        Encrypted:false
                                        SSDEEP:6:tfIVikbg6j5LBPmPaY415Bsp78frSJVgxGnFY22w20FCnBR:tILg6jb+PaY4Dyp7aE6wKBR
                                        MD5:C280E28C5E9F670E243CF960C020CA48
                                        SHA1:77E45846118AF1871C162665557FC2AA64469851
                                        SHA-256:230AC5621602B93163178CA5BE6E4785A8A12F6D759E82AF7CC45B01C26592E1
                                        SHA-512:2A3BD43E408EAF86415BDB520892E5C09824CF2E64661E35E7D81750DC3DC1C6743B834E95EB2308B279CC63636D1851DCD949AC52D714D9C9071946F57DBEA1
                                        Malicious:false
                                        Preview:.^...k..r3..PIz...4..z...".. ......>.v..i.N)......dR.Uv.R.......a@+../..a%.,......CH.............gD9.6.?......#`.T.z.v.$._mVRKv...8.6.....,...l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):731
                                        Entropy (8bit):7.724518439513996
                                        Encrypted:false
                                        SSDEEP:12:P5fVeNlO6aEYCsj/dBoaYygSWMEFZV5qRmWutswrhewx+l2rHje3+bp7aE6wKBR:P94+EY7y5pV/qUKX1l2zyObp7aOc
                                        MD5:2D281BB78D7EF9996A36BE5CEE2C29BE
                                        SHA1:F46092C22E91C0373A35BAC61A0F51E1BBED2460
                                        SHA-256:E29B176D6C0BD4DE147A54912F71FE0A6CD703A9AC661CAEB1ECAEDC58F931B1
                                        SHA-512:5BFC554B35BE8FF2601C91A32EFA04B7470D04ADD579F875CF588674322C3AF3ABECD0DC8169AB2CDA5E19D3F048F4950318D6CC790985F2D68CE446003184F9
                                        Malicious:false
                                        Preview:....y.RH....L..2.mO.#?0..w..h..w.....*%e.._....V.q$<.0.....\a.B...u2.=+DN.-..imv...Fx...b"..4d.!....@..MA..<..}!..I.F*...M..h.K0O..F.32.T...&<.y..4L*m.(Vu..o...0...A..~.}:\....>...HG.. ....H..#...N....q.^...s..Ry3ps...&J......D.Bj.......v..Gl..xD/..U....U..oI*..Tf".....^........}k..r..}.oml_.BK#.n.....H..jP.h.n...0r...l9.!ZY..b$J.. ..>..z..A-P.d......bt.r.q=wE....f..`Z..Q......].h.......D.)..B.R.0[...u.....G>........"YP.Q.....5..\..}.||.._.z.../.z...h.`)......ds.dv.R.@.....Q4..}..a%..,........d.....Z.R.X.~^..}....x.S5s.;.s......#.y _...R...\9.....k..:...G4q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.293166889389478
                                        Encrypted:false
                                        SSDEEP:6:J8idj55KVejXvRM4Fcp78frSJVgxGnFY22w20FCnBR:FjLvj/zcp7aE6wKBR
                                        MD5:3FF82E756940134EE4DDCEBDC8C094D0
                                        SHA1:3778593825E4E48E95540AD60F538A7BD54FC015
                                        SHA-256:5EF7FBED92B1E4CE524C59BFEC0BA5FFAF899A210C31D74290F534F8B7F7E130
                                        SHA-512:12A80C35A985553456149F47B8F7EF54F6649156A7DA93A59260AC175F412712ACB3947D5B30405D4461EA571F0E616021B8BD7B474FFB9A5BC96DDCE2305DE0
                                        Malicious:false
                                        Preview:nHf..c...k}*.H....R4Fo....M.....#...p..i.N)......dR.Uv.R.......a@+../..a%.,..........~.x.".s.^P.....6..I.].{V.4V,)(.c...........)'..=..?...l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20712
                                        Entropy (8bit):7.99173683823548
                                        Encrypted:true
                                        SSDEEP:384:OAJtyQBven9P2rBuF7gxH8Mx54SLYeGYXmQncdtzzbHrmiM8OS:OLQCOrB9x9odzfml8t
                                        MD5:1F445442FAEFA366D2D066D2D190F3C1
                                        SHA1:0031B0F879EECB5D9CAEF2E63F7778D1D04E53F9
                                        SHA-256:9236BFC4158D661DA9B63F09F843A64238ECF86F53EAB45CC81EADCA3E62792F
                                        SHA-512:327D043C5BA1122C51C0C190E7E837FBDAF7783786BD0578066B8D1B3A7869A09D9E373763071DB8AC6C04A552F7E69D7D50C6EA28485903490C1DD76473C76C
                                        Malicious:false
                                        Preview:.._t4.(#}Yk....r.\.w..{.=^..uk\.8..S6..K..(....^L.......r..8|.1T.....1)9.#.yn...-PR.e(.!.._.p....O.........J..KX.N:.....A......S...].qXw.=,...Q(.)...S..."c.joL......(....p!.*..Qr^~.1...+.x<..\....tO........f;.j.z.!.AU/.N.O..%.."...4(...l.1..N..P.....>QZ..K.G.....M.2..O&x...P`.N.y.'..!...S.....G.{.cr........2.' .Xw...9.,..8.A*d..$..........Su....4}1.*.t'....J..IR1.>..h.x...P%s..d.5!.B@.{.K.f.W.+.Q...]6.e..Qd.....@/..H..a...h{....K. .?J.e*b.5.....e......}....H(!..ay.t..i6.....X.<7.....E..YX.8?A......L..e.@.d..f].o...Err..`..n.!.9.6.{'*...Ai....Q..<Xv.M....`:...<..xq......HA2..m..}.H...p...m...........^.../..?3a...1.z...I..R...J..hA2H..6.4.).t..^}Y.l...4...*:._....q.._V.f...B].[...........5..3.....7.Yf..7`......J.D..&.Ux..?.....Y_.P..e......{.8T_^...2....2..V..c..7.>!.qA..;...j...9..v=.o.<t.Z.o.R.9p.".;F...*..._'t.n._=.;.DR....v....-&..E I5....M'.6U)Q..p59(..s..".....%.3...e..?..n|..*..k.Wvu.j/$.Lo./.U...'.. ..+.oy..L..f/..x...........A[
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):763
                                        Entropy (8bit):7.744954871292749
                                        Encrypted:false
                                        SSDEEP:12:1pg1//LfN60FMcVZrYhJEzlAK8Y0CB14Yo7cPg43uaAMEtZJ/vkJIPp7aE6wKBR:1pszdMcVZrUeTpB1qOD3DNQiIPp7aOc
                                        MD5:5C5CE179E83C4E5B79A86E15C7606BF0
                                        SHA1:ACDCD71F7BC3D130D463CF6AB04AA945615EFB4E
                                        SHA-256:228935FA0E770B46771CC472FAFE0AAE2F527FA7162036E78DEFB5F29DF50DD6
                                        SHA-512:6D19E7238148CB998CC67526DEEB8EE01EDB229FFAADF16E1D487A8EB36D85475710CC44919F89079EF3D0148FBD880B573837140EB8388EE9702FA21349B7BC
                                        Malicious:false
                                        Preview:.....JA.+..........<.K...3.`=......F./p*.z.FV....*.c..h...r....M.7.._Upz.m..[uw..RY{..z...c.*...C....&...43..%.d..bx.zW...T...............z..P`*/RXC".,.G>.....'Wo....J.).=.A.p...$y..q....w.[D.u.....t.T.d...<....M.z.i....Y.T....<X.k...X{.. Tm...K..8B.v]o.-.+-.^*./#..LN..Tb./.0.h...=...X...w.<..$=...o.Kf....].7g.K^(..VGC..:..7_{...s..<.yp./..v.N.}}.....}._...xJ......<..U...s.:.~...+.l...c.....;E.....tN..*........13.y..Az....6..~..,.tR.......7....].9....OT...._.T.VKXE.*rj.j)......dj.!v.k...)...CE..QN#lD.T.........d..C..SV.(.....t.9....D.(....F.m.W........t..tw....J..!...Fl"m....WJ....y......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37113
                                        Entropy (8bit):7.994501702732889
                                        Encrypted:true
                                        SSDEEP:768:2tv1SOTPy5z5pAGVJtu52bXCelMZHEFv2aExUqMURVqdVFDGDx9D8r:2tAOu5z5jtu5MXCtZH8v20KR8dCx9C
                                        MD5:3160EC9B9F1091E4258585EE8D70119E
                                        SHA1:F0DCF4F338A517F5E2FE866E2EA0929D82699B45
                                        SHA-256:5C33070523AB12096B91EB41F25BC0D44A8EEF2B92C600D946AB327D76A2854D
                                        SHA-512:3336DAE0B81DD86EE9E068E063BBD5F67FC3E6DBE526C18FA33912F30E16D3AE6408E47C0BEC11D37310534C9653510876AD85EA68EDB4D254B66CD30DF90DF8
                                        Malicious:false
                                        Preview:..-.........Y_\t.xP.g.^.I..d.]..C..M..V..4..... r...4..P.,....<G...=.`.....}.......w.f..rk...}.z..y..!ia.Ch..g./o...+.s.F........o....p.\R....p..a.-FL.ij...q@.....Qfye.........._....'.....z1q..G....*..0jVW5$k..;...<..\/`.fo.$T+...~..:4.......i.L...nA2.%.X.~...2Y....5.c..A.........g.....r.;%l..1...`.{..36.Ri...]VR\.ri...Y..+..Xs.....W..y5....$..{`-.,..K..0\.d...E.;j....9...m..3....I..........x...x.....\.Q...t.w..%2.'.P...8X{.0..e....{X.P;..4....S.......).t..R.:....b...mo.\G,.0.`..]....g....Kl...a.W..[...}...../u...2.UQ1......c.c...!.9...3.....cN..lI8i`o^.1.V........."#...5..X=.........8.8..........i....".........W.s.l}.Vs....7....sq....c....._H....f..0....`...6.....k......>Cnq....{Y.....Tv.|..f.4..'.XO......@..?.;\}.;.!.n......Bh..J..(..S2.. .../F..\... ."..Z...>.gR.T....E.....vYLYoo....9..z...p<G.-.M....-h.....d......'t...H....P..P....Zt]z.....KN1LU.m....SW.+...&Q-...6y........l+..n.p.=}.?UG....93.E..|P...a..#.....DC.9
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3846
                                        Entropy (8bit):7.948211529787566
                                        Encrypted:false
                                        SSDEEP:96:zzXoAd3Q27CQO8WUvhdeYqPhR/POu1k0O1pqXnhyGFd9nxQApJc:zTfd3QqCQZvWX/UZvqxyGFjnzpS
                                        MD5:03867BD0BF1264E97A286F8ECED101E3
                                        SHA1:22B9C7B806E42E1EDEE8969B44D3D98DE258F432
                                        SHA-256:6C468553A7683409A6AA4A72A2EE97500F8C5C68553599AF32E713F917CBC3EE
                                        SHA-512:BA2EE69EA78DA1072BA7AC40E5D5C0F79583DB4D15A3DA5F7761D00F99590971106D665A01AF545B1440AC05BCAEFFBA9D6A20F7C150572AE29C4F785E1EDBC6
                                        Malicious:false
                                        Preview:......Dr..D.O....G..y4^.f9.*.M.v.x$#5.we .....|...e.O...i..S..6.j..#~....%..t.Vc..Ux.~.H6....%.........[-.v....Dk.... .q..&..y3....d...LL..H.]P........}.9......_.sE.p.0.@......=..q........w...K.......:..k..4......[........-)'m...Kg}A.{q..&..c.j<px..7b..L..w.......u..+...b.q...R#"X.Q.Su.j.H....FT.vsZC+5..g9u...S..0.D..9......k4..rl/.}.l..e...n...MX...E_S...e.o.....4....../H....>t....VI_#....%...F...7.BRJ..Y.3.lN^.Y@.pi..*..D6.....r.B..YX.U......_...m.@....^.j.J.ZZ.*..4...>v1k.y......W.m)..f..{/.f3.v8.L...T......WY.7..c_.....+....jPiv:......'.....B..D.$....b:.h..).N1i.)....AY.Y].)M.`'..T2.:.."Ig..P.......4.UyP*G........6......r..j;+.($...bi...j..k.=....2.r...k]..p.rMX.R...3FLZdL.cZ...5.V..sG.....|.s.#.o.....>..J...........[..>.+\.:...Le.Y...RjPqFR.M.w....Doti..Aty.D...T..-]........i.H.X.....j..9~.v...Z,.5.."0..?..k.s...rxp.=.,%..yJ....`n@!.R...........l.`s.o....H..HYP..#..X.....+.Wa........1..!..*1...$.%ac.......{..b^C.....[Ug..D..;..\:....}|(i
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.107106794118267
                                        Encrypted:false
                                        SSDEEP:6:asbEcB2cYdkVkOUNz83u1Ap78frSJVgxGnFY22w20FCnBR:as1B2tdkVkZzu4Ap7aE6wKBR
                                        MD5:61B12265597963436CF118C6569CE64C
                                        SHA1:71167078BCEB5BBD2B6AC80CF33F14B2F5728C9E
                                        SHA-256:3D425A43483EB29BB43B0AF1A7E61FE34E3E42D9E52E21D3CA2644F98B8BA1DB
                                        SHA-512:0A911A42AC0C203BFC809334379C2DAB0B8D1FDEEC404663872CC136CEBC09F2A9E98AB34EC75DBD4F5BA7AE531000F118DA39E3F0D141F4B2C3849AB46650A2
                                        Malicious:false
                                        Preview:......?.v8.B..~.g.Z). .m....G........".aY+..~..a......Lk.%..~Nm......QA.......w.p$..XX.{...[.-.S...!..7.CZN.Yb......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):548
                                        Entropy (8bit):7.620349244855086
                                        Encrypted:false
                                        SSDEEP:12:RXa7FLF5QCeX2ZbIt8aFrAxaO7cre3fZ35S+p7aE6wKBR:I7xUN2IBsaOQC3R5Pp7aOc
                                        MD5:2F3C49D44671D5ED22B0978B88572A88
                                        SHA1:B3AFB2D135420DD92E9A1513E71DFAC0DCE879DE
                                        SHA-256:BFDBC2A16437CBBD44F9F4325E5060C515D1FE2FFE2565E8A1B9463DEE2606F6
                                        SHA-512:204A6728084F6F7938E589E7C884E813999F497172B9A635612DC12B61F6A87BA9319195FBF3C7296926E3DE976D90BA2FF6BA757618916E8C8E16595D934A11
                                        Malicious:false
                                        Preview:m.f..w..m...l. .bSO....Z...f..b..{.,...[....T.C....7R..g.h.9.uun^.(.......8=Q...Er.r.<X....&....,m.....P.....g.. .hy2..tcB...zpG.g..}.U...P.@;..6k..bs...bE.q.4.~..#.J'A..U.WK..F@&k7....nP....f.JC=+mmS6..~C..g..WQ...@.3.?....a..+`.r...2.&^./H...[5.K..2....D.<3.I..y...L.....A...Z.z|.\L.....z#F.6.=..._.........V.h.@)...*.............!.aZ....!..!...h,./TeAB....(W..V.{....Kv/.gcv...F...B....6..r..>.v..[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):556
                                        Entropy (8bit):7.594382947938113
                                        Encrypted:false
                                        SSDEEP:12:REuNXXcrToL8Z/FvbsPChHyGsExPAlJOpiIRi5MHzNQp7aE6wKBR:iuFXcry8/vbsPVGLx4lJOpiIE5oz6p7O
                                        MD5:67A6989D80C9C9CB58AB81B2405399BF
                                        SHA1:D0E668C22C4CA037D6841B82882DBCE959F2514C
                                        SHA-256:7EA1E31CC98E4E3F3F9714334D23CC1CA7D086717ED09E9A951C04473E6EDAAC
                                        SHA-512:6839546587CA283324F7B80636C87AE1C8BF0FFFC72B9A4E89323A40B12260F14755E021ECBE55627F5B8725E19062E390C24EF539CB2786193EC0A3639D5AF3
                                        Malicious:false
                                        Preview:../.8.+4)...}.....\..0..T@KB..6.......2.....2......!....!....p;..X..7-...<..v.^].$.E.~S....m.-.?...*.E.NI.....%..f. ...W.....(.r.x.;..BZ"......i ....Y.......J..iy.#.t.F..W.P._..= ..f.....nZ;..h...c...,...m..^Vg......B9.4.Y5..J.~......A;iG.!k..$.?V..7oO....jG_Ji.T.ZVal\.?.......0M....,.$..P..zb^u...)(O4.%Rt.h.@)......de..........".aZ(..}..a%.F.|..G.....'W.9..~.J.L\KI...j..U..:..>2...g.w,.8..ER.........c......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.249967021936535
                                        Encrypted:false
                                        SSDEEP:6:z09DUbNBwxj5AexRvpcZPIqHAp78frSJVgxGnFY22w20FCnBR:VujS8dyZPgp7aE6wKBR
                                        MD5:E246FD91263A8099277A4E06D4F2C8E9
                                        SHA1:CEFCB768C0B467453C48CF513C58B64057A59770
                                        SHA-256:E948494F3AEF30D31B4B8256C0002921F37258D2EFB7838DC58AEDC57408077B
                                        SHA-512:7DFBE53FEA31B4F8CCA5D4DB07D9DA4DBDAA92FFBBF2A2BC57B97E0466FB3C914E1D259D527662D43DE20DE9A314DD1E058D608050E9ED3919061329E84BD7D7
                                        Malicious:false
                                        Preview:....{<..X%.N.....T.z.$".9_....c....O.li.N)......dR.Uv.R.......a@+../..a%.,.......Kf..I..*.[dI5.o.7.oo4e/N...gP...uG......a.p|..Q......v..9.}x.l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):131313
                                        Entropy (8bit):7.9985564596564975
                                        Encrypted:true
                                        SSDEEP:3072:+izf6PF64sOMS4ch6bV74MULtSRrIqgnANUZdOBwPwRu:+i2MNhcs74M/SqPBwYRu
                                        MD5:09B97F9C0969BCF76A350A3D38764AC2
                                        SHA1:9F7434EEE8EEFCA6B7C4333A1724FEC0481B76F8
                                        SHA-256:C5DABBAE359D714AABDDBF4DEF2BD58239A4C5A45A2419BBB39D03030BD6F683
                                        SHA-512:B06A76F31E5478A3B3AE1658D64C22F3AE071FCFDE12CD407BBEE251D1E2C2BFD19C76227C62A23EA2F04EED1FBB569D02E2E72330A63D1AF8BF95DB7A29E546
                                        Malicious:false
                                        Preview:..`5..........z.......qCZ...}..T.Z.....;.rc7s..R..\=|...]..#.{..l...&z.P1CP.Z.....p..f.Gv)...'.wb:#G......:8.'..1.4...#..1...g..H..Pk..9.......O...=....vS[.G....<./-.|.4mQ.\h.`.<=....Y...'9..b....l.nl3l..!....WE..9yv(..glqU..-7.7q...meT.u...%.z..?.....`...RcN..G+...3F..z7.,....2.+W;-.&....iK...e.'...E....K....!..6|@....yBt.e.z....p.g.e.....c.Y..VJD.......9.}q....[..7...9-^.d^..o.K.:d....^..%I...i.`.......{..K..O......a.a.......T....n4S..bR..E....w.'.Q.:|. .P%-A....z.%..|....SB...Evj.u...@...#D..........5 Oq.AI..#i...6..9......$.+.8..I_.A..{....+;..... .`)..n;..|.......:..E.....V.~..?_Oxj......DA.zF...a"pgx..Q..h.._./..S.9N.".....<c@...9R..;|..j.t.....V.@[...b6M"..]$.......<.;.......=.de.k..d.>.OZp.Xbsn.i?~...7..........B..5hG^...$v&'3.\....j3.)S.?.............Aa(2_.Z....a2V.....Zm.Y..d=.2...!..r.D!.|Y....x....)G.2..(s.)...6...............;.._c..Q.....L.b.X.O....nKnz........E.YU.#Y../.Wej...py.+..N7.....&.x....b..0..YQkq,.t.)...K..R.15
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):287
                                        Entropy (8bit):7.165004302897993
                                        Encrypted:false
                                        SSDEEP:6:9e/6QqH918jpiIO38TmPGD5Rp78frSJVgxGnFY22w20FCnBR:9e/cdWiIO3KmuD5Rp7aE6wKBR
                                        MD5:9FDA35584D43BA02955CD93BFC80B414
                                        SHA1:DA5D4BFE37A8DFA035A445C68A07CC6003BAF879
                                        SHA-256:DDF67E3C10B8E6E55FC43DDB40C5F0AFE5B9081BA0F0472F8D22DD25FCEE9569
                                        SHA-512:AA601DC994CC9BA7A1B877F979A6B2960AB0926950081B7FD63E2EE3314DCBAC01ABADA4A46F2ED2D6E655BC1AC576A69ACEDAAD7F501F0D0BDDFE35F937894C
                                        Malicious:false
                                        Preview:-....-jB..gX~z_..y.i;$<7.0..~....9$...1...V..Dk%...S.i..W.......df..........".aZ(..}..a%Th.....k..s..>...2-4..r.C..$G..&Ty]....K*..FJ.)...f...bVc......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.030012376865182
                                        Encrypted:false
                                        SSDEEP:6:MeMEcB2co1hrnegO/Nysp78frSJVgxGnFY22w20FCnBR:MP1B2H191O1tp7aE6wKBR
                                        MD5:8D234806809FF078E96877A4E3DE5B92
                                        SHA1:43EBA2E7F66981D85E2E12F9CA139835A4C9229D
                                        SHA-256:B662D0C0F2FEF78930F804DB1562C4BCE64A3BE6146503CB66E20D4AADE1FC6B
                                        SHA-512:EF12293AA538FB4BCDFA02AEC2144231644C35A283FD01ABDD2BFA0B0A64435BA13EDFB66609E9289055F77CE7B664046B5D9554929BCC7AF7F2823E5C318FA6
                                        Malicious:false
                                        Preview:.(...5P....(.g.Z). .m....G........".aY+..~..a.|?4.N}'=}...$"Y......m...I..&...`e.`m.n.h6..e.%$......Kf..b......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):510
                                        Entropy (8bit):7.501591582353494
                                        Encrypted:false
                                        SSDEEP:12:rGpY0F9YS0Jitgkql/TXyqUeD8p7aE6wKBR:yK0zYS0Jimke/TCqD8p7aOc
                                        MD5:CBF477754EF557B9EACA0926C1CF42A2
                                        SHA1:76E156683C237DC4A43D6513FEFC4C45F5642BB2
                                        SHA-256:B2D270D8A6793A0D907AE501290C2803D7FBFF67729C612071D8A984BE9A7522
                                        SHA-512:85C41ED39C325DCDA05D8FB28752CEE7C8683B92EF92CC4DF59A475108E5F2824A17D3BFCE269152919010C6F19064F15FC74712ACCA6F650E6583DC80732A74
                                        Malicious:false
                                        Preview:.k[ \4..-B0..'.P...^.B..S.......>.;.0..mZ...8.m{....hK...x.i^0..62m......!#......9....&......D..fc...}.-..i_..D..m.Gq.......3C......y........|T.....dR...&2I...3s..=.z.]s.]z.......&..J.+.....S-....X.....E.....&%......0.&.@..U....'Q....r~?.&....X.h.....ia.G2..........uCr.X...h.@)...*.............!.aZ.c..G>Dmz.a.$h..?ga.Q.R.....o_j..e.-....W.ii........T@.....L..{%[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.306504124410035
                                        Encrypted:false
                                        SSDEEP:6:aHkdx+iyj5/xmBA30WsLfJrsp78frSJVgxGnFY22w20FCnBR:aEmnjYBsp7aE6wKBR
                                        MD5:BDE00CF81E6CF3F8A368753528B4F93A
                                        SHA1:F9039CBFF9D2723D9943BAAD9925B5077EF48233
                                        SHA-256:6EC54078427B4CCC937095E73556B7557AEC1CA1C5D402FFF103096AA0FF191E
                                        SHA-512:6E0459B1519117636456510544B81AC0E316668151D9B9493229FAEEEA5C25F8F16E0F08E3359585BDE9F0369150950F57CD2522548F3F36D9196C73C6A8479B
                                        Malicious:false
                                        Preview:E.......e..V..uQ.Lx.]...HS.d..H.T.....i.N)......dR.Uv.R.......a@+../..a%.,........W.-...\2.....=.jj..(...U..:..*A..........*.....E.#dt.3."2..:l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):359
                                        Entropy (8bit):7.4203282913977375
                                        Encrypted:false
                                        SSDEEP:6:IVVAyvPDjk/VdNnTpTjIY7FC+H8jpiIrESNI9Mp78frSJVgxGnFY22w20FCnBR:I4S4lgeFCBiIrwWp7aE6wKBR
                                        MD5:9C266B34A2859EE62216A199C6AACE48
                                        SHA1:47915FA1A38CDD935D158739C45DDA4A3AA5B779
                                        SHA-256:4305D1CF04C51BDFED2E3B034440EC5E8763B89333AC338712245185258761F3
                                        SHA-512:C39AECFA99F73B179140791D841BC106C0594B64E978B702C37F05190409A6174DFB6543F1AE1850F59F1817483F773BEC9AD44C304DCA1802442F3D4323D5C0
                                        Malicious:false
                                        Preview:.|.&.!r...q....0..}$....=..E.4..n..`o..<........H...a....GJn]%J.O.=^;^.I.,.=..:y.........4r........}..f...i..).<.. ..3s..'...W.......df..........".aZ(..}..a%n.OF{.._.C.Q.o(2.>....l9|..EB:.b.TX..:.A.3.S..R.X{sF.NX[......Uc......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.19474928401145
                                        Encrypted:false
                                        SSDEEP:6:kL8cEcB2c3GVTdJyQiAp78frSJVgxGnFY22w20FCnBR:/c1B2g+yAp7aE6wKBR
                                        MD5:90A57A9128D59E02FDBD9DD64403E97A
                                        SHA1:0E8B6747FE193A1F0364C3EA2F715F2C997AEF4B
                                        SHA-256:66CBDB3E8A14680F041668726C39092671C9A914DF84E71179C7325C1516ED5C
                                        SHA-512:B9268E2F9D011DDED8F18C6919DBDF688257E9D3E8D2ADA0DC18C816A00AEC9FE27D1CB110FD69BEF84F73F82ECB86612E0455F00F227E6DD3DA30BB8F6A2401
                                        Malicious:false
                                        Preview:.>.K...m......g.Z). .m....G........".aY+..~..a.CzE.B...^.&.:...aD..,QAt....[.0.....^....l.5@........Mi.....b......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):528
                                        Entropy (8bit):7.592782284391033
                                        Encrypted:false
                                        SSDEEP:12:w3zA2Cx05VfrcmTOAOLjaSfETOmWekfakUIlp7aE6wKBR:w39DV5XOXa3fhkfBrp7aOc
                                        MD5:8362043B3E5869777478A045CECEE763
                                        SHA1:8F3136E4B3D1D55783D0A3098760E9CA45A957AC
                                        SHA-256:C77CF1573D70B3285C0797700A72A9FDAC800AE6FBD58D3F33C956757D661B01
                                        SHA-512:2B4D50E7D84B5364E71217EEB4D8DD2F481BC65BE8A21110173E6F7FAAF3B0177D5CED32F74AFB9EF5F534BC0EBDBBF9E3D455B602ECE589A9B0FB9EB1330718
                                        Malicious:false
                                        Preview:.....b.+9g..U....P...)...;...m.......'.._..Q=...=...@..f.|<....jR.Q...>.a.xd-6O....P...+uX\.._.......di.!mD....:...Z<..au..Ui...WA2..m....Nr;......9.g..m.U..t.x..Z.A...".b...Y.....V.].......Z.& ........6....Xs.d.S.0..y.......fA...=.O@..7.xX.P|...Z.D..)....?.>.j.E...cH....h.@)...*.............!.aZ:A.cI.9.J..S-.....Z...V..`x_..{.F.}...ZY...z.y..R.H1 .&.O}[.[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.166984889585426
                                        Encrypted:false
                                        SSDEEP:6:iCM28952M8Rj5+eAoDXtUhzGYYQrsp78frSJVgxGnFY22w20FCnBR:T3wkM8RjYEDNYpsp7aE6wKBR
                                        MD5:74CAE06858C797A2ECB4C4B670D57DEB
                                        SHA1:556119959527B500F1B67F6983EFFF3B8D061B1D
                                        SHA-256:ED4285E8F12F10B46560C07346A9DE95A66642508313E7D98A703EECC7B92946
                                        SHA-512:1BEA18EF583C4A9AB4658A3BF4F345F8B2E49A475A02F92EB9E67D04B7B762A75A840951B36893FB9A3CB103D25119EE6D00BC45CCBB378ABA517428A7553F71
                                        Malicious:false
                                        Preview:.%j^N6.8kk.a....2d-m......Ph............i.N)......dR.Uv.R.......a@+../..a%.,........Q]...0....r.j..*..).0......w......04.@r.Y+..cJN.z.Z.rB%..]4l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.102593022026477
                                        Encrypted:false
                                        SSDEEP:6:7LW2keEcB2c28AkTVgUxZomsp78frSJVgxGnFY22w20FCnBR:371B2p78gqZIp7aE6wKBR
                                        MD5:89837FA6B6EF1B483D974EFC8F1CC83F
                                        SHA1:F91802D00161F444D4FA335B533F103E2D3D8F08
                                        SHA-256:34E0B2B7A1FDD92B14EE3D3F0CA0C1B2CA091C2735728E00E5830B8AAEC62673
                                        SHA-512:66122EA639DD91FB271D8D6AEE55EEBC7A0D852F3FE751992AE2C647D4990CE32E4C0E7AAB9F2C8D38317DD74982188299F08D32F749BD7C344E7BA44412B5CB
                                        Malicious:false
                                        Preview:..O[L)V.%).X..+"g.Z). .m....G........".aY+..~..a.C..`!...in.#.UY...A..... "..JF..z.."..Fm.y..q5..$>. q..=]...E.b......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):458
                                        Entropy (8bit):7.587009841835885
                                        Encrypted:false
                                        SSDEEP:12:crHum08au4Vy8up4g2QMy7NeX/NwToFzYp7aE6wKBR:UOg4k8aUQv4XmToFsp7aOc
                                        MD5:0A6B437485521876846298A5E93A693C
                                        SHA1:C8EC4FA13065AB860BF28F2A4F38335A6EBE15AE
                                        SHA-256:3CC34675931429763658F781CBF5EF0CAF015E7F2DA3B09CCF6D6449C2AAC196
                                        SHA-512:FFECB67E497447190BB416301B9B74C490807E1BF356763EDBAD9DCB953D5DD2D13DC78F841B556E2DDEF237411786D0375804048CB7DF898F3521ED9B59D566
                                        Malicious:false
                                        Preview:L.8Q...Fx.b..S..V..Nn..N....[`=a!...2..{.. ..._%.N..hv../.xJQ..c...D...r..GY.Q.j.t...I.4u....1.O.......a.w....?k.GB...Mz......>7.....^.o.f....(.8...U......a...|...uft:-.$(Y.Y...B..\..O.n'R}.T.......>...:).......].AcW.s.a.)..g*th....@%.~........d..@.-../3..S......jaF...5....2..G.H?{.$...H..M.d..L.a~.k....|.^s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):420
                                        Entropy (8bit):7.596198903209468
                                        Encrypted:false
                                        SSDEEP:6:2Ns5/bX8pCpPqEBYoGC0KjhisfqN5Yh33PVwFzcYOCKp78frSJVgxGnFY22w20Fi:9hbX8IPqOP0KS69GwYHKp7aE6wKBR
                                        MD5:F27C4F1F7E260C68E2B887347E100B40
                                        SHA1:DD3C0FA281908FABF580AA7172245FFAA9C7136F
                                        SHA-256:34EE7B0433630F75F732C4198EC8A56EC6110341D72CF0DD7CBB95BC4340B93F
                                        SHA-512:40EC1CAB59509745DCDF5C405F536C94712927DAF0E61153493244D27AD38EB390158F51C9EC6EDF8D1BC14FF775E20AD7F3E91411896A0E2CF95FBA1248A83A
                                        Malicious:false
                                        Preview:.....>.ev.C..?q..-G.1..9.t.5"....L2..p;(.....jI...D.r :....#..f.uH.#U.C...x.bs.g.7..N-.m..G.]....(KZ..1..k..CoJvs....#........AS......gU.u.O.F.....j...\..0............8).......b@2....... 4a@+../..a%.,.........J..../L>.{..].o..49....P=...U..p..`.9.?.,...M..i9..K;..d.l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):498
                                        Entropy (8bit):7.631301707147887
                                        Encrypted:false
                                        SSDEEP:12:7ngI/xj8D9MTd4mYdgGxXglgk4q0TAp7aE6wKBR:kuh8DfqGxs34XTAp7aOc
                                        MD5:B421A0D2792A61292EE6F01FB58D31DA
                                        SHA1:28B0B3BA711D7A88FA4A478C06289A0F66E57DD5
                                        SHA-256:6712B9B34E731CD6EEE45C78ACA14CD4BFE3F2B8B068619D40FF1B251376CE20
                                        SHA-512:F23BEEDCA43F973D207BB7521633CB93F07E35794247197F0F31B099C50D949CA3E8B65421066190C0EFEE85A1A17F8ACF43697BBC2D03A06A5EC62CA30BF95D
                                        Malicious:false
                                        Preview:0...I.n.=o...1........w.(4.W.0.....PQ)..`e.$.i..%k....7.].....?.zT.Wo.Fy_...t.....R....?.#...HuA.E...a..(..SKG..jJk...m..=.6.._pC...f9...M..[...,..p...]..... ...p....B.C..q.2p5.-.s...Fe@..?..../0.S..F........#...]t.2..37A1.....N[.{...s"...]p...6....L...$..d.......Y.F....)a%..,........g..@.5.*..-.U0r.N.CZ....O..g...|..K..X.i4*g.v4.q.Q..._....e....;r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):461
                                        Entropy (8bit):7.510952470046921
                                        Encrypted:false
                                        SSDEEP:12:imRyXMV92uKNUlmEV6aqWY7ikN9xgK8p7aE6wKBR:FRyXMVgruK8p7aOc
                                        MD5:AED6071B88DE0138A8662C9A14D08D89
                                        SHA1:30D3E0A124EDCBA11127D3229878F853F84F7957
                                        SHA-256:5AEA0E2B2648635B1E65FE7355D25671B8FFC1517EFD98C429A3C0BEDBEC2D9C
                                        SHA-512:4D4492BDD0E29BB6C9AB92B3C6B59234B87A3285E9A527EB1E74F3DD818DD9DFED60DA4687EC674E7DEE659D44F1A99464276A2BF53AC42E684D9D8630C41DBA
                                        Malicious:false
                                        Preview:..?,|.....,&.3.lK.+.....N.....Bw...+.1..w.3CJ,.):.9C]C.CM.I.)i.{H.;.....H.K......O.F(.q{...G.......i.../..a..y..Ex.~Z.36.. ...m..P@.p(.....N....._...b_geu..J.....y.{..L#.3.......{. .u...&..<..T..Y..$..-.D%j..i)....q..8Ye......3.W...S}..a%..,........d....?q..Q.....S.(.M..t/1.:..d..F.L.[......g.$......b....d./Cq......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):467
                                        Entropy (8bit):7.4902959593102265
                                        Encrypted:false
                                        SSDEEP:12:9o9qLTyNBROojt8WJNGVyHEOa9FEp7aE6wKBR:9aqLTyNeAxdER9FEp7aOc
                                        MD5:BDB33E3CB0C8A1A276C915A1C23150D1
                                        SHA1:BA8EF213AB63C231AD952F13A3B509678BB2C5AE
                                        SHA-256:4C1D1543EDFB743A85C19160432DD829E0D07D9F451386890393F2402E9E4796
                                        SHA-512:451CA323A33B3F04860927429BA540B4053428E9A2434F8787731606E895367CCF089DC9CA9157FE7977C41F1371698F65AFC8440E72DCFB3262BA3F61A71533
                                        Malicious:false
                                        Preview:.X.W.+...Y1.p....=.qi...>.7..G..U.!...t.kmd...2...o.c.b[b...S$...._..}..l...Fx.....K.\Jy.K..n.*.Y}.mq1q...U^. U:.#.9x.......y..U..m..Z.~...<.8.!...b......;*..g`..`...H.x..V......c6...8..j0V.%.3......O4y;G..P......<).......[.v........R......}..a%..,........d..#..f..M$..T.1/...)..K~2..3.\.........-=j.`j..M..I.Am..0..x9a.r.q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):461
                                        Entropy (8bit):7.541145292006904
                                        Encrypted:false
                                        SSDEEP:12:fnlF8Xj+jiwbOx/xUhlac5ozAw9USsRIAp7aE6wKBR:vL2jsbu5UhlaLVUSsLp7aOc
                                        MD5:3C7F804D441528BCA35CBA2CBC10F7AF
                                        SHA1:750B91793FF2484F69A6708395664EAFCAA15B56
                                        SHA-256:CCE6ABD60EE8116971A3A0B7401D7AD2CCC1809F7660B03894C809EB791FFD9B
                                        SHA-512:255311629E81735FBCDDAD542486FD6F82DFAFACE7539C81BA907E2262AF7524C1DA442FB5EA9A41E33CA05F5BF6AC02A92E8AD93C16CD15027928D02CA56CFC
                                        Malicious:false
                                        Preview:.~..yd..;. l.H.H...D.KH....l.+2R.#[:..A?U..~.t.-............t.'.z.;P?.F.s......n..f....}...,U@B<..1....z..W..T=]5. .p.....rR.+...OG4/.o......|A....].nY...-N...."YZ.z:&....X.j....)~...%*.2...4.T.p.>s..!..8).......J.'.......t....lt....)a%..,........g..@.%1.#w.*.P.....,)..`'=.(R..vCEtw.0..|.h.h.]..ML....I.h..3...r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):432
                                        Entropy (8bit):7.490322907647473
                                        Encrypted:false
                                        SSDEEP:12:UA9JmuCGJgsQQc4ZQH9AYJjAZ2Mp7aE6wKBR:j9JmuCGJBLFQdJ9ap7aOc
                                        MD5:2BDC7202EEF969D1D38E874722F9EFA3
                                        SHA1:D094752CB74C86D9EEFFAE41DECE71AB062225E2
                                        SHA-256:D061F4C398F336B42C3448E37EF257C7E9F4317982FD8A3779FA53A82B45DC07
                                        SHA-512:CD5CF510BF41315601F385358652EED2C670520E5CCB4DB08E254B75F77D484C4959CAEC52FEE343D11993B8B79AF2F19563F73AD64EA796A0063C4E6B01C0F1
                                        Malicious:false
                                        Preview:Z.g..&...<......~......(.Rty..%.r.t.,..K..[..;Dw._s.o...b.a..QR............F..D?k.v.@..U....pE......b...x.y....O.}%=cE^k.u.^..~...4.V_3y.dM..&.....c.'.z.N.z....~..^8....[..n)..S$....0|E.U.g.s.f+.t.......@%.~........d..@....`C..[.R.p..P..#..PI@./.......~..MB.b..`0wkC1......*....8@.s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Secret Key
                                        Category:dropped
                                        Size (bytes):431
                                        Entropy (8bit):7.462804370231982
                                        Encrypted:false
                                        SSDEEP:6:6lI51CurCJBeAgezywh88ydbX5WMERtq478JZdqlcOpDxZDp78frSJVgxGnFY227:68CdyeXh6yMiq478pql99p7aE6wKBR
                                        MD5:19B095068937FC7E2C191E2847F9899B
                                        SHA1:B05BB7131AD6478DB68DB3C42987800F122D3931
                                        SHA-256:11143642562FAF666E8B622E3650F6E44042163435121B9150FFF1B666B95318
                                        SHA-512:272D567155D13742C0B573FC17A143180ACA2BC89E87B36142BFDE32445D4A5FD723251E514D055B0EB970B95FCC17671A949EFC2070DE2FE55274ADD9DF0C97
                                        Malicious:false
                                        Preview:.X+..>.Z..Q....oj.L3.2{..Q.sN....u.Z..5..AK....b<...!.V........M%W......k. *Z...x.....x.O..L..%..Xbl&.n.x...;...J.B....Eg&...>.C.....).J.._....Rb&.7...m.....:Sj../..>_.k)..n)......~.4Y6....U..@.R*H..@..a..,B.......d..@..W.%.r...i...7.. .r..na..dw?.gv.......F..?@}....Z%#E..O...t......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):462
                                        Entropy (8bit):7.543345289432834
                                        Encrypted:false
                                        SSDEEP:12:b/WdUJK25K7/HUZFTdtyb7UikEVjUTixaQup7aE6wKBR:jWduK2GPUZFT+fUf2UTigpp7aOc
                                        MD5:F294C4A62C681ABC01C1B8F475883451
                                        SHA1:CB05B51F6BC73B1BC4B5EB828079B8D8F963F510
                                        SHA-256:C3C5A5431343EF83795A6C6832DEF414C6A2FF27FF18E54AA41B68ED29773634
                                        SHA-512:974BC7063D4161406AE34B40C308F3372ECED38019A65EC100A751BCB462A385528619759DBEF58215ABB77D3F59CD3FF7601A4F3A11C65840245272077BAF1A
                                        Malicious:false
                                        Preview:...[.4..MELy.S3..nl.JA....."...-.....jm.^.B...*60..f.......;..e.>.....H8A\'..sO.o;J..p...C..^]....W.Hk.^..|Qq..H.oH.._."F.]..c.!&ck..-0.?.x.=.lc...H........]].P.0_=S.p...q4.(Q.....}...iH..Y.tB.. ...:3&7j....P...l)........}..... ....j..S}..a%..,........d...8......fH.#.W`Cv.<.YL.f....K..%.b........5I.WM....)Hb*.+.*...q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):438
                                        Entropy (8bit):7.516306846514175
                                        Encrypted:false
                                        SSDEEP:6:mQsJj5G9yeFKcbJB+T/hs2dLZf/CJggK02TbgwmtD9WRpTkgsp78frSJVgxGnFYN:mQs6V5bJITSKZf/ezq/1wmCp7aE6wKBR
                                        MD5:E089B30ACE848CBF6E998E87DC0D2189
                                        SHA1:B39AE469460FAA750E5CEB5E00C50886D7D6252F
                                        SHA-256:83D3C5CE5C5FF3ACE2C44BC70DD3C7C32896E6E1E40EA3C6E62C5E6605C5D9E4
                                        SHA-512:708C8AEA0B70401C1D116F01B9102E0BDAFDE3AF6E90EDBF089CD4BC2F1D50D3FF0520A3F358A33455EAAF57F39818ECAC0BCA7CDBDDB4C776E563FF7D6A6C1C
                                        Malicious:false
                                        Preview:l....._.c...E.{S.....5.u.f[....;..c..lyz,-8..X...0#\#..#..{.W&wM....S.6....@.5.X......Of..La!u....1...#.Hq!.[E...;W`....<..{m......b...4.8.w.Qe.\..Ad........3,.:...G..^..tI.U...>..9).......d9.cv.k.....D.h.>k.}..a%..,........d......J&\.\.........gb..2.U.....M..\w..f.L.....\....,8#B"R.H.q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):497
                                        Entropy (8bit):7.559875144251548
                                        Encrypted:false
                                        SSDEEP:12:j24zjIaLz3kbd6h/jvH6XYQbiZSvUvYp7aE6wKBR:x5LF/DaXYEGgp7aOc
                                        MD5:571F3A014C63117B26E79F7A40EDCA44
                                        SHA1:125D5ECFB339E6678B175763336F121377D000E1
                                        SHA-256:89BC87D9B47E3A66356FF8B7E50D24AEC891B836D40340847482C8F779D85882
                                        SHA-512:E7CC775453B3E856A6971FFFE8ACC5FBB2D927FD33FF4C0483DB6CA007199D064E9D9DB4ED765A93AA06C0C74313EF557DCDE574471B69A2E6BB72AC22B4FDF8
                                        Malicious:false
                                        Preview:n..o.F....T....8!|..9.Tu...8.Nu....w...{?......|..X.&.#|i...nn.[#.[.H...b..@....8.O.KE...|Ro<R.G".........g...h.x+....92.....B>,.X....|.2.....'...........ty{..Q.vO.0 ....<...2..9'g..C..:.m.c: ...(?.y.T6.,r.9......5.|....._....m...~.{..x9...9).......t.....<.......P...@%.~........d..@..a...0..~%.a.Y..,>.6..,i.0.=...7FIL..*.<...].).D...7....V.H..s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):463
                                        Entropy (8bit):7.4963809783184505
                                        Encrypted:false
                                        SSDEEP:12:8fCbecRBkKiZti+fDfMoifJ+5p7aE6wKBR:0CJRuKehfQVfJ6p7aOc
                                        MD5:A50A0586E17237C46172949CFA666C7D
                                        SHA1:BC8591233DC5AFE074B43E7A8747CC7F96A2D98D
                                        SHA-256:F67D9E913AED1589CF074C0669F06CF9EC6C0C772A146013715D889B271DF828
                                        SHA-512:352CFBAF4093D0514758C8604279C31046C353806F8F30BF8A18E66136F8A125562996BC7EF66883227E728F9ECFD3268DE608ED805007E125B856068E97FF33
                                        Malicious:false
                                        Preview:...E..cT....w..!.x._9.m._._....z.:o.....8i_Q...w..C.2Q...zw..\..9Ft.`..v.<....!@.z.X...I)..]2.d...2c..?W.iI....[.rE....`...T.:9<...0......:o.n!/......).~..4@....Tl..E.k..T\ .....^....o...27..........,V.%.*..i)..S$...2LbW.s.......P\t.K..)a%..,........g..@..."7....W.xB.j,u3Yo...h{....X....{.L7T......>.&...H.2..p.`..r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):455
                                        Entropy (8bit):7.487620684959679
                                        Encrypted:false
                                        SSDEEP:12:TQKJDWDFurgX/JXsJX81byWiv+dxZ1Dyp7aE6wKBR:TQ+ueGxXsJXma4xbyp7aOc
                                        MD5:BEA43A04D40D0F71DB5054CA997D5B34
                                        SHA1:BE84D437961E2BCAC016AA23F34211EA28BCE7E9
                                        SHA-256:A5624F1A77C2AA1DA73C622797DA4F0819EEAF14093DED8A750493DF34689E97
                                        SHA-512:441A2585C8A920EC241DF79AA24203930437E48CC3C4129C99C759988BA3A17AEC45AC9270AD48AC64CCD5AC621F989D5A113674869C62C983884FEF1F242C93
                                        Malicious:false
                                        Preview:...<op......>l..uC....m.I.e....z.&..&6..+[..a...UZ:.)D.+..8.....@.Ro~.R.PV..0.de.x....5..B..E...b[H..G..?..p.V.......!7*kj....r.aA.hl.%.....u....|}.X....Lb4.n.W.P..U..J..".Ga.0Y.vu.:.....R.X......>)......d4.cO.........?...h..@%.~........d..@.6..l......B..s.{.T .{:.G%..R...;.!...{..,.7..x==.2...,{.+k..s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):461
                                        Entropy (8bit):7.537205418924941
                                        Encrypted:false
                                        SSDEEP:12:g4/0FsuuvsxGfbbCNlvZmKkP+p7aE6wKBR:B0dm1nCw/2p7aOc
                                        MD5:18566FFC48FB4A80383AFDAB099BF950
                                        SHA1:41032D1ED699299CD02E3C9F77B84642DCCB660E
                                        SHA-256:AE9BB36CD52AD5F5FBED0DF7D85E6F146E4E350843DC54D85AEA3E7D78786D0A
                                        SHA-512:CB4D891FB2AD9BDEE6265A72A3FF443B5B76727D0838C8C008D67CBB38867ECF6CE888FCE2A95C839E007C24F7EC77C5C8535164B6E8024C68BF5F3C0CBE9874
                                        Malicious:false
                                        Preview:j..-..2.T.+.1...;....h.d^..d.e..}!K...F.bcY.:0c8..P.~..fDA...^{e..RW...u..aS....%/.a..N=.X..._.aZ.).B.}l5Ys..r=.......2. %tRy7.>V..c.......G.l.. ../.VY...%..-...{.Q....:.H..{(..Z.......Y..-*..Q.:_..'.r...G..>)....-...p..l.....R..j.c..aw.,........d.x.3.6HP@....o...U.......~X....4..E{...8.j....fA...6........Ap......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):478
                                        Entropy (8bit):7.546105056210775
                                        Encrypted:false
                                        SSDEEP:12:QTHuyaef5y7IpZALA4SKlmxeIVwF9m8Sf8Zpnp7aE6wKBR:COJNI0zSKlmsF9mp8rnp7aOc
                                        MD5:C199900B9EC67D12F46230E755739233
                                        SHA1:51A3FD0E25062F7A0547DE2232EFE455823F2D03
                                        SHA-256:6B0A11F8AE834191FACE1B0C9F84C0B9A7E3DE418DCB7BB4E2B3F7E1CE3FD785
                                        SHA-512:882985A06E392987F34FA7703181995370971C7EE6A1DE8BD7E0DB4DC49C1DD2276FDE310B8281D9798973B2ED743824AECFBEFA6D0E575883EDA2704FB3D6DE
                                        Malicious:false
                                        Preview:"....4.3.U...;.-......"..M..7...,?.1_(}.........c.FX...{.p .k.A.n.......P.....D90$V......J...h4.^B.7..ld....,...-...T".td.j.9L`...@. .\D.>...u...N.b..4....a.4,.)a}.\&V.e....1......d.O.-^..-..i.....w...,#..@..y.l..`A._.F..=)......I.s.........>].....)a%..,........g..@.C\.?.)..i..`~.....E.).ij..r...$..#..2.>>.u/..U...m.h.w.3%.r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):465
                                        Entropy (8bit):7.558487498594847
                                        Encrypted:false
                                        SSDEEP:12:sWZtwsRRaCTUS+tc09Yl4BxUkq1vhp7aE6wKBR:sWZtw+AIKc+Yl4Lq1Jp7aOc
                                        MD5:E20E9820A4BF36F857F2D96336499A21
                                        SHA1:1D3D0A62FE7DB4EF47285D400D999A6B6D0B46E4
                                        SHA-256:16C174AD19114E1CD306291DF5DC90877A80CA441623BBDB1A946BEF2C90F1EE
                                        SHA-512:C390AB633D7566DB25B404085FA0DE4A36FBEA846E0537AA6D823A9410594E69ED23B7FA594FC83A03C6C410A23EB9E4791DE51BDAD943D0C39910F4173701EA
                                        Malicious:false
                                        Preview:2....o......}.w...Q.|.J....>.yV.....#..f.m.}.....`.....PK.{.d.G.#.S.u.0...5..at...i..2'UlnWa.Q`.....X'z6..6..9t2v....M.<..c....C.Q...~...n....._.x......i._zL,.5.....a.+...z....%..M<..=....J......1.{.n..&..>...7)........t...).....R...[.K..)a%..,........g..@i..(V.O.5}wSp...-.Ufi........p.!sG.9..M...s.@./.....!...Y{.[r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):457
                                        Entropy (8bit):7.560342280745405
                                        Encrypted:false
                                        SSDEEP:12:UK4880lBJwHYuDJNl9S6JBwSu3nTGVsp7aE6wKBR:T4880lBezNu6Jid3nxp7aOc
                                        MD5:16339B026FEDDDB30660F64FB5F05701
                                        SHA1:5BD006DEE03AA4656D6EED0AC75B16EC6BB6221A
                                        SHA-256:64D2ED69C9B9F1301433B9DB5670C3C643210D57535754A1FC9E250D0D99BE44
                                        SHA-512:267B57BD774C6913FA3CA725BD6BB3465C9A9D95161917BC9DCE2519D48625818C5ECD144AE5F21F82F4E56C7F0852F139FA5E1C5E21DD58960AAD492F794FF8
                                        Malicious:false
                                        Preview:/...a..............$..Q[....6...........\\7.\4..j..IO.>CB...o.z;Mb...=D...<re>.V./.....'.en.........lX...Q.7...]..Lb>yt(.}mH...rqQ.8.q.l'f..h.tv.b.#..n.....w0...-..a..6..y.N,.aF.; .....;..Q..........9)..S$...9Q6..........>.&..}..a%..,........d....}.`.y.T.T..s/4.Xr=.Pl......D....N..1G..t\ku.U..+.P.1..q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):466
                                        Entropy (8bit):7.49349919021771
                                        Encrypted:false
                                        SSDEEP:12:5yuyqeIAfCcuFANP/TPfckPUc0a/rAp7aE6wKBR:AEYCcuSP7Lcp7aOc
                                        MD5:DCBE5A41A3288B0754B92D0EBD282705
                                        SHA1:0240CC21D9E430863A75908F9DF98AF037640DFA
                                        SHA-256:F4B9691CF9827E627A8B3FBCE15318395059582A9B82EB2F0BAF76A0BD08EF40
                                        SHA-512:108CC751745A43E0D01D289A52FF359E2421C1DD8811D99A434838C6E59C7A6FB6FB00EA0A8B9180AE9F3C81ECE6CA8C99FC7EDEE2D3C70D9DA81C374B4AE065
                                        Malicious:false
                                        Preview:...W,....J..%...H..~'<..f.K~.<....#.V.....4..I.+h.>..:.J...U.X%C.v...Aa[@..m4I......K..>...?..Y...|.>.0a.]..7.]y..%C...........~.R#...f.......r)..".."..R_....O..Z.X........J6...\...;..`.\@......X...n.%...}(1c...l).....=.&g}........}.c.+..}.[a%.,...........s".h.g2.....9.a.z[..C. .v.W}...]......(].}....w..u....+.Wn......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):481
                                        Entropy (8bit):7.6112356190533
                                        Encrypted:false
                                        SSDEEP:12:cu8Vin79az61TEr/Uu7D1gdtWZ/A6K4zxaYp7aE6wKBR:cPVa9az61AR7qdtWIYp7aOc
                                        MD5:B703961F95B0D9B6C92FDA9657EB11DB
                                        SHA1:39DBF6D47D3548EF85BDD6EF86C89215776FAC01
                                        SHA-256:F8A862865868BC6674100E1BFF80DCE227E168F918E0064AF4EFEEF2FDEF814E
                                        SHA-512:35F214EC5962BF870618989BBE49080673E0F2DA45D56AFE253C37B79A55EE8C922C162E0B3810647066E1D706A7D280BBE8DFD5380A89135DCBDC9B2A4FB6D3
                                        Malicious:false
                                        Preview:q..E.Il.`+4...........u.?..kA..26t...s.Q.....J.ujO.d:......dB..w.iCj.&........."...B.[..L.....9z........[........X.>..6._Z8..=51.X *...`.53.g.c..U.V.J..Y.....S..w.1_......s..2.E.m.T.Q..r../8.E...i...:.-o.^.....34;..l(N..4...3^`.....k...Qxtk.}..a%..,........d..0/?._.|xk.rA.+VM..\.u.V..!.........1..X..L)..XDeC....j..K...q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):438
                                        Entropy (8bit):7.495427287090142
                                        Encrypted:false
                                        SSDEEP:6:HNZWOLe2MvlTKJ5zDhsNtmfkLj6YOEPzdJZ5nCxEbk5p78frSJVgxGnFY22w20Fi:rW5HlKXhsN0c/6AHHCebkp7aE6wKBR
                                        MD5:CC6D0BE1A6DBAC797919C00FB910D137
                                        SHA1:1C9EE7CF3FFCAC63546768D575F2A080442F07D8
                                        SHA-256:3B138E6B33FA41F14181E82DD5258F75A3B3CE93CB84052F9B5C1F7B5F796B94
                                        SHA-512:33804C40932740FCF66F593B90FDDA52FF6DD0B7288EDBC7F983BCD1153598B17D48D8E4AF9A078E3DA2FEA7129C13E22B6CF03624C93CEA48D1F1B2AB6E861B
                                        Malicious:false
                                        Preview:.K...]..kh..]1........;..eCp..=.@.3.!7i..el.W....0.|...../.dq`.,..0.e...6. '... ...m..+.~{..j1@<f...s.d=.4E./....\oq.Z..V.6.....0.n.$0.uY.K.Z.......xW!..BY"H&..GK.r.a..#.G..6..#.Qm..j).....:.8.eW.s.a.s...Wzt....)a%..,........g..@...nl..(.k......sQYR>?......m.....R.......S..yO.........>.T.r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):460
                                        Entropy (8bit):7.549974766394187
                                        Encrypted:false
                                        SSDEEP:12:bkFPOWowv/x5KI5jrOLXscfTp7aE6wKBR:4FBoazKIZrTcrp7aOc
                                        MD5:92044876E63ABF73596B5F73FA9A9918
                                        SHA1:7A40B63D3E7CD7C4AD8D50F5626F8E4143AEA109
                                        SHA-256:0E9AE16575E4E492A685AC89D076BD054D420A67083F104BF7DF8DA2FF572D1A
                                        SHA-512:765F20B7EEE03EE18CE6B3EBE2546B65045F6995AF8FC6600CB45F1C1B6F38FE9D507B54A366FEE70A9DD55074A9E07534F5A297430A4A62450AC878326A8D60
                                        Malicious:false
                                        Preview:....0.....[LyP*.j....g.<.....Q.@b".}:...D..A..........3..........[........z.H.....M.7_H.n.7....X.d...}L...+..zI5.r...B....Oc.....i.[....^...(\.Y..`...........S`..A^.....5j...4..9..E....D.p.X}.K.c..p...>)........'..U.g.]..,.oo&....@%.~........d..@....{.....~Y.C.Sf...`.O.vm....>....R35..y.K...{rKtd..1.. ...#.I5s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):463
                                        Entropy (8bit):7.556299439591964
                                        Encrypted:false
                                        SSDEEP:12:jRQAYb11+t38yLG+HXurXrMFbRgp7aE6wKBR:GLQd8yLG+HezrwRgp7aOc
                                        MD5:68A205561C0B288CEE0CF977A87C9C12
                                        SHA1:3A3F866485B006FFF839B8048E4AA69F9507B720
                                        SHA-256:FEBA7DE4E0BD982351EE34BB4B10DB8A85FFF409354F1E6265841EAE2350062D
                                        SHA-512:6152F10837C57E77AF4374C296EEBFF4D88EC918A03C3E5BD352833104C8B8A797F3A41545F0F67F13ED47798ED6DCC195DDABED72F738AC3370EA6C3D1A5CBD
                                        Malicious:false
                                        Preview:...}..#.F.......]..u{!..1../UbY....R3......+..U+...k@.ti..'. R.qy.wC.....U..s?.J.H....u..<,,...O...,..5....@~......J..m..v..P.nm.$.>%|0.D.z..2...'..]0.L.t.E.....9.=[.{...?.....C.........F.a.:...u..0.%i....._..=).......e.]7.....)..Tbt.....@%.~........d..@...>R..m7..U=i....2U........3.?.x.%...F..X.S-..9J...&..\...s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):475
                                        Entropy (8bit):7.598209809507958
                                        Encrypted:false
                                        SSDEEP:12:4m+JeHzXLwGzCyaJqyX4pOvBBHB0DnkSgdBp7aE6wKBR:41eHTkGu6w4pEBhqnkSYBp7aOc
                                        MD5:CF4999E598BAADA1A2041F95C4BCD34B
                                        SHA1:4C4B3D1B1FC9BFB71B719CAFB36500876641C438
                                        SHA-256:669B5B4C256CB1877B087D2F7AD2265CD21E5B0F41E04D39EB030A8318A3AAF7
                                        SHA-512:0751F9DFA0A1DB2897965F9BA6C0BE4A1624A27715BBA4805084250BCD6FEC5C9BFF5930B9A254233A55635EFE87DA35ABDF7C1E063293E7FA797E70C29F15C9
                                        Malicious:false
                                        Preview:6....`._...v..T...S:........1$..*;...D...".....?..W.p.V.."PY..'w4.iJ5...<..5a...Z.2...v...............=.|k........b..N..m....t....HF...6.U5o...y.ky.0...>......W..A.._.....P.~n...R.Mj..d.....^I.QP......&. ..&.c......=).......d`..........@...[.K..)a%..,........g..@6..8...Q.7q8........t..vl..+E.9...@.1>..l.}G.WF..q.k....7~...qr......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):464
                                        Entropy (8bit):7.5207988060029685
                                        Encrypted:false
                                        SSDEEP:6:M2UDoZ32CIUuCqnjytk+wjvBYTA8rxJRHdd+2NcUkTy+vQ1CVsp78frSJVgxGnFO:M2UDk2CIrnj2XHx39TNk01Jp7aE6wKBR
                                        MD5:30F14487A0875CF523A0AC4192ADB648
                                        SHA1:65594E81618E197F67D767A1394DA1C61C25A4C3
                                        SHA-256:E44E340D54B83324A2DBD1FA8E9165A26D9E6060F718CD7B7B738C7D955A7D15
                                        SHA-512:4870B5477DE07F0C54816FD755F25CAFF76E5F279F4B7378548EAE389A15555845D245C4FA9B70098A17F3752F3AE65095C66F2F89B261078A5AB7BFAD086067
                                        Malicious:false
                                        Preview:..S4a...=C..Y...U.....l.@.Z.A...............Q..U......../.Mf...s>.f..,.....y... ...~.!......x.....\.19..(-...o.=.m......3..a..[.zd.toR....1`.SP.l..{.V!o.*L$&..57...#3P..=bY..@..`"G..bT.o3.3..=....x..j!.n.3J...;).........w..6......>F...}..a%..,........d..E...........+..bK...9.k.q....+.....T.iZK.F5r...!........g..q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):460
                                        Entropy (8bit):7.5285148554849055
                                        Encrypted:false
                                        SSDEEP:12:9mtFNveD+7VJJp63kkVWJbqHi1Ap7aE6wKBR:9GNve4JJnGMAp7aOc
                                        MD5:ED2E83CD8250AABFD42586F549D84ABE
                                        SHA1:E39B76C2F160AFC57798325CD0D4878B6A528FD7
                                        SHA-256:9D20851821B4631E438B060D7DA1596CA5F4CF4C22E5576F51DF3E751899B520
                                        SHA-512:2F791E0B8FC992A3DC26C717B9092D74F58138A43268C51128C5DA3B4A38E805579DAC8674BC9F90A39CB1D4FC378C637DCC61E5502E132AA5EEC0DA34B6FFC8
                                        Malicious:false
                                        Preview:F.W..)....b.........9M.5s?{.b....)\.9...:4.m9T....f..e?...<.C`..h...p.~.3.~..9.......]?.L.I?l....d....M.%C......rN.....Q... .^....<..F.6..............h.3.#B.....,..T.....(.G.<....R...yc.U.FK..d5.@....9..7).......I.!.......:.7>..5...)a%..,........g..@8...Fm...B...T.f...G......tf....$.N..?..gy.)n.XD...m...v.?......r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):440
                                        Entropy (8bit):7.538782605673769
                                        Encrypted:false
                                        SSDEEP:12:hQAToo6+G8J3xU6+0iNr+WOx1Ap7aE6wKBR:lToZ+l3xTiUpAp7aOc
                                        MD5:0009F13ABDCE891139037501593DC0D0
                                        SHA1:647540454AC7FB3D0486E47671F9CF9C04F7AAB4
                                        SHA-256:2CD9FC968B50293EF958D06307E4A1DD4A3524C311B32E3C5B7EBEEEE0A11D44
                                        SHA-512:DD482ECABFD09A5E69FAAAD2AA28D5C9AFC59A2034D0051B701E29F1DA7FCEB32985ACD7B1E2568FF1B2A7CB0368B9988F568486912BB56DCB307BDFE1F06629
                                        Malicious:false
                                        Preview:.O@r..S.4?.`s\....J.D.n../.lb&b.......z6.8.F...^.H....agZ...~...#./....._M:.ZF..C...'K..LuLgj@.}...u.Z.= (...,.B.a.e...H....:x.l..M.#.&.&...0<..f....n....x9.....!....-...@.......F._.gE.m(N..4...1Yg...[...W{t....)a%..,........g..@5.hO.Fz-.1...k]]..g..v..G.;.oxS.+)n.l'.....Y.H...5...1....r......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):469
                                        Entropy (8bit):7.5448476862907725
                                        Encrypted:false
                                        SSDEEP:12:mxs0i34q2+3+jVP4JrZQ7fz1b5Dp7aE6wKBR:mx04qjujoYf/p7aOc
                                        MD5:32C2C44DF43F127CB1168A3B4BF4CF9D
                                        SHA1:B68275629E8551E8D233DB0C56EB798BC259DD66
                                        SHA-256:98A4CE59EEFF233EFD10EB691BE68A6F8CFF2136CBDAC0D10668BE95FA3F65DF
                                        SHA-512:1DD13AA1C00ECB6A1B104D08C948C7B5AE3FC46BD70F40E41F8D20C3816EB4B8501BE327B945F842F6A008CAF903EB842C76B82073B953649961F564D024D238
                                        Malicious:false
                                        Preview:..3....l..5..S..j....3.......d.rS_.y.Q._..<'.8I3K.....-PY.;..8...|..&....f..B....pC.wN..... i..H...6b..w..U..aIT2...A&5...9C...!..-`.^.....1z......J..GFi.-.L......y.G.t.9..v.L....y`....4.J.w98t(....Y9.GeLF.9).......5.9W.s.a.)..Ec...M...%..,........d..C..S.;.....@."R.X..4..`.\_.\..5%T.T...r_bx3.Bb..f./.X...^...M.^b.u......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):291
                                        Entropy (8bit):7.249853114375779
                                        Encrypted:false
                                        SSDEEP:6:Um9xLdgLYzh9uGgqloGsjvO0pn7sp78frSJVgxGnFY22w20FCnBR:UiNOK2Gsrjup7aE6wKBR
                                        MD5:E18EBD9758721ADA036736EAF8BF638D
                                        SHA1:DBB39B73840D2919A90A04CB133468D95A4D3264
                                        SHA-256:BBEE3D595C721088D6C4868EC9AA5B7CD569AD003C792B75E2874CF4C35FF244
                                        SHA-512:30A04856276317EF6B83D39B850694FC6CEED941DFA5072F0AB6F03FE9AA65479CDB2D7F8FE0F17119F095F6C06EBB74BF07CDCF86C267F9C788BE43484F765D
                                        Malicious:false
                                        Preview:s..jy.$..8..D..:..2.~..7.,a?d>...."S?.U>..3...5.P.g)....-...)..U.g.]..9.aZ0..}O.a%./.......:...R.3r....U.....!....7..y=".....{M.7.oZ%..|...%.xY...7$.:m......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):253
                                        Entropy (8bit):7.173376627908607
                                        Encrypted:false
                                        SSDEEP:6:1oD2HF+T1cym4EIpTD8h1WpySEDp78frSJVgxGnFY22w20FCnBR:1e28Ky/RpTD8h1MEDp7aE6wKBR
                                        MD5:59C84B3FF8198C8D1F4C3CF67B3EF947
                                        SHA1:336E06B6F796B1ACBCF8349CE6D687677EF1C1D0
                                        SHA-256:ACE7896D12FB007F9D922676C6CE5EFD4453A9C44478379031EAE27663E72623
                                        SHA-512:EB88F431BF891F20514357368BE7466260144848613C22EEB1FC5B8D28A8BB5DC35358AEDA4695DF0528229572D8389C6CF4D386700396A4604B700B893D6CC4
                                        Malicious:false
                                        Preview:....$c.....-../P.2.yB..M.a).....R..H........!.aZ(..}.s..Zq>.$P,&.Dw.T...0*D.v/...l9......B..*...~.........y...n_......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):510
                                        Entropy (8bit):7.570484578254997
                                        Encrypted:false
                                        SSDEEP:12:Mc3EPoxEz598WoL2PeS+zVTkR+fp7aE6wKBR:zUPOD7FTkR+fp7aOc
                                        MD5:97BE29FE47346ADADB783713C5A7FE3D
                                        SHA1:39BE935FF9122120B20618C1D5E99B7F431B48B0
                                        SHA-256:DDD9F67B9B066CD48CDB876BEED144774F9B8836BF5581600B85B7372EE23B1D
                                        SHA-512:F4D0C7944BF41154C9965D23336211C2A3859A597DBA22560E4305817BEC0C58D64A18E98FB2395937A0FA44EA7C2C683A174AF05645C530F34838C19DE4D708
                                        Malicious:false
                                        Preview:o..cI_g.,.c.g.XB>..$D.}K.I...MB...7=..Y...`.....N..Q..*...c9...d-..M...^.5.v`....8L......-Z!B&...:Qr.....Q.K..'..r.&..Q....M.(a..~!W..{..\..<n.M.5@.F[.....u.._.....60.6..!@.B.....$..<..t....B.....Hf...1.I8......m.p.....H..>.P%..v.G..........t. 1.j..SO...q......T......h.@)...*.............!.aZ..!.f.5..&.Sk..9..p.............p.hp.}..9..4(.`.d....yD...pb..[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):480
                                        Entropy (8bit):7.549353176179337
                                        Encrypted:false
                                        SSDEEP:12:8YaScQk8vlN8UCUHJsOpiIcmAfp7aE6wKBR:8tmv8UCHOpiIcmAfp7aOc
                                        MD5:D52342CF500AAC22A9B9F07140E9D75B
                                        SHA1:A7DE77C4B2A6947B4824B389194722DC5D02C7D0
                                        SHA-256:76EA0169CE36BB43B03B52EF805E7EB5674C30C45159EEDBFB67907E8DD2B1E3
                                        SHA-512:4F27DFB891FADCB5EB620D7075F43E420EB7AF6DE218F60212F7C43A6290F18F241005C089E0F57B64628F0AF1A418D2943F12469BECDBE2EDCE1F972A665E1D
                                        Malicious:false
                                        Preview:Q.:G... =..S#..a..xsv.I=..:JO.....P..p.:......Z%.%...`x.r.....Vv.....e....k.%......H.u.=.}.=.."|.e..r.Y.c....._...%.C\.[........s....f.x.....@_..X.lX.Q= 9..G..n..]X.~...<.yX.2@~..+.H.....-.w..o8..L.....,...,y.P...!f..T...;..^.d...&.,.,h.@)......de..........".aZ(..}..a%'.-i}8..xJ.h.C~....A.z..'.O|.....7.g..CG.A.#..I..w...._..E..c......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.203880987666655
                                        Encrypted:false
                                        SSDEEP:6:+KHbEcB2c7ueDlLnqOaptsAp78frSJVgxGnFY22w20FCnBR:P1B20ll7sfp7aE6wKBR
                                        MD5:356CB643C4139FEDE1A016D937CDF571
                                        SHA1:0A1E2C43F1EE816FBFDB5AFF5278DE06485EA881
                                        SHA-256:A0AA1FB6574FEE7D4A905418A2EE724D74B7CAB48B7AC3B63616640A1AB76096
                                        SHA-512:DD025DF8AC599C5BA25DC7F501956A475D5E092DC4ECEAB7912AFA811CF758E11F81AC6C42F93CC6B5B6D7122AFC8705F978774642FD51EC49C22E428ACF756F
                                        Malicious:false
                                        Preview:.E..Q.4..D.z..^.g.Z). .m....G........".aY+..~..a....x.([.&|..B.eA]9).LN\.;...'......l.1..........~*..}.0b......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):557
                                        Entropy (8bit):7.642117255601655
                                        Encrypted:false
                                        SSDEEP:12:VL9fMwj0hKUOSAT/DeYvilBgef1gy+p7aE6wKBR:NnUebDDsBfiy+p7aOc
                                        MD5:7EDAC33A0824BCFB445222F7A616A316
                                        SHA1:D6103C2343CECA0C791D27C28A615904F8A7D7C1
                                        SHA-256:BB82C69C82200B04EADDD42C43B4ACFFF65866860153889AFE323F8703D12D52
                                        SHA-512:40BE876D549CB7DF85F87090E7DAFD2EC73A3E5C7B65079FC1DB1F507C089E8F9831C5D971CF3C55F84A39EC1C053A627B8FB6B70B70617FD03AE4687957E190
                                        Malicious:false
                                        Preview:!s.Uk.x.......e..X...Ag.B..g.....]....M4M.....nF.b.J.....Q.2.....V..19.4..1...W`.@....E.?.4.5.W{.16.}F:.B..n.-...v<{.....s....L.a.....Mi..>=...6...5.f..+.RjL4Q..2..?..z.q..=...c].S...N..JR..sc..1.....P...'...{C.V..&.7.0......!..l.h.z...p. .UC.4.....Q&t<.W+.+3f...~0..g.b;..\.L..^.I..vjQ.\.nk.....QF@.G.]...v.lu....h.@)...*.............!.aZ....[.w.p>j~...y0...6.[*..?.,.j......-.T............iK.3...c*[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):524
                                        Entropy (8bit):7.613510496956271
                                        Encrypted:false
                                        SSDEEP:12:uRjdlfiCvOWvPBYpktShfKWIOpiIvvwIzAi5p7aE6wKBR:uP5pWW3SktpOpiIvvDH5p7aOc
                                        MD5:ACBB5C6160A5F640C041C7BE336F56AD
                                        SHA1:AA1291C9E5B0AE64F06F68EB04AC084AE1969250
                                        SHA-256:5FB3895829F5D40607BC57B0C750A11B82D07B95A2C525A9DDCFAFEADFFE9A53
                                        SHA-512:12B95FB0ECC3F2B240F3C12A8BF53E37F35834E4256DF61ED8B3AD02C4DDEEB6895E13777CC47CDC8FEA02B61DFC399C0E634F57004366A0555FF64078E406F8
                                        Malicious:false
                                        Preview:x.;..D..aH.9<.I...H{....j...u....t..V....b?g...}.*.DH.......I....N..:.z9Y..M..Yff/.F.F.>.<...!..Q..e}.U.q.B....p.6].fu..&s. '.t....;..Y..DP..ELl.....t1AXe..>...@..j.N.a.X"... .......yI3.....9.j$...k.I).Z.]..t,...H.i.....w%lq..wmVtaU...;RQx.z?\.:....z.p......'.[.I.....).$.Mi.m.5iI.f.h.@)......de..........".aZ(..}..a%.J..=L.3...Y.]...........k~......C..o.....!.`]..h...9H+..sc......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.225162958301719
                                        Encrypted:false
                                        SSDEEP:6:B3wSHxzf6j5tDsq4kwAp78frSJVgxGnFY22w20FCnBR:B3wSHJ6jzVLwAp7aE6wKBR
                                        MD5:F3D83EFF832AD7A76EAFAC75C9E14EE8
                                        SHA1:974BD40C9FA325767241757F7980753B08D0A4F4
                                        SHA-256:32500A6DD1F14FCDCD7B1F5A1CCC2F9AB420A17BB7AD01663297D45C9243DAFF
                                        SHA-512:70A466E97889A548AFCE4A75D6CD992BCDA60F56FFBDB0CB5ED0F8C5E9E1B619CD40033BED4BD910D5FEF404DD06EC4D4B1337BF839E58B742875F37652DFEED
                                        Malicious:false
                                        Preview:......Y"..s...V.I..'.cHfX..k...=.7...S.i.N)......dR.Uv.R.......a@+../..a%.,............&1..a..y........H.......z.w.../]>''L......7....cN|Oov5.}fl......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):731
                                        Entropy (8bit):7.7004985639183445
                                        Encrypted:false
                                        SSDEEP:12:M/ufoY261cHZyaryVl34FW8I69AejnO1sFOTVlbxPeT7Z2rHxiIVgj4lp7aE6wKn:IufoY7c5ygsIWQ7jnesFQVlbxMV2zxiN
                                        MD5:D9C8C1F274C6DE03C007EEB49E59F79B
                                        SHA1:150D9737478599D9F6DE6FF54751F2A083839A23
                                        SHA-256:B31E5DCA0EDFA876CB3FCF849A04CB6995FD0E450AF62464FA7091CC5C82FCA1
                                        SHA-512:F2954AC977A37F8995409087F98F2E80204FDBF3C2571B9FB6250C2F5833270469AC1C21F51A058AACF6CB533B0777D6D149BEE22D8CA1958C7D709885559B8E
                                        Malicious:false
                                        Preview:P%......&HW.;.~^C.9..@e!X...dh(...]..S.ez..K..2.".A...B..b;...~.`)t...e.S.@S.2....<u.D-............hx...."-.Tb......Z..V..K.PM......S.........|.~..,Vdv....2.....a.s.z.....5S|r........L.d..C...-.1.{S....."@...M.L..2..T.s.7.......U...+....gM.4.c.0.#..S``..56..........~.r5...5.y......KJ]..r..1b.7...w#.s...H.Act..G.f.u.uv..3..s};.....2!.\......5..u.r...ab.JF..j...O.Z.!.=.D..W..4..*.#.M....PF..4.e...'.b...........&..H...U|.:...I.bpm.....L.s..):..<V...o\..h.`)......ds.dv.R.@.....Q4..}..a%..,........d..... }.O$.Q......_..2.,..]&L.|~e8p...Uo..|..#.[>.}.O...UdN..".A7q......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.241611799404381
                                        Encrypted:false
                                        SSDEEP:6:5cdpN1Dj5A7Audt0YKhMp78frSJVgxGnFY22w20FCnBR:5cdJjjudt0hMp7aE6wKBR
                                        MD5:67DE4F152F5087A2458069B44F4900A3
                                        SHA1:4EC46E95993AA94E9C8FBE4EA2AE59E055687918
                                        SHA-256:9A5BE67763ABF660C8956FFD4820863ACEDA9713274055AD34FC12A3B7203F4B
                                        SHA-512:F2926AB7C53FB3C0802297E44EFAA113338509E660D127379C27ED55D2F9DE27FFF8BEC0B9F7A0F208A8659A597A43398056E5D380025E43EB39C3381DE0E0CF
                                        Malicious:false
                                        Preview:.q.g{..Z..3..[N.Z0n...d.. .0..&.Q.P2..i.N)......dR.Uv.R.......a@+../..a%.,...........=|..5..%.0Hb...."=...;._........#..:..>..`....'.%Z....2...l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20712
                                        Entropy (8bit):7.990200264441056
                                        Encrypted:true
                                        SSDEEP:384:5mECzNhzi5gwMQeXYT6aBRA37MJ/oCn+b8A33wze77pkzwH4Lv3uNJuowH6RjHSV:5mESNh6HMdy6DSoCs8AwzIpkI4CSvaR8
                                        MD5:05DAF06C598310628264D13BED50074D
                                        SHA1:0B37AACDCF0547DDC0F031ACD4B55FE176E57492
                                        SHA-256:177D8F26AAD6D91A1BA2B1A47FE5434AA659A4359D16185970620CB5D8B23D7A
                                        SHA-512:BB9995B2BEFE1AFB3FBD29D507BC5CDE983E8CC50994C1CA3E9171887DAD811DAAB911A4644719990160471C20D0583203ADEAC956208AF9ADB89AA4D357F112
                                        Malicious:false
                                        Preview:....[A.?...o........Iy.2(|...+0.........F..a..d....E...5.@........M.......b.*.g...[mH.NMi....+.:..i=.u....V..0f..+.pii..}.IN...\..9.[.D...^.q..r].)...j.})Fh...Eb...O......:.3.b.'b...q.g.e..CY.*......_i..P.\.g9. W.G...;.b'...>> .{.>..JaP.4...\...4.....E.q......h..%.]qd.<N.u..WU.WL7....C.a..........yl.Z......nYe.\."*.k...u..Q.M.)K.)\s.x..R..eu.,*>k..;.=.g........D.%.. .....6....T;.$......H+.(.X\.9rt<lTs|....n.+...p ..Rw4...G.B.D......eJw_01:..f39c.Qi.%.#=]-..>Zz.....@.`..]..:Z......|.k....4......=..yQ....?D.E..B.T._m..Q..u.........m.......C..2[.F...l..M.m...c..=.k;.."d..{Wd.c....v....K3....E..b.P....j.F9....l.K4.0)...-..L.!N..~.....4.(S..j...L......#a....\>......`..P. kaeaH...]...-vE..$.lr....Y.8.4...#.5......e......[..0.|j..}Z...D.....y.3/.....U..b...2...]..@.k...RR.A...i...'....z.0D....x.[>BD....2..!..g.....O`]|.uK~!...h..T%.....g..$.l.........:.5..i(...}>.g...|6...>..U....zHT.j..?.....K.....X*63..3..FJ...t....S..?S.<.%....^.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Secret Key
                                        Category:dropped
                                        Size (bytes):347
                                        Entropy (8bit):7.3047359722664975
                                        Encrypted:false
                                        SSDEEP:6:hrlSR89ena1x54irBPyTMEt+m2L4s9RzXYDZMSp78frSJVgxGnFY22w20FCnBR:a29ekwi9AMEtZSRzoDZdp7aE6wKBR
                                        MD5:EE8CACE9C314DE258EA1A22F0F4CA87D
                                        SHA1:213D5271925B00E91833E620B537DB798F151F1B
                                        SHA-256:210E3757917D497541C19A5C54ECFA04A389238C1B913F5B4040B7E0B84FF517
                                        SHA-512:D76EE70C00A1EFB26A75F8BAE7FDFF22935FF611F17721465324623470AC30CF6B178920D572B651CC1256A171853B4FDF811DB006DF9268D8C595543EA86AA3
                                        Malicious:false
                                        Preview:..k...R= .N2...d(F..1\........#..X.I...7tt.."..]..t...../.a.....Z[...x.)....\..O..e+.|..oj.j)......dj.!v.k...)...CE..QN#lD.T.........d..C..SV.(.......".....T.j.M.\.n.z....6.,..!...o....T.x.]"...C.:Xby......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37113
                                        Entropy (8bit):7.994951147609178
                                        Encrypted:true
                                        SSDEEP:768:nS3gPDoZrbU83fQoKzNEVBoyurIO1OfW3:nlDoZcufQoHIyurIO1
                                        MD5:8B75C61F55AFE7EA92BFE4935ECFABF0
                                        SHA1:864E1ECC93A5E5073AF55BB1AB6E89281F9E9BED
                                        SHA-256:5799E667EB3C548A863ED67F6D45F7CC263723400C36769DDA08A4E5A840C25C
                                        SHA-512:66FF1D383EEE1C42DDE92701915435F2392AED39C0A4B5452C4E00A2416CD70807EDCC29F3F1AF4D899DBBE096FAD39865C6F0EEF4B67B9DF3C3EB7B1EA146A2
                                        Malicious:false
                                        Preview:R>.aX...Be.&...HDa59...O.ar.....U.e/..;../.6...XS...C.9.j._=.}..o........B.....?L..]....w.vZ....#. 2...rx...Y.[...p.......[.>F...*!....j...9..=l...g.mj>1...U.(....y.!j....mx<.g..^..1.G^?>.p2..L1...}..=.....u.......6:&.P.....)@....7&..k....U..\.}.".ZI.NvO.EJ..b...........K.[._%pODz^j..i..Z.^L..n=&..Dv..%j....W.3.D.C<Ad....'.;....<9..J.SaiH....b....|...+.OKo....?....C.|..rO.3.[6..<U=.E.B./...f....<w+..1.2....=g.....l.#$...=......,..........tX71[c...T.Tf.+..o..d...Z.QX.....~p.%`...K......(r}.\.v.pS..n....n...;a,..S.[0.d.0.........i..5~{...o.9..:V.Z.u....}.=..0t...g...=#..R.n..|..........l..@...<.X. ..^...KP]...o..H.|...F...S........Bt6s!.w..D..fo/...R.B_g...g}zJ.u...2..A..Wc...@..:...$e.G.q........,..r....&.[.P.1r.z....MV.x..#.......J...8......K...j....e.........Sp>8.].i&..'.3C]:.......(...b.>.W.....N.'..t-R.c.v...~..+..G..a...5........E)PL,8..V..|....F.HW..3..;...Xq.6T..}......g.....|.%..i'.....w..O..d.-...yh.R......s%Y&..9....0...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):511
                                        Entropy (8bit):7.663193413498713
                                        Encrypted:false
                                        SSDEEP:12:zIrheuG0wqCEuN0EjLtQcsiI9ZerwR6MMjnFp7aE6wKBR:HZdfpQcsiI9F4MMBp7aOc
                                        MD5:C0DF5ADF730E750658E0B7F06F08B922
                                        SHA1:95AAF6542A28B8AD12BD6C4D09D6475DF583B145
                                        SHA-256:F5D0F36E77DB295F8BA72DD8DF52FA47624D25973188495003E0793A7C907C3B
                                        SHA-512:ADD6787FCD487504731A453B23B5EEB46384E0FA5FD28A4DF841D4DA1F60F6BC2B423E2A15EA69228F0905FE1C03050B0D5060CD18A1E2F047BAC41A3BF8D4E3
                                        Malicious:false
                                        Preview:O......ov.}.............._v........&..(.....,.$..R].E..+J`8.)....n!..ri..[Z;.l......w......v.2..-`.. Wk.G^....O..L..Ph...3q.#.......lHG^...a..E ...d......3R.D8.....)..hp. V6.}..?...zF..xv.c.k.c0..#`.*#.X._.....:s....B.2....G...O..>VJF\..8.......!.4.u...P. .......W.......df..........".aZ(..}..a%..L.I|..V.O.$q.*6...j.?.X2.m.S....-)..H.....kY....{./.3.s...c......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.16857902193212
                                        Encrypted:false
                                        SSDEEP:6:OZlnEwEcB2c1xXJWcZ/q+p78frSJVgxGnFY22w20FCnBR:cb1B2aI6vp7aE6wKBR
                                        MD5:1031599132E0E4D409B834F15C3DF553
                                        SHA1:B7743529E5F8B976132C5F42D23510AD87F30C30
                                        SHA-256:5FF337540663777821BDB010FEE68E8B3FE7BC76A242E3831F5D330D1A4EA995
                                        SHA-512:DD2F3930250CD1D5317A71329B207853C6C83868BFBD64A20D1C14612D627B7BCEF92E6744C72126EF04A9352C79C1F6BDADE9ECF81305D3A56EA2D78D50595D
                                        Malicious:false
                                        Preview:8...:.mP.U..b.~.g.Z). .m....G........".aY+..~..aM..tr...BW....\.I.i.......u.&-4L...VN.....2.92.\..@=....2ab......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):545
                                        Entropy (8bit):7.617247199011407
                                        Encrypted:false
                                        SSDEEP:12:QwIuDAnb4tKO+mtG9SKEJqEADKvs3feWY+JWIjI+p7aE6wKBR:QSm4t8mtG9SKEJFADJ2WY+J/tp7aOc
                                        MD5:3491425A06B8CBA5B71EB02468ECD7E3
                                        SHA1:00890697856E1668F3CAB9EE5258B4BD6899DE93
                                        SHA-256:ECEC1552403A73BD52F00A05C724027D7BAC62E196E8062814D3EBF834476530
                                        SHA-512:00892088C75D105903C08F0DC39EEB38C602B283E7C4149863FC2262831FF5EC38CF21A64C51BBD952A77752F2E7BC85E4667911D42186EDCCB8DCD2F1D5A3D0
                                        Malicious:false
                                        Preview:...(..#3......!..>..$....^.......G|n....S"(.,E...].d2..X.Z{.........+..j..<w.i...q9#.....[..H.O.|....6UZ#....|..C...P.....7.....F..."H,.+.K..E......1..sF._.y....d..".......YU!.S.q..9....5./..#..8K...zR.w...t2.......)~.!.r...G......4.:O3....@..,......<h....0._....<Z..>.hY..]q3`BZ3..%6..^. .vY,.;..8.$V..rd'h.@)...*.............!.aZUa.........o#.yC...*.t.C...-....-.B..,..'....{..k.P?G........t[......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):512
                                        Entropy (8bit):7.609754207131442
                                        Encrypted:false
                                        SSDEEP:12:osZz8BKYO08+iHnEVeYIOpiIJxa7V5Fp7aE6wKBR:Tt80/k8E1IOpiI/aBp7aOc
                                        MD5:AD34EF95DFECBFA6C689459C98CDD21D
                                        SHA1:6959CB1C793F7C88E2592DD1AF69D380BC5B02CA
                                        SHA-256:968F3E4DB7E05269139364388A3F039F91EDFB491D5043509C7AB18F54BB5D56
                                        SHA-512:FA4C85B3D2CE52BF26808FF74A1C517A65FA35DDEF58E7A73F339FB798B89E79419AD13E45F4A2773A50D6D7649EC6FAA544809DC7CE396287143BF711AE775C
                                        Malicious:false
                                        Preview:....g}<.k1....E..){.....'..}5.^G....$.<...x......F..7.^M..h..t..v....N..."_...>.N.9*.ii[.F/...WF.A=....=.).C.&..:. v.L@R..r.....H.f..(.F...#..m...].h,.R(...<..%.e.`........P.HN/....l..Wu^..."W..".=.\..J..U[{....;n.5..?.G$O.ZB.y0..."$...I>..j...Z......<rw.p.^M..%...."h.@)......de..........".aZ(..}..a%..}....g.{a(.c]x..S.u.5....."z.."76.w..#.i..Ep.0.Ju...%._.&...u.c......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):283
                                        Entropy (8bit):7.18182492824345
                                        Encrypted:false
                                        SSDEEP:6:RaRLBx0Aj5uoqZlLF6YEJAcGAp78frSJVgxGnFY22w20FCnBR:aH0Aj26pJjpp7aE6wKBR
                                        MD5:C833DD0643F84B34EA2C87ABCC2FA74C
                                        SHA1:F5E75035ECCC2729CBC47BCE2F4BC126BA3BD127
                                        SHA-256:3CE20A3DB7F896B0C44730A068DC6AEA59A5249ACF414C95AD84AEA1CCB2F59A
                                        SHA-512:A438B150FFA543D08F50B7B96AFBA40CA171BA472898096CA8C2C8BB10D83D63BB620A6AA5F1310F3AC4F6C46A0C70494B0C2E08CC6CA1BEE38097F7A102D31C
                                        Malicious:false
                                        Preview:...@.-/V..V....:~..s)%...6.u.....8......i.N)......dR.Uv.R.......a@+../..a%.,.......I.M[H..n...E.S.U...K....M...Z..f.&.a>H.X....:\......A.I..:j.l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):131313
                                        Entropy (8bit):7.998672278258837
                                        Encrypted:true
                                        SSDEEP:3072:BWeFRjNi1h1oYTMnG4Xh4WhWoCEjDEkdPdwkeyd60ip8ABxy2p/:44B1GAOPnEE0lNuFp/
                                        MD5:33FAC16C71D73A9C7C1FADACF5A3828E
                                        SHA1:CF8582765810DB032A9E555CEF20912796B5F619
                                        SHA-256:99D817DA3B548414FC4381D703DBC22C2D3C7457301CE636CA2D0600850F4BB0
                                        SHA-512:1342383B08FDFBFF2630938AEE50CA762A96CE1794AEB89304A12B6856D58BD292F712F9D844D9627BC1F4B4FC5A231951E00C39C8000E61C2949F22E1F71AF1
                                        Malicious:false
                                        Preview:.j.5....oFmW...P....Q....Np.c.'..\9.I!Z.%.zo..c.xw.......G....r..U~n.n...\..{..h.$..}.H..E}-!.$;@.g.oo.1r\..J>.2.1..z.![\..sY.c.l{W..._.Nl'..Q\4...<.!K....e.@=.+.#..@c...<?.m...wm..r.'_R=..e...J.R....W.P....@[.i.nN...F..BbS.U.E....H...........W...;..n.jn...n.....w..;P..%..:.v..1.8.......xY&x.H.,.O.].5Q.B...>...#=F2.'tfbM.D.Dy.....`.%q.c.. C..uV.v.Rf..1..d[3...1......Xc.5.v".^.......g.J. .....U....i.rc...i.G.{z*.......j.....x.M..Ya.:.c.W.......v]....Q.Z[l.O4.T...<.i........].\l).ChDw`...]L.....;I].[g.....Q....:m;nN.D?.5OIY....7..4...j.....F..XN..KWvdB,.w.x.2...U.}.2.B.Z..itI.W.......uj.......gdz...|.V.z....:/....~.Q81?.geh .e...L.r.......L..'.m..t.~w.srL.x)..;7.w.f......f.Jp..W.aA...............'G...Vl...65.2e....|....?..1n.._....eO.,. .H..z..^3..8..U.$7.:..e....{9..H...H.?..........)[Qp...-.-+.....7.......("`...B"..N.:.^.q.@{.RaeXyi...+...z.Qb.....(.:j..h......R..B...9.b7j+{..-+......L..}[w~o.n..r.#..6.......G.xb.T....aS....E..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):842
                                        Entropy (8bit):7.757582559817211
                                        Encrypted:false
                                        SSDEEP:24:25UtK67kqeWEC6eRPfO+x3h6p2+/SesAp7aOc:22ZeWRPW+6qTApJc
                                        MD5:948DD28E44B67308A061938EB6C2FA7B
                                        SHA1:E7C1A934AAFD8FECE1445990A488C2C1BFF727D8
                                        SHA-256:7312C875D0AE14B616A50CB1F709B5B3FEE64C0952B7FAE64899447DE7642585
                                        SHA-512:E78BF00C0B80D568CBE6F1A1884DD980D5EE39CD205D64A7BEA80CEA8A845F4987173A762A01F5E5B8DAA8EE37EAC609CC32377E9D67137A69FAC558404CBC52
                                        Malicious:false
                                        Preview:..+W.Q?.._.q.1.V..C..X...U.P.^..d).e.......EJ..O<.+J.u..L..&./...$.....q.9&.1..W...G.....7..v,c..qj.&..br..![...S.-.D.YG........<u.U..._......D.. .=....X.yG.^..C.*.,....+..#..#.U.H{0..Ud.......7U..M.o...Fn.p....B!........[.9.~........s...r..o..*(...~uo. ....a..+..........~...l/.Wp.........-.>.e....l...m.n.*.`.AH..K4......oG#.[y...Inioh&(....2.X.9E.NisE.....?.x...._.F.........*.!.h..NGs+.QH.$..(6.S..B*........|_ ..U.... .\/..f..#].E..9.Z..C..-!!I..d..'.5*p.Z*@X...E../E.(o..D..GH.7........c..d+"&..d9..aH..*.X6.L!D5.&...e....U...s..D"8zOK..?....E...;...........!..`.e.L). .I.... ....g.s.YVU.X+..}.[a%.,............&.Y...P...!..7.p.@o-...r.....E.i....B.UJ....F...@g...(Q...n......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8424
                                        Entropy (8bit):7.980329379878296
                                        Encrypted:false
                                        SSDEEP:192:uR/E8T3X5mufKBXEico3fam+STlhdqXbJ6B62daAVbjpS:B8rEufK10oPgSxqXbJ6QYVhS
                                        MD5:9ACFDA664668AD738B0B00CD7E1AA78D
                                        SHA1:4F16C0D17B936888B88164C541B2B554EB1BBE7B
                                        SHA-256:2072D87F0484C2A6547AF89ABAEBD29359FB53AA7DF3851E83A80F5FDAAA8C54
                                        SHA-512:5B54AD7EAB8BED25F69FFD7651351A0827732962AA2E59578607E280479B1F3EA9B98C5D7A604A63C8AE6AC52E9210E14E4964027DA57C28BA2F730EDA7ACE1E
                                        Malicious:false
                                        Preview:.....C.5wk..I.3..Hs..b..Gt....>Xo...&..(.R..{/gN.l'..."nM+.>..k..(O.!T@.no.`rQ?|..n....AV.x...X..[t.7.".B5......6_L4...K..1Q.1..X........$U.5/....X.-.".4.1.5gS......x.J:..@........c(..-.Z|.G..!..22p^..Z..0Ah.\0h..[-...cn92.O...t]c-%Q.X..@..yk..S...n..C..c...W...V#...-.M.....B.....3!.iw.V'.K.V..w..Y.....%.b.2H#[u.....d..d..c!.r+...)..S.0.J..;x.m...KY...B.!.f...2.n'..pKb.x|<....JQ.h.q.N..b..]Edu^(#T....../..a.-V0..../KXe. Cw..1..q.,`.ETG..o..g..0.....*.N1...rl.#.>...O.....B.+.8...{.f...{.`..a.3N...b../*.B|.*#..EE{ c.hU.......z...f...w.K...6....9.[...AW.edl.].?/k....SP.\..R......o.%M~0..,.$...3(.(W.....r.].....,^g.s...TGH..}P7qu.......F.bNXJ.....!.1..M.r...^...G.....c...c...W..M....y.......;..^.....|.S..1C....k..Y.L....2..tu...^*u.P.t.J.B.)j..eS#/.%2/%i..M..-.]..5f2.|.H..|.....H...!.........Ug.uU0......V...{.f....Dk......Wc..t.h....+P.|Y."B.0.LIix...S.Q.%}!s..5.K......hk.j.$...o<.O,.I......X.8q..@..T.s|G....<Pv.>.UT`.z.q.Q.(".(=T.P
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3145960
                                        Entropy (8bit):2.450398820268795
                                        Encrypted:false
                                        SSDEEP:24576:e/eFNQReT/6+T3IFWXMw5K15GBDCHW9dQt:LRTvT44Mw+5Wf9+
                                        MD5:131EC55DBBC197007618925A43275520
                                        SHA1:E4A817702CD44FC52BAD53A9CD45F91E7DD3C9A2
                                        SHA-256:41E49D71E7417CD2B80720F5F494DB607255F511C2F47DA1B8E6704C89A2AC17
                                        SHA-512:BCFA29DFAE4AA9C01D151FE48542841525CF9B92251094195E0A643A550EF6ACF2DCB5C3BB5FD51355288FF15AD5975DA259B76584E80BE46BA4438F2EB40F08
                                        Malicious:false
                                        Preview:.-......@..Q.l..R.V.|[./.<...3.....].N..D.f ve.].[....E.......f....l:.7q.A....n..^.....y6...v.&M....cM......)..l.m9,....x.:...%>...L$.......-}j\......9...~"#N.b........p.U............h..sX...I.o..i.p.g...e..Y!=....+./[...4a.T..._g....vi...O..er..H.E.....Sz..J._\. s.d+..;0IH4.....8r.:I.........q^.;/.....f;*!{U9N.......9.j3|..^....B....g...........0...w..u.A.K._....u1P....}0..c..4ky..43Z..J.%.4..L...kh=z5..^[C.ww..3...Dr....5.A6_.......3.t.S..%..I.?.y...@..3.nC.Q...g.+R%....&.....}....y.3m......?..@:.h..#......2..h.S.qL)?....l.R.q.rp,...Y.,..n6.Vl........4^ .j. .f6....%.4e...H`n.$t..pO..R..`0.....7v..0..K.....&I.1..V...y?.$..xf.n....iv......a.k"2*.#z...>......U...2../.!.#...4...5...;Z...?..V..*..'.B.vT....S)....%dU.O.8&g:....L).....QQD.>.....9CA..H...l...m.._e1...;F..Pz..]..3~:3...3D.... 6(.7.u.a<W..W....#.E.........f.....!`S..t.W.p....qg......I.9XT.^..\.gSv...._E...Pg..F...G.BvW...M.....Ero.Dz.>.S.Z6r.Ha..5......a.i..Rk.L%..9.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3145968
                                        Entropy (8bit):1.9761834549977368
                                        Encrypted:false
                                        SSDEEP:12288:eJWA8s/AYYVhI8Cxu+L0GA+KefOge7SKjTNukmB:QYYYVc7N1K7g5yMB
                                        MD5:28F183D382BD20FA4A42556CE4670178
                                        SHA1:E03A0D0DC4B584EAAF65C7737831C3B6225CCE01
                                        SHA-256:A00AE62AD35DAA868AAF728F42BE875B70FFEDC4919980C8F6734F86834AF1D9
                                        SHA-512:2D9FE2B816ED3F963241B42A27863DAA1B1F139FA7FB1D475ED579E8525D9E10B25749E9282409A4CF362C3C7367FBAE8FE229E767D3773A0CD0AF2EB703BFEA
                                        Malicious:false
                                        Preview:...../...2yv.."...@.x.2~.D....._/n.m..zG....=E:..o....H.(.i.o.S H.Zo@kY9.Bm..@......m..3".L%...w.....!v.'.R..?_I...5r 8BM.P.$]..nu....%....+z...|..^.):.t*.U.,...y./Q.....}".8-.t....y..=i..,..lW.."2d='...7.bxK.(hn6<...r;").....p...x.`.....G.2d....Z..]~....Z7.R.j...}G+....2......U....K!Zr]$.f.].'N...+S..s...?(.o..$e.6?.~.%A.)=.2..\Vp..hb.<..E.x.K.B.Z.:...]|.!-*....=.r.F.rq.....y.F@....aNE....X.:..#y.#.Y.z.1.$p.#.~.0H^..Z.....Z..j...?....N......~9....u;.4%............_...I.N!ME.hQk~?_....bs.u.] .Q1h..).....6..{..1..-....D.~S.dX..b.2YT(...\.q.......|C].?...7*.,t.U.5d&m.).l1a8...$....rc..z..D...h.P.?Hvza.y.)...{..g-...h.....Bw'.d"3..\R...t(SUS.5,@..../u0.1.......O\...0...x9..3<.G..,|.w.._. ..........m8.\.s{AK.."..q.m.w..#..%..3.O.......;ze....S.N.`.Z..NL_4..+..L.r...Q..w.._.Y.%Vl......!..8)z..r..WRS...Vz.]..<..>.&......-...At..z3...e^..Bpe..Ak4.._m..8.Q..+.Y@..\..p..s+G.~Q.(.M...).C.tG.E.).c:.. ...M....E.(7.2..Vd....!...=.E[.R.....j.JT=k..]..<.uN..L..l.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3145968
                                        Entropy (8bit):1.976385352834159
                                        Encrypted:false
                                        SSDEEP:12288:76OxQpJ0PY5h9wJzNfxbFm735/pbqQIJwMYvgbvN7TGAOLdFFoA84g:TSWJzNpU7/bqQKVvh6AWFmb
                                        MD5:741A159F96F40FD22313ECAE6B1F6E65
                                        SHA1:A158E391AA46A43ECF103110BE4152201625ACE0
                                        SHA-256:224CEF0C769EAF2BF49ECF4B849DD173A46C2AD991F522D167D395EDCC1EE9BB
                                        SHA-512:1AED5FB4903F843D4F314C6149277132EE4CA0B345B3CFFDF868D579A4FA1B591D683229D74FB60270FE80DDDF8B7584AE97A5FA8E7464578D15FE68B72AC110
                                        Malicious:false
                                        Preview:.6^...!5......eW......a...(..%..uCP..LB3)..s..'mTe`.yu.... L.wB....".>....>.^.`.t.<...b..wu..@..u..-.&^=...<! .mC+..f.$.)......|..Gvm.(}..v.r.\.....I...>.A...<@@.....l..68C.i...z....K..R..q..i....1.[G.|.t.....;.Sr]pl.J/..OR{}.....X{`BN.=..S.....................z.......&...4E.8h.'.'.?6..M."A.~hk...<...'..TH.....#.h.4.o8J..k."..:.nMm0......[.LT.A/b.....'..7.Wh;..[+.^..:.M..f.+..I.Ib.'.'._#.k.lG.^T_.V...Y.4p#2....07F0...pk'5.....Q...-..P....>.d..^/..Y=..K./4q.o.V..*..z$L.N......Q.....F.*....1.e%..J.$....8.,f.....T...W..SW....u.....Z.:.*.(..........=8.+....B..Lxu.....b..Akgv..D.r..X............q ?:..Y.Z|U....U.....E.oNR...m..Ib.b.......,4q^.@.a.&..~P....T.:=...)..%...<|.......0D.v...Tdf..?zW...Y...j*....8{.p.....Y.].....8m..C.M.5Z{._L...w.Y...h.)qGSC./........Y#..5....@.)..Y?...zpO.'x>z..A.+...f...,(..Ls.qn....I....l.$.U....nt..4.B.;.=..uJR.|..y..M.;..s2.....y.].=..5...M9..W.{.g........[...we..E7.... j.......{.]......;..Ass..?..@..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3145964
                                        Entropy (8bit):1.9760784611242814
                                        Encrypted:false
                                        SSDEEP:12288:FbWkC7eRL5ZwkDiqvbdbgV7H8vjwrJ8EOw4Pqgcqa:F677eV5Z7TvbdbgF8kyugcqa
                                        MD5:58B45793199C896F18782C4FABA65EA8
                                        SHA1:560D726DADC3A43359DEE63203093A995E1538B9
                                        SHA-256:0021E1FBAFEDCD12E9F0AE3C3691B521BE06F2B281F63DE43F2392BC1CE4DF9D
                                        SHA-512:7F65569AA876F39574C79A9DD64F23103C5D6DC81EF3B184FB3E3063D44186241097914A5A5924996458B11DEA68A3F5E746BD79131AB77E02FB96FE397D4129
                                        Malicious:false
                                        Preview:@.....&.Y.6..l@g6..-.sCm..... :.g...3..)w..J...}.....V..2....cc...T.!r{n...lYm.rS...e.w@......Hu.;..N.84..y...$.....3.(..N?.#.cq...\p.J{0..`.+G...'...v.L%@......q.....=7.`..q.......Rx.....Yt).9@...\..Oa..#......M.A.....D..Q.....'.V....Gx......hk..d.\c..1*.L*.=...$..>q....wfy...U......#l<W......%.....joM.r..F.o%n.8....Q...0.a...0.5....O..Q..3......|.].(4v4....?.3Y.!z...&.....P.:.ZHP...{...L.9........H!.h6..^..e.....2.....P1...F.c"e;9r.......$..7....R......0..pDu]%......_.`bi..M....y..8<....q{..w X.'.....?..s..`..V.5|jf.fK..(.E......Z$.t...F>....B.{....,....P.N4...z"4.K...wu[..-..EaHR?SO....S.W...}..c.R.X`.~.Y..,.....v..m......J.a.`.^..G....4.w^{]V...D.'..Q...Bq.2......a.R..R.b"|.........w..Lt.1.-....[+...YE.d..s.y:.@.Hc.3.Hk(...<...3..u....b..$,...Bs...g.T..>l...t..Y....S....n.Qg2S......?....oi.#..@......-j..4...<:.."9...u.v%f..=m.sI#{A2G).....1...x:..0...GlC..v....B3...Q@r..U...?..+.7K.h.M......$..V...@.-..@.s7.".L>fG...%..&G...MG....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16621
                                        Entropy (8bit):7.987989823762941
                                        Encrypted:false
                                        SSDEEP:384:NRkLsGa+OcyjoUrv7hr4PUBgzJnEQoByTOf7wsd5MAZ2K+S:NMUtDFrv7R4wECQoByTEdvM4
                                        MD5:4161E06DC84989744D00183F93CC2554
                                        SHA1:4D04F632CBAEB3C413614C8E1E53078D117D618E
                                        SHA-256:20991B0C1E0251B8A42B8572AE98A0EBD2B9BD72FBDF89BC12B623AD2B8F2556
                                        SHA-512:7BF0FE897072E273EC728D0756AE133D4F1B6CCE4ABE499CA0563D4CD9BCA2BF82DCEBED43B792FF7E922808B55C7FD51A58F8CAC3F11B2FA0D4229940F0F676
                                        Malicious:false
                                        Preview:.d|..S....(4...*vG..]....&m$wy..;.af..T.0d........\.#H.. .l..#.....x..v.5....b....Q}U!$.J.T...*........XXs.Y..........P@5.3..e"..Y.'z.. .z.Ly...0....9...Z.j8.x.._+.....X-k>i.....`<.1.y.2..N....z8..p_I.....K...R.p..r.....)'.%....O;lk...tr,...Y....x..Mr..~.^..X.^.......~..1Z...08....|T..zR=....$....en......i.^T......n..iG.<.I.I.'.......UI.v..w....t.>29.b.<.....KU2xJW......*...b..E.k...i..Q.g{hh.[.2eV`<\.1."....X`H(.[...5......8..].4FmT".R.].Z3..L[..R.....(..W....50.:.......g.Y..]4...S...*...H......W..YD.xI...-r...=n....0.Y.P63..w..6.>....:....%(/..W?......n..Ex..?C..4...1u....56...@^.y.s...8...E.T...1X.sG.nX.X..I..V...B.z.J|..,...@..aa.....6..m.../.(.+..gsF."......a.E.?..P.....].).S.E.58.3]];C..y.$....HJn...>...$x...E....t..K...f..a../{|..n.k...Jx.D....Y.fA..=.0..cP_1....:5...j..&...II."U..T.!GIP..c...K$X.48.......H....V.....7B....uW......^.....G[.D....w.5...b.?Q.T.....J.H..Y........."....f....8#...m)o.?...Rg.u6..-........<Ze...xRO.0...:
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):5767404
                                        Entropy (8bit):1.3967384136103804
                                        Encrypted:false
                                        SSDEEP:12288:BYr+RKj7nEzWCh7R7bC0yNrCit7ADDPx7U6/BdwCRdb0Q:Bkt7ECsR7bCnFb4U6/PwCRJ
                                        MD5:B19724747C18A522A44FAE368825F9A5
                                        SHA1:6058D2148E5C23F1E41E3DD3FB7D7AA771BA424E
                                        SHA-256:DCEF58C6E569AF48C6D748AC1E44AAE1B2178D16ABAC9620EE084484D0350F97
                                        SHA-512:57033A37F151DE228B37EFFB3DCC521789C6961AFA7C961F5E3035BFFC7FB086B51D034DC0B199A09FE29FA297DAB358C84922FB9F5D2214A20F1B4CAF7B4B70
                                        Malicious:false
                                        Preview:D...eBx..B.n...#3.sz..L..VL.r........ . (OS.e{e._.S3I0.\G?....LP.......1A\..q.+...v...+c.t...).:~....v^=.}.[.."..;.p.....p|.'..j..O....M..5.ut'5.V7....v.j%..s.....m...0.V...m.G9vP..|.2v..E.b.b'....VX1!RspEw..c..Aa.M..'..f/sU......2..........-.B{...>.....!....p..]"....<`...E.B.,.<i&../..<ht/.].....cr.|8.2..o.8..~...f....s<2...z.n.d_.q.......6..".,.d.{....W._..Y%Z...z.d B.....x.:.J4.....X.i.RS....@...9..."n...A._@.p..T..-)..S....+u"..[E.v.gRld...6.Xv.\..........r...j?...X-.p.G.....i....S.=..%].1*...)0..7.......Y?....z..t.....D.O.M.j:....s.l..P..z...}PgL......!zY..f.Q.B!e_.i...#!...c..ZC....!h..=.i-..u..8.=..(.....h$.}a.......I.........)....ySz....rf..jO..F...:.v..3.m\.T.....Q...\.....`...-)Q.h.)Ww..I....H..3+S0...F.b/9.............*.@.h.Q..vYN%.4.....'n.m.<.z..>Y..?;...rCAe.......H.+u.?...w...t.".f.@....<a..wi7.*Ii.5..v8..p..[..Y...,.....`..}2f!.J...e.4Ow..i_i..j.%.D%.....&&4..C_...@3........~.E.8...6.@.#.)....... .J....bH`@.>f.@..J.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):248
                                        Entropy (8bit):7.066888372944731
                                        Encrypted:false
                                        SSDEEP:6:2cqeUqTOdq2AwX5Kp78frSJVgxGnFY22w20FCnBR:FUOOoBjp7aE6wKBR
                                        MD5:35AFFC7CB03E06E03C840EE2877F2F09
                                        SHA1:EA49F235F5E53FCB7D46E3CBDF006F5582BCDEED
                                        SHA-256:994E2011FCBAC5B090DB0B18B4BC1ED164619F05E5DA9A4659E903F154506CC9
                                        SHA-512:2530657AEB77FC3C49509D4F5F51629520FDB5AFCF81DF289BF1C8E9BE76A57E7BF8FEBFCCB8FE3AFBB8D13193682F615B568C1BF9C320C73BAD83D582FCD8E0
                                        Malicious:false
                                        Preview:....e.h...M.....TB...).4..X+..}.[a%.,.....................8.....N*..r.L....or.WP..*..?....*H.rv....g...K..n......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):5121
                                        Entropy (8bit):7.966615194897709
                                        Encrypted:false
                                        SSDEEP:96:Zct0ushPOI/djNpfmhBLqnE7m7xbthYcaFUQOXotPl56tpJc:i3eWI/9vA8E7m7xhUUQOXopj6tpS
                                        MD5:8F1AAE6ECD0472DC8092BA8E0596FD54
                                        SHA1:0B0FA9860A4C3D23EA6CA2E3E4A47C3D2F39E8C9
                                        SHA-256:53AE8D6DBEA0C754FC2B24810D8DAA4707A85E0CE21F558508748895E8A3518D
                                        SHA-512:69A4D8C3064BD23A7CE0CE25F7FC91FB399197A55640639C45584A61FF4326569FF69D5F03C3E0F3C2555148CF717E928493F82B8DD3114B5BD0B2C6E25DEBA4
                                        Malicious:false
                                        Preview:.....f...tz..w.U.<.x.;X.Y.VB.<x.,...%.P....>y.t..o.}..M.......PQ...."....L!D.I"...G...U....i.]0..C...U.S...V....[.].?d.=.O%E43&...P...).i...........0..Hc.a.1...g....z6.B.Bf.t.|3j.\5F......*....y.....b..I..T..z&...p.gu.\=s..o.q....O..p@....Y..;.[qc8.G:....*....@~...d|..4U0...-...C.$..4aj.Q.g@.&...6O%Uf9..-........v.....L.|..7.+X.3.....F...E...v$.w.}IW.|.p.r.....gg...#'......1..".<1...(OW.Ri.x..-.u.,x".f..1!A... .......P.l.r}.c.%.wGb.......A.&.;.{.......hY[....'/8KX...ElnT.b......q...a.Rp....I2.....|..;...*...,o.I.\.Pl..ur .!...g....b...!RJ......0.....O...+...a.P...=...=....x..\..;.7..T.rM.,.r.*:...'.. ...A...`..HB...:=............7(a...;.......]..o.Lf.-A.r.....WB*2...O.Cu.4e.ZA..D./M....jMV5.Q...f.LN.y.L....6/BM....+.n...T............z..;K..$3=..$9....d.&..?.&...pY.X...q.P.Xno.Q]..da.........O..s.L......+.ebL...........r..Q...Ud.I...I..B.6e.....^Ux..B,...>...=.)_......a..V..l...s..w..$....O..v.L...D.?.....k.hC|.w...C....)..s,..er.)..'..1#.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):933
                                        Entropy (8bit):7.7741236482103355
                                        Encrypted:false
                                        SSDEEP:24:kOVi/FL1eIR1MZJSfIsNz8LB9bwyw7YE6wGS58YBBp7aOc:kDeI4gItLB9av5JBpJc
                                        MD5:CC070ACCEFED1F79541AD2EAB76D74BE
                                        SHA1:6BF96756FF61641FE3E5C7116FD49743003FF4BE
                                        SHA-256:5E8863378F2AD1F7E1F85BC333B9AA4B744E4CD2A23570466A5DC8AA1A5D3A5F
                                        SHA-512:53DC40F8F506A76AE24DF7012E4CF0FC40A7BF943637B9CFD157435D3369F2FFD40CB10A64975279D36BCE1DB41E4B4360433A1BF96D04B34D6924BB9571347C
                                        Malicious:false
                                        Preview:ah\tE..-....g...c.HD.6......<../<...d)..z.zY?...8.{...EO._c..q.i].|.....l..I0....W...$D.@...v../...An...2.`/yC?S....u....6.......X..B........E...E.....*\Y.z..rdK`.bz.E..O.;..@.V^3..C.!.^..a".....-+.kf*..........x7o..Y.L...qo...l+......n.o...P....=1.A..E6._&{.\>....&..-.3..c...(...6...S.J...pY2.....#[.G.u.\9..>..K.!2...<}..Q-.|..`\.<..|)DQ.....jD.W[.l.....I;......_..v..I...i.5(.....c.\..U.<H/./0..8p...dD.ca..&S...6..&.....Q.r.t..kT.$KO6....W...M.q."....i.T+..3.X:o...L....0.1Z-..G......g.....O...1.G...$......:...Jp.RTl.....5d]..?.1c.....2..7..T.Q_z=.p..(......T^.&.@..2....3...&MQ=.Tr.r..Ng.P.n<....S..9......&...3w.;..g.`). .M....!.U.I.....-q)..R..h....^....XD.,._h..o.,...+.r.....h....p..8R4.s^.3.....H`.(..(...e..../.^.r... ..t.....E.n..$...z...z5.YE.pu........f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1211
                                        Entropy (8bit):7.832596261163228
                                        Encrypted:false
                                        SSDEEP:24:mGVDLZ1EmwmlgyZVfU8XhCsSaDzIY1OVhkNd0luzex6Rp7aOc:xpLZ1E/mlg8cCXIOAGr0luDRpJc
                                        MD5:1B106FF7E92E196B04C7DE47AD091ED6
                                        SHA1:FC4AF59F5A9A342EE8893765FAAC076AC2F37719
                                        SHA-256:FB06C9D465FEBEB0DCD052907B4B5990DCA26482DDBCB0BF162799FC51CC48DC
                                        SHA-512:A9319690CFCACEA64A924815C3F96BE73C21F91CADF2B0E21EAB4FC5142663F70C195A0C2BEDC91CFD370A9E896505FDA611E40EBFC2212B33DAF9C242C7ABBA
                                        Malicious:false
                                        Preview:..}ZF@...GvO.%...v...|.....0.|.......3h.1...m./..||...(..20v.H...Xq....w...1/...xVG2VJ0k......mu...4.Jf..k.@r6..J>.<.@....{.a.2.....s:.Y..O.d......=0Hmoi...TP$...l._......b..A9j..Ee..T.+..;...IVP..?...c...Z\_......0..:..._`e}...-.c.j.l.b.)..V...t..L.+......X.^I<.0.U...e.r'.b;..m.&/....d.....e...3..q./ka.-...2...%.T~.Q.{...n$.O...)..iP.+.......ub..q<Re.85L....g.[.....5.`...%.k.]Z3 |......8|....gd..U..*.\...^..x.f.zW.W{..}.G.r.r....F....y...iB.*A'...b+22....;....v...s..[.._.kyF........x.DcfH.'..0..e.l.0.s.'d..n.._.S?.z.j...L..K..>.JZS....z"...K7[...vOT..H.<.39.hVsAd.U.......W.XO.7p ..........o...,..d.-..=.C..V.?U2.....t..%Sg...v.....R8...].x..R..Z-%.J.Z...m. NJn..9..3.YW89Kx..0q$2...;3Z..N..p.Y..{O....X;;.5$..F.c....'.xO^"._.$(.p.......%....j..~Ro.<J...=A..-..j5.u.d...C.J.x.E.x...C)N........%.8...5p...^O+....W.,.... ..]..v:.a....Bef.U.\.a=.@)...>;[O....Y....G.. [.S7.x2....^.r..7..:..8.!0Qw.lc|..!....N....W.....d(h.!)......do.rX..... .a@+../
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):306
                                        Entropy (8bit):7.293837659669372
                                        Encrypted:false
                                        SSDEEP:6:as0KWCCnOGFcbyDuVM4MNDkRnkOwCNsE8zmDp78frSJVgxGnFY22w20FCnBR:n0UCOyyokR4CUz0p7aE6wKBR
                                        MD5:D5998B6F388FBD81D66D6E4F81F9793C
                                        SHA1:267B40E179794ED80A4672A5C91D25D5A5A64EA8
                                        SHA-256:8FE1525024236ED9F0A9C6D6329ED35C2A45BBBCEBF5AEC4366CF0E64B8E1778
                                        SHA-512:1DF9CFEFB5DF987000ED83216BCDD0B920D5240F953214E7AE4DCE1C34419482D4AF982F85BD93E7E245716FEAB2575839BCDEEC7F1A13CA1DCDDB3F3D2CB748
                                        Malicious:false
                                        Preview:......3j.!..p....Q.0.pMA.........w.b.mN...x&.*.1..Y.h.!)......do.rX.....P.....h~.c..,..M.....g..@..SU...yW....5..Oh.......!l..>..I=8.-D...j.#L.oz..g........^.X.v......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33022
                                        Entropy (8bit):7.994352217680519
                                        Encrypted:true
                                        SSDEEP:768:vyAIwgiG8YIjeMYZ6UklHdp1CrfsMZz+mlAtZGhx4fnxzxk8n:vyOGRIjFYZ/qHdp1C736FHVzN
                                        MD5:F6BCE47AFC9BEB0AD9C65561A940B0A1
                                        SHA1:C064067FC36D0C1A19FEAC0E1D8665BB0EB77E53
                                        SHA-256:C5A39CA0EC956BBFC29B153E870A41F40104DF3B7DDF17A67643E78CB24BA3A9
                                        SHA-512:AE9E2496C7A5BA56C3AED95CFCB31650103CE9E604EE927BB68E84474BB4DECA1119C960CB1792064B5F7DD56255785EAF62BDB319F75DF45BB2B5CD1BE0FCCA
                                        Malicious:true
                                        Preview:...%...8....].....8.....P..U.:...S.%m.....i...*>....]...8;...ZK;.EQ.U...R.....%m..v*'S..,..T8...D.}=.lF.Aj..S...G[\...../....Wq..s..W..q...h1.t.....;...N"R.V@Q?C.i.y].`^....S."J.....v.C.RMB#....AH...d.Z.............v.1ai.6.>...r.6.........Vg..{Q.&.=..).A.......bF:....>.*?F.b.."..!..h..Q..!......V.....R.u.i..X5_...G.Da3#.1Ll...<.M. ..g..Y...K......V,....s.......$..Q.#..q...?..'M.....S.Sp...|..z/......i.%tx..2..RW+w...*..R>.%_$%........G.Q..k..LL8aA2...g....]u..4...........o.e...e..y.r..a.`.......P....@....@.-...B..p.s..!#..f...=+..v.x..l.1x.R..fe.i...T.....D......_...PfQ4.?a!.........m.IT.q)0....j.x,"g.......8e0m..3.fuA...ts.-....".......W#..h.).E..t.}x.".e.R'..Hl.U;.G.]x....H...;$.l.".4..U.B.......K...B........#w...t............of.......O...E.../.^..Y....G.O4.H.b...j2%..S.D.."....3..7.B!'.a:.(.....;.....'sB.4,.a..0`u.....4f...`B..m..?..+.qiC..*..P<Yi{b..k.;.2.......tc........./.e....w....P?~.4..1.F.G.1.....H}..q..N......vr.\B.-S...E.... ..c.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):255
                                        Entropy (8bit):7.2063810721259705
                                        Encrypted:false
                                        SSDEEP:6:663MS6FyQm2L5vwpJcHcvCX79p78frSJVgxGnFY22w20FCnBR:Z3MSUyzIYp28aX79p7aE6wKBR
                                        MD5:C0215455193B3829DF0C01D6E89E98E6
                                        SHA1:A2BA0EBCF835C318373C5062CB59354830D85781
                                        SHA-256:B79847A5A7409F6819CD1E6E61DE321D7FCD7B35FDD178AB46AEC27F40CEC07C
                                        SHA-512:A316C0088FB60BEB40140153A8F97EC66ED4DC4CF67CEC8463EF46702F67986C66EC5A83A9342FF1853291CB372BF61540016E69CDC6F3E0D473266B80BC9490
                                        Malicious:false
                                        Preview:e.l)....2.9 9......;.Y>..P.~DIR..........d..C..SV.(.d..YY...&/...C..Ur.T..o..6..s>$....D.k.Qwy...;f.'.=.04j-w.y......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1048824
                                        Entropy (8bit):4.98232549588922
                                        Encrypted:false
                                        SSDEEP:12288:0hI9sJXS2CQk2NSDZiGBrdAiKzt1K/TksC1SGU:0V0/5U8rui41Ho
                                        MD5:350457B581D4CDD2F09D0AEA2E4E5317
                                        SHA1:EF0DF4114E3270E8DD185CE21FB963373C8F5000
                                        SHA-256:EAFAC706CA63A8184FB9281B5D691E0002594F8A3CB0FA45CC0E1BA3CA0FE894
                                        SHA-512:3C02484AB92E2707C199020AEC563ED598089A0BD0A879E6F6081451B852E587781B52AD67A613C47105B0A2F6ED9B2F977E3B7680AEBDD573CCE08414217ACA
                                        Malicious:false
                                        Preview:=J.y*...R......I...2....../H....^..|.l.^..Xc..=...!.>~<.R*pv.i.../..w.~=[&.>....y.....;.=..7.&....2...Ui....b.x...G...i..t/..e[RGce).g.....'..,Sy.C.B....1..M...e..0...<2...)J...@...I..J.3._./$........~.../W...i.,.Z...Yq..J.O........ym.".,e%m.L...{<..9<.r.w.T.9...99.w.+./h.....8#.E.l..F<.Q...{.<km....eX.L.V\K..>.%...t...E...&..z..C.....83.!..........%Y.f..p....c.P.. ....I>.n......t.q.w^@..&..{..m...A.._..^.4Y.......Wb.J.l..../`..1.........8...z.4...^..j..s,.Q#.J...{<......f|H.........e.....1..r.,...rt.W...2y...9{....u......-.j]....M........B...myK9=......'...;5.......|...p.y,S...<............O+....O..*.......Z4......\.-.+.(_."I.F].X=%....J....0..14...Hq.M..+#.~'.S.]I..O@h.qC$O.%.P..J..."..EhaO.....f..!....g..T...h,.#...CFH.T.'..3.?..=r.?.....=...e..T..3W.....3...5...L:5...C...?.I..O....(ms....7.X.9..m.x..u......a.^.)(..K,....r...4...id>u..{.Jn....4.a.........Y.2.....p',Bz........y.....{m....#...e'o.Z..ag........O..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):65536
                                        Entropy (8bit):0.2917968882673931
                                        Encrypted:false
                                        SSDEEP:48:5VydhuoJAAjR8QPdTw2Ll899dY6mDDpJ:5KJTpPpidYDDpJ
                                        MD5:D17035D7E2AB4BFE02C2CED134CEAA71
                                        SHA1:E7370A945226BF0C3F5468B5485CBA7368F594B1
                                        SHA-256:965993F381184E78B1D37313861A8C1FD2DFF20DA667BB87722414E5F0CE2EA2
                                        SHA-512:98A7A078FF9745B69DB6135F4F9FB83A7032C34D013AA35A7D0E492819AAE29F9E498704F02DC53A389BE3452542FA971297CA716D4C051D3BDB10C87181107C
                                        Malicious:false
                                        Preview:-..V..N...`...(I.3.yz....D..aZ1:..<...Y';?./.3...o..V8..y.G.?]....h.#.....d.4...d.-~.xO0...Y..^j.X.G.....,w.:S....k...8w...k.......U....>.;...z.G3M...iOpI......W.+Rg../!...1g.6....Z..2.=.S9.pl..V..q.....+..~3...T...r..<t...-.RN..*..JG~Iw\..Ud..Z........f|..#...R.e...;.......P....Rre)ma=.3.|.......s....OWk...TQ.....EK..Y...(2...1s.e.Q...*h({.$.H..f..NBq..0....".i...[Af.....l6......Q....^.V..G.}z...1...{......!.1}..7{_&+f......B.....\`q...7.*..QQ..$.Z.n'...%...`..L..R;..V.%K'.'.j".........d.-.@..(.>...,...TS.:...e....X?..t"..b....}......(...L#O...+. !=#......l&$...._o.Y...$.....@f...S...Zsr.m...Z..s.....c..D.......7.kX$KB`...x..J~.....fC_.o.Lg.....MJ2.2..#$.....W.?.Zp.....{y....\pH....4.o.n$..P.(.&3....?.9`..k.q..@....1.7+\.j.- ....>....R......}.@_sE...BA=..h{.......x..8.z.4mw.+75.h.0....B.w.{..0..w.g............[^.e7.8..4q..Y..w..YP.../Vv..@!B.w.V...V~.p.$..9...%........0'K/a..O.WG...OZ.3...^{.9..H.....#G........_.+..yNb.....98............ciT....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4194576
                                        Entropy (8bit):1.5379765733815594
                                        Encrypted:false
                                        SSDEEP:12288:A80ZsrBHbGSu0+A1ATji8rCmN2OFMKNO2nvhm98:AZsJb021Avi4NXMUzv
                                        MD5:53CFED7A2B76A0F5F898741719C30A0E
                                        SHA1:1B7AE951B2199D435A24C22402D01A03F1AAA95E
                                        SHA-256:F0799749AF8863DC46410552D632BC483B0B0B484EA401C86DF97ED9B8A0F029
                                        SHA-512:5362FE22A16E5AD6E00639AEFFF3B3E63C91D7E44D3E7967C19E5523FDAEFC2FD51B63F9C63028DD4575C9437041104B7E3B7882CA381DC1ACC30758F7708A84
                                        Malicious:false
                                        Preview:/]H.w."..j..dV.%`.cE..8J6....WW..r!.{...\A+.pV.....V..a.9/OV.m.Rc.U...M<c..)/.A.i.>e....8F.pv.s.+d.&.Z.Z.&#..SC..'..j.......Lr..y..R..%..}B..~..Z'B.M8,pW.$.!...u...~.L.G6w..B.].:s..i.6.z>.M7...O..V...f....FU..t.c.....L..|.a..K&...*..Z_. $O....%.i."K....D..S..<1{;....P.l.IH.K..U.. ....czN...../T...C..D.XL.:[B...:.....l~....=......k......?a.%3..c.`u.......o...#B...K.../.f:. bV.L..RN..@ee..-..8z.......:\....-...@........u=..t.../F'w.O....[..B..<.@g.h.o).I.|N=_...z..h...B..@....J.Rt..V..z.q.qq1........4.Es..e..;.j|S.....U..ZdD...9.....x...f.....B}U.Fz.....T)..kK?N(..(.-Vva".?.......Q.F..v.>7q.....r....Cj..S....5..F.m.....u.5&..;.v....A..@..h..:...3....R_....s+."....[520.,.$.5..#c..`...#..1.....x..R..7...5......e..d.^*u..Y.ZJ....!.rx......H^.4..g;7.....=...u?...oO...G....=..z..H.....h_..?.Bf".......q/.RZ.*aO(...s.....#}'..z..6v.......1..-....t......`...I.j,....2.QbB8.Y}dy.J..../..o6;.p.(9.F v-..f.0.Vh-t.... c."....@"..}V%V..]....?.:...9r...W
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):279
                                        Entropy (8bit):7.2895941163568585
                                        Encrypted:false
                                        SSDEEP:6:DTpGou8aN63lkr6RoHtLTwkIDp78frSJVgxGnFY22w20FCnBR:R88aYk7NLTwpDp7aE6wKBR
                                        MD5:A5AEC6A3E0F03AF32AEB25E0E8554304
                                        SHA1:CF06D5DB8334C8DAD162E8B781D050DC5BDAFE27
                                        SHA-256:7EADFE046E15F79AF9E26038154E69D075F65DC00CD3EB152815287E3DB59BD0
                                        SHA-512:D5F4963A665B825C5BBA34EC76D08041C760F24B2EC23A4BE1A88AB408EB3D004362DDA6F411DFB150B995A044F3E3BF6EDA512640BA2C9AD0939F18E9F61F87
                                        Malicious:false
                                        Preview:../XX.LK7.H.....H..F.0"...xe...:G.LN8./.W.j). .A....Y/W.s....5.aZy..}..b%./...{-.....}..~,t.R...v...$.O..R...O.D..vb.\...o..`"u.aR...G..Y.i......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.976512003133592
                                        Encrypted:false
                                        SSDEEP:192:6H6bPD8v6+XlBg9J1WhifJgmMjE+kdIppS:A6Xo6ATiumUkES
                                        MD5:0830D426FE98EA2123475866FC40697B
                                        SHA1:B5D43548FF7175A52F2F1D032F4A1272C2B5A65A
                                        SHA-256:A9AF8B29FF8FB35F686A6CFBC49BEDB57A1A2893AAC9FE9D4C3FD9734F5EE578
                                        SHA-512:65FCEF9D06BD1D521D1F3362F2B4F76B082EED39EDD22F1AD700CE909C18181DDD13A2E274D094E84C18346C99A19AFA748297483CC62EC8696A2215A9E634B4
                                        Malicious:false
                                        Preview:3..x.W..5..*.......$e..\..m.5.j..s\0P.8..}\.?a....\...:;.s.+7..A}H.q.H.. d.Pnn!......!.:F.p....!...q..x..e..xy....y.;........,Z..B...Y..^..L...!.;..ocdS.M{..w....F..q:2B|.d.......!...q..-.Fx.!.-c.)..l..9._PT..^..[W.7.1.`.!...5.`..n.@.m..=.m'...O...A...c..+..w......bw..=.tS.&..r.......^?.\.IW.k.t....X/r.{...l....?V...Dt......g.g.;..=yN'....b..."j?K....ET!..VuK.^l<.#...#=.U.t^.........o.6k?K.9.<5...Qb...i/..K2.J...N...QP``#.w~.n.L.L.y3...u...$K7...!.S.Fdr..^sP..?,.Z..a./....-....5.T.i+..+.....al.H.R....$..VD........|D..6..0.Z.5A.s...H...6..J......r.....90zO.....).RqE.,.X.I.'.......kb..a.j.W?.{..[...Il....(.Ew..d...Y....(...8p2...TGV.\.(.....x].=..i;...1.....l@.E.f..&'=./t?...g..^.5(........i%...|}...\.Z{...a..4%.I.`..........8.=1"z...R.+U.../..1..X.M..H[x...;..}......".b.l^..BO...n.....}.....oLD.;.2GkQ..F$rv....H...=b.,1..(.j#k{qk....('I...N.....|.!.O. ]+.w...z"y........j.....'..).~Z.%....e.q%~.d.....[F.H.....\.b...x..S..O.[u="X~C.n
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):270566
                                        Entropy (8bit):7.999359975344024
                                        Encrypted:true
                                        SSDEEP:3072:YyByo5BvDxLeCpny8Rc2N4wozGEGtbcMNEG4aDhDU/yRrtzmkFfayKPy8tIf4L9p:J74Qj6/wQ6B8chw0BzDAyKXt9R16b8
                                        MD5:7BC2A8E3FAF18663B051BA4EDFF4D091
                                        SHA1:140BBD4D59C1838B57294D08050A1E6C1D7F6948
                                        SHA-256:A48E2F653ACD000F2224030037CD5760F4036925F72CB10DBA73CF5A34B3B725
                                        SHA-512:AAC9309333109E1142BF604B43F07976AD9508095D827CC98936B94BBEFDAFBF0836D0343ABFC3C55857AD3AFA9B413285EDA742297F3B0E82FED3E5C39DF233
                                        Malicious:true
                                        Preview:,<......\.xG...i..a.Mm......eD{......j...Pt...K:P*.k.*.#`-.......d..+*g.s#...(A.....#...TA..Q.S.#..k......RC..>=..|..#.b.*.t&.........u...n.0!.=....ghDv.>.......s..c.).q....b......z.{[..}u..B^dy$/F..)m.......G......S..!...Da...:..DFf....:...q.p.8Awv.P.............q.?. x....'8.J.l.....m`._....../.9..O........5.aX....2($(...}I^v%..A..........KNrq..{./F..<........$P}+...9...6...3ax.X*gMP.S.?[..[5Rn...n.':..8....W{...MlS.x....{.n2b.%.n..Z..."eF..."...........P..8.Y_.'.....k.'q.c..:..0G...V.W./Y...T=.U.=.....3..%._.....i~...|.....CY.(:.....S5p.#.....5...n...=r.C..w..E......`AW..p...N....Z....FQd....I.....d.n.....3=....../.+...E{O...i$2....Mf.v...M.E.6WD.2..f._....=.Jd..s.B.....E.1.n..lbX...=.oe.K......s.MQQ.A.....3.........|.J.........q.({._....2.j7Zq8./..jO.....o.=5...cm|I....7A.5|.G3.y.P...U..j=^T.`u.....[.]Q..Q...2C[..jZ .l..u.C.0......../.....L[.s....i.|..hnTm...:Ey.+...O.........~2+X..~t..m.1,6..|q....Pr.YY.o:..N-~iu.u.>..y.G.V....cFi.:
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.981616585755928
                                        Encrypted:false
                                        SSDEEP:192:dSO9X2qpBq7QfiF6JzZHDHVyGwJxDBMLYwq1K+DuHYbDpS:dxXPyQvHmjMUryH6S
                                        MD5:2A8EB0BDBFE5BC258C1333C9847D972D
                                        SHA1:677D4F7F7692A6CDF338B6BEBFA7998F3EF21C3E
                                        SHA-256:0785F8403F0755D3A109DE6938DD155EF63F2992EC83ED52372310DF6965DF95
                                        SHA-512:98C17184D2850671B275BA55E94C8E7F27CBBACA04DD9DDA0306438654BE9CD83E387E975E59C0D980FEBB5F173248D0FDAE4B035AB9187F91B24901C2E3D9C0
                                        Malicious:false
                                        Preview:...........Y.$k......(..q.O....qbth?l..9.7.,..Y......>..T....x^...P.d<....`?5.8Z.*......}...}82`....}..\....m..N3. h:.......#..4...w.G.2w*..S.wC}.~;..k). .^dr O/~.j@| .;C.....~0.vEG..C2..3U.FX............;.=...&#..b...^......on....a....Q.X.`B.......'........D..+.....&...XB.Y.|....I.....4.6.....s@...A`']vj.<I..i.R.XY]O...@..M<..g.A../).....D.RX$<.....t.u .<W0..Fx...-:.8....)....a9.[)O..8$.*....].h..[...W...%.^....\..Dm}._..m5Wk.Z.1....o._..}...............Q....6X5l..Ph.s.r..5Q?G......w.8.r....)....p.n2/.....V...l...:.!q.7`.........".`.D.......TU."n/a.@.=m.....,...R.g.k.....h.j0..3X.....:.W.....D.9..B.......Y.F.m.D*.M!1.C.M..vhh2[4"..kg.0..i...1N&).K[9......~*.U4....!......^42...&..q/.H...x_.^>=_/.O.!(.4I..0V...-E..s....O|...'....i.qT9.\s.O..6f..7cftv...).iM.qS4.-......uj...O......(._.....~.....j..PR..z......Lk......M.....6Y.....(.h.z.A.x.W...b...-......[......Zg..g.0(..q.....r...{+x2V..;..a6..-..FK.....s>.Y...j.`..!.$.N.aW..7..p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.980687967822783
                                        Encrypted:false
                                        SSDEEP:192:7JCPUyUandH5m28pyPDcuL9hjiH/2wi7GqhTHN3YtpS:QzUEdVDbcabA/3Kp9xYrS
                                        MD5:34E611896DEC14709B4B5F7D6DBE2BBF
                                        SHA1:6FE501B87F76DEB361C3B3034087AD55B1AAC568
                                        SHA-256:8032A6EF107C11D50C94CBA8FFA4992E57EB0DE19E52C04BA06B581EEC998AB7
                                        SHA-512:F5DAD05C7B2994516B833E093594B25385A6FBA2EA71B24FF797F018A15729E1A3FE43F5A8DB6D95E5743CACF7009629638178DEA209E6E42DBF95751D356133
                                        Malicious:false
                                        Preview:../U.5.C....?k.[......h.`...N...c;...#...A6.2..A.H&..b.A&.k.i...+K..|...i_.R..[.S..L.......>........./.:/.....GL.9S.0.:.r....%....s..?.z...t..Q.Ei.@3..2I..'..............o{...z..t.......&....SJ...;..YW..OE...>k]."@.U..{i.....@WuM.\..^...B...#t7......!r.z....Y.c..QoT.;...X...}.&E4...1Q{.a...`.,a{qp..~....8c.>..tW.....\....8.".%.A./#^....`..0...{W......;..%../...B. .....U.T.m..?..0&.L/.....:|..$..>...Gu.8<..0.........jk`..P.6.GLa{xm.J9.t.+...g..x....Y+a .......du..Q.........j7L.c:....IL.Jhn...c.{...J.E-...rk.L~..y.].3.b0..(........Z......a...vn...."..K{.\u!...m...B....%T.M7.71.y-.sk..Bwi...X..6X...<...b}.~J7......0+I...N*.q%.x).H...#..Jwg...5..o.........L_.Q.......~.....|.M.h.7.t.Y!...h7..=......."..z.x..9...........}.......Xf.G.i...,>Y.....6.37..b......g.._8.......rE.S....1....$..8.....U.._8.2...Z.....@..D.Fe.I.....G.$D6..w.0s.CY...T.....<......;.......F..?.....7.&.+..ls..H.\7...G....;M.fZ.X.NI)o..H_.9.a..O..q..y......sA......W'FB..9.5.0....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):262741
                                        Entropy (8bit):7.9991802175398545
                                        Encrypted:true
                                        SSDEEP:6144:zFv3xhmmYXql6CP+9qDpNBhunH4xclfcU3l7fjk4GQLSSZQ3:zd3bHYX06CPUqDPun4ucSZbk8vW3
                                        MD5:46A01EA97B0F4527B19C8503D7E3B71A
                                        SHA1:5C7A04DD87F985684DC4F2BDB4D185215A9818CB
                                        SHA-256:89A81E4FCD28ECE64C3EC1A6CC8077129595F4D6CFB281DEE8237C34930B707F
                                        SHA-512:42A1307526E07307C2F4EBEF218B2129EBD99BFB71C6066B7E61A4F504D9412A08CBD7C1FD4EF832C8719F111053EA8C32A9F785DFD52E7AD3D908C33FD94C04
                                        Malicious:true
                                        Preview:....=@........s.../.` A(r..1)b.m9V2.....\m\...9L...i>..W,s....D.H..2I..6p..q.........]M.m..7..D..C......H...#.M...E+..2......?...:?..;q.U.g....)...c%=K<.....b(.y.@ou....#..O..k.+g>..0..>'..,.~.$#..5..N..vO.2...8....\......[m_r3.5?...../k......[.4P.......?.:.I..&.2....d..t/.P~<.!_j....r..^."!.2h..33..\...1..^.\k.7ce^Q.J.=wL.k......[<._9l.p*.....kt(...A.> |A.....U.."..HJr....&!..~.6y.P.m<....q.3]...ow$...t.".{=.J'.d.jy'L.....^...s.Rj.,.U.$..H...I...k...R,.S...e .j{o.5F....l Vw..-).p.f..^.T...s...q..s!. .B.x..+Y.`E....^........%..m....w.. .~LX....4.\6g.Km.].A.$.@....#......{....s}.$.^.{..s...$.M~?.A.B2X.O..5Gog.&H1),=2...6G.8..s.Y.....!s.7^/G.Xux.is.D..<.)..6j...&.].I..~/....O".......85G..6..\..\.u.;.......mt..........F..T...........mjH.....e......Z....=e....Ds.....hC...G..O.nt...k.v....U...=P.F#.W......u.![p....l....C..Uy.8.?.A..@..*.....u.>.v0.eP.V..e..?\...t.h..-fN...[.z.s.8.f~...c."~T.syO.=.}.....Z.....u....LG...<..T.....i..!(......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.978165061842514
                                        Encrypted:false
                                        SSDEEP:192:+Q9W4+00hL4C3EEGZP84Rug9Jq5/DgfaNzfzYcF4HFN2KwogEsU55MpS:+sZ+0Q4PEGNRugc/DgiNrz74HFN2ZPS
                                        MD5:0205769754EB80250B41C38360FBCF71
                                        SHA1:AEBBA742EDD9E63C0332292FA5ED12BDB7CB49C7
                                        SHA-256:330FF241C89BDD196843233E6FD8D455590D37562D8AD8B0222581F21F7E9EAB
                                        SHA-512:4253603D42F7986B4908356A2BDC6231E33AC96F825D258EC9C80B692668FD3FFD6EF198F349500ACAB10BE3BAF11BBAD6A5989C046CD29795952EC6E513C14C
                                        Malicious:false
                                        Preview:e(....uM..bw.J.Mre.g.>}.j!8:.7.c..).....JI.V.L.__8.......m.... ...l..I.6..`. .0...r.h..M.}6.../.E;...N..gs.=.... (...x..Z4.&.l.{...R.,...i..[$....$...P...?..P18.^..Ah.oa.........7.|...>a..{....(.>.=.B,#3s..{."..(.....V<.:.....P...+....P.z...CN].mN...Y...."..%d[...l.oM.... .@..^>U.r.<.....=X...k[Vb.@%G..Q.Io@..)...+t<.....}.."..E.a..._?...-.0....:....A.'...1jK.. {|.?.j.^7.H=..q..T..\0....w...5.....4 B.._;.zd.s.|G......~...%.F...JhUM..B.]O]BY......y..#r?$.J..l..@7......:..e.G.9>..|lX%...4)m.._..I.t....X.%...d..'..u.FRO4..A...../G")..O..a.3,o..!5.M...4.<....!J.7_.....F/.~ ;]H..@..>..X..Z..bM.....b.?|h.......K[6....+WI.Qj(...n.....9rC-.9.$R.*....y.R..m...7.kD_.k6 .......3M.....F.*^..^.n.O...iD..^.!....?..gJ..2N..L.)Fl4..`.....<..'..a...u?6....}~g...K..!.|.hl...fv...C.?G.E..,.........Y.D.&.SV..r.......W.9..0.P..{..STi?x.]...<!..u.6..'...}.......q....d....W...ei:@.m......%B..qM..s.`!........PL..0<..p.H<.[.".....k.`..m..X..,D....*...F....[.%.,.zH.;.v.g]
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):270566
                                        Entropy (8bit):7.999229054922113
                                        Encrypted:true
                                        SSDEEP:6144:2P88FHJHRf6JWRoX7HC+3paL7K9haFlahaOcv1xhmw9Jl+G+:2P84b6EoDCapaL7UUFlhOcIGTn+
                                        MD5:09623C2EE8B8B6EAF85C62ABCBBD319D
                                        SHA1:BC112D93DA4A37605A6F0EB201F83045793AB056
                                        SHA-256:04CAD1B822E6EAF49C728AF7A21F225B99FBD863088C7869668ECF241A3CC03B
                                        SHA-512:251BC301BA53E55948A96C92E1C186BCA925B5B74165F0868D0E7AE8783F10D8A82422B388039CFB2D33366E7297F7CEA7829ACB131994A982E40D3776FCCC92
                                        Malicious:true
                                        Preview:r..2^..b..<.....N....8.ci.......&`j<"....=HN.."02WFJ....X.........".a..M......g...!.... h.......y....4.K]F.....z..cSzvH09.R.....a.d'.....1x.....p\.+zH.@zp.J{@...o...'.F.%mr.p.]..4Z....3..X.R.Qc.]3^...G.p.Z..L#F..."Vrf[{..H!.Y..u.)+.K,..Er.|..C.0.^....<z...6.....`...k~2c.ej.v..P.....$JH._....KW.....BL.1..N 6.|u...0@*.22T.....Hd.,.].Fm.VR._....CB.....wg.MKs.9.U,/......wS.s:.J.....@....L..9...g...>%..R..\.....n......c...W.*.O........:.QG...r..;.o3P...q.....P...*.J..=d..J....d...rI...8..?wK+!...../K.Fb<..tk&... z........~..t|a...vrk'{Y1F.d5%..7.5.X!...t.e......?9}4{..]...n.L/m[..,.....<,....C.~].J....Z."z.Y.m..~?..s......u.X..9..t?... ..:..x....LI...Kh..b.7./.....R..3~.GfO..c>60..B..`..rc._Y.Yu....p0-.4X..ZCW.~.,'....P.Pm.Y.4h...)....bU?....x..v.Z....|s....0j...l4.~.r.[.....a.k}.>+.....}.`..+......[.l.K.R...<....HG....:g.^.,...GO.!.!_.../.x.k^.%h...oG.,.b.~<2....v..P.S...sx... .3..0.z#...Pm..X-.h.H..ua]...;O.m.>.NRQ..*...x&....A.3.....W.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.9770796953599294
                                        Encrypted:false
                                        SSDEEP:192:2cEutwp01UIRCYgIHyXSo+EKVDSxO1WjTJp1KfQahv5zpS:X/tfJRC9IU+EO1WjVSYaf1S
                                        MD5:0654AFF8F682EB324C9A0E70302D0BA1
                                        SHA1:1FA5F0DC36A0903CDC2A3B80A3C3F607C387F878
                                        SHA-256:F02D420142FED70AE997EC83C188F5C0FFF9120E988B62B46B27D9981514A1D0
                                        SHA-512:E8957B24C35988636567D54F4C3EC4BDAC646F8FE9E7726BFC13820E4B8C4111C8B22A0783A7C7382E45F3C93DCE5BADA7BFEED6F37D505312F48C91422392DE
                                        Malicious:false
                                        Preview:..cm>r.C...j .8.[..l[K.yl....F.'J..X...Y....... J..c.'\oQ.......K.xt.f..e-...M..e....=A.a/i.......3..b..{.%..PC...c.tZd.....\.j'j...U].a.m@.d.+...dN.:$>.x..^. f{.U6....J......7c.h..D.................^2.Gn{yC.Ik.YGS.p#.*...7.!y%..^.U..?.`.%F..........f.......J.go.G#......Riw.,....w..7.y..(.Z..H.....9A..b/..2l..0.............'....:(. ....6fb.l..d.]m.....F._&*P...g.^........q|.{....L...&...o.FM.....a1..^..Q....7..4....BS.(.(_.L...d.A...y.3....m.xE`...I7.G..~F?MgZ..E.."..1..Ww.K.o.(.<G..E......z..\."......J.a......j....F..PO.=....d...N&.^. A..wC{....H7.N..g.w.w@tL3X#.><.wRd..u..k..$6......@...ku.o......Ef}n.q{Vu. `u.UW.....*...j..."....MLO.6U.<...s....L.OV......7...W.x.P..^.\.7Mp.;.\-.2&s}..A....{....:O....M..y..Y..C.d.og.[......=.....=..]..w.$. ..wG .U.J.?dY.>{....,.F....L1.(.#8[}0.3.eV....=...k?z.Mq....N...'E..6*....|@2.lA!.:...K7..!..1..s.....sN.....L..8..|.Z...L....J.Z,.B.~......?...OB.C,........r........o.M..|h1...N.-..e.:..E...XH.I.@.^..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.975028569855807
                                        Encrypted:false
                                        SSDEEP:192:F06TUMHIncP5R/RbKHx2+Ma87ozBP8sipS:+6AoIcP4ENahtCS
                                        MD5:5824BCD16D24C333FEBF7DA8EB02A6A4
                                        SHA1:82DBF10B88C60D330865DE8AAE75A86708CBAD0E
                                        SHA-256:F4C1A610B92D8907F477F6F55DD7692316E6232AD4D98B6ED6C25994BB84C983
                                        SHA-512:5742B69E987D550E96F28F9D015CA7862CF941909E65DF6508BC085D29E12294B3583866D9E1B0D002DD17BFB1B96D17875E8B19BB05F63F1E5BE86F2F434549
                                        Malicious:false
                                        Preview:...F$.......R.fZ.'.L.*D...6'd...M..Y...-Z%.w{.%...b,...K....U..".E..P.J..z.S....b."{..F.e..I..-u.8..}+1M..,K.|A....`n...u.*..i.....b.).......#...W....^~.;.b'.yQ.......[.....)$.T.}z.A.Y..6,......H.B...m...^..WGO.i..!E.x..T..2.M..v*..m...V.X...Q.?....r/.i....Q]..\ "..h....z.....;.cE......<.|).ez.-,......o.......r.....W)].M2....]$So-c.&..5.5o..,..:v.....V. R..........L.Z...,.P..Wp..P.H.......D...<.F.}u......D.3s.b...4.n. Z._..B7.J.c..Y%l....VWo.[...U:....2..L.7.....Z..o8Hg..b."..@fIe4....^T..........L"v..|;.jR.&I.T......`.G0....#.H.._?.WD5..;T..V...f..,"..C.......7...B.).4.X.m.2...6P..;..2DIy.^..fcp[.......X....&..D.... i1.:#.0..(.@.%.p... >?........r.X<m.F..u..`~.f...g.._...w...zG..P.W.....S.Z..C .@W. ...(7...Q.W..v.U..Xc1..$"..5.'.....j....o....2.G.&..8.M..D!`...;..$&A....Z*.zW....uQ...[wo..a.;l...y.....*Y..F.gA/}t0c$.........~.K.|.....LB:...:...T...Q.....;.`O..dc.-^2....F...g.U.L..4..;...!5'.>..G<.....;..N..#..I/\..N.Op..h.6_ ..N.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):262741
                                        Entropy (8bit):7.999347107482269
                                        Encrypted:true
                                        SSDEEP:6144:IE95zHOxX5FdYVpi7O4su7+lGIB0FDtd0ErW/VVn882yDqi7:IEXHQX5Fd0p2Vs75BAkECj8Zy+i7
                                        MD5:D7223618FFA77C249F7CD08C6A4AEF9D
                                        SHA1:69979CD4E9F9A264E3422A339F20203D67672648
                                        SHA-256:D3FE124504FB90AA90D1ED73DED624DE71677C324A499A0AE29D645125498B59
                                        SHA-512:E6F96DB783C6A2FD5FC9AF9D9EFAC5A840AE4AF34EAC0E6415F3D4C0854B3DA68E67A6A41A2320AADE234448329102F1C384E72C0EF7978779E497F7B211B6D8
                                        Malicious:true
                                        Preview:.$...tT>.W.......S...~.............b._.....2...L...O...U..."...E...a...Z.......)a.,VK.U.F..a8c....a..`..6KYI....L.T.u?..^..P.....61.<.Y..@{.v..y{h6./n.e..J..2).gb....O...[99ZA=o..3.......-..3......Kk.z...5.OcNjt...-.H.....Cu...0l/..7]""R;Y\.".!Q.n.Y.9.1...].].W......w..G.Ja...Ip..V.&...o.?....N....7.g.]?..3D.<.)..y.:n..V.5L#...$..^0..&.={.l.-.q9..n.=2...m.<\.G~.G6.R..o'x.nP.)..S:.....'|....%W.i..V_:...+.....9.;.h.#g..dw.L,....b..l.....{t.....S..ze....!h....X...u`)@.i.h.l.h.{.oHd.cz.N.k..\&..#..U...R....-._.)7....m#U......9.N?......L.3.7.T...4$(..t.4..C..4..:mW...d#.....(&%xB&UaZWMz.B.b...!./[..R........G`.......TZ...k.A~%h.&..l.....'j.bDtX.GV...W.|d.>..G......{....rP.vj,.l..*..[HW.M....ZNl..x....[.sp^....Ny......sD..C.:.....N]J..-..7.=.A..c.}h....XC...f.......Y.d.......r4........^......)Z\*......unc...Qe....n..[.$..f6.n.;.G.ry=.+ALY&hc8.4..~n...y.;.. .e.f..U[O.+..7.G.m.......t]o....eEb/.....=h1?B.D'.wh{<X.(.r..DQEa.@U.......M...s..>.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):346
                                        Entropy (8bit):7.347182373476777
                                        Encrypted:false
                                        SSDEEP:6:pA2EARGm8JMEkRz8Xtaf/gZJ2KwBR8DktcG1adBrw4WCDp78frSJVgxGnFY22w2r:pAeILkV8XtPZJ2KwBR/tcG1yBEYp7aEk
                                        MD5:E3741D43EF7A115C2E674F8BE39B7661
                                        SHA1:4365518A9045F5B4E52BD46B1752450EE91EA784
                                        SHA-256:DBE273A2EB05B5D5D3E0FCB184A495F87D9330BD7F433D88367660976E23E972
                                        SHA-512:550762136B040EE89FC7EFAEB157AC383742200EFDDBB6F1CB8351BF27EFF7EFA54ADBFBD2E8C687D9E8554622FD229F4417E565A3980EA26D23347A9781C5D6
                                        Malicious:false
                                        Preview:..._q%.c.$E+v!r{J.J...NN.2.R.G..H.z.iY.....i.B.\7 A)c.....aR1$E.:...........v....."zi....hW..A7....;h.n).......ds.nv....X.".aZ+.}..a&.,.......k2x..............q...B..w.T..?Q...@."..J.[p..A,..b.a..Lj......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):256
                                        Entropy (8bit):7.137370751809458
                                        Encrypted:false
                                        SSDEEP:6:2OX8NMW3xw6hogfnzNsp78frSJVgxGnFY22w20FCnBR:DCr3/nmp7aE6wKBR
                                        MD5:B68162F67DCAD0CCD4C3D28B8A71EEE0
                                        SHA1:475420CB3FE4C656EFD7A4CBCD7585C0E51363A3
                                        SHA-256:BB0276BE17C01731E7D7069D8D079C816BFBD5B3D39BD6DEB449A52030DB3609
                                        SHA-512:CAC8443F96679F1B866929C2DA93DEB1667E85558FAC5965BD89417B0C4E87F08230133A72CD7895752ADB15827693368BE7A6A50688394F4336D768BFD43207
                                        Malicious:false
                                        Preview:.&.}..h.N...h.n).......dd.sX..... .a@+../..a%.,........u.]...".n2]...s.S.8.Q.^n..@..ex..p.....V.."TR...J..N..{..Sd.l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):601604
                                        Entropy (8bit):7.9663682586955655
                                        Encrypted:false
                                        SSDEEP:12288:Lvf6CYGMrmswZaOIzHFkNuvnmJUGI4/tNsJPevwZoFLmBjHF:Ln6CrDsw8OIjFFvnqKqNIAwZoFOl
                                        MD5:67C0FDFF63CCEFC68107526E63CB3F05
                                        SHA1:F8BE5BC676E7FB0D08F1DDE6C7D11A7B6533A66D
                                        SHA-256:B6CEE669015E3B62AC2DBD3FABD7CA3435E3317A1EE252E79B47B2F107C05F28
                                        SHA-512:0AB03F95E74014E29768C1AE7CABF856AC28D373ECBB55934540EE3838D3253B5D5D21473DC8A13DF1B514E405E939B67FE3F9559BC0B7F517D13DC9CD7E455D
                                        Malicious:false
                                        Preview:k:)..[..c..f...K..!.!:.X.gq)2.p.G...}..5.F.&.G.n./.Ms<...*,.W3....8..fH.C.).....ou...tL.....mH.g.7....o.....9.-8...h*I..F\!..3&$...1sP.q.).s4 .......@Jp..........%..........<.Bt..x.....-....M..*Uf..DS..Y.a..a.....1;.8..Bd.3bY.L.....8...Zg%.x'..Y4"R..9N.Q.G...u..A-M..".4|...Y.Q.X7Gi.;A...V..-... .(......@.N.....;,.E....N0.....W%as.U...;sA....%.$-f[.9l.=n...(....b.s..%$.C..u>....6.......d../C...jB.(.N.m....1.Q%.=..2m%&D....AV....I.t..7...3.B......Y..C6.......#E.S^"f...(UF.......CM-_...=...:.#J..@P...a..%QW.i...8.nY..IS.73.o....e..._..W..zM.xT....t....3...i..v.Z....I.r.......W:.T..n.f.Ir+..n.Xj)...x...dZ.-...L.)9 |.B..Zs._B#..}.h....;.Iw..M9.*..5......g..L.....L....<K...U`..n~..&..%...V..Pe.].OF..T..Q..3OC .....Q5...7.2.V:.!g...|...Q.......1~5...c49L..S|...{D..2...}[G..{..a....a.^..P..{..=....K.<...Y...$'...ocm..9y...Y..}..g..<...~)..(m.k..*.lO.z..}....WC|.%.Ec..V/....v...a.f.i7`x.;lt.)I...#5.W.._...*..X.e....G...!..}..,"\m......[
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.977784503549799
                                        Encrypted:false
                                        SSDEEP:192:mwU4kz5X5fCAQ0xoTQKMQzF7EK4n3xw/J2bWuuL9cQ/RDrnLqIw2uipS:tk56AQ02yQpYK4nBw/J2re9cQ/FqFXCS
                                        MD5:A4FC910BCBD0FCDB86E37025B9A3D8D3
                                        SHA1:492D99C066E71E9056459BD81406610BD62FE0BD
                                        SHA-256:6FC38DB66BD3802A0FEDF9B3D7AD885A8D0082670458DB74B777B7F86C370969
                                        SHA-512:E2D0B8F374BCC725EFAC775F0394A650CE1F339902499D377C56F8A63732BF3B333593C028EA755CBC31D2437625CC3E49F99A62EA812DA06C9E965143C0EAD2
                                        Malicious:false
                                        Preview:GvHY;.N..Pp...L...91..*..v...N.#.t8....w..t.,.!.......HkL..G..].(.............2.#.;..J!...2.....P.3...7....Y.G.=....H8.m-...`.P"...Ee..<...L3]..8.8-/...o.sn.....{m.5|.M..`...9....#.UQ..L:.2...4....#.1A......<"Y6.v2.:......(B. WY49..p.j.P.Kv.."k.~.....;..C..{.w.br=.V7H..;......*.H..gD..B....6>O.../..U..K...U.....c...>#....H.....P....]c.slY.=>....a."..y3.bY.....o.......m<...Q.(.H.....nP....Y..... ..k..Vb.....\.....?)....#...F.u(.e.~...cJ....#.=..>M>..9k.....c...Ny.1....H..7wDp..U...y.)..X<..Q........^m..OA..ACu.H....ur.2...Lu..b.Q..d..&j.d.-......-.<...2.. .n.D..q....j_.;...<........Ts.4.``...P-.,.|..9....A.H..s......se.~......{o^.o....Q.{.Li.Rq.2:?S...S.n...p..8..%|....K+Y..;./.....=#..4..,.....(.l=QY3o.i..?.....?=.j..j7.#.....K.".....X$.7..zb[..n..n.:Ju.....q.]..L.P6uodnTs..E5.^....|*.....t..........B...Cf......N..R.....`.d.&.q2G..>.3.N......D..l4.k.'.....+.....f.........dk..j]....P.....,.l...i.T......&oJ.v.....|rKS.5.}&.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):270566
                                        Entropy (8bit):7.999328405886675
                                        Encrypted:true
                                        SSDEEP:3072:BhmifB0a8ShNFMdjcpBM5gR7tjFKFBY4VfEHqswbiN6/O6wYNVqLT/XstFGgx:HfBBFzpPReF24uHqswbiNW6LDKGC
                                        MD5:C7E4F025A2227E6D1B7AF96B3F4DBE3D
                                        SHA1:D31637C6C13608E7467D8522FDC5603E0D7E87FA
                                        SHA-256:2C2932202FBB315D2A0DEC417EBF19406E1DF08C755D4B79AD3AD87AB3B3E8E9
                                        SHA-512:48769636ECE91DB9622EADD28A66A74A97F4A2F3827C9FDF7140CB193A50DB48AA893B68BC8D367BC175B1261171444546FD50A26CD2EF4BF0F0C07A44ABEB18
                                        Malicious:true
                                        Preview:...Shb..4......G.....A...I.+..))....Y.....>.o$..U..)...q@.1.}U:.k.Q.Ac.........<[..PlL....o2.\>;.4..RzB...(e.*v..P.iB...x.j$.<j....}.q*0!.'(g.u...~..".....NW.8\..-[.wB...l|....B..I.u..G..~..?el..3.T.I.......H..+/pB9.2c.3.P....&^k~..}...Z}D.|..y_...)....?...~.DX.....g...2....rQe[....@H...*..9.i......O.p.GC.g..ik~W`)E..~.*.c.<.......cP.X.qi....e1.....T.v..7*...J.i.|.qg.j!.<cl..=.!.....CV...3S....K(.,.......k).8.YD.S...?.........C..*..5S.&2.9.}Z!.].x.#.......W..g..Ay.j\L.[.W...f.yu<=.h......p6.,..:..sx+.GiyZj......UO.....I`.$.Ks.,[./.t6.........+:...`....n.:m[..,B..h..o.7.......q.Yf.f.4.....*..j........x...pZ..p.y....^.#vF.[..I.d.R{..{Wy......Y.@..B..2.4.U.....7....,...w}uE..D.a.<.D...A.hV...~.eF.:......E.k.&\.QM.TY.&...NM.1..hdH..@P.B4....^..*.Q.k.[.$.LN........hB....I...7..8.V)b!...Y.C...|M.....jbn.3.-..>].$.O.0.^_..y..!..BPR0....d.o....J#N....p=...Y..@.c'w.......0].r..1..a2....].2i,.#U6..Ro.h/h.~.....-.Sd6=..L~....7....}........N.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.97745658864369
                                        Encrypted:false
                                        SSDEEP:192:RhnrM1PeN48jjfaWZcz9IRsIi95dhtYWRL+gUzHRxipS:PrLNPi6GIG5drfNcxxCS
                                        MD5:B9FCEA0F04B583BABBE6CDBA574CC516
                                        SHA1:3D99C60086BB64CB1D8ACFCD5E321C3B5F2D580A
                                        SHA-256:01F026E68253409493B4F85A482A00F360229B287E34F6BD3DC3B3D749A0FAFF
                                        SHA-512:E11E167D78F4F0C519BA2D97E36522D4F96AFFCD01AAAE5EB6AD61CA8C7341A8F615C133299648706254AB42D901C87CCD7DDA8F9C316B306CE057BB5FB5FF9A
                                        Malicious:false
                                        Preview:B~..`...:.'"j.U.m(X....1z......OD....A......~..;v..G....o.D.V.ze19.ZW(f....e..Yw..f\-..D..7..R9d..6..".T...7OnExs.k...=..b*.3^.... t.....s ........2.U5 B;K.Uw...7...1._.ga..../#*.1.......q......B..{d.._.....[..%.3.D....0.F.....Z.2....V.^0......../.. \..(Z.|8..K...me...b.......).d.(....M6!2.c..aC#>..N.r.h......_.....x....%D.#...Vv...i.z...kU..0.5.#.>...L..E..f9.h...*Bz.'..f\...........s/.5s......Y......_.OR^...,...;.....i~u.r..Q@.-./;..6.M...jp.../..x..;....L1..1p._.....R1.E...=.\.8.jU....lT.O....f.N`.:....Z..z<.^v....Me~.qH>.g..[...^..S...%...I.v...Eh.2.O......v...~..O|..)*GS.k...1...7(...#..H.1-.]_..!..<s.H.....s3...B..6+..H.B...t2..RiR.UJ..%.7.J...?..........d.9.2..r..yc..)...YF.....C...>.r[).`.w.v..u.r..I.$..1YmB.=.P.a......[. .CZ9.=.x..}.N..T..W.....rz..l..........".oJ....C..j....s.\y]..i...,`...,...}..>yY2.......}...).kOe....n..3..}.z.X-R.P4EF...D..'..,.*.E.uYu..C........8..w.'.....C.>.^_.@...k...O.N.jG......V..R;Z..k5..+S.,V.\.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8422
                                        Entropy (8bit):7.979365622341745
                                        Encrypted:false
                                        SSDEEP:192:u/0zY6W2OcKELgDOjeO5vDmFFdc55HskvzGrjPFeqyyLlH+SfRyaUygpS:u/YHOcKEUiLMTa7VkjFpVLlH+SfRxUyT
                                        MD5:47FC8CBB8BDE45F0E43EA5A4E4DE7BAF
                                        SHA1:885E83E02C91C6908A990849B3EC6CA2C5A59BA2
                                        SHA-256:196833EC5680DC7DF726F10722D3656F37E0AB55F9623CA2DE58390507E0E371
                                        SHA-512:4E1D77D5A5116E94823AFC27DEFE9AFED4E32F5DBF13B5CFFCB2BE73A31C71A46CB5FF3B2CF05EDF78941D83F491E7F0BB4353644C618D60DB576CDE146BA249
                                        Malicious:false
                                        Preview:.pY6NG..0...j..g..iV>..K..U=... m.m....q ...G..........]*.v..M.x...B...BQ..D...0.x..NE..t...X._n0*,.m.....$&.L.x.n.{.!...X......@..#N.C.$O ..O....&...n.d..@...Qb.....T...6..A.#..pEi.."....i......l.....Z..JN.%.E.{$....0.1.7.......d-..r.....x.^.{6.....{.8.b...T.k......NgT..:R...X.o|*.O.......kT..P.!..f...._O.G..p=....m..]<X<.^..T....5v.7....dn...s.MI.(.....V..ti....4.......^.a.u........1......z.... .....".SH-,.........a....z.E.<..0......h.|..3K.5j{gvR...B.<Ml4|...ym.w....Z....<......"....y...>..7o......<.2....j.X...(fv..(.+.@&9W.rRd....)Rh.8.|.._\..kw.....kRxS7.X.....b..[...~......:...j.{~O2...,`..D.2.G(.=.....W6.C.R.9..Q~..........a.".r.L.N*T....0tj.t.w..o..e.:...\K.].J.HH+.]i..,...).G.KzK.0.2..5...H....%m.x...."/t......#6..5Q.....`{U.=....5..^..j.&.......4.8.$.6..ZSd..=.h...Q.../...7......D.n..]cw..k...WAA.<R.g-Lh.xg.E..z......\.[.u.....:.B]W-.r.w....p(...Q..E...J``....x.7.._Q)`..W...q..~.w.\...g.G:..{.K.{......F....ZEq......]
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):262741
                                        Entropy (8bit):7.999304796810229
                                        Encrypted:true
                                        SSDEEP:6144:oDCw8KqY1tAXGZj2vbp5RTHKGnlaBAhWly8DKY3lyU:oDC0qWKGZj8RbAeW42f
                                        MD5:EFF3B4BCDB6D1A30B53E79AC3614E568
                                        SHA1:156B9D9B9313B95B2F3BC5299254BF874207E708
                                        SHA-256:F73396224279DFEBFF8355892177BC1E053DEBAA98B542A1D8C4DF9E94681BF3
                                        SHA-512:0497748F7DF555B33CECDE986B123368080B97DB63E03F05BD5EA1EFB777AE09FAE95CA226A3CB33205147A83E96048217EAFCB14B1481939FD623068072C994
                                        Malicious:true
                                        Preview:....D....N.z./...8.?.i'..L.[...2?.m.6...%R..._*.]..n...QmJ..E..j.rQ.....0...<....a9hHW.....H..Y..,v....:.E../..oI....-c..UZ.....#.....(.D..K....50I..^.,.;>....1v..i,h.{X......bk}...W..M....H.|...3.Y...*...X.&....DFf'.3..m..Q/....._}n4hE....O)..!.HVR$.} .M.uK..w..3.K...w.O..s.S.....*.#..(.#..VRgw.RY.......b..u.....`.......I......!wMqcg4M.. .6.J.c..N.N......R.%0..TP.%.[?...q@`....g..z...Rm_Z....>.I....(..,:...A...d...I.KV.3;.r1....>U.-e%.....a.H..\dMy..._.........;s.~..e..,:..*...i.v.JJ.N.4.\.y.....j!.d.z(...&a..R...s/J......7OE*=..)x...o..b1a.DZ).....o#.d..'..F.......'...,....!....mclz....,.R3U..?2.f.@....C<vp."$>.......Y.6....K.....Pm/.x._.....j.V...g...On+..h4.Q.SV)...&..z#.{.x.i..T=K<S.).?.X..@.K.;...|w.9i.L.}0v.P..:...#:p..N2A..O..B{RGY6.u:.n.?+E..:C?.Q.........4.$h....m....z.......+.&......n.'.K.Yjh...._..*<..u;K.R.<eMG.O..}.{?e..%....o....w..'.8S...))*..}..z.u.....%V.+.q.h....k..y'T.hX.6q...N.*.rj.....f.~..?.z....E...g_c.-.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):320
                                        Entropy (8bit):7.333125293442816
                                        Encrypted:false
                                        SSDEEP:6:s0KYlRkC7yXpZ4gO45iIRY1VBj1eCoPt4sp78frSJVgxGnFY22w20FCnBR:s0jlRL7NkeLBj1noPJp7aE6wKBR
                                        MD5:2A1EB60993286BCF894C860D2BD07F9E
                                        SHA1:E8B43D63319972175B043E5924C2D52587C17042
                                        SHA-256:2F9140984129B42AD216B3C78B44CCCEBCDEB746D95B16ED110F4355B46DBD3C
                                        SHA-512:5163D8601174ED5DAD18B04F63E4252C1D433DEB023786E4D3788A2C5FB943E5E8AF4E282E474F0E474B3BAE54B1D0363B1907A0F398F2888CC1E60269A362DB
                                        Malicious:false
                                        Preview:..r.v.......c.^....`&.^...`N.....[.i....(t"..8..d*._...Wug<.:z....s.]...].{..|.Vr.n)......~..+......p.aZ+..}..b%.j....{_..(..!o.K..Z.".'...W..d....R........U..o_ ...<i..w..A..e......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49403
                                        Entropy (8bit):7.996804834836401
                                        Encrypted:true
                                        SSDEEP:1536:6pmlkawnmPLiAQQfVYKo2i2cAN5Dv0n0LvMq:OwPwnCGA7fJncAN5r0e0q
                                        MD5:9420114B4BB0978C1E5390581A00BA61
                                        SHA1:4BA73F4085C7000644D30C42765831C33EA90B6E
                                        SHA-256:AC431A312EC4AD7D09F0292A341F02D5536CD72B2231425A9812728B1DB3B793
                                        SHA-512:9949B174FC3D9295E7FA530BB27DC4CEE1D74D84DA1024D91071B3D9A64D0AC5095FFDC16050AEC2AB3A7733DA5E06119A0F95E1428AF8DFCD9E5B7D3C8561EF
                                        Malicious:true
                                        Preview:c.(..........Y.......\4..rZ......A.X...6~."..E.+g..l.0.RO.c;.dwm.k.""-L....Ak.8.....J....}..l;....mx.}......l..d.u...,.X~......ZJ.M...X.a.s.}:!..s..e/......8@.S...Y.....7...XKr.C......Ox.c.$=B....)..8.j^G...G.l..&.p..7.UH.4.}...f,T...(I.i...{%...&....|.WB!6......d.....i...Lh..c..7.#.n....."..K|2...M...$*....O..m.'.M|.P...b.E.v>..;..[.$Opd..4...,M.[MH..m..b....I...$Xm...v.~#...v..i$.}..[..Gz.\..1..\}N.Q......,q.9..L...$I...&5U".ORNF51..U..T7NF.........9...@.o'...J%...D.@..<V.K.w7..cs...5....z. .&"d...?.aV..4..4yYT...X.~T.<..GL....f].wM...t..4,....tGo.I!.t.>D.A....|.g0.....H2...&....6..Cb.C.i?/...b.ll.8...N...V4.u..*.N...p......N.....9<._.>d.36.F(...O.m.v...T[......'....v....@....(...S...=.zJ...Z...H|...n.I...6.....l.a..@I._.S,.....#.......Q.n.e.....q..1p......{.k.........,..T..I...z...../..\#-.L7..1m{.8..[....m.i.bF_X...(6,.ta....q...G7Ad......e....8.w_....yS....8c...:.-..f.....b.5f.......7...j....s......y.x.......]...|\O.`. .t.t...<..T.7K..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):166208
                                        Entropy (8bit):5.340923751880194
                                        Encrypted:false
                                        SSDEEP:1536:y+C7FPgOsB3U9guwwJQ9DQA+zqzhQik4F77nXmvYd8XRTEwreOR6Y:PIQ9DQA+zqzMXeMT
                                        MD5:DB67717FB9BF0939F549B99FE18D7864
                                        SHA1:470BA895CDE1B6AE8A32EA4708F420AEF63A5B64
                                        SHA-256:4CD95FFA0E6EE18AC7B2F81A5ADA7EB6B3CA616EE6A56C8C2E22FD8BC7052ACD
                                        SHA-512:7F78D3CCB92F88772C2DED4FDF19396C3A99D7BE74BC1F340BB43D6ED9BA058D1D63A26A23EB45155297913897717785A719A94FC5EF1BCEA884D67A5427CB3B
                                        Malicious:false
                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<o:OfficeConfig xmlns:o="urn:schemas-microsoft-com:office:office">.. <o:services o:GenerationTime="2024-04-25T03:14:41">.. Build: 16.0.17619.40127-->.. <o:default>.. <o:ticket o:headerName="Authorization" o:headerValue="{}" />.. </o:default>.. <o:service o:name="Research">.. <o:url>https://word-edit.officeapps.live.com/we/rrdiscovery.ashx</o:url>.. </o:service>.. <o:service o:name="ORedir">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ORedirSSL">.. <o:url>https://o15.officeredir.microsoft.com/r</o:url>.. </o:service>.. <o:service o:name="ClViewClientHelpId" o:authentication="1">.. <o:url>https://[MAX.BaseHost]/client/results</o:url>.. <o:ticket o:policy="MBI_SSL_SHORT" o:idprovider="1" o:target="[MAX.AuthHost]" o:headerValue="Passport1.4 from-PP='{}&amp;p='" />.. <o:ticket o:idprovider="3" o:headerValue="Bearer {}" o:resourceId="[MAX.ResourceId]" o:authorityUrl="[ADALAuth
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:SQLite 3.x database, last written using SQLite version 3023002, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):0.09216609452072291
                                        Encrypted:false
                                        SSDEEP:3:lSWFN3l/klslpF/4llfll:l9F8E0/
                                        MD5:F138A66469C10D5761C6CBB36F2163C3
                                        SHA1:EEA136206474280549586923B7A4A3C6D5DB1E25
                                        SHA-256:C712D6C7A60F170A0C6C5EC768D962C58B1F59A2D417E98C7C528A037C427AB6
                                        SHA-512:9D25F943B6137DD2981EE75D57BAF3A9E0EE27EEA2DF19591D580F02EC8520D837B8E419A8B1EB7197614A3C6D8793C56EBC848C38295ADA23C31273DAA302D9
                                        Malicious:false
                                        Preview:SQLite format 3......@ .......................................................................... .....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:SQLite Rollback Journal
                                        Category:dropped
                                        Size (bytes):4616
                                        Entropy (8bit):0.13760166725504608
                                        Encrypted:false
                                        SSDEEP:3:7FEG2l+4zotsH/FllkpMRgSWbNFl/sl+ltlslVlllfll4zon:7+/lRz4Sg9bNFlEs1EP/oE
                                        MD5:60397F5DB715D4B74A6A3B87BA40256C
                                        SHA1:1330772AC626810128FDC0429094B42800F0C326
                                        SHA-256:8A26656E476104A6E08C5C1366985B82380A00733E6EADF45145EBD20B821088
                                        SHA-512:9FAD14FDDDEB62852E265C990341751CD38910D04DB87E45272EE6BA3495456141D331A216677C2E5D44EF886016C95D426441B5EF7ADDD941DA739B256AF048
                                        Malicious:false
                                        Preview:.... .c.....+2......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................SQLite format 3......@ .......................................................................... .................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):32768
                                        Entropy (8bit):0.04482848510499482
                                        Encrypted:false
                                        SSDEEP:3:G4l2Bd+hLPU1qSiCl2Bd+hLPU1qSvWlL9//Xlvlll1lllwlvlllglbXdbllAlldc:G4l2BW8ll2BW80L9XXPH4l942U
                                        MD5:087BBD7461F1DDBBBA24676697D03BFD
                                        SHA1:44BF74FECD9BB970319F301D35279F9A7CC73FD9
                                        SHA-256:4A0510E7EAEACE712CC96570DAC95C563C55B5B755FDE5D55ABC51B5B1FCDCB3
                                        SHA-512:D15058A978D8E618052FE01385FEA35FE48C1B202E2F2BD862D14A682C2A7C40EEF76BC5D9A96F77DAE5A724EB23F3AA1F94B954562ADD9B8844322EE1B784BE
                                        Malicious:false
                                        Preview:..-........................zP..5.Oy_..A.....3.w...-........................zP..5.Oy_..A.....3.w.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:SQLite Write-Ahead Log, version 3007000
                                        Category:dropped
                                        Size (bytes):45352
                                        Entropy (8bit):0.3931969049707905
                                        Encrypted:false
                                        SSDEEP:24:KINvHmLQQ3zRDuiUll7DBtDi4kZERD2pzqt8VtbDBtDi4kZERDo:3/8QQ1SiUll7DYMapzO8VFDYMc
                                        MD5:B280B3D3C70D87E6D7983A7687899396
                                        SHA1:5A5977D529EE35EF41DA1C93941FCCD04DF19946
                                        SHA-256:3FFF08F58758FFA3C2001899570145E63BE240B9E6D28BC87EFAF7A36307170A
                                        SHA-512:4B06DAA5EB54236F3D24B183AF407AC4987316B8C5A31174AFA4E7E0CDE35F48BC94B537ED140EDF4F73C9AC499EE2AD7963E1CC1684BC6576A786AC9BF6E911
                                        Malicious:false
                                        Preview:7....-...........Oy_..A.4`R..............Oy_..A.sL...<.{SQLite format 3......@ .......................................................................... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49152
                                        Entropy (8bit):5.076820625261051
                                        Encrypted:false
                                        SSDEEP:768:gYpsKafnVHWt9VbLVrwXXkA+asq/H68C35V3PUj7OHhVBnTVXvz8fw3DcpB8wgS2:gYpsKafV2t9VbRrwXUA+as18C3Pf87OO
                                        MD5:BD2A118E8167E2A2D217B5155B79BADA
                                        SHA1:FE7B2FEAF500D3F7897F5656E1A49BE0F68078E3
                                        SHA-256:19AF64751CDC03E4525C5D114D7E5FD9A4665F84DB6BF3BF6A7F00DB5F1AFF83
                                        SHA-512:F6DC13197826C63931AE10CD31CEC778CE5DBA625AAB55359A80F58581D8263AA04EF7B5B2E17A2E286D13C542A8E7923ADD47F3E6F80595A6D87405417D490D
                                        Malicious:false
                                        Preview:....P...8...X...P...@........................................................................................................................................b...r..0m.............................................@...@...@.......)..m..n............)..m..n.............h2..8F...=..."..8&..r..@....h....*fv........4.... ....!.......!......................................................................................................?...............................................................................................................h2..8F...=..P...@..............................?.......................~............................................................................................p.......................................................................................................................................?...............F..@N!.....@...|R.q.!...#.......x..X4.&.K.1-......;.H...@........._].#=+.:.....Y{.....9.....$.{....>........,..@:...t......|R.q.!...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):0.04401584019170665
                                        Encrypted:false
                                        SSDEEP:3:RRk//:Lk
                                        MD5:CD74ABACE8A00B17BD8107BC5982C21E
                                        SHA1:D53193CF8A43D766FBFA52976192F44D6B0F79B2
                                        SHA-256:B670BC07C9CB554511180DCF3F6A2C7818E8CE6E67B84784F0EA4D35EC61D516
                                        SHA-512:1B48A37FCF0F9FB9ED9B31A8F3E36596689BF1EEC6F41F5EFA3C728121944919CE7A81F0379A108D80AA051CFEF07DC296F9C0691FC8855983B2F29EC15C7FEF
                                        Malicious:false
                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):0.49317414713099117
                                        Encrypted:false
                                        SSDEEP:6:NTc0C+l2em6UgPD1S5t/GwJdL+Kw1EVNy:Vc0CaSfG85IiL+KQE/y
                                        MD5:8BF76D71ED14E95741D38B9D36533ABE
                                        SHA1:1D5C94663CF79F64327D499BBAFB2C37EE763066
                                        SHA-256:7025CD1CCDB8E2895BBCDA9D1A67DD8EE0348E37712F88EFD265042BA0728AA6
                                        SHA-512:C46E23C7BE9CF351727BFB67FD5EB7CA9AE8740D7E3A2F2BD733F4EC52AD0832A513B3DB6480223C247DF1333FD2D3B09FE2657B498EAA97C685420030BAC6E2
                                        Malicious:false
                                        Preview:2...>...........~.......................................................................................................................................................................................[&......[&.....O..[m...a........................[&.....O..[m...a[&...................................................[&..........................................................[&.P..............................................................................5........m;.H....7.5N........k.G...........w.../3.D.. .4.-.....N...^...........................................................................................................w.../3.D.. .4.-.............................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.727400654239059
                                        Encrypted:false
                                        SSDEEP:48:wS7Fd5FfWAxz3LCxyw0Lq7cBlkw0LNpruECL33wEwLMrKdDwz:1PxjexyLucgLZpruECsEworK
                                        MD5:2222DEACEBEEBC084F126EC528AFCCE9
                                        SHA1:CDD09E2EB8C7EACD782F26001A86BA22AB92D864
                                        SHA-256:ED44AC052FE944A6BB6E9306E9EBC23775BE5F8E77C61AE88B486E725E8720F6
                                        SHA-512:42A5525F412056B501DA2F6572E6D2EDA0940D72D95D51CC90C87546F2E924D72E2374F562303DA675B25E48A44352767B568C2D6C9ECE9665495D2F564E6236
                                        Malicious:false
                                        Preview:j.......`.......L..................................................................?....................................................................j...............L.................................0.......0V.D..$$.!gRM...2.......2&..{..m/..|.vyQ.5T`.....z9.9vyQ...2&..{..m/..|...2....|R.q.!...#.................2.......2..................................................9.......9<. >.........g.......g^R..N..fBB...2...^.............................2...9.vyQ...g..%.................2.......2X......2..2....2.......2.."...a.T$...9..T%m..G..T.N........g..........c..,0...e...B4.$..........C@RQ.H..B......Y.....................%.......%.....M..L....y...........|R.q.!...#....9<. >.........9.9..2#..A..n.]*l.9...G...5b.C..8.....G.......>.................2&..{..m/..|.9..2#..A..n.]*l.G...5b.C..8..........9........_]..c..,0...e...B4.$...........I...M.....0...............................0...........e....4..................T.i.t.l.e.......|{....B.l...R......(....Y......(...D...L.e.c.t.u.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):4.730882673432808
                                        Encrypted:false
                                        SSDEEP:192:DswWox18tIhAwbX/+PgLRi5E+1HqLSgLla9UggDgvdx8IkG:4wbxjewTbLRi2A0liUzs1x8IkG
                                        MD5:C817DD9C6864576965C656191E0105AC
                                        SHA1:8A9257B2EB98CF516EA86E90F0C3A525B8BCA7E6
                                        SHA-256:B3AA8A9111F76E5E829FEADDB7E4B1FBD36EFB774768601AA11C83C715D9E641
                                        SHA-512:90962A1339562A9D21220DD0E814F363F9B5335E8E9ADDA7A1E26C98E9103D85E4C26EDA8A361F56CECED0D09DE9B23DEDB46375E64E70BC11BCA0CC7D24B123
                                        Malicious:false
                                        Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZ%3..4...%3.8.Cf....'c..}%3.8.Cf....'c..}%3...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............:w._.~.$..z&.D.....N...^.....................L....{..I............>...............................$....I.qk..B.....LZ.............:w._.~.$..z&.D..........:w._.~.$..z&.D..........%3......%3......%3..........................................%3.j....%3.T%;..%3......%3...W..%3.H....%3...+..%3...S..%3...........Z4...........................................4../4......p...............C.a.l.i.b.r.i..................%3.:%3.k%3...z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40884
                                        Entropy (8bit):7.545929039957292
                                        Encrypted:false
                                        SSDEEP:768:MCBOA4d+ElOXJ/3pI7cRBiL7L6qERqGz65WXzZqJsKQSbIsTT6XB:hIAU+2cGdLX6qBG4WDZl4Ihx
                                        MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                        SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                        SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                        SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.439801143042936
                                        Encrypted:false
                                        SSDEEP:192:DspT+8s3VIRAQu8LSorh88caV3+RhEjvwXyKjRk3sghewzNSqj9XI6T:4c3qAF4SoKzaV4hEjyyURk3s8ewzzx
                                        MD5:4F0E03793FB0E3C449207A114036F3C7
                                        SHA1:F0A6CAE3BEEDF5DFA1758BFDEEDB286CDA96DB29
                                        SHA-256:4358B73476CD64C62FF1980B75003731E2BEEADAFFC50F14066CC9609C41C9CF
                                        SHA-512:7105B0C714F227E09B8539B06BC88CE24BBE60ADF9D4A07F9EEF5EB998FA6F749115BF59AB7A58E8EA179D4A52895B11645B103218847F48138015965B541CE7
                                        Malicious:false
                                        Preview:2...>...........v........ ...)..2...>...B.......v.......@....(...........................................................................................................................................I.......I.qk..B.....LZ....H......qA...:+. .......qA...:+. .........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............=V.d.y_.-e...}......N...^...............jT....%B..(KD.............................................."....I.qk..B.....LZ............=V.d.y_.-e...}..................................................................................................j.".....T.................T............. .A............. ...........3...:...8.....z...y.. x.. ........ ..$...$........D..........7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.5........................Z4...........................................4../4......p.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                        Category:dropped
                                        Size (bytes):24268
                                        Entropy (8bit):6.946124661664625
                                        Encrypted:false
                                        SSDEEP:384:d2wiieoHTRh5a1HAteZCWOZIM+L7WhNjYn:8wHFHJ+/OZIKhNO
                                        MD5:3CD906D179F59DDFA112510C7E996351
                                        SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                        SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                        SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.670851473554114
                                        Encrypted:false
                                        SSDEEP:192:jsTksIPNSYhZxMupiIIL/hjbG4/42oQj23g7D+bRiXuP+sRpg0IDx9DqAWp5WLl2:YTJuNSYBAI+5jC4A373gG1cuPTRpzIa3
                                        MD5:60817CFAB30BDBE37138565139624FB4
                                        SHA1:B04E3CB8B6808923B080C78CDF3CB96985FE7154
                                        SHA-256:86515E6BB1145C05DDD9784B671F7F60DBCC363EC33B4AE2B7F962A3D84052BB
                                        SHA-512:9EC3B39C24DCFB883511172018FA46BAB0C981AD6248E7DB49C20C559F4C0438424D02E831DEB9E70AAD6E5F9293B267994526EBB44EFA9B9366616BDC144005
                                        Malicious:false
                                        Preview:2...>...6...z...v...N.... ..X,..2...>...........v.......@...H+...........................................................................................................................................I.......I.qk..B.....LZ....N........1..$.d........1..$.d........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................#6......%.."=....N...^....................M.N.w.E..M.............P....................................I.qk..B.....LZ...............#6......%.."=................................................................................................j.9.....T.................s.....H.........0.......`.&...............3...:...A...8.....z...y.. x.. ........ ..$...$...............7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.1................Z4...........................................4../4......p.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):39010
                                        Entropy (8bit):7.362726513389497
                                        Encrypted:false
                                        SSDEEP:768:6tCjwO+E+KW0ZtOgepcoWW4pAWQ6/KWcR474HOAZaDfK:68j+E+KW0HOgep/72/NKWcRNefK
                                        MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                        SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                        SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                        SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.954987659592667
                                        Encrypted:false
                                        SSDEEP:192:QnP8sDs9X9JsNCSB26GReNDcK4vRcfgBfct483wq8LC4YkmDWr6vXqyl2M:qPBDwXns3BxGReqnOUct4Wwq8+4P/oq4
                                        MD5:990B3BA14016DFEE614B4480CE0BCDA2
                                        SHA1:7BCF84FC034D0B924C39ABF55B415162F98DE666
                                        SHA-256:BFB3490F1FA5E210A52FE65FE6B02828CA898E93FF06848BA9884494615836A3
                                        SHA-512:366EDDBE014EFD98E9E789443DDD7200488D6A4717D78BDCC420EDDB0E5E6FBED035193B6955939CD7CDBEAF274ADC9DD81CF507E13E09512F200872776F1367
                                        Malicious:false
                                        Preview:....>.......B...v.......0 ..x#......>...........v...^...@...h"...........................................................................................................................................I.......I.qk..B.....LZ.Pq......Pq...v..'QN.U~.S...w.G.1.......S....Pq...v..'QN.U~..Pq..I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'................@Z....[.7......N...^...............]td....@..D.............b...8....................................I.qk..B.....LZ...............@Z....[.7....................................Pq......Pq......Pq.........................................Pq......Pq...v..'QN.U~.S...8...S...w.G.1.......2................................I................................Pqj.#...PqT.G...Pq......Pq..Q..S..H....S.......S..$.7..S..........S..!S....z...,4. ............................"......$...7...............T.u.e.s.d.a.y.,. .J.u.l.y. .2.8.,.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):59707
                                        Entropy (8bit):7.858445368171059
                                        Encrypted:false
                                        SSDEEP:1536:k76rvGc8WKC2/UX1uEgVRY/jvv9CblyL/T:k77Z5C2/Ow1e9CblCT
                                        MD5:47ADB0DF6FDA756920225A099B722322
                                        SHA1:851946B8C2BD0BB351BAEECA9E5BB6648A87D7CA
                                        SHA-256:EC8CD7250F3D82E900E99114869777EE859EC73EFFABED108815F65742078C3A
                                        SHA-512:85A9920E1CE4A2FCCEBAFA425C925DF33580FA3C3C00178F058539B2FBC0163866DB8A41B320E2EF2CD217F00FFA06A1A831C728D3F9F910C9EAC58B5DA76E2D
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..A..Qaq"....2........B#..R.b3$..8xrC4&'W.%e.(.c.d.5E6Ff..h..SsTt..u...Gg..H.....................!.1..AQ.aq.".......2..st.BR..56.r#3.b.S.4c%...$d.CT............?....3.7...G:../P....z..K.:6..w......6....... .z7...~.....{gdF60...9....{...'[N....m.........z...g{.......7...4..1..=.z...._..p...m..Icd.~.v..9.P..0Z(.<j.......R6zm.....v.z...>x..)=g........zo{..w..f..y.t.....%.D..#.}.I.>).H.QM..cLD..x.../.^y.{.............y.=^.......I.T.......U..0_?...u..og..3.ky..K....6w...Dc......~........ik.z....N...en......_.....x....._u...4.{..P...>.....}.......>.R.....m.....[mt.....}.........|.....m......~....B.F.]C.36..q....yg...{]...+.DZv.9<.o..;..N.n&im.,....w.3...V.s...Y..e#$.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.840341144925149
                                        Encrypted:false
                                        SSDEEP:192:ksXWrGW6IAgqaEZGX1qRlRd2Cp5BSMq9Yf36oXMLRp:5XDP3aEZY1qRlCClyYPqLRp
                                        MD5:A4E2114A9304228C747ABF5B9CF9B20B
                                        SHA1:5CB7A645F9586F51D2522E374FD67B29A64DE9A3
                                        SHA-256:10CBC6DC42DDB45AC69874AFB13E5EC992E51D8D67793F55955BC3B1A3EC2E67
                                        SHA-512:D352E67FB500E5630A8EB85986B0B7383250E8BA2FFCAB368B0254D99D469309C4198FAADE8C0733E75E7CFD56ED67B2181FF1FE0E845B9E3247C973F05CEF0E
                                        Malicious:false
                                        Preview:2...>...........v........ .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ..$.<.....$7]]C..^..9....$7]]C..^..9....$..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............pM./.q.4.zeE9.0....N...^.................x+.WB.c.N.B!R............................................D....I.qk..B.....LZ.............pM./.q.4.zeE9.0...................................$.......$.......$...........................................$j......$T.T....$.......$..|....$..;....$..h....$.......$ .W.....'..$2..$..z...,4. ...."......$>........4..p..7......S.u.m.m.a.r.y..........................$3..$8..$..z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.9...............$
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                        Category:dropped
                                        Size (bytes):27862
                                        Entropy (8bit):7.238903610770013
                                        Encrypted:false
                                        SSDEEP:384:LTawAZvhbrXzDc6LERLQ/b5vXOl6pXQ/wD5OUMrdRUUhCplQg0ESSz:6wm/vT/b4wxoqbdUhWnSs
                                        MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                        SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                        SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                        SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):5.407557509723266
                                        Encrypted:false
                                        SSDEEP:384:Vu1VgNtsKEK68+KWxMqXGMtb1dnEWTuyhAVpwYQVjGEAA2EqP5d8ysElNDlEjdmS:VfYVAV5NkvNS
                                        MD5:E40FC234C3BD68ED065F2A657932AF0C
                                        SHA1:66E811DFA782280777369F17197415891D6C245F
                                        SHA-256:9F6899F197190356451C1AD3406A3ABAF50C15725DE87421AB05AE2B846CAEDE
                                        SHA-512:CEADCA07A4B5ECA5EB1D1D4D72142A0371A96F5FBD66D8D985717DA4AE90EDE20E033F07CE28D52F84E1C41661DCDB4BBEDE46128D45042400C424286070A6CE
                                        Malicious:false
                                        Preview:...@...@.................A..( ...M.........@...@0................K..( ..@L.................................................................................@...@H............... L..( ...L..........................n.w....M.,.w0.......0..:..SF....B4..<..'e?h.........<.....yE.Z.. .\...>...y...u&&..).....z............v......v.....................................................T.^..0..T....K..T...... T.....!+T!d..'.nT!.....pT%B...zT"8...........0...........e....4.........................A..:4E.2..p1......(...`.i.....(...(...B.a.c.k.g.r.o.u.n.d. .-. .Y.e.l.l.o.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.1.9...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e...:t......:t..SDu.'.4....(.!+......!+W&.hC..%r....2...............4.......D...$.......4...0...:t.......!+..+................0...........e....4........................yf.....F.Q.........(...pO;.....(.......S.t.a.t.e.m.e.n.t...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.077114171794445
                                        Encrypted:false
                                        SSDEEP:48:bSTsHwdjgxt8KtcEau8DXHG9HG1hKToOrdHrrEIydXLC4iu1:Is2jgxTcEauiXm9gKTbRL8Jb
                                        MD5:1414921AE656B9EBACEED8F77D45B296
                                        SHA1:07DAB42F86A38EFD36E6CD2BA355E9D5D523053E
                                        SHA-256:2ED53F1418DA71E7F83238482E40C24D47116E7819492EF9BC08B562A405A71F
                                        SHA-512:B3BA6F5B61EA87B47664B1D64F9DAF26098681C41047E7CBC80BE17FE03FCE4CFA7004E6A0E6675B51B4364D16C8A2722616F19A6AE46303D2CFCD798D81BEE8
                                        Malicious:false
                                        Preview:2...>....... ...v....................................................?....?.............................................................................2...>.......|...v...H............................I.......I.qk..B.....LZ..,.......,...y..../../..,...y..../../..,..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............f..`......&..l......N...^................p..m."K.6;6y..@........f........................................I.qk..B.....LZ............f..`......&..l..........f..`......&..l.............,.......,.......,...........................................,j......,T.]....,.......,..B....,H......,..B....,..>.)..,..J...................;........4...4...4.."................,...,...,..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........,.......,....#..,............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.099262552216668
                                        Encrypted:false
                                        SSDEEP:48:7Rs8TY71//UtFt4Efm6cXHc9mnZToArdqrGItdXTikDjCaUa:ds8SN/UN4EDcXHc9CZTlRylE3aU
                                        MD5:86B2D8E025DFF30291584F6710035E7A
                                        SHA1:C53464EF1B21B24B53D862A0A6F1AB9F7DFD5A87
                                        SHA-256:01F5D10F4C12E6CF28EA2B29CC098D3715C1E5DC7E0AC531C9DA9960751A66DA
                                        SHA-512:41DE6FDD590D66360C19EB008BF5B4AA6490EF37A1C601F98828278D68EC9182E2D79EAC94E07F345E8BC53DDE897991EA061612F07310B6DB2750A8544490EE
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZw.......w.....?.<.z...'.w.....?.<.z...'.w....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............E.y..=u....j,......N...^...............?.^/'..J. .............f........................................I.qk..B.....LZ............E.y..=u....j,..........E.y..=u....j,...........w.......w.......w...........................................w..j....w..T.]..w.......w....B..w..H....w....B..w....>.)w....J...................;........4...4...4.."..............w...w...w....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........w.......w......#w..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.071691709619119
                                        Encrypted:false
                                        SSDEEP:48:psHxqffu3ttEfgE3phcXbc99u91pTocrd6rWEIldXLrrxsg:psMffu3LbE3YXY9491pTJRiKPs
                                        MD5:FC0C67FB5368E9028BEC77A27C669408
                                        SHA1:8C2535149A7E9C92312D341C22E891BB8F1F4BEA
                                        SHA-256:449D332AA5DF2C48968471A31BE27C42B3FB77917C3BF9278C7DECC2075DDE08
                                        SHA-512:D759B51D854DE1653E9DA4C19439EED479FE95FC444831155F741EA8664DF1C382372C95712B947877D40816EA0878BEB6B61BCC77478A5661D5DA46FF724F7B
                                        Malicious:false
                                        Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZR......R.t....8]..L.(R.t....8]..L.(R...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............j.......,..R.L....N...^.................K.t..D.j...".........f........................................I.qk..B.....LZ..............j.......,..R.L..........j.......,..R.L.........R......R......R..........................................R.j....R.T.]..R......R..B..R.H....R...B..R...>.)R...J...................;........4...4...4.."..............R..R..R...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........R......R.....#R.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.103557229351409
                                        Encrypted:false
                                        SSDEEP:48:VXs5m3/As4V8t8wElBX89YnToyrdnrgIDdXdHO2Qg:lsiwV87E7X89YnTTRrFBQ
                                        MD5:8E3F3A40F70528B52D640B41393615B8
                                        SHA1:028F683B76F66770B16606DD08EE910E61E2DD4A
                                        SHA-256:C3A359DAD390EC187100D1BAEF7530587040C9DEFEDF28ACCD465DC146EDFE0C
                                        SHA-512:D15F023AE6DF5B75E7FD666155E058C97C4D654FCFCF7A301C8D205AABDBB9E59AE6B13348652027FB913143DBD91F14F6EC57ED5D6612BB7256935A97F51848
                                        Malicious:false
                                        Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ..`.......`....#eJi[....`....#eJi[....`..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............4..............N...^.................=...>O..sL%.X.........f........................................I.qk..B.....LZ..............4....................4.....................`.......`.......`...........................................`j......`T.]....`.......`..B....`H......`..B....`..>.)..`..J...................;........4...4...4.."................`...`...`..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........`.......`....#..`............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.078796899934866
                                        Encrypted:false
                                        SSDEEP:96:BDsIxNZ4aa44ecEH6X49EqTcRyrjUsZcbRUDSCxUlpbS:BDsIxNZna4nH6X49Eq4RyrjUsZcbRUeL
                                        MD5:E954C0EAE40139772FD6F3AC359F97A1
                                        SHA1:2345253833F89E61B3DCF62E5C7FDCB49D290E58
                                        SHA-256:9A2CE18BCCECD48BBB39B10EDD4879B889E752FD3896C650226F33AEAAC8AB02
                                        SHA-512:957DA0C5DE67A82EB16934D7F55C9F498670282CD73EEBF6FC6BADC5E884388C1B52D79D9E68195362B3000A22A8C9587375F572A100F0BD5DC497F3B994C9FC
                                        Malicious:false
                                        Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZh.......h...5.T.0..V:..h...5.T.0..V:..h....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................k..@.9.b2......N...^................v...y.H.ri~{[.8........f........................................I.qk..B.....LZ...............k..@.9.b2.............k..@.9.b2...........h.......h.......h...........................................h..j....h..T.]..h.......h....B..h..H....h....B..h....>.)h....J...................;........4...4...4.."..............h...h...h....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........h.......h......#h..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.0810584965302965
                                        Encrypted:false
                                        SSDEEP:48:YdssaYlVFsL6e+toJmEErX09RfsTojrdDraIM5dXQAkRsVXE+o31:2ssVVFsL6/TE6X09RsT2RPY5PnVU+o3
                                        MD5:8EB1657245C326CD76007A5DD2FA9429
                                        SHA1:B0DC3B49E6145F698B6F4B63C6755E99DEAF1EA3
                                        SHA-256:EB727FACF099925FC64929EC6B449F5A8747C772111560E746B8DD9C6C115EAD
                                        SHA-512:80C5B2A00CF676146E50119D3ED0DEA66BDDDC5D0D1E5614B2A22F3A7C2B43F952AEEB48D93E4169B1336C31D79B3E2AD668C72DA1B658E00A080AA0889DD148
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.B.......B.(;......g...B.(;......g...B...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............f.A..2.(..D.H......N...^.................SR.h.M....&I.........f........................................I.qk..B.....LZ.............f.A..2.(..D.H...........f.A..2.(..D.H............B.......B.......B...........................................B.j.....B.T.]...B.......B..B...B.H.....B...B...B...>.).B...J...................;........4...4...4.."...............B...B...B...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........B.......B.....#.B.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):3.989841477651738
                                        Encrypted:false
                                        SSDEEP:48:YC7esScMuoj5twtR0EYwFYXrY94mpToMrdmrL/ItdXrz9uQRR+zcF:beshoj560EYfXs9JpTlR2LqOvzc
                                        MD5:BE92061BA87FB00CCCC430983BEAC279
                                        SHA1:A6AB08F1C1B5D8C093C90F55F508AD653D03A199
                                        SHA-256:648A52FF7A3F26CFD7C505BBEF0AE13762F379F91AEFE9EA9926C61E6A2D69F1
                                        SHA-512:CA41F592309D21CBDCC5A61DDB6FF850CD217FCC54D2FD768EEF702DE9EAAF9321EE6047B84411CFFA0DE806D96B92C3031330B9BC92263E5B008BEC6A180038
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................?.......?...O..=.3.vy...I.......I.qk..B.....LZ.?...O..=.3.vy...?...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............9+.(.......KPU:....N...^..................].MyL...4z..........f........................................I.qk..B.....LZ............9+.(.......KPU:........9+.(.......KPU:..........?.......?.......?...........................................?.j.....?.T.]...?.......?...B...?.H.....?...B...?...>.).?...J...................;........4...4...4.."...............?...?...?...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........?.......?.....#.?.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.0658216203795465
                                        Encrypted:false
                                        SSDEEP:48:YlTsiUF396qLtSftyEn6rJXY9VATonrdvlxrsIV6dX8dxlRRN1:8TsSqLsfkEEXY9VATaRHaa7
                                        MD5:E81DA33E977CF9307000C71BCDAA9979
                                        SHA1:77486146213B703ECE0DA0C03E91C867019F9971
                                        SHA-256:A939D43E404FF809C160654C8BF3EC04FF6CC27712CA6CA5943DC768F8479423
                                        SHA-512:060CF20FA6DB32AD3C65D7EC3C06E50B51D533F881D95FDB3AFAE3DC6ABEAE6A85E7A10673623C27A2030AEEF0D1624C6E960C5E9A8ED0B83FFCD28E6E927187
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J......................................O^...?........I.......I.qk..B.....LZ...O^...?............I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............-dOi.{[.3m..*.3.....N...^................/.`j.zF..7@L~..........f........................................I.qk..B.....LZ............-dOi.{[.3m..*.3.........-dOi.{[.3m..*.3.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.04471293985102
                                        Encrypted:false
                                        SSDEEP:48:Y5stXO5U6tPNsKEXgZbcXrc9H0ycToN9rdPr1IwdXERRrjd:qsE5U61hEXgZcXrc91cTORjNQ
                                        MD5:8578929E81288A91B5D8F9A060DF54DD
                                        SHA1:6FE9B27FFB3529045C8034905F35B26D32979505
                                        SHA-256:8D1E22917DF3CCA4A99838D3FFE12DE14BAA70E1103327123B1873CCC4E41394
                                        SHA-512:4F005AF33B81CB57A7CB2974EA3F32DED77F55B17CF8ED57F98C056669417C59C7D104578FECB3A9796609A4B0867110CD880A424ED9D103C7BD387043EEEC06
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J...........................4.......4........K4...S..I.......I.qk..B.....LZ4........K4...S.4....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................K...."H..........N...^.................8..M.M.It..+.(........f........................................I.qk..B.....LZ...............K...."H.................K...."H...............4.......4.......4...........................................4..j....4..T.]..4.......4....B..4..H....4....B..4....>.)4....J...................;........4...4...4.."..............4...4...4....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........4.......4......#4..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.049381364169831
                                        Encrypted:false
                                        SSDEEP:96:uspw0t6elREXXs9fFyTcRIB006Tp4j6Ie5:usp7MquXXs99yARIW06Tp4j6t5
                                        MD5:EAE61373363C05F77EF1922F25A11C31
                                        SHA1:561C010C417DDCBC0D5779FC76B427FE1C345568
                                        SHA-256:3CB1D8FF99F7DD27892CCB37EC118B7D160BFDC457C554393369B87BBA854858
                                        SHA-512:6127E843A0BD3E575BDCE4CBF39BB48D61288560FC791587902B932B37C52B258F029ADE6D75C7DD0DC274E6A69D4D09E1862308A7CE53ABC60F7ADACB91669B
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.........`....%*Yu_'....`....%*Yu_'......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............V.:..E.9.E.#m......N...^...............soM!.d.B......,.........f........................................I.qk..B.....LZ............V.:..E.9.E.#m..........V.:..E.9.E.#m......................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.076672882066051
                                        Encrypted:false
                                        SSDEEP:48:YJfsqccC9fhF5mMP+tY5/tLL2ELh93BXcB9N9tWToNrdP7r8IadXihREJiUK9:ysL5fh3mMP+ORKEfRXY9N9tWTQRf8RQ
                                        MD5:CB1806D2DEED9DC7B4FA536755505D65
                                        SHA1:5128E2C49C330EF153DC32EE22372E4A3D8BCB32
                                        SHA-256:71F38970D572C39D2F924EFA68CF46071F5251F321FC0A1E628BC25E619EDD26
                                        SHA-512:83BF94F00D07B8EBB0FF30DE17457230D8F054F5AB6FF55BEFF966A65D244AE6CF5CD4658DB265EA0A85A7C2693EF4D402FFD573901FA027337097936EA9A16C
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZbu......bu..Q..02....bu..Q..02....bu...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............(..P.7.+..PvqY.....N...^...............C.n...I...'..!O........f........................................I.qk..B.....LZ.............(..P.7.+..PvqY..........(..P.7.+..PvqY..........bu......bu......bu..........................................bu.j....bu.T.]..bu......bu...B..bu.H....bu...B..bu...>.)bu...J...................;........4...4...4.."..............bu..bu..bu...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........bu......bu.....#bu.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.052958661374192
                                        Encrypted:false
                                        SSDEEP:96:zeBsfrrrwr6FKR3OSEFwXE9moITWRemtbqrwrjrXjrrrNrMUbOxu:SsTP26FWAOXE9moIKRem623HPZ
                                        MD5:C52ACDD0720DDA06246E78407D06CEC3
                                        SHA1:69CA179F2C654E7D67A9E3911F9188CDC05E345D
                                        SHA-256:31509345F16DDB0F016DB04B82B5491CF7BCC40661DD378E82BE9D088EAA0BE8
                                        SHA-512:F3DB8EFBF2AB1F40756A6752ADDB10DA112016F735390322098B99A24DF920046A1A58240C1580F010D4EA5BAA5472C16CB2A69291FF7DBF15EF9B683AD29BFD
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.k......k...M... ...R/.k...M... ...R/.k..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............Y.=....:..x.D......N...^....................*.N.....C.V........f........................................I.qk..B.....LZ.............Y.=....:..x.D...........Y.=....:..x.D............k......k......k..........................................kj.....kT.]...k......k..B...kH.....k..B...k..>.).k..J...................;........4...4...4.."...............k..k..k..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........k......k....#.k............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.048903631280613
                                        Encrypted:false
                                        SSDEEP:96:5sxVdM7ofFMEjX89VPwqTCJRfHznqMxfZf0I:5sbkotpjX89qqWJRvzb
                                        MD5:B97919DF97B5DB96E3D57FFEC1EE80DD
                                        SHA1:4A082344881568449AE22EEA8AC9C500D1E0C5E3
                                        SHA-256:4FDE914F6D506BC6A6111ACD61369EB5C7FA751D42506323E575E14C80F2C196
                                        SHA-512:A89724C18A4517D008D1BA7C2DB92B4FAA5E1338803D26A274A2AFB0617BDE0EE85DD8055A28A644325EDF4869A11D05D045228751516F6890326C77741578B4
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ4Z^.....4Z^.`.........F4Z^.`.........F4Z^..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............Blw^...... Y.....N...^...............m..I6..@....\A3?........f........................................I.qk..B.....LZ..............Blw^...... Y...........Blw^...... Y..........4Z^.....4Z^.....4Z^.........................................4Z^j....4Z^T.]..4Z^.....4Z^..B..4Z^H....4Z^..B..4Z^..>.)4Z^..J...................;........4...4...4.."..............4Z^.4Z^.4Z^..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........4Z^.....4Z^....#4Z^............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.077753189741639
                                        Encrypted:false
                                        SSDEEP:48:7i6dsnsXIat0gNytDptcEno36XU9Ito0ToRKxrdlrHaIndXZ+kbaf1PXRY8a:7psU0gNyFcEdXU9eDT5xRpry28
                                        MD5:9E4336482AD453AB0EF7AF06E7C01221
                                        SHA1:AE19A7F6050D4606045FDEEC46456627DDC4C884
                                        SHA-256:5989F66522DF587D8A475296D08070A469BB885E642D2BFEBF698F2CB44751DD
                                        SHA-512:9E65FB3DE39FA41AFC971C82F7CDEC088310F546BA75E2DCBA39770C4E02BE7F8DA31C526E3A3B473F31EE09F755F2248970023F1D3171C2CBA34EA87E52E3C5
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZZ.......Z.........:.e...Z.........:.e...Z....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............~Rd..0..fAe.....N...^...............0....C.t.D?..\........f........................................I.qk..B.....LZ..............~Rd..0..fAe...........~Rd..0..fAe..........Z.......Z.......Z...........................................Z..j....Z..T.]..Z.......Z....B..Z..H....Z....B..Z....>.)Z....J...................;........4...4...4.."..............Z...Z...Z....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........Z.......Z......#Z..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.064965064824384
                                        Encrypted:false
                                        SSDEEP:96:BsgYD3GcommYs/AElXo9t8gT6RR7TBxDbgM0Gqk:BsDVoYEdlXo9t8guRRPr9
                                        MD5:7BF269A9F272155FC7F70F7BD0E2FA30
                                        SHA1:FDBF3C1F94E07FA36B295F1F6C2F8E9B0E5F3444
                                        SHA-256:06C1F2D4F4819EB95178FB4AABA67ED06CD7C2BC9677ED41E44164EF18D9142B
                                        SHA-512:99C8C965F1316418F2EAF63EC6FFDDF2CC56D2429F6FC43B9DA4D022444788FB36C6F9025D149064283843BABEA6B4B75C11D118948589E45DD9AE925C4C4EED
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ...........N.A=.+...>G.g...N.A=.+...>G.g.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............-......0LT.".>.....N...^.....................`I....o.%.........f........................................I.qk..B.....LZ............-......0LT.".>.........-......0LT.".>.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.162178488104287
                                        Encrypted:false
                                        SSDEEP:48:zR0xsnm//S2120tEmkEtYXc9zBXToY9FrdjrmIc2dX9D7T6GHdig:ms812023EyXc99XT3RvbzB
                                        MD5:4FD0F45B090F6A0E15800B9F4BCF533E
                                        SHA1:CD895132D04BB13F6B86C7EDBB5DB84ED749CA29
                                        SHA-256:8E21E42B7646B3F4F1640309ACEBFF89626708F39055CA21D72395DD9EC8E054
                                        SHA-512:6B04C83B110E3D0DF0876F9A9230EB0C1F10E23D33910AB9C1D0546FA5842CA06737C9775563ECD69D97BDDCC70FB4656712EFE3EC4C665518AD195003906B7B
                                        Malicious:false
                                        Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZ..............&.3.X.......&.3.X......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................,z|..5.V-.......N...^................1$dAswC.T..............f........................................I.qk..B.....LZ...............,z|..5.V-..............,z|..5.V-...........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.178390585954608
                                        Encrypted:false
                                        SSDEEP:96:WsTkVcw8QzKdAEPcXs9XTcRInMcwc70mh:WsTFezAdkXs9XoRInf
                                        MD5:2400DE23BC922D7B11EBCBA88A05BE66
                                        SHA1:A68790918957C1616E1FB832016906800D1B9506
                                        SHA-256:A831ABEE7836615A0D6CC1EEDAF2B91D3F28879A6014E260816FD87B9958F2C4
                                        SHA-512:11CCA27527276B9195D6B0D43E094AD22BCF6E90C67AA5550F63D5FE28553C383D14D340AA5268E5FDFA7EE8FA36196A1E50C4729DBA478E75FCC21B3BAA871C
                                        Malicious:false
                                        Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZam......am..Ae.....h..am..Ae.....h..am...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................3...2....H,}....N...^...............z@.\4dH.E.k............f........................................I.qk..B.....LZ................3...2....H,}............3...2....H,}.........am......am......am..........................................am.j....am.T.]..am......am..B..am.H....am...B..am...>.)am...J...................;........4...4...4.."..............am..am..am...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........am......am.....#am.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.137505493732325
                                        Encrypted:false
                                        SSDEEP:48:Gf2sPrmVvKHtgdWBKeEBAC+rCX89ICD2ToTrdSr0IwdXkSJMKJ:Rs6VvKHKdsdEBA7WX896TKRKC+K
                                        MD5:06C3F072170063A244E9E613BAA0E075
                                        SHA1:723BF60A8739A9DABF30375709DBF9C8EE3242DD
                                        SHA-256:F63E28E40DE9B659CBEFC6067A663BB20890D375C5EED201CB55BF9DE1D7A028
                                        SHA-512:7390054A115C5ADAC7D60FBFACD6CFEE4D68F964708BF17312CB8C5266317C37EF5E763894C6B0E07A2E270DC194B2235BBB899435EB990954C286ABCAE8FD72
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.............5.(....v.....5.(....v.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............9../.7.m.......N...^...............dRkz...A...8&k..........f........................................I.qk..B.....LZ..............9../.7.m.............9../.7.m...........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.124274531231
                                        Encrypted:false
                                        SSDEEP:48:FtgksGXADqtduDyE7CWnXc963+nToMrdSrmIRdXfOigh:FtgkslDqvu+E7dXc968TpRKZ6
                                        MD5:1CBDCAC1C750B80B66943FB24EB4E2B2
                                        SHA1:5A56B26B1F6CEAF397173A5CF4445AB49097B0DE
                                        SHA-256:FDFB5C0862687A689DD546BD1DB75A3A8A32D7592A7E7173A4724FBC4096BE58
                                        SHA-512:659ED60FEA586D69C402BA15C5D45687AF97EDD11C90FE66F2E58858094A5A49158EF9CFC3D1B4853AFD318BEA2D8A1329A30BE67D5CEE127A4496B3360B4A71
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..............{j..!........{j..!.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............./G.~SA...Z.dq......N...^.................,..@...&.Zd$........f........................................I.qk..B.....LZ............/G.~SA...Z.dq........../G.~SA...Z.dq......................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.129322471264205
                                        Encrypted:false
                                        SSDEEP:48:tsxGTj63lstT82EEC/VX89cP8gmNHToCrdSrrIfdX56kg7O/zk5/Jf:tsN3lsNjEEoX89cP8fTHRKcc
                                        MD5:FED023B6945539C025F8375090B1680A
                                        SHA1:6ECF15371F776BE5B82121B67DEFAFF4DFBE4366
                                        SHA-256:235807C46C4A372A8243CD319D1950131752A8748164A413CB15BF4DC525562D
                                        SHA-512:42BD7BC6ABF26C3277108AD46E5CDA36A2F42E21C4B266B6A427C38389ED7B2C4CBA698BC45E34A652C3EEC974C5C945D0999C102F2D6C309A0B7F191C18F4ED
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ9.......9...!R..4B....a.9...!R..4B....a.9....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............>.&.?...).H.........N...^................l.R6.rM..o\.h..........f........................................I.qk..B.....LZ............>.&.?...).H.............>.&.?...).H..............9.......9.......9...........................................9..j....9..T.]..9.......9....B..9..H....9....B..9....>.)9....J...................;........4...4...4.."..............9...9...9....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........9.......9......#9..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.11656594589611
                                        Encrypted:false
                                        SSDEEP:48:1sUeA9HbuRVktIKE2CHEXk9F9bCwdToSrdSrKIzdXtn2sba2smkVPh:1sUNbcVkZE2RXk96gT7RK3XRbaFmkVP
                                        MD5:4D816E7BC31BF9EB689597A9EC21BE21
                                        SHA1:8A045C9631BE2F679A29EDF098D588AA76A4B402
                                        SHA-256:D4AA1CA48E509AFB82C2ADE385D583F5D031C42C24C0EDE4CC8F5BD52C1248D8
                                        SHA-512:C5BBF60F10266E70F0BED43741C2A756BFBD2B03A8160220D9B52BBEC4F6316D8D1EB8AB0C6854011F9B573BFD417674835A6995191C033172177D13BE7E86C3
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..~.......~......4...`L...~......4...`L...~..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............~!..{.N....q........N...^................"5....O....F.U.........f........................................I.qk..B.....LZ............~!..{.N....q............~!..{.N....q...............~.......~.......~...........................................~j......~T.]....~.......~..B....~H......~..B....~..>.)..~..J...................;........4...4...4.."................~...~...~..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........~.......~....#..~............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.1133963789518875
                                        Encrypted:false
                                        SSDEEP:48:ls1IKtJSGvt4DSEG9CCZ3XkrR97N1/ToexrdSr1IRdXRxyI2EyHVr:lsDTSGvmOEinXQR9nTfxRKc2fHV
                                        MD5:2A8EAC5DB72717AB93EADF1237AD2A42
                                        SHA1:B91E063CAD20D5B23194ACF24679899B39475A9F
                                        SHA-256:35F6BEF2EDD8865CF99BA08672EA8902A340A3AD514D6FBB3E3114DF951AB58B
                                        SHA-512:2E3C4AE8B8FE1C0AAF9C0658A1F6A06A0CE6DB6D2AC45322D1E77805FA78BDBFD66B35C9884FCBE6211461997348CDC91788A92B448A652AA21FD61A59E45E79
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ............NQ......./......NQ......./.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............|..Qn........WK....N...^.................c.:h.D..-.............f........................................I.qk..B.....LZ............|..Qn........WK........|..Qn........WK........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.129003269432336
                                        Encrypted:false
                                        SSDEEP:48:aIsNB65GXIC5tkGEnpDCZPCXY9PZUm0ToprdSrBIedX+m6Zit:ds3bIC5JE1JXY9B10TkRKDV
                                        MD5:93EFEA607D27EBE63F1C82A955CB1D61
                                        SHA1:7748E9802C28E8FD7F7C5836F6680F88B3E200AB
                                        SHA-256:CA0FC933F59842E7B4293FBBCA93397EDE91139FD3CF76386F5B75AC4DC2E17D
                                        SHA-512:0D7B4D8AF94E1061DB358D9687ADCE45D9467DFCBF386E7C5E15F6604688BBF3D0A5CB66E78E6BC11BCC11458AA789AB914AE4BD15CB7ED88C1D328A0F7A91DC
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ-.......-.........9v.4..-.........9v.4..-....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............A..Ts.q....BO.......N...^................5.M..*M.P...O#.........f........................................I.qk..B.....LZ............A..Ts.q....BO...........A..Ts.q....BO............-.......-.......-...........................................-..j....-..T.]..-.......-....B..-..H....-....B..-....>.)-....J...................;........4...4...4.."..............-...-...-....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........-.......-......#-..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.110281473215743
                                        Encrypted:false
                                        SSDEEP:48:9iGsov9zlcoHNtAMUeEmCKyqXRq9wwgToNrdSrDQIEI+dXuy7sSp:9vsEGotqkEmTX894TIRKDDcl
                                        MD5:11F979140D8040C8076380BC89716A4E
                                        SHA1:99EE05BB438745113EE11E655E4BB2AD20D8D462
                                        SHA-256:D81300FE4155AE761DCD06CB43C4AE9B80CF57DEA328119BB34572B6DC977BEE
                                        SHA-512:6DEEE030CFC04278E34A312AE634CB064BA704C77868A340CC50EAC13563E90394B18A1F38F07E63AB577E71412FD52B0689E14C4CA1341224BFFF21DB23D895
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ0.n.....0.n...e.....?.0.n...e.....?.0.n..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............`...C.,.'.....R....N...^.................f.=.jJ...C."..........f........................................I.qk..B.....LZ............`...C.,.'.....R........`...C.,.'.....R.........0.n.....0.n.....0.n.........................................0.nj....0.nT.]..0.n.....0.n..B..0.nH....0.n..B..0.n..>.)0.n..J...................;........4...4...4.."..............0.n.0.n.0.n..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........0.n.....0.n....#0.n............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.12555936796589
                                        Encrypted:false
                                        SSDEEP:96:K0sMiVE3XpUcOWgbElCPXI9ZAHTHRKHm41EtU5lHrD4NTh:bsZMp9gYuXI9SjRKHm4vnD4Bh
                                        MD5:3C108E337613EA3EDA9E69B0C3EFB8CE
                                        SHA1:D6BCD1B188C35690A66E753A160F266B152505E4
                                        SHA-256:AE11E73D7D67716D1104E42ED52A60F179325D36B486B3E2C7F7787FF5CE8E9F
                                        SHA-512:9A70E21172F1DCD55076D5F461D43491B527B368D2D543AE8CAD8974E1113D2234342B595052613A00EA566417F471D10DFE4102746ECCE51D8037F8B3240297
                                        Malicious:false
                                        Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ.(w......(wK..D....;...(wK..D....;...(w..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............pN:.......s.a3......N...^...............?{..Kz.A..~............f........................................I.qk..B.....LZ............pN:.......s.a3..........pN:.......s.a3............(w......(w......(w..........................................(wj.....(wT.]...(w......(w..B...(wH.....(w..B...(w..>.).(w..J...................;........4...4...4.."...............(w..(w..(w..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........(w......(w....#.(w............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.09141609708951
                                        Encrypted:false
                                        SSDEEP:48:K0szsG2OYjtuXME6tiC+GfXY9B6JN0ToxrdSrsgIGdXgDJ0Q3yjN:K0sj/YjlE6c7IXY9B6UTsRKs0T
                                        MD5:740C33FF63C21CC32D0C8F64DD27328C
                                        SHA1:8B9AB670FF59D52F5F7B31ED500671DD09B870C6
                                        SHA-256:EEB50C96C1EB4077D91C44525CBB6630EBBFF31BA762863AE66B91420E4EC06F
                                        SHA-512:47A5FB590C6C777145B05CF3A3528B1F4291690100A5A62FC6F862556ED8C0ED0EA0CAEE42AF1188BF4D3AA9C3DB01F40B7D3ED2E9385E3670AC879AD094B01E
                                        Malicious:false
                                        Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ.............C..2....`.\.....C..2....`.\.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................'4_...`..N=K....N...^...................m1-K...............f........................................I.qk..B.....LZ................'4_...`..N=K............'4_...`..N=K........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.106986687580678
                                        Encrypted:false
                                        SSDEEP:48:QICsLTcOs2jktf2EIWCCYVUXzU9tMlzTo56rdSrqIW2dX3lRJU+d:QPszDjkQEPyUXzU9tcTU6RK1vt
                                        MD5:BCCD07A1434FF550B6B0CDC69694043B
                                        SHA1:44DEA4F0CE5E5CD1CF6C48350D053F923F438243
                                        SHA-256:D64DB0865B998316C888B4D410996868D2A06CF02D0800207D7995231BB0EECB
                                        SHA-512:1E938AFE9A9D8AB30742CAE804058E5AE981D3B7C6A0C7AB1ED1C86100EA83D3B786CE9684C15C887B98B557DFAA1D2D45D879A0AF1D9C84A0E5E46C4F09C15A
                                        Malicious:false
                                        Preview:2...>...........v..."...................................................................................................................................2...>...........v...V............................I.......I.qk..B.....LZ...........O#S...&...R.....O#S...&...R.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............n.D.......2zR....N...^................u.z.. I..h.fk)........f........................................I.qk..B.....LZ.............n.D.......2zR.........n.D.......2zR........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.118924767101091
                                        Encrypted:false
                                        SSDEEP:48:TQ0sfhg42Bt46EVC/tXw9Bs2OTo/rdSrbeIkdXUlajM5U3aoeV4:Bsr2BBEVoXw9BgTWRKgr
                                        MD5:6D5246B63EF586656D4A42337003407C
                                        SHA1:988C54FDA90C2C956C8457E81C87710D809B6065
                                        SHA-256:6B015925E7139DB77E3BA6FDAD936CE10DA07A80259FF11691B782252B6DC1A5
                                        SHA-512:FD06EBAD5F5A41BC264C3C049630A51C5C1F879270DE3A216ADB3864AE3CD3B819896E0B16FDC7733336DA13218ED6612D6842ECF47A74502986FE4BE359925F
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..1.......1....!.Kn|...1....!.Kn|...1..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............hV.*.n......t......N...^.....................UC.Z..K..........f........................................I.qk..B.....LZ.............hV.*.n......t...........hV.*.n......t.............1.......1.......1...........................................1j......1T.]....1.......1..B....1H......1..B....1..>.)..1..J...................;........4...4...4.."................1...1...1..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........1.......1....#..1............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.102608002939301
                                        Encrypted:false
                                        SSDEEP:48:5sFQuKwDxeJtSN+EsWCjtgXY9rrwToNrdSrZIydX6K8C1:5snxeJsYEsWMSXY9gTARK31
                                        MD5:8E1321BEE14145676DFA20A0C658A444
                                        SHA1:653136011449411C8BECC77B12661573AE367F8F
                                        SHA-256:20DBA010946CDB64BABE24ABDD9D4F08893EF6C6463AD3898EF9FBCB8C2AC9EF
                                        SHA-512:CCA86D456A6EB36965534BD2C8E73A02EE0025D252DE8549CF11C77D04619BBAF98A7126B5F4D0B61B95C537056180A53AC14AFDDB21DAF26DAFFF8FA281FFB2
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.y.......y.M......!km...y.M......!km...y...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................3.......{!......N...^...................o..M.7)............f........................................I.qk..B.....LZ...............3.......{!.............3.......{!............y.......y.......y...........................................y.j.....y.T.]...y.......y...B...y.H.....y...B...y...>.).y...J...................;........4...4...4.."...............y...y...y...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........y.......y.....#.y.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.137195836417298
                                        Encrypted:false
                                        SSDEEP:96:psnQ/gT274/LJER3caXo9ppT9RKK2eh/lGwv:psRT27eSxDXo9jpRKK2e
                                        MD5:140432783C43F1BFAB133B57EE0B3176
                                        SHA1:3131C1BD8273FD95184F1D9D701AC06A31220CD8
                                        SHA-256:4B692EA1C756572D6AE11F863CFD6A97259356B565B89E740E626154D18DEDA5
                                        SHA-512:041427509DB69EC94837698BFDC3A6ADBE66A74006B18C40D3C4E3935188C22EE9A83CACB0FCAABD09CDFAC74AD8EE5E421A1E50AB6950764274486C8B2C2571
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..P.......P.I.Z.....F.Y ..P.I.Z.....F.Y ..P..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............\#.....?.....[....N...^....................D.'..9Ya.........f........................................I.qk..B.....LZ.............\#.....?.....[.........\#.....?.....[...........P.......P.......P...........................................Pj......PT.]....P.......P..B....PH......P..B....P..>.)..P..J...................;........4...4...4.."................P...P...P..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........P.......P....#..P............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.100925409765434
                                        Encrypted:false
                                        SSDEEP:96:dNps0et5hENA1s2rXc9ZKGTN9RKsxf6r:Zs0etsyrXc9QGPRKsx
                                        MD5:E7B918F87F0A429CA3653E58ECE9E819
                                        SHA1:68B17D7F8816327D6C7CFBE5D01A51FF6FC4B341
                                        SHA-256:331E7FD4F64BA1A2CFAAC33CE7A1F3A6F93D39A3E1D87BFC1174A6E64F1FDC5F
                                        SHA-512:E686B75369C70D96E6E9218B474E008C1396638D6D5A6177955A153C403B201A334CA94FB093CBE8401677D0421C2B5033BA98B88946A20A0A8B020471907C93
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..{.......{..v..2.k.IA...{..v..2.k.IA...{..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............D...5.....=.......N...^................-q.f4.B.....L1.........f........................................I.qk..B.....LZ..............D...5.....=.............D...5.....=..............{.......{.......{...........................................{j......{T.]....{.......{..B....{H......{..B....{..>.)..{..J...................;........4...4...4.."................{...{...{..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........{.......{....#..{............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.1494917095775055
                                        Encrypted:false
                                        SSDEEP:48:KC1sBKXyfTjZZ9tUcMEEyrCQGXw9poEoSk3ToYrdSrHhI9dXD2uN0QpmouQpunLF:KIsmWTjT9f1Eyr2Xw9pz2TxRKHEPk
                                        MD5:0CBBA41760A6954B8B8532094C27055F
                                        SHA1:9FD49A38DDC5D782027CA572C5B6C342D5353CB2
                                        SHA-256:A3FAD901F6340561E7955530AB908F92782C5DB873B193AF1B4AF2FB570573FB
                                        SHA-512:FAC67E7339EE713565BDCE2FD6A32ACBBC93A6ABAB8D941E8BDE2EA3350C7EE289EC6A0550E15CEE408F4D769647EFC8949F6975822835D8410E273BC64A316A
                                        Malicious:false
                                        Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ...........+]...s@Wq.tz...+]...s@Wq.tz.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................)T..1L.t..".....N...^...............z.N.=T4O......j.........f........................................I.qk..B.....LZ................)T..1L.t..".............)T..1L.t..".........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.097837369470074
                                        Encrypted:false
                                        SSDEEP:96:7s3NnncaEXhXO9tCRTpRKkD4VT9LET4As5W:7spn0xXO9t0dRKk2B
                                        MD5:1E12F10F78568C513C3C986A731AD1BF
                                        SHA1:6A0E246DDC455BB6991B19DF3BA69A5FF8E62E7E
                                        SHA-256:BBECDF0B6F18CE5F5BE4F4743606524A18E60FAA2D6E46E7FE9999311F445351
                                        SHA-512:E6B5A2092E0ADE23FCC0EDDC956149B941A1858C9CA9123312F539AF45993FC1BC454FB9D6E42938032E305801147F463DA5A5354880BA3267042352CECEF690
                                        Malicious:false
                                        Preview:2...>.......(...v.......................................................................................................................................2...>...........v...P............................I.......I.qk..B.....LZ#.......#...s'....-.....#...s'....-.....#....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............{U.:..)..0.......N...^................x..%.!H.[...*.m........f........................................I.qk..B.....LZ.............{U.:..)..0............{U.:..)..0............#.......#.......#...........................................#..j....#..T.]..#.......#...B..#..H....#....B..#....>.)#....J...................;........4...4...4.."..............#...#...#....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........#.......#......##..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):3.5471449948187765
                                        Encrypted:false
                                        SSDEEP:96:6So9yfc5zLC5qwryieLEG4IgE8usMFc4IrH4I8XglA:69RRmqJ1IO9zsGUrX8Q+
                                        MD5:722BAFA2D55EAAFF257119317A11D16B
                                        SHA1:E8B64CC7B5CA7E30D0C93C28D49BEB6DA5CBBC26
                                        SHA-256:FEFC970F1BEFBC64593066E28142A0DDBAFFA101D64C9B85AA4640207DA2A5BE
                                        SHA-512:520C542FA876166924EBB39D4C64EEE8A48192D9A5894BF1BBC32D70C5EF81430B65020EA209A3938A1929F8B869AAE6003EBDDC483346E9A74921A553391078
                                        Malicious:false
                                        Preview:<...,...............................................................................................?...................................................<...,...............,...............................................C].0.............3.M....`.... -.q;...f.txUC.. ..9.....$.{....>.9..&..i.......#:s6&............&.......&.................................................... ....... -.q;...f.txUC..m.......m...IG...8....2.......^...p...............P............. ...m..&......9........d.T)......T.....l2T.s....mT.2...V.T.....&.T)O..&...."..&....n..................c..,0...e...B4.$...........GP..A..}.....J....................F_x.....F_x....3..$q..t.&.......&.=.NM.....y..............C].0.....V...G.C...q.\`..V....m...IG...8......m.....>...|............9.....$.{....>&..i.......#:s6.&.=.NM.....y............0...........e....4.............."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w.......B.^....F...r.QH.....(...........(..."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):4.616452128356718
                                        Encrypted:false
                                        SSDEEP:384:epcRkbrUX8fT07FAizeM8xRtz/nBiula7ud06FSkguw4xPWNwjvGELxEz/mG:epc6brUX8fTSFAge7xRp/ng8ayd06FSd
                                        MD5:EC3D5A894E587ECEA4365DCC55AD3F2E
                                        SHA1:18C967A4A40F0EBC7A7D8DF7CA6110AD2F027623
                                        SHA-256:8D0DE4AF6753493336AB3C114150E115B3B400AF6270A90E1BFFF966D5B1F92D
                                        SHA-512:CE9E578DB38430E4273DFD2015E63576481E686D3155818AE634EBBA6D6558AAF42F29FF384448473F745DFFCF779D53BDF19211670632ADEE536FECB0193C16
                                        Malicious:false
                                        Preview:....>...........v........@..( ..`J..........>...t...8...v........H..( ..PI..................................................................................>...........v........I..( ...I...............I.......I.qk..B.....LZ.&.......&........~@....&........~@...&....I...~.....u..o..I..I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'.................q...:.g..ajw....N...^................4A..AWD...................J...............................4....I.qk..B.....LZ................q...:.g..ajw..................................&.......&.......&............................................I(.6....I(.z....I ......I$......I ......I(.5....I ......I$.........&.3.&.8.&...z...y.. x.. ...........$........!..7!..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3..............Z4...........................................4../4......p...............C.a.l.i.b.r.i.....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                        Category:dropped
                                        Size (bytes):22203
                                        Entropy (8bit):6.977175130747846
                                        Encrypted:false
                                        SSDEEP:192:5q3R1VBvq3R1Flrk6Q0QPJJrR39joOVMJ25d1NkMhIwobbtAAAqYnLJZMJYZ2AC:xw6Q0WJR3FoOVMJIIlAAAqYnMJdD
                                        MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                        SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                        SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                        SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):3.966008462578475
                                        Encrypted:false
                                        SSDEEP:96:/ssZK7MgYXfNP3YR/pxyKyuepdWE8d9tJkfqJ3JkfCynzw:/s4K7MgYXFP3YR/pRKp8d9tmfq3mfPz
                                        MD5:A8E279ECF1E65530B3EBEBD35E67216D
                                        SHA1:4F9FF354688F111D40D720D5E3FCD268C496AC5D
                                        SHA-256:2BB9E631EB4543E36F5C6855F758D03225C9551A6F05F14F2770667CD6ABF418
                                        SHA-512:96311242D7E1F1C61C70508A53ECD849E9F4ABD0470D08F04951F93C83B36253CA6B3CA5AF5B5A227A504D61186D31D74B4C25CB520786B034E77E80741C747F
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>.......Z...v...&............................I.......I.qk..B.....LZ....)....../...).k......../...).k..........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............9Ss...=...?.4.~....N...^...............>.P....D.E.;q...................................................I.qk..B.....LZ............9Ss...=...?.4.~........9Ss...=...?.4.~........................................................................j.h.....T)................L.....H.]...............H.......}.......Z4...........................................4../4......p...............C.a.l.i.b.r.i...............................z...y.. x.. ...........$........4...!..7!..7..................:...F...G.....z...y.. x.. ...........$..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):52945
                                        Entropy (8bit):7.6490972666456765
                                        Encrypted:false
                                        SSDEEP:768:cjvqR0XvFaGCTJffi0tgybmWDoTw71kHUAnjvawrlp2+NUO8dWSNl3PF2PjK/q09:cyRffflgybmWoTw1UUADHUbU21MjpAD
                                        MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                        SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                        SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                        SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.533305612496011
                                        Encrypted:false
                                        SSDEEP:192:8xsgWjq3RTv15LP4/HTNUicXzkJs4OEcRtZ3jRA4YWI0daoe10tAxc9kNHfoHDUM:v0v34/HTNUfIs/dRtl/ji10tAGkNHgYM
                                        MD5:FAF62599DEDFDB56FECD0A3CE0E98CEA
                                        SHA1:E7A634E712166105C971E9F73AF67646CBBD7563
                                        SHA-256:B14198D8BB4C802544F9D904C2A81A016C00E4278D119AE12EA0CCBEF807D882
                                        SHA-512:BAC82D8CBEA7C6FBF6D8313EBCE2BDE30379FDE71435C13122C58433F2E6C3EDD7229B37F260E39FF6C1D247608A36AF0F01F7175715C6195C2CD3CC80F7DC5C
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>.......@...v................................I.......I.qk..B.....LZ.Zm.9....Zm...|.3.z.....Zm...|.3.z.....Zm..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................F...4..?ClR....N...^...............`.u..&{A..[................................................r....I.qk..B.....LZ................F...4..?ClR............F...4..?ClR..........Zm......Zm......Zm..........................................Zmj.....ZmT.H...Zm......Zm..\...ZmH.....Zm..3...Zm..O...Zm..........Z4...........................................4../4......p...............C.a.l.i.b.r.i...................Zm..Zm..Zm..z...y.. x.. ...........$........4...!..7!..7................Zm:.ZmF.Zm..z...y.. x.. ...........$......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):25622
                                        Entropy (8bit):7.058784902089801
                                        Encrypted:false
                                        SSDEEP:384:EhK81gTCyJ/Gf9Aw3t8w8EtdPeGDh6bEi1Ie1u4ZbvgwTwrSRh7ZKNpIGY:IjcRXwdJvtdGsUbEi1IeY8vgwTyC1+Y
                                        MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                        SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                        SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                        SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):3.196909638775678
                                        Encrypted:false
                                        SSDEEP:384:VYfhZAb85bVgeO+Y5yVzyMlq2RS3KihfnWa/BLP2DTCD4s:VYfm85bVgoY5yVzDlq2RkKihfnWaZLP
                                        MD5:F8CABFB88A95CAF9361F2C2AFE468890
                                        SHA1:90C948BA73B3C7E2FECC8F37716C99BA5F851E2D
                                        SHA-256:D32B75D0B00A750E3223EA126E7F01B38AD6771FBD95CF49ABBA73FD896B525B
                                        SHA-512:3CEC2C80B949ED49A48011E694B1B9D7317727701274E2804A88EAB1AEF41C806600215A9D0AEA258D772120F86F767A5E9243CA2734DDCDF2F804286526BEE2
                                        Malicious:false
                                        Preview:2...>...........v.......0 .../..........3g...G.q.In............3g...G.q.In.....I.qk..B.....LZ................................2...>.......B...v........-..............v........-..8....................I.......I.qk..B.....LZ.}..T....}..R..........}..R..........}...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................3g...G.q.In....N...^.................3...5E.yA>Ag.(............................3g...G.q.In..........3...5E.yA>Ag.(................3g...G.q.In..................................}.......}.......}...........................................}.j.e...}.T.....}.......}......}...a...}.......}.......}. .H.......z.......R...................!..7......}.....W.i.n.g.d.i.n.g.s. .3.......................Z4...........................................4../4......p...............C.a.l.i.b.r.i...................}...z... ..$..............
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):15740
                                        Entropy (8bit):6.0674556182683945
                                        Encrypted:false
                                        SSDEEP:192:Elv3GG8/OOs+GouFdxMlxjoPyerzkpuOo2vPMc62PaJseZC+BJoS/:EtNiwdxMlZoPhzkpuOo2PMc6rX8+B6+
                                        MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                        SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                        SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                        SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.7654199325489284
                                        Encrypted:false
                                        SSDEEP:192:dsxJvdev00rSudnSBF8WXjgZUk8RtV6yG2wxD2sO4XeNl9Ug6knhOvn:ixJsc0rSgmfjgmk8Rt0yVwE6XeNHd6kQ
                                        MD5:3F993C1E803F83DE5718EFF41AE77A6A
                                        SHA1:8B5BEA60A86F0603EA6B544F36F6840EA0860953
                                        SHA-256:25260E55CE2C518A16954D43ED59B2204B27F26B21D3B5D03CAA90F29693731A
                                        SHA-512:2CEA08FDC219EB40ED6D41D94BDF00894AA122EB66F34E9B257B379D6065EB630FBD319077E5AAA0315FF392AC2B2045ADEC3979703730DCC464FD5E11689B3B
                                        Malicious:false
                                        Preview:2...>...x.......v........ ..`!..2...>...........v.......@................................................................................................................................................I.......I.qk..B.....LZK...9...K...x.....$...bK...x.....$...bK....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............B.T.T'0......$'....N...^................[.\C..@.....D'j.................................................I.qk..B.....LZ............B.T.T'0......$'.................................K.......K.......K...........................................K..j....K..T.Q..K.......K....n..K..H....K....9..K....V..K............Z4...........................................4../4......p...............C.a.l.i.b.r.i..................K...K...K....z...y.. x.. ...........$........4...!..7!..7..............'K..%K...K....z...,4. ...........$>........4
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):55804
                                        Entropy (8bit):7.433623355028275
                                        Encrypted:false
                                        SSDEEP:1536:gVvci05lhVbfBcWvBLeynluexaWqzww/u5:gVUZhHDljaHww/u5
                                        MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                        SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                        SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                        SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.711693632604244
                                        Encrypted:false
                                        SSDEEP:192:usaFrOxP6/ohZ7IQUwqo4PIxe+0aP7SZHCPT/aXTom/3kRtl0f/9PzF4PQ7P09ey:baZOh6/or7MwqoCf/EwMj0eRtifdzFCv
                                        MD5:5AE8E7A0BD684AE809DF8D0650B3D36F
                                        SHA1:002B5B6B60198EAA6F1E076514C3C668FB8DF14E
                                        SHA-256:E98CD0ADCF32C1542DC012588597A1CE29F8623BF8C77389655988C2938457BF
                                        SHA-512:6AED44BFB9B1A700D35B0AA67B482E9FE3F67CDAA2E005AEF2EFE4BB1DC9F5E7E1992CF1DB52ED42E8B45E633BCAC9C4728E5C8FBC2F8E32DFC2B1D6CFC875CE
                                        Malicious:false
                                        Preview:....>.......^...v...2...0 ...+......>...........v...z...@....*...........................................................................................................................................I.......I.qk..B.....LZB.......B....|...N-.M.Q.B....|...N-.M.Q.B.....A(.@..{....W....I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'.............Y..g...B..ZqD.\...........................N..&.M..M.5.@.....N...^........................................I.qk..B.....LZ..............N..&.M..M.5.@..................................B.......B.......B...........................................B..j.N..B..T)...B.......B...f..B.......B.. .<..B......B.. .......'B..8B....z...,4. ...."......$>........4.."..7......A.g.e.n.d.a.:.........................Z4...........................................4../4......p...............C.a.l.i.b.r.i..................B...B...B....z...y.. x.. ..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):41893
                                        Entropy (8bit):7.52654558351485
                                        Encrypted:false
                                        SSDEEP:768:pZvVQkUbOHxx3pvVmO5rsP5gUdXwFMuv53knzyncaXgRDqPU:pZkijV5wScXwFMYknzucaXgRyU
                                        MD5:F25427EFECFEE786D5A9F630726DD140
                                        SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                        SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                        SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.573016741618155
                                        Encrypted:false
                                        SSDEEP:192:DsrSs/XqhgXPBF9KQB/uBmFdU9ppadf3OBvBWHWD0wXuxa/YEgSs+RttHBtVpFBa:4msmgXPBH9B/uB2U9+t3OBvB2WnzNXsD
                                        MD5:2A5B5619070A7AB9AD97988A85BDA681
                                        SHA1:780849B12545FBB26603B97D35DBDED622F69B1D
                                        SHA-256:643836D5E196B56997FA08662FD2A8029755B88B635315A15C71FF7B542F32FF
                                        SHA-512:C45F56B11B0D846CD588BD0F691785267872F1DB670DF0881AFFF7C45721BB3630595106E6FD90782BDB1C5BB4D17AD85FCCF8899E558924B8E9F962E97CD607
                                        Malicious:false
                                        Preview:2...>.......,...v....... .. +..2...>.......|...v...H...@....*...........................................................................................................................................I.......I.qk..B.....LZ..t.G.....tC.7%.7F..M7....tC.7%.7F..M7....t..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............!......4....Lp#....N...^................M....E..E.bm.........V...x....................................I.qk..B.....LZ.............!......4....Lp#...................................t.......t.......t...........................................tj.A....tT......t.......t..r....t.......t .7....t.......t .........Z4...........................................4../4......p...............C.a.l.i.b.r.i....................t...t...t..z...y.. x.. ...........$........4...!..7!..7.................t;..t...t..z...y.. x.. ...........$......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):14177
                                        Entropy (8bit):5.705782002886174
                                        Encrypted:false
                                        SSDEEP:192:EbgGcV/hlvpfal7rgYa8S7auAxwfuSTmCSNoFQ6NO7L:EbgGcVnpwimnd38FdQL
                                        MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                        SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                        SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                        SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49152
                                        Entropy (8bit):4.63228295739128
                                        Encrypted:false
                                        SSDEEP:768:UaNEZvx5tEZ7yDngcFOBDMSHJ3LhiuCzeA:9Ehx56lyDgBDXHJ3LMn
                                        MD5:94BBC64DDA05FC3856032A40AFD961C5
                                        SHA1:17E8320EC32A84FD7A58C4C9372AA9B19AE9CF66
                                        SHA-256:A565FFC6771AFF70C82A477DD592F61659DDC34E0A52A368C21FCBF6ED5B6A5C
                                        SHA-512:57C59A3493947D117D38681C316A5161381A0C62D2790F0BF6B078B45AAD093FA1A53B9519187079B3B092325C55D9757A3789E49149B7A12B33BEC283AF8A32
                                        Malicious:false
                                        Preview:....r....&......f%.."&..8... ..H@..@`..............r....%......f%..>&..... ..H@..@`..h...................................................................r....%......f%......H... ..H@..@`.........X.......X....7....=b..+.PM......PM.Q.R...j....ntC.V.<7.. ..-.l.NC.V...I.z.p..{.O.....I..p..tW...+f.0oL.p...........n.a.....n.a....................................................T$......T....rT.T%......T"...%..T.....4(T.....f-T%....<5T.............0...........e....4........................u.^s.Q.@.).~b.......(...@kO.....(..."...P.l.a.i.n. .a.n.d. .S.i.m.p.l.e...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.5.2...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e..........}+......}+.O.....@..#..f-......f-...}D.d...PA.2.......N........$..............PM..........p0......m...rT...........Z(......k.*..c..,0...e...B4.$........{p.....G...^...?@kO...................;/i.....;/i....G.A..S30!/.p...../.p..^..02/A/x..........m.y........'
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.354006764632179
                                        Encrypted:false
                                        SSDEEP:48:xWsoNC+ZgwOwUOYt5mgVE8oGXnyi9KuCcLrdhSro4tXKR7S9pVuD+7Zqcf:xWsIZLUB3xVE8nXyi9JCGRAlBN
                                        MD5:DC94D6BA231A5EE83B5D77C4FDC539EC
                                        SHA1:C236B1CE02017729BCC0C817018A7406B98B97EE
                                        SHA-256:084956719AAE8F367042726337B0F9C42DE2164F3910E3E8333DE086D03AD629
                                        SHA-512:55D42EF8E80C58437D90E9F85BA921B03A4A33AAA04F9E3238D71974F3A930D650A6A2272A741CB51540AF88E47064E004CE18DAB6380E8B832596A6B5B25883
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZry......ry...!....rE...ry...!....rE...ry...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............x.2<yZ#....Zxt.0....N...^...............B&/.A..J..W..h.t........f........................................I.qk..B.....LZ............x.2<yZ#....Zxt.0........x.2<yZ#....Zxt.0.........ry......ry......ry..........................................ry.j....ry.T.]..ry......ry..B..ry.H....ry...B..ry...>.)ry...J...................;........4...4...4.."..............ry..ry..ry...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4.........ry......ry.....#ry.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
                                        Category:dropped
                                        Size (bytes):12654
                                        Entropy (8bit):7.745439197485533
                                        Encrypted:false
                                        SSDEEP:384:JheN2cq6MLu6MLGu54cHeNzhcmhcDu53eNE3UPkhrxvu:Ji2Wix7fzVsbE3Zm
                                        MD5:4BCCCDBB4273ECEBE216C84930A8D0B2
                                        SHA1:FFBF617787E27BC94D9BAF89F2FE34A2BD42794B
                                        SHA-256:474F9A8C25D5E21192315397EA995B1E11E2C1608157C6E0277688091BFD136A
                                        SHA-512:DAD73A8C0E293B88685C0C71EF15E0DC95EE39B7FC9F849DE5D634173FD9FA0AF0AA96742D9E94BE03556AA4A817D5001C95A6736EAD5D5DF03661876785EB74
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................i..............................................E.....................U....V...f..ASTc.......de.1Qq...!Rb....Ca."r.................................B....................b....Ra.....!Qc.....AS.1U.."C...2Bq...$#3%&.............?......3.....~......:..g..s"......:..g..s"..ic..Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. ..0...Q_..X..V5E~..c..X...@u...cTW...0...Q_..;.m.....@w...Q.+....*.4W...lUFh....v..._..wn...dW....y._..v..E~...*...@wn...dW....y._...v..U..@wn...d..{`;.|U.2g...*.3...:.0?ViN.z.@w...4.M.:m..`~..i7...q...I....J.`l...W..n..PQTiB...6....+..sj.*."...6....+..WA...x..A........(.N6`..AD.q.....'S...t.Q:.l.......f.]..N..0.. .u8..A........_W..Y...}.C...~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~.v..?U..^.r..}..Bep
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.358524431750295
                                        Encrypted:false
                                        SSDEEP:48:QsSNJzy10Uvpat3uDEp8TcXnc996c1rdhSrHkZlStX5pztUtr9eohtbUtA+Rg:Qsl0UvUmEp9Xc996YRA+lSU6e
                                        MD5:7112C86895D178BA7897E362A4E3F792
                                        SHA1:817897F1B3F3580724CC20B15D835C0A3EC112EB
                                        SHA-256:0D9A4EBA5444E6173E88B0808B5490513599DCF1C00BEB487E105FDE6DAF79ED
                                        SHA-512:E2339F0C97E53861283B97D507094AD6BD552671B6614FF4A6A0239DB415E22388A62DB29BBA4798B10D1559588A3AC2F6E0D1F66E3B714181F0B1A83EAC1C24
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.f.......f..........N..f..........N..f...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............G....N..!...T.zC....N...^....................RJ.Gd%..\.........f........................................I.qk..B.....LZ............G....N..!...T.zC........G....N..!...T.zC..........f.......f.......f...........................................f.j.....f.T.]...f.......f...B...f.H.....f...B...f...>.).f...J...................;........4...4...4.."...............f...f...f...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........f.......f.....#.f.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
                                        Category:dropped
                                        Size (bytes):2695
                                        Entropy (8bit):7.434963358385164
                                        Encrypted:false
                                        SSDEEP:48:N9YMsguOZgKAz2vcaQU4R8r4BU0/Rc4nbIQdsohw13ZmFLY6KsVvMdBL2mr:/hsEgNz2v5T/rQC67SoWniHK4EdBH
                                        MD5:B23DE98D5B4AFC269ED7EBFDDECE9716
                                        SHA1:10AF507A8079293A9AE0E3B96CF63A949B4588AA
                                        SHA-256:646586CB71742A2369A529876B41AF6A472C35CC508D1AE5D8395D55784814F2
                                        SHA-512:BBACBE205EC0A4F4E3AB7E2B1DEE36FCF087DDF77C7D18B53AEA4B15984A47C64E19F9B8D8FA568620619CEA0361D94FE7ABEA6E502EC6ECAEFE957F42ED7EE8
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......M....".......................................,.......................1....!ABQRq.2a."CbS.......................................................Qa1A............?....{............i........l..-D.q.~..|cS.S...R\..d.8,!.....]f$....Q..di.;~5......vj......MqCe..=.*.f^..=.}.Cm]qCd..s=..u.e..v..t'.,.....S.s..N...>.d4'.,..k...N...d..9....G...y....6J.Y.l.{Vf...^B..i.3.z....:5W#4@.S\fj.%..Mb.5.v.5......S.E..#.v.I.....I......m..H....D..|.Y|...W.Wf..o..U.0.E..@.T.....................................'.S../...Z......!J..1K..rI...T.f.>.+.N..o.....\..^u........e..q.qK.GXP..-...F8".;5J...]Y......j.a.,R.......J.N........z}<qu..J.)`.}X:..}.............B...[. ......,B.).b.......(Y.O....c\.o.e&.W.#Bo..N|..N8.#J.>1D.1..b.&....q.#..UT%,.d.....m&..^...VXA..b.nbTV~.....^........q..#./.I..=Q..=..Y.*.Ib...VZ+......Y.........'.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.344195876153121
                                        Encrypted:false
                                        SSDEEP:96:4sh3iTJQ6zRSv/KE/AmXQZ9ld0SBRAmP6i5AxX/:4sh3i1QMAH/AmXg9lC4RAmSi5AxX
                                        MD5:E5C25F10F5E01AECADF0884C8C0F4664
                                        SHA1:2703BA060D17AA9DB1AFCA26B4B2A80745400AE5
                                        SHA-256:730832C57EDE569A96DCDBB8B1661BB928B6D8C411B772DE78D41CB9275C7B1D
                                        SHA-512:8E901068B0DFFCB90E080119832F11CC2908A3EE71EF947B34B5FC82C75E95517106B99CB63B8162B2D4169775D010D8F8A34A5B9A21A3C44CE0308B062DD61A
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.S.......S.@..k...HZ...,.S.@..k...HZ...,.S...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................&...7}.L....N...^..................k.X^A....B..|........f........................................I.qk..B.....LZ....................&...7}.L................&...7}.L..........S.......S.......S...........................................S.j.....S.T.]...S.......S...B...S.H.....S...B...S...>.).S...J...................;........4...4...4.."...............S...S...S...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........S.......S.....#.S.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
                                        Category:dropped
                                        Size (bytes):11040
                                        Entropy (8bit):7.929583162638891
                                        Encrypted:false
                                        SSDEEP:192:u99+91V42ho91V42ho91V42ho91V4235z9pUkDCyixxo4PS6b8tEy3BcWWhhSy0b:ubKD4/D4/D4/D4uzX38u4PNYJ2zhhmb
                                        MD5:02775A1E41CF53AC771D820003903913
                                        SHA1:2951A94A05ECF65E86D44C3C663B9B44BAD2BC9D
                                        SHA-256:83245F217DEAE4A4143B565E13C045DBB32A9063E8C6B2E43BB15CD76C5F9219
                                        SHA-512:5A1FCC24BDD5EE16BC2C9BACF45BCECF35ED895EAC22D2C4EE99C1B7E79C8E8B9E5186E3D026BA08FF70E08113F0A88FBF5E61C57AF4F3EA9BA80CE9F33410E9
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................v.E.............................................S..........................Aa..!12Qqw.....3568rv........".....4Btu.....#Rs.(W..bg.................................D.....................1..2.!4Aqrs....Qa......t..."3BRb....#.$S.Cc..............?...K/h._+.N6.-.a...5...;.r....,...0B.s(..zp..4.%r|q..E.Q^.../...C.R..?u.q8XN.>.e..:..gJ...._.n>.70G,..(........3b.&.5m...Q../...7Ie..k....e.l6..&..`Gt.P.Y^r...=..Y.e...N.B...O.#..J+........u.V;G.'.....V.]8..C.]..........E.....c..w&lX..f..\T.J?...F.,..m|..93........,.....+.R..WG...%.....(@.....p].iEz<.8.^...J.h.....a8P.1......(z..y~.........H.Z^.>..<.....L.k..IG...R.(.%..m....&u...B|.....@]ey.W.J...!d..R.8...[..>8....(.G......!.)X.....,'..F2.Z.t..Aw./..Z..#..i.kK.......b.i...qR.(....RE.............O.XP.#..(...9J..]...,.2.[w....KrW'...tY.......{~.:.+..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.498631065773949
                                        Encrypted:false
                                        SSDEEP:48:ghieBsX3fby3b3LBhlv4ztUEP3F7YXC9C0colrdHrDptXRvjR3b343/f3A3EN3qB:gDBsMBhB4zWEP3FkXC9C0RlRL9mY
                                        MD5:B0D9C34ADD81597C325BBB11BD09DE72
                                        SHA1:FF7D60CB27C79FE9A133E59BBCF8B4F0CBED8ED9
                                        SHA-256:0F3439EE7488A1138D7950211704437C17545623B5CBA05973AD8C65B44630FB
                                        SHA-512:FC8DD34CA91D3A9E8479FAD3E9A59246F53566C5B8E07F0F989EC91FA2C35D66AB5A7A52DCFF42A63027D40DF52D426E8007BD3C7B473AC3973540DA549C9278
                                        Malicious:false
                                        Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ..k.......k........ftA....k........ftA....k..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................../....Bi.....N...^................0....N.^#............Z................................... ....I.qk..B.....LZ................../....Bi.............../....Bi............k.......k.......k...........................................kj......kT%c....k.......k..G....k..H....k..>....k.......k .3...................;........4...4...4.."................k...k...k..z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4...........k.......k....#..k............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
                                        Category:dropped
                                        Size (bytes):2268
                                        Entropy (8bit):7.384274251000273
                                        Encrypted:false
                                        SSDEEP:48:N9YMn9H5gXlM26vroVXWxyNnl1LmLR+rn4FOeewGhDbby:/h9SlMdgm09ll8R2/rby
                                        MD5:09A7AE94AA8E517298A9618A13D6E0E2
                                        SHA1:FA5181A7414BA32F816BF0C4278EC20C615E8B1A
                                        SHA-256:3C68C7EE798E62A4A99C740153F3980D7DF029605C843410942C7F85E794823B
                                        SHA-512:074E9A2BE2039D0AFEAD360157550B934FABD0CB86B5AF476C1FBC885EE60331F5A68EAF70BF76E23C8248A20FB900346839F4AA8892370B5889E64948DCC6E2
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222........i..".......................................3......................!.A..1Q."q.2BRa.b...#$................................... .......................!12AqQ.............?..D.z.4....;.....7...3.t<!..d.O.....+O+.;.z6.4cz7E.........U.Z)-..@..y...........}(W...<.xv/...5.ew......yN....n.Tk.Tm.Ty.vA=...T..U....h...e.8.5%....'......e^......L.g.$.~e..O.._...... .F`.....xnL.<.......]jfv...}..\G..c.......-%...#.C.|.].`..^..W..c..B..5D.QSTaZ.5A=....BU..z%.4.h.6..=..U...W.$..l...7.:...........IPQT_...~..i..x....~.l.|.n.J..TV.21.Tg.....................j.z!+.-............"j.j...)*..TT...."....T.Tc.**j..............j.z!*.h...&.&.&..e.%..TksTW%G.?".l+$..c._9..[x...TU..........i~X..#'.qm?ttO.....}*.i...q.....9..r..?..W..d.w...f;..q...tZh..0.....2.......OD%Q-.......$......56.K.O...y._..*_C.k..p9.p..O..vu...'........0v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
                                        Category:dropped
                                        Size (bytes):784
                                        Entropy (8bit):6.962539208465222
                                        Encrypted:false
                                        SSDEEP:12:869YM8fij0W/xfuCp7ovv1bidiMn3bGi6AETQcdH8SADjoZgV6v9jUEvS3/g:N9YMWeI424diMn3yinsQeHvADu9QEvJ
                                        MD5:14105A831FE32590E52C2E2E41879624
                                        SHA1:078FA63FC7DB5830E9059DF02D56882240429D90
                                        SHA-256:D0A3A1C3CD63C4023FE5716CBE2C211307D0E277E444D9EF76C7FC097A845FD4
                                        SHA-512:8FC0ED24E8EC14C46EA523D9265DE28F85C5FC57AA54AD5B9CA162E95F79221E2AD3DD67D1293CF756B67F3D3DECAE122254134EA8D4D00DDED02114B5383947
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......a.L..".......................................-........................!A."1.Qbq....2Ba.........................................................1............?.....3.Ty\......vs....>.>..a.W..s89.d...Z}......rz...`...Z.r.do....u.W.%....gf.>.L..xz....B8=w...g.~g."HD...$..IKJ......nn..*ly..I....L...\q...Q;6.KrxZ.,...j$..ZQ..)f...q`.*..C1..cZ2]-..\.~..J.....^..(.f..9m?..C.NI.UL..X.fy.Z.........+n....r."Z...d..R./\.#...kd.D.5.!...h.3*s-+.......Xjt..}i..rK..y.../>u..]N.....Y..J......1.x./.....F6.......I...._3...k.sM.+..v;.%|.f.~.......:y....S....UKovh...W'........lF... .................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):2.7399986602086757
                                        Encrypted:false
                                        SSDEEP:192:VsnNNPTR2NlSXmizXL9fANgRCG4PCkqoH:KnLPNMl3Q5fAKRCTPCkqo
                                        MD5:5396E57BA07777BAEF1008DBD24B94D7
                                        SHA1:50434A9D900FD998BCEBF9499A0A4DD208DCC8B4
                                        SHA-256:B6056BD6129385CBA954E135A2D2B873046B104DD683773FCB604406F48997A2
                                        SHA-512:207396FBF44C9BD1F1E8876637C9678A75289253A5B7D2C6C2A0427D91B6C0A31B1AF5099E94B918460D2801D6AC2967BCB59E204A69B831E4E2FC184413D2AA
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>...........v................................I.......I.qk..B.....LZ.>.......>....T./.g......>....T./.g......>...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............,\5/1...='..-.m.....N...^...............KS"..mH../.X..u............................................^....I.qk..B.....LZ............,\5/1...='..-.m.........,\5/1...='..-.m...........>.......>.......>...........................................>.j.....>.T.l...>.......>...Q...>...Q...>...>...>.......>. .3...................;........4...4...4.."...............>...>...>...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........>.......>.....#.>.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
                                        Category:dropped
                                        Size (bytes):3009
                                        Entropy (8bit):7.493528353751471
                                        Encrypted:false
                                        SSDEEP:48:aRCTf+0hagMrbAZMJShPdvF/5OzlQFlDF7npkDdWvVBTEnBLT6NrgCX0:D+0YgMrApL553JtEdEVcL2NcX
                                        MD5:D9BD80D40B458EDB2A318F639561579A
                                        SHA1:83BA01519F3C7C1525C2EA4C2D9B40F28B2F2E5E
                                        SHA-256:509A6945FACFB3DDC7BE6EE8B82797AD0C72DB5755486EE878125A959CC09B59
                                        SHA-512:C368499667028180A922DD015980C29865AEF4A890C83E87AE29F6A27DC323DD729E6FB1C34A2168A148E6A7A972F65A5FC8ACE6981AF1D4E7057D99681CB366
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666........_.........................................:.......................r.!12BQ...3Aaq.."CRb.....#4$c.S.....................................................1A............?..p..-.....u0$.......l......)..o.FTd..DG....... .t*e..jO..Z.U......r..j.O.,..VD./.....V5D.&......A..Zi....E.N....*..........#..M<|.2.Y.../QO.x.cTM4......+.F;V.x.de*....]e..O.x.c\Y........r..j.O.,..T...hw..k.^.[B..J.sEl.w.x.m.5%zzt0..T.......b..<\.3Q..W</..!.xh6..Z..\.+M.o.Y..1............#.........|.a.l.KR>..U......e....@...\.1Z...Y...[....F.6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....Uh....FkYm.m`P...W .V.g..FjVj.\..1Q6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
                                        Category:dropped
                                        Size (bytes):2266
                                        Entropy (8bit):5.563021222358941
                                        Encrypted:false
                                        SSDEEP:24:TuRCTP9rSTfIEe1HbcVY1YbDXq8eCI0bf2QQe0GVDQAzZw:aRCTN7HbcW1YbDXq+I07Ien0AVw
                                        MD5:DB8A181E3F0EAD4A9472099E42ED6BE3
                                        SHA1:92096AF05CC6167B1AA816811A1160B809393FA2
                                        SHA-256:E9746B4E9AE9CE7B3B0068779DB3E113E2DFC9880F25373D745D0E700E69A906
                                        SHA-512:A9E246E10E28D057090BA9F034ECE6131780D7F794C5C9421523388997C7EDFBB49BC32B863B6C6668911B359C304AA54969B48CB9234950D5CECD2A6F3EFFF8
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666......r...........................................5.......................!1AQ..2a...."Rq..#3BSr..C..................................................................?...X.....U...j...F.W.V]'KV.uWt.iT...{.......`.(.....V%..=.....z......V..ct+.U.B...@.............................................{.....5.........0...x4....c..;...........+......|.7E.%.9.1+}..d.........+.V#.P.HUL.E...g.li...8.>U.";0pi.]5.\..zo..."@.........................................y.6.mLN..S.....@...i..A..p.......~|V9.+.Xy.........+,L.....7Z7..p...-X...\.....:-...i....v.1...-..H....9.zk....l....^.......:.."^.t.Q.F...X..B..$............................................a.%f&3..1.5+.X..'b7bwr.).e.x....!...H...aa_..kD...b..g..p..K^.k..qX.[,.........Q...U..x...YMvj...w..:k.....j.W.8..4....c.u.}m.....o.=@.......j.S.t.|.....5h.y.%.~...G
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.351910531931645
                                        Encrypted:false
                                        SSDEEP:48:YuUDsXNJA9iIR8itnTd1WLCxEg0XVy9KeW0oBrdQqriOrBX+hmSxuPetmKELS:YNDsk9iIR8ixd1JERXM9KeBwRQybrK
                                        MD5:9B2F4C0E1CAA3DD1EDDD3C6A491ACCFA
                                        SHA1:3A2EF771457465AD4DE1B0621C1D54F868D0AEF6
                                        SHA-256:F470521FC4D1AC6FDC9BDC3F6BEEAA5AF662E2AE5C5D2BDF3511300C7E95ED53
                                        SHA-512:67CD62BB4837CCD5E03EEDEE4B4A99F422C6C0484F174B65AA2EF1BE9037C648AB15C52C040565D6D539EC5FA96BDEC2EAA2CAC14A01A2174A42BBAA0D6EE903
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZQ.j.....Q.j=.i..8i.....Q.j=.i..8i.....Q.j..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............C..Z....{t~V.......N...^................s...E.O&a..N.........f........................................I.qk..B.....LZ............C..Z....{t~V...........C..Z....{t~V............Q.j.....Q.j.....Q.j.........................................Q.jj....Q.jT.]..Q.j.....Q.j..B..Q.jH....Q.j..B..Q.j..>.)Q.j..J...................;........4...4...4.."..............Q.j.Q.j.Q.j..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........Q.j.....Q.j....#Q.j............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):99293
                                        Entropy (8bit):7.9690121496708555
                                        Encrypted:false
                                        SSDEEP:1536:Moq1jVORV5NO5xLCBaaNk4vhpCr1CH/DATOQlWvHMHojiaAMrxArLFRZPj19AWFz:eVEbouBaIk4T8uDGOQlVHvaAMkhDh95V
                                        MD5:EA45266A770EEA27A24A5BB3BE688B14
                                        SHA1:9F0B23B3C8EBA4FC3C521E875EF876FBE018F3C8
                                        SHA-256:EDAD0F03E6FF99FEF9EF8E8B834CE74F26CD23C5F8C067F5CEE66F304181E64D
                                        SHA-512:D4EE36BDA897BBD643A699A0332DD00DE9CDCC6F46D861789BAD259A4BF87868AE3B4CFAAB6DFAF29941C7055B77A95D76BAA86A4A0DB2BF3BAF7E3317F03EB9
                                        Malicious:false
                                        Preview:.PNG........IHDR...-...c............sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..[Oh\E...y3kv........`.%m.R..6.1.4).o..Ki...D.......P!.].=..K...C[....f.}o7VPJIg...{3.|....d.....i..=.4.u0...n y......@j..Q..f)..mQ...4-SJ..9.d.?..5\-....:b.W..i...c.5..{..pj#.....B1C/.I.......].Su.k?.2..:.9Q...5.U...UZ...e..U.c],..2.}...1..)W./..Epr.Zt.....K.=..{......e..."...v..B.4.#....A.V1.".V}t..[..2f..Y..V9.".6.......(..gbm.P.....Y%2.c.z.:Q.2.<tYF.....u.@..KJ.;u.q:.].....$.....V....Hqk..DW.l.e.j.Z.YP?:'R..*.<........6...m@..r..j2..HK"|..L.Nc..D..y.9..B4$.......`.3.m1LE....7(OU\+./.O...%6T..w......h....).I.&n...*......#..W.41...5.#.`..I...<.?.|..*+Q.....#i........$,..n...`.s....[..E. T.w..j.,&-.r..;a....#.>(.P......f...MU\3*..;B....)..5....z..(....-...a.....}y.l..E...z>......&..g.$.....*T...N....E:./.>..#...^..E.0..%......(..@..W.X.NDM.<~.]A.>..fW.O.y.'...Z...h..).F..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.335847673885307
                                        Encrypted:false
                                        SSDEEP:96:YtswFQRsKPtW4SX+mEPYXvc9K4ARQyXhRarG0h:WswFQRsWtW4SuDPYXvc9K4ARJXhRarG0
                                        MD5:64691C25396D51474486549DB4A3A564
                                        SHA1:2C30C53B3095053A47AE91F1C05124949C323037
                                        SHA-256:B54248D2C198E4CD684BBE73D208779768A3AA7369B3322A44053EB98DFF0666
                                        SHA-512:12F41BAE0E77D7F4FEA20520683762DEC7597A461AE3FBDDAC4CF4D0118D3F162D8CADE0436619040E811BC0C1C7F5D21A2275DF6A583CA6846A5EC5B3D666B5
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..T.......T....!..z.iT...T....!..z.iT...T..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............#P./...5.JM.@C.....N...^...............{...}{.E..............f........................................I.qk..B.....LZ.............#P./...5.JM.@C..........#P./...5.JM.@C............T.......T.......T...........................................Tj......TT.]....T.......T..B....TH......T..B....T..>.)..T..J...................;........4...4...4.."................T...T...T..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........T.......T....#..T............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
                                        Category:dropped
                                        Size (bytes):2898
                                        Entropy (8bit):7.551512280854713
                                        Encrypted:false
                                        SSDEEP:48:N9YMTXc4gpw+EIWnqQ5G+NE9VTzRFvS4+Xh+AKrNx+JuCluc3Eeky8etajhDCFex:/hDc4rPIoNEzbS4+XhOrGJu1cUHeoVey
                                        MD5:7C7D9922101488124D2E4666709198AC
                                        SHA1:00CC44A1B84D4D94A0ACE8834491EB5F65D04619
                                        SHA-256:20016E5FA1A32DCE5AF4E92872597E36432185A7BB2E61C91F362BD68484529B
                                        SHA-512:882944B2CF040485899128E03B7499C540D481E45FE8017DBF4FE0330157B2D8ABB7334DDB31C112BA0EFE3722A554883917C54155A7F60044D2D7F3D848260F
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......k....".......................................2...........................c.....TUb...Sa...QRqr..............................!.....................Q...R..!..............?...$.)m.1...%%bV.J..H....-.%a[...I"WJ..:.X.:TT.$.......N.-NR.E..-NR.E...9..E....$.k.....B.I,I)..J...kr..+)..I,Yj..YbI..+,J..e..Z..V.e.$V..TV.X..V.YQZ.EQ..U%PY[.[.R.EP............................| F.. ...j*...!m.!j.I%.j.$...YeEYYEEUE..eY[.hEEUeEil.....%..el...V..TUYA.U.UTTUT.Z..UQQUQE...V.,...UlE.U[.lEP.P.@......................................R1...AR1m.....#..$:.T.p..IJ.t.....A..AH.,5..]F!a.XJFaa. ..a.!*.aa. X.e.......bB.b..,HX[,!..,,.c0.,..U..X..(,,...B(.,..4..B.`..".a..-......"...........................>D..IKEb...t.....)u.....)K.%+L\.J]i)*b.JR.IIL\i)u....T............T.....qs.it.iJ...])ZJb.....X....U.A...V1..B.R1....X...,.c...,%X...,%#0...,H
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341400086372359
                                        Encrypted:false
                                        SSDEEP:96:WslshEtZTAVOEShHXFb9wARQyR7NnMRCHN5CSAX1:Wsl/ZUb4Xd9wARJRZM
                                        MD5:E6B09D76651F6F56CF40A855175F2E0F
                                        SHA1:10C449743C69C27DBF3C1FB92BE06B2C090ED453
                                        SHA-256:980E900E139E2E3F9598FBB88D50830225E2D805242A2F17B80AB3B2D88D3904
                                        SHA-512:6356780F82FAAE4139B1F813B3081E4FAB2392B79953519F2F05735DD2A62B063F2FB81B1101AB953843E2A0497E8CF463DDF56CD28F54261E78E3BEB123D081
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ ....... ...........:, ...........:, ....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............Y..V.[...a.........N...^.................F...(N.....r.........f........................................I.qk..B.....LZ.............Y..V.[...a..............Y..V.[...a.............. ....... ....... ........................................... ..j.... ..T.].. ....... ....B.. ..H.... ....B.. ....>.) ....J...................;........4...4...4..".............. ... ... ....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4......... ....... ......# ..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
                                        Category:dropped
                                        Size (bytes):29187
                                        Entropy (8bit):7.971308326749753
                                        Encrypted:false
                                        SSDEEP:768:RwjBOlCk+nYnGagKJWJhwMJiRO22ZIm4VXvXx1tA6BQs:i8snY3JW7uROlEfbtVL
                                        MD5:DF99CAAAB9A7DE97B63343E60A699AB6
                                        SHA1:B84334135CFB73BC6EF55F85926770D5AC6DFEA8
                                        SHA-256:74C131777E7C437FD654427417097BC01B0813BA8E1E50E4B937BD50A1BEBCDB
                                        SHA-512:5D15AAAA8B71DDFE01A7C0ADE16D9E1F5E9AAE484BCD711B38CCB103ED9564CAAC23A0031471167B660E15972D70179C2A387509B213C05D60261042A0456025
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.........................................................................e..............................................`.............................!1Qq...2ARa..."#.....3BSbr...$4C...Tcs......%&DUd...E....56Fe....................................H........................!1Qa..Aq..."b....2R...BSr..#...3..Cc....$%4...............?...b.d.8T1.;#.S.DO...~.R.......3.xe...z.6..."m..k...;*.'.f.5^.....m..<$....8.R.j.D.v..>...*dT..vGbt...I......sEWp.r3.. ..G...6.....w...l.S..q...b.....-R....^Zu5+u6...A..Z].:...5..Uzn.,l.L.....?%.*.S.+zVg7.=.s.Q.....8..:,c.......ZE...>'IF..W.0.d.......c.e.d.V.t..S$.DNR.[....g..#i.$. .U.SK2.....k...J5u u\R.....T.[4..A.O..,.T..................] .i...B.m.^f....._...{S.....<......:..|D...+...NA....Y.^f.1|..%K~1..B..^...S..v=.c..g.tX[..kTJ..t.gr....R..@.F....5j..2.K.9..g.1N.....*.U...^w......>+.l.v...@N....%Qd...t.Ni.....0;lggm...K".+!.,.....[J...>..?f.]._;
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.3571588485586155
                                        Encrypted:false
                                        SSDEEP:96:Msy9UqIF+qjiEYY61XUZ39TcRQy9r71Rd:MsUUqmxqXY39TcRJFxf
                                        MD5:D3EF13F20F42075A963E05D00CC70A02
                                        SHA1:974201BE172B5A098FAF9A616DAD457F6622A09D
                                        SHA-256:B38091317C01EF3759ECB7AE4AE484B5514B7338BEEBBC0896FD9AB90716B20A
                                        SHA-512:685FC928AEB9230A9B26BBE6CA4E61267B6400D546C3262B9A2641CB01BC0862A301A7C0768E1422E92F2BC63B329D387027DB332D0B9D92C2FDB14BABA3A4BE
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZd.M.....d.M.G.|.&.t..d Wd.M.G.|.&.t..d Wd.M..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............&Ut.E....3.Ev......N...^...............<n._...K...j..y"........f........................................I.qk..B.....LZ.............&Ut.E....3.Ev...........&Ut.E....3.Ev...........d.M.....d.M.....d.M.........................................d.Mj....d.MT.]..d.M.....d.M..B..d.MH....d.M..B..d.M..>.)d.M..J...................;........4...4...4.."..............d.M.d.M.d.M..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........d.M.....d.M....#d.M............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
                                        Category:dropped
                                        Size (bytes):4819
                                        Entropy (8bit):7.874649683222419
                                        Encrypted:false
                                        SSDEEP:96:/hnQiz+ET2/hDi+tv34VtpWfowTHgegb6hhLT1NTS:5nQ6TAhLtvIzMvbi6hhF0
                                        MD5:5D6C1F361BC04403555BE945E28E53FC
                                        SHA1:00C254F7B3BC0289590C2BBDBB39C8EC2E2B2821
                                        SHA-256:131D637CDC5D0B094FB9FAD17F4D2A1ACE0D03613588155AACAA2D1CB4E16DA9
                                        SHA-512:34D2C0929FCC3CC10D0A2121BD55BFA9A07062C2A7B8F101071164C946895DBCB2777641E79DE4193D57A3F0778DD4F1351FAF333B7E4B4DBE31A32DD69C51F9
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................<........................!1..AQaq"...2B...#Rb..r..$3CS.cs..................................................!1A............?.............u....p.p($.Y...9,j...V.*..S86yh.G.#m.5..9...6Y.."C.R:.[..-.7U3c:..].;.....f.?%..<T...&F.Lh.N...m]..x.D.g<B.....k..S........>j.K....#U..Z....<e.:..8....o..xq.[..4v..U..y...k... k....A#..A...pn.jJ.I.7:..{.b..ns.t,...8.Td.I....m.I.5Z.).-.. ]..X.Do%.....?..4jV.`llt.E...5...u.|..\F.=.F.r<...5dV....xc.%..&...4,...f...3..H.<......eQ...P.J....7...lLc..?..-.fR..7.#.6.......}:.]'.ny..........e;u.Y..$0...i..-....f..9(....}..T,.Inb...+=Cca7....WULA1@.s...4uY5.N.f.c..].ks.....3v..~..k..m)...f gNE`S......#.....Z..6.uc.m...#k.s.f*.l.$6..?..xC.Cm.`...N2..&H...._.&.E...[....f.Z./...!.a{K..#.V.5..v.B....1...9..B.&....%s.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.35574553564949
                                        Encrypted:false
                                        SSDEEP:96:ysabibNbR4RtmazdEVUNXZ/v9xERQyQQ2pbNbcbvb4b+bp/:ysQ4JR4RtB6KNXtv9xERJZ21JqDWk
                                        MD5:FFC4504BD1D2C59807294788AFB23A80
                                        SHA1:CF10550E28DF0C51922BE5B287D28A74830AFBB3
                                        SHA-256:BD21C54A64C9659E772AFD6B992E8286C25F5630B2F23D16CB62EDB7215CCE6A
                                        SHA-512:DA03B2BAE06EEF80E5C08126907407EEAF5C862E16BF19ADB896B1D2B2461B040EDD482077DB00C454BE211B2ED63C0025CC3CBBB8A504B200C1EA44849C7B70
                                        Malicious:false
                                        Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ...............$...4.k.......$...4.k.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Z.. L..>..OY.n.....N...^.................4..8rG.2....:........f........................................I.qk..B.....LZ............Z.. L..>..OY.n.........Z.. L..>..OY.n.........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
                                        Category:dropped
                                        Size (bytes):1717
                                        Entropy (8bit):7.154087739587035
                                        Encrypted:false
                                        SSDEEP:48:N9YMzO6BOfqH/dAIWpdAIWpdAIWpdAIWUtr/SD:/hzJgfqHaPYPYPYPUt/i
                                        MD5:943371B39CA847674998535110462220
                                        SHA1:5CA79B7BD7E0E93271463FAEF3280F1644CBA073
                                        SHA-256:9C552717E8D5079BBB226948641FF13532DF3D7BE434C6CE545F1692FA57D45A
                                        SHA-512:812541836C8B6F356A4D530E5CCF1CFDCC4CA54AF048CAC19FE86707CE5EA0F41D73C501821AC627AD330291EF58C040DFC017923A7886CEEC308048DA2CE7C9
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......-...."........................................&.....................U.....1T..S.R.Q.................................................R....Q.a............?..d.. ...............................................+A...Z+E...V+E...U..R.....}........Q..Ah....Ah..b.AX..b.PZ+A...V+E...V..J*....Q...b.Q..Ah....Ah..b.Ah..b.PZ*.(.@z.?.`;2.......................................................Q...b.Q..EZ*.(..Z>.G.....`Z+E......J*....F+D...F+E.......b.Q...h....PZ+E...V+E......J*....F+D...F+E..............[u#...a-...f<.9^[...l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m..0.....l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.338056064512297
                                        Encrypted:false
                                        SSDEEP:48:ZkiWs9Ya6qNv3ntm4XEKd79KBXnB9uBoRrdQqr1qeBXvjN+vl9N0g:CsrvXlEKd5qXB9SARQyoeVA0
                                        MD5:E4DF8A7FD7BC3B66AAE60CFD0F7DB935
                                        SHA1:4FF1F9D46C0F25432B5ABCF1DAD6D369FC34F407
                                        SHA-256:BA10FD2FF27D82E00C7445E5D588799A54399BF44129B191BE34D8FCDC89B210
                                        SHA-512:D69A057CF6DCA564DD4E987A87E68F744DF92EAE0D530C0E4A786D65F984600D3A89BDF2BBC6C99732934BCD8DABCF527B29A5A8DCF07FD903EAC5924FE79D8F
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ...............-.H./Js........-.H./Js......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............S..Y.....<.@s....N...^...............G..]k.D......%i........f........................................I.qk..B.....LZ.............S..Y.....<.@s.........S..Y.....<.@s........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
                                        Category:dropped
                                        Size (bytes):3555
                                        Entropy (8bit):7.686253071499049
                                        Encrypted:false
                                        SSDEEP:96:/h3JeYCQV5Hn++9HBdAjU78S/mjLLwqnqahJD:53Je8b+EBdAjm8S/mjLLRnphJD
                                        MD5:8A5444524F467A45A5A10245F89C855A
                                        SHA1:ACE68D567B02B68275E0345C86DB1139C0EC1386
                                        SHA-256:7D2B01F17354D9237A6AB99D5B9AFDF0E1CC43687125848B0C2DEDFB44CE3843
                                        SHA-512:8151B447B60D110C32EC1EF286B941FFC09B99140F41BBACF5A1650A385FF4D13C0DDB2878E9A470FC7CFCC95A1AB6E44F6DE72562B0FFE093DC8A3C3C7FCC14
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................2........................!1AQ.a."2q.B..#R...3C................................ .......................!1.AQBq............?........)&vD.)3Hn*..X+....r...tmL.k..(.E...R. .Z..&...,fJ...!...6..S\t3.=...g&..Bqe.)_U.....1......-..fl.................J...u.i.mU..K..v.w.0O..E.h..D~K.(..9.,8..E.}.............i.\.....t."v..q..C............<..|3.........................*Q..../c.....f.}8....D..|k..Z......0..~..c..e..m(...|.c..'.5.5............==bx.5x.8...T;....=.--.pc...I;.V.m..,(....}...NH.ho....Q..U.E$.~...w.t>.S\....'f.{.+.g._.t....;>.....P...........-..G.h..2...J.% !.E97Ir.D..N....j...oE._...._...".?.......#".S.........Q.Tc.I..*I..k.......=$.........sk1Jp.\K.....F.3.Q..q..J....N..[l.&....OR4bB|..2ul....J...B.$&H..9#j.f.n./........?R~....B.I.@..........m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.350161208590484
                                        Encrypted:false
                                        SSDEEP:48:n92ssQNHr29YGXMPteuxElOX9a9yeoZrdQqrbw+piBXuUN9N99KNnD6N0N9gfNiA:n92sWMPjEEXo9x4RQyEDL
                                        MD5:9D7ED6A2DC8DCA59CC5913A174F3659E
                                        SHA1:EF50E5E8182D73AB2D6C8887071E5BDBC38D53E6
                                        SHA-256:F7D6959067DCA7FBE4FD91D4BC7B41D390BEDDEF19C8A2A3843C73AEB8967586
                                        SHA-512:860F5A0FC101CCAECA7F91664624FD4DFB86C2B9F3F2B8F535400103EAC915DD4E7CFF1EE4C133C2DB387A688FCA9E6216941F337D19588D551EE3C64ECC7B1D
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.$......$...A....Ng.0..$...A....Ng.0..$..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Tf......9....p......N...^................._.kL3D..o............f........................................I.qk..B.....LZ............Tf......9....p..........Tf......9....p............$......$......$..........................................$j.....$T.]...$......$..B...$H.....$..B...$..>.).$..J...................;........4...4...4.."...............$..$..$..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........$......$....#.$............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
                                        Category:dropped
                                        Size (bytes):3428
                                        Entropy (8bit):7.766473352510893
                                        Encrypted:false
                                        SSDEEP:96:/hdu7isPwAp7zesusUyYAatNG87llTONQYS:5di5tfuQ9atNZlaC
                                        MD5:EE9E2DF458733B61333E8A82F7A2613D
                                        SHA1:A86704C969F51B86D6A05ED51C6C60214ED9FA89
                                        SHA-256:BE4F0E6C89FCE91B9EBD2623567F7DFC259E0E3C77C9158742B8F64B724DF673
                                        SHA-512:BFB5D6DD6B66EE21E946E90D1E482384CD10244308562DDA814189602681DADDE5752B80519E5B8515F115A71BD6BB4317A59BE65B8B5E3474AED119F8303569
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......r.F.."........................................H............................!Qaq.."12.....#3ARbr...$B...cd...&CSu.....................................+.......................12..aAQ.!#q.."................?...#...3.Za......rV.5&...../"..i.t...j..W........d.FL.V.2K....]t.f.d.NK..:.....f...... ......2.[...#..D...ZK....p.z.E.N..T..L.-....1....2.\.6FIr2..zS\U#..........fB\t..5J..~q...D....A.......!....MY..../.HY..../e.M.Y.n.~..,....'..Pc...l...d2..m.f.it$..qx-z*...._..].cOO....n..&.....FIA.....2J2..d:<qc..6.I.G.N....f.K..Dx.-.......`....2.FZ."K7.r}..<.P.Z.da.Y.....8..s....G.....b.e..g .S.......FL.Z,&..q.MG.J+..x\..m...qN=.....)..`...&Y...S....u6{.z.g.....@......FL.ZL&.Iv.w..8....U..v...*.q.B.v_./A..#.#.g.j........*J;...u...W.Ao...%....#$.....M..^\{W.SO...s,.N.....c).,.B.Gv...."k..z."..S]H.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.351609661722639
                                        Encrypted:false
                                        SSDEEP:48:ss4GVrOSUhZtQSgNEXNrx7qXs9C7oJrdQqrp/1BXR1u9iMMgFl:ssh6J73oEXNrxWXs9cQRQyV15DMtF
                                        MD5:B87D3DBD7732C661D74E6B0EF63E9544
                                        SHA1:14899903AA410668654227F684793A1485A93DDB
                                        SHA-256:C6B38D96CA5205F7539A8B19E20C8287340E78E92981B80671B2D4A107C8A16C
                                        SHA-512:E39ED6D9B8E6C5A1CEF01843693B7B776037F7BDF47B24347F70E3B881080537AB3F1234836ACE8AA68DEB233292922F50C6808D33D451CB273CBAFC7036A094
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ`<......`<.v..:.;..;C.eV`<.v..:.;..;C.eV`<...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............]Hk.(....H...._....N...^...............F...../D.E...8..........f........................................I.qk..B.....LZ............]Hk.(....H...._........]Hk.(....H...._.........`<......`<......`<..........................................`<.j....`<.T.]..`<......`<..B..`<.H....`<...B..`<...>.)`<...J...................;........4...4...4.."..............`<..`<..`<...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........`<......`<.....#`<.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):65589
                                        Entropy (8bit):7.960181939300061
                                        Encrypted:false
                                        SSDEEP:1536:2Hlrjw3xL//DPgff+9j6yPWvHMHjkbfnwHO3AW3GL:2H2zDUU+yPVHITwNfL
                                        MD5:8B48DA9F89264D14B83FF9969F869577
                                        SHA1:E1BD58E2D80FEEF56DC514F3F0B3AB9669F22F95
                                        SHA-256:62AD3C277E54F03F1ADB44062407346F789E63859B7AFABFD64BE6AF5E9F66EC
                                        SHA-512:03B783EC968DF3F648504D068D64DD1AE110E28110FE5B3401C9D04F44897DBE0CBB5680D42CA4C665FA94A6CED4B559106EB3C06C9BF2C5B14951ECBFFAC8AE
                                        Malicious:false
                                        Preview:.PNG........IHDR.......{.....;Za.....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..Y=.+I....t.y...,^vv....;. "|. .i7.....$.2g..']pH@p..]b....H.H.......d'@ B...U.xm..3{3k?..5n.._}U...3......~..>...g.....f..t...t:...p>..Si..d:..k:.Lf..t6.K.i....d<...x.8\.8.+lc...)i.$.r.....x.t.BG.R.cm.c...p.:&.6.4..K.......^...~b].0....oBYv..u.'.=.K.Q.g)6.....4.!.M......4.=....G.%.Sr........nxC.F..t.U........1...J.t..eQ....".... |...81.$D.!.>...........$...^.vY..EY8tb..'.P.g#O....S*..0'.V....x.W..........k.......s.C.S...J%.iVb..].........3....j.}*.z....+.s..@..K.....\x.C..e.Qq.....;N.....;....,....^.*..$F..{G...8.#....8'..&....8..5.....3(P._....S......|".....u.cr....+a-....&V..x...iI-<|a.{E.c.X.......?..&.C....'........(.x....>...M.?.9..#X......l...0...Z.F..<.z.0}Q..Z1..........?h..`E$K.2o.A*c^.......*..D..uL=.}.#*0.. M!.A.C......|_..(.Y........!E... .O...`;....M+..x.u~g...q>...N."D^..K..x..D.`.!.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.361516175299188
                                        Encrypted:false
                                        SSDEEP:96:esXQQUYezdEmd3Xz99m68RQyr6nE+ntiTTa9:esXNUj6mJXx998RJrIE+ntiTu9
                                        MD5:40520BC08F65DB24DE53F85B93210965
                                        SHA1:2F8765F7C89BFA6887C2442F275F361429D423B4
                                        SHA-256:71A8C022B0E96CEC858FFA7CD42A4913A29B27727AE48F96CC60DE29F2206016
                                        SHA-512:5303ED7F87A532C60F38CD5C902CE99EE580926C254502C7BB714F265179B11E6650043E311CCD8B046DE1A1BA2E15DE6E560B77AA6103C327CA43650F175AEB
                                        Malicious:false
                                        Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ.P.......P.....$.9"G.Nk.P.....$.9"G.Nk.P...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Hq5.q..>g..........N...^.................O...@.>w1.D.+........f........................................I.qk..B.....LZ............Hq5.q..>g..............Hq5.q..>g................P.......P.......P...........................................P.j.....P.T.]...P.......P...B...P.H.....P...B...P...>.).P...J...................;........4...4...4.."...............P...P...P...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........P.......P.....#.P.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
                                        Category:dropped
                                        Size (bytes):1873
                                        Entropy (8bit):7.534961703340853
                                        Encrypted:false
                                        SSDEEP:48:N9YMw9kGzE4xTdow1C3kyIkyM66KeJY3fOxJ:/h8HzE4xTdoUCUyxyD6LCvSJ
                                        MD5:4FC8500BD304AD127AF4B5E269DFF59B
                                        SHA1:9A5E3432358A0FCDECE86AEB967319B93A65D14A
                                        SHA-256:B4DAA90D5A53FCBC85119050B5B76962443C4DD18D7F42CDC6D4E0AD8EFAD872
                                        SHA-512:E5E07054A522EB91EFD39722AFB3776389632B8F5F923C1D29796716D68CEC93BE5E44F79913804CEC7ED631FF520CBBBAAB841E01FB90AF8E8ADF84DCD47481
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......`...."........................................>.......................tu.....45.!#$%1s."fr...2Fq..AQe.Eav............................... .........................!AQR.............?..e4.bbu."m.G......u.S.-Qq.b.a..'#..E.......u.|:.f[O..jS.S.&....=.....[.....S...N.~~...'...q....N.T.Oyf..a.6..%.I.1j.e~.4..[5.WW.Y..Xp.gn...u.......Gb.O.W..k.!mJgfq....~.F.......m..}bn4.5........s,F...z.b)..O..*...5).-.-\....=`.fP....%...A..Q.&..9.....QQbD.%.:u.f...r$.10..W.F.T..MI...9...ZQH._..).....D..n.F].........*.:.j...!6Z..S....0...B.6..Ga..S.O.....U8S_.J.>...i..?..<.P..........M..F.T.C..7.E...`.4BKcMh1j....4y...+.|.^......2[.WG.W..+......E..r/V^".R...."..6..hht..f...........;E..Kx....)}Le.A.x.>..$/).._S.n.L......}..H^Sw...2. .v.io...../.........x.>..$/).._S.n.t^;O.....n...[.S...h.v.io...../....:/...[..7yK.c-
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.487521630500666
                                        Encrypted:false
                                        SSDEEP:48:ysoRRysTa+3hbtUEeWXW90GQ7o0vlrdQVruWKBXFDWksaTnwXRO9:ysoaga2hbWE9XW90GOPRQ5kIaTwXRO
                                        MD5:6B87905173B899AA90D4E15122CBB56C
                                        SHA1:3346CF18A222FFC584AD3358F13D0395301EBCEB
                                        SHA-256:D2A9B2025DF65416C8F9C7B37A314B22C483BED4B9A0076FDDA19C0BBDD8E533
                                        SHA-512:EBFC1E6282965F063B1B7933C053658B7DD3E69DF0187752C58D65F265B361F2B096FAD933F9C69E005910F26923F6960DEE8C3088F2F4D455CEFAAFC5D8B543
                                        Malicious:false
                                        Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.+9......+9.....;0.[.f...+9.....;0.[.f...+9..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............."Z.M.Id...O.........N...^....................7FN.....v..........Z........................................I.qk..B.....LZ............"Z.M.Id...O............."Z.M.Id...O...............+9......+9......+9..........................................+9j.....+9T$c...+9......+9..G...+9..H...+9..>...+9......+9 .3...................;........4...4...4.."...............+9..+9..+9..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........+9......+9....#.+9............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
                                        Category:dropped
                                        Size (bytes):5465
                                        Entropy (8bit):7.79401348966645
                                        Encrypted:false
                                        SSDEEP:96:X0cZneDWlIKmXwxacOHHI6EhzNlSSDDgafbofgt7mGrw:XleDWlIJwQHihRdgu8imGk
                                        MD5:8470F9A96B6C6CAD9EE60961E96D19B2
                                        SHA1:AFE1F01FFA4E4CB06B1D770C9C59DA75B434D1AC
                                        SHA-256:2DF453410796AEC7B9EFEC00059B6CE64BCF67313A95AE458BA600EA5DE14811
                                        SHA-512:CAE5C2ED091BA49761F0348516D53491E578FB165F32F93AC7DAD927383E9A398B06229FAC6A8233777DF708E5001AE0037A1FA960293BDA49892C40B37F2240
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................E.e.............................................8...............................!"1...2A#Qa.$34bBDSqt..........................................................?.....`0.....O...3Sd..@..5.0....Q.pw....;....!pN.DR....`0......N^...k.=.u.e.7{.b........?z....zV...M.....P:a.SPj.....WRK.=x.2.h..2..AS..s..A..|.Z/f$D.YX1pr......}G6._.~..)j...+.s.r".{..q..-.^@...#w|.H..*.K)....g...y..`0......2.w@.Ro.d....@...K....}...&... y..f.y.0.|DC..>p.[E.2......v..N.)Z..4.RF.D.8]..Z.|f/..+\ID.r/.o........0i..*.G.O..uj..RN. ....j...xnF...Q.Ls.U.c.D0m....z.k.P;f...b.=..L.hH.,./;.U..`sa.I...?*...I....M.0<.u....!..C..U.T.....s.Q......_..7K..*.....?....R\&=.<.u..oQ}WZ..Yu...{Fe3.h...@.s..mW.G..^....1.W.#[.q2.&u.c.G......`J./..X.C....M;.....3k$}.i.3...#/x.m.Oh.}FH]. ..5NNDIS.-.M~...6..w.d....P.;..k...........v*..T..L.P...s.!B.4..w
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
                                        Category:dropped
                                        Size (bytes):3361
                                        Entropy (8bit):7.619405839796034
                                        Encrypted:false
                                        SSDEEP:96:zDqnxqMt6gGr/Nln5ANln5ANln5ANln5ANln5ANln5ANln5ANllHN6:CxqMQr/rn5Arn5Arn5Arn5Arn5Arn5AN
                                        MD5:A994063FF2ABEB78917C5382B2F5FA8C
                                        SHA1:BD5C4D816B04A2B6596DFE38DB01228F553FACCC
                                        SHA-256:D72900E8DA72D1A7F3729971AA558E1E9B6E9CF9A0D51E83852E567256DBBFEF
                                        SHA-512:CF2279033DD3EDFE6F6F9E5C517BEBD9A52863EEFD90F57F7A5AE0E0485E705254BE7ED6B50E6CA142669687727AE85E2E6035F69930B75F2E6D3EEFA961EF88
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................U..........................................>...............................8H........59...$%&7F#'Ddf.....................................>.................................58EG........!#124$%&ACFbcde............?...n.p..v..a.~.._.>......#....8.....w.G...&.W...i...%6m..K;...4."...=..?.~......P..O...j.l..AW.jo..,..=d.h.ta..../.."...z|).J.......Ww._..<Wp.3+8...-5...G:..2.D..I>o..K.F;-.....#...`...6..T...M.....OOgV~..5...np...P..TYr...........b..{r.2.9..].DA.%C....=.v.z......CK."..R..l..y}.i..;.{....JzS.....~.?..Z....=c.h~*..p.@(@..G.....O.]...Hsd.xf".V]..S"..w...4e>....3*U.7..|M.x...|\......FD./.cIe.;.bId..+=...w.......[.k>....}.u...j.xZ.....Q4..+.....B....1O~\......I..h....LaXJ%&.w.<C...n/`.W..U.W.U.}~...}>..^.0.J.....@....LN.b.......5W...m].Eu...:....G..:4.=4ixx..@_0=.mab.T.U.....w..~.V.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.30677586083873
                                        Encrypted:false
                                        SSDEEP:48:esoAZ5OwdOutE+KED5KXRX9eN6olrdQqrP76hBXWh/SihfFF:es/5OwEu2tEwXRX9eN68RQyP2hm6YfF
                                        MD5:EB4FC5D79A15AB77DE713EC02005D025
                                        SHA1:F15D33DDFAF0B1DAD6453E2A5B49F9771C31577D
                                        SHA-256:1517D95D54BED6D49F189AFC1B208B2A617FA34720B39947820E6F9702C7C7CC
                                        SHA-512:77CC7C42F530E73921D1136354C0B5C3EC215A1CD4AF667E8152549A1E2A5D19DBFB652697320BA536B7450A6670CC91ADEE92F61FFFFC6933F611C729EDAB02
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZsp......sp._..!.8;#.$I.`sp._..!.8;#.$I.`sp...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................u...>&._..ln....N...^.................^.q..H.4.(/Uo.........f........................................I.qk..B.....LZ................u...>&._..ln............u...>&._..ln.........sp......sp......sp..........................................sp.j....sp.T.]..sp......sp..B..sp.H....sp...B..sp...>.)sp...J...................;........4...4...4.."..............sp..sp..sp...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........sp......sp.....#sp.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
                                        Category:dropped
                                        Size (bytes):140755
                                        Entropy (8bit):7.9013245181576695
                                        Encrypted:false
                                        SSDEEP:3072:i/aDiblRsFcOco8dofE5Zx1+NQI8Wh9aiOe5NTO:mnbM+TxaAi98W3aiOwTO
                                        MD5:CC087700C07D674D69AFDFDA0FA9825C
                                        SHA1:F11113DF69DACDB255C6CBCFB29C1D1CCE40B346
                                        SHA-256:A7FA7F092EFF43030A56342C39A765F8D5CC48C7DB815DDFC8C1E5EC40117FAE
                                        SHA-512:843202D975EFA91E73287052A893584B6E5AE601F91612B56539AA2F73D1AD3F997FCAD1E711E0F483A2E91D46D9643D0B026B43F4E94116A5D2FB6551536034
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:15:20.............................\.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.......J...\O.,......../$..........OE.m.o......T....Z..l.g.-....m.?...Y....3......"....].j.X.k.S.k.....4..R....{....?F.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.359852861894593
                                        Encrypted:false
                                        SSDEEP:96:YJsdQGPrWshEuVJXU9eytSRQy7TTmGVRDdbMaTY/Y:6snrWduVJXU9eytSRJ7
                                        MD5:7D9978CE2C51EBE452414286E70F1DDA
                                        SHA1:58405A709612A7817219FE26CC13E00C5BFAA456
                                        SHA-256:27AB21184AEB7F67F6BA75B6F472873A7C007AF85FFE9B3FD930DAAE806BF598
                                        SHA-512:57D9B6ACEE94093FAC357EB32CBB21B90AED0249D40F865CFEE045950494A059A8CD3F4D732E50A21EB4377B4B5099B56881087A85749E662A018AFDAC81E257
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZP.......P..%.Q..;9"...wUP..%.Q..;9"...wUP....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............$.....(...~=~q.....N...^................4g.#.QE.9.....!........f........................................I.qk..B.....LZ............$.....(...~=~q.........$.....(...~=~q..........P.......P.......P...........................................P..j....P..T.]..P.......P....B..P..H....P....B..P....>.)P....J...................;........4...4...4.."..............P...P...P....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........P.......P......#P..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
                                        Category:dropped
                                        Size (bytes):129887
                                        Entropy (8bit):7.8877849553452695
                                        Encrypted:false
                                        SSDEEP:3072:QS1x1rXglsteJ79wHi4vNQR5yBlUdOSILe9hSj9jeWMPjdlOJ:vvglst1HiwWR5yBA2LeS9jd1
                                        MD5:737E96E41D79D3BDACE7AB4F8CBF6274
                                        SHA1:E6202A41A4F86B27D9EBCAEF7670B16C0ED67CF2
                                        SHA-256:7966F3D8A2D61ECB49A35E163781858E052C0B122A18A1238AFE27B57E2850E8
                                        SHA-512:D398C8521DB2FB3F8456FE792CF37472F3B851DD7298DB20E2DB79144F8E846D051878E77E5EF5D00E6840EDB90C6E2D97935BC1023A15FC45038CCE731E9895
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....iExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:13:06.............................:.......................................................&.(.................................3.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................u.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...W..I:..*....a....Aa ...w.T.M.v.........3x.......8Y....$.."-..m.I.0~sxB[@..=...:..\.Y?....@O.L;9i..U....?.5">+9.s\Z..vN
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.351104279473443
                                        Encrypted:false
                                        SSDEEP:48:Yu1PaP3sWcoStVI/96EtqSEr7LsXz49bwdQLoqirdQqrjdSBXOhDN9:Yoyfsxti/cEDEr7AXz49bwd4sRQyhS+
                                        MD5:B1C00C1BBA4AFE2ABFF7B082025D5FD5
                                        SHA1:E4B80A13C578929F5154426D55D7B0CFB393D5BF
                                        SHA-256:D4DB12691D5100934BEB64C0D62EC1F78B60FA42EA613961CF18C0DC3D4E47A5
                                        SHA-512:7FC472C8F715676CDE60A5A5761AE978930BBF93D6D4FD4A5B4175DE93A2FB6D3F84D41C0885F772ABA8CEC7EDD6C8E9F3D8A87138F2095D1BD4DCC79B601BA4
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..............g..H..........g..H.........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............m%........VJ.%....N...^...................3..A....-../........f........................................I.qk..B.....LZ..............m%........VJ.%..........m%........VJ.%........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):84941
                                        Entropy (8bit):7.966881945560921
                                        Encrypted:false
                                        SSDEEP:1536:X3sWfhTVd+xu6rA6SOONM0/YFXnviDwoPCaNSm+z/ze/fWNj7GfigeKyCGzw+QKW:nsOhdDJOwY1voPCaom+z/zeHAfGihCG8
                                        MD5:CB84C108A76C2AFFCAC2551A3C1EAD56
                                        SHA1:8BB7C2A12B056C1ED12EBBAE5BC9F60CCE880FFE
                                        SHA-256:139BB0E79F89C3DDEF79B1716A5FBAB4C07DF5785FB3CDF6B4EEDDBF6C078452
                                        SHA-512:6EF85144E9A7ACD0FF2E52A5FF42093153EFB69127B1C8549EEBC49B6CC196A46B65EE39A2CAD0206F6A41476D8B5B35D29EAC9942B8F84972B32E14CAFEED27
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d....................................................................................!.1A.Qa..q...........".2..BRbr#.T.3C....S$.cs.D..4%5......................!1A..Qaq."2..BR....3...b#.r.C4.............?.......m.q..'O.....r......_.1....8h....?.....O]~..k......GO...''._...!....o........''..g..H?k.......1...?.....z......>...+0..................GO...''._.........}.O.Z|.L?...........?.........[~t.......}......NO.....v.......J.......?..g..H?k......GO,m..r}o.z.....}......dC.9?..g..H_..........?.....O]~...m...C?.z..f....W.=u.B..m..C.-?.a.....3._.?.......o....np.M....g..H_............9?..g..H...../..kO...''._...!~...o.....0.M....g..H.........../......O]~.~...o.......7..+.... ..l?.}........&....3._./....?.........W.=u.C..m..C.+?..o.W.=u.A.^.O....:......_.........}..t
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341248624926927
                                        Encrypted:false
                                        SSDEEP:48:YuzIrsaXU25P6tFPhmCcEe+h4X/89mroFrdQqrjx7RVBXLDtjKY7pB:Y6IrsA5P63Z4EPmXU9mrkRQyFHhZDp
                                        MD5:E44D4FA1A04F0BFB413F38216165564F
                                        SHA1:4AB5C9DB1D283D6F59B8533E017A0FC6CB01182A
                                        SHA-256:AAA3C32CC1EAEF6A031DD707CEDA417F533647BFAA83FF6B96F622DDF161931E
                                        SHA-512:DF99BBCB90D5FE55E9574709AFAF54823FAB2BC5C9B84E94604D6F4D7586D4D43E3E0077DDF66CF4AF73BDAFB2DDD03DD921B53E65BC6A9FDD7B9F24372237E6
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZI.".....I."..t..'J..&...I."..t..'J..&...I."..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............W...5..-.Z..f!.....N...^.............../..o...@...\!$(0........f........................................I.qk..B.....LZ.............W...5..-.Z..f!..........W...5..-.Z..f!..........I.".....I.".....I.".........................................I."j....I."T.]..I.".....I."..B..I."H....I."..B..I."..>.)I."..J...................;........4...4...4.."..............I.".I.".I."..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........I.".....I."....#I."............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 623, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):1569
                                        Entropy (8bit):7.583832946136897
                                        Encrypted:false
                                        SSDEEP:24:KArPoy/sSfmBL0EGEsRgeTLLXFnViAAEslVorlP0i8OmO57EnGAkYelBKMN:9oQPTgeL5ViAe8rQs7HAkrlc+
                                        MD5:07DB3F43DE7C1392C67802E74707DAA6
                                        SHA1:C173ADB1999065C5E1E6DBEF934B4D4D7AF0CC23
                                        SHA-256:51E05999A1C9F17DF28CB474E57DD8E64BDAB824874A532C20A23766A01F8967
                                        SHA-512:E509255519D4E521E82332FF418DD5A6BBBC8476399A0D9C3D81542C1CABA535B2D79E5BC90F73F9EE8468643302137671934ABD600FC696F16161C91FEAC111
                                        Malicious:false
                                        Preview:.PNG........IHDR...(...o.....>.c.....PLTE................................................................................................................................................................................................a.o.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.Y.. ..........}%.../].`<..y....V...m.....<....)..;Ki..'9...2.:.c...t..V..d.t;-y.Z.=K>B.."{Lj.~G..|..ENC.!Sw,....";.p..g....E.B..S.-...k..P."..E......l[./D.-.....Q+.G<>.+..b...#..y(...{a.M..J...<....v.W..F.qm.`.....(.mk.nX....l.Px8.0\Z....7G...$*.....&..Z.VJ.~......J.2|...2H..../...=.)q....ZT" .,%..h.p....Z$.!........r...Hh.f. ....P .d..1d....2.3h....;.A.... ....d..g4...A..^.....2.ew..."h...y/..j.h..B.......%.2.%..{r...+dG.=9h....P1...A...c...^h.]Q0.8x....q .!3....ZW"Z.!3...G.vC.GG..".&..X!3.|xB..V.P!.+zS..NX!3.....Nh.y(.Z.1.h..B...Z+....l8Xcu.B...K...@U..@Q...mB...x...&L C....mB.....@kC...Y.,.... ..e\F.B..........y..e\..:$(....Z.a...yn...f..z.~Q.{o...].ln.r....^.@.{..c.7..{...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.346767481124215
                                        Encrypted:false
                                        SSDEEP:48:H8LsQOfMGMntCDE+YlLnXN29+boxrdQqrrkQBXjCL9kxgR:UsbMDn6EplLXN29+bwRQyoQMUg
                                        MD5:D9646ACC0911E17480822280D69429D5
                                        SHA1:87D3E44547506F06E29BC86949084009551B22CC
                                        SHA-256:BF900668B2F33F977ACAA62E467CDA5C1A4DF72E288B19EF6624174EC4995E32
                                        SHA-512:CD149B0405FF5A09C0493FDE16836B8630AD43759118C1D45EA89CA75BC646FAC5C61B31256C82A57AF23E563E9DFEB046B851BA8A17764A6C42261A1D1E5CFD
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..O.......O..`4...O..l.t..O..`4...O..l.t..O..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............dV..XT.$QR.0KSC....N...^...............k.(..#.L.......`........f........................................I.qk..B.....LZ.............dV..XT.$QR.0KSC.........dV..XT.$QR.0KSC...........O.......O.......O...........................................Oj......OT.]....O.......O..B....OH......O..B....O..>.)..O..J...................;........4...4...4.."................O...O...O..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........O.......O....#..O............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40035
                                        Entropy (8bit):7.360144465307449
                                        Encrypted:false
                                        SSDEEP:768:MQhziQo1RKGlyyzYjlxuxwRUj/BN837xRmwH2uDTCn8qXFQziN:ThzrSzalg6O563l4uTC8q1Ig
                                        MD5:B1DDD365D87605F96D72042CB56572F6
                                        SHA1:ADF71DAD1A62B8A58A657C2EDBDD665A19EB846B
                                        SHA-256:06E09DE80C3F32254DA4FE6B2CBAD7C05EF144DD54B8C65745E195BBF7317A2E
                                        SHA-512:9C686092CC9524F34EA6CEC9AAE936A6225BCC54DE38DE1786EBA8F532959A80FF885E8664A09E4C318D7CA4B278E807D3D1F135BE55F30979B844FF5EC9699A
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!1....AQ.aq.....".3.5...2B#s.$%..Rr.CS4&6...bE'7.c.DTtU...d.eu...VFfv.Gw.....Wg......................!...1AQaq........"2..4..Rbr#3$...B.s5Cc.S%.D............?..^.f....R*.N{.{f.....O.r.V.;U..~...U.(..>M._.yI.{8,..^.t...s`...j.O..U5t.&&..h.G.6Da.;.....J.......E..QD...C...}..N...tR.....~..].J:.V$.*.r......]...W......4.[.)6..Y_.....4...........m._'HR.a......]U=.....n...0.W..]..K..){.+...w...f...<|..1/.|.....b..-..y....]U#Ctn.7m.._.|..2I;|....tM....q.q.}.N)....'...9&...nR...R..}.........m._.LZ}u.../K....9.~..?.{....V.#..dx.Zk.:=..:.j].....E#....E~w%....J..[S..[......gr...vb.r]..<..ut..i...[P.w....:..Gkn>......#..m...9km`......t).up.....w....VOR.{&.nQI..}...wD.7Ey#n....MO.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.619385888008212
                                        Encrypted:false
                                        SSDEEP:96:Mq7quswmDtkE3/aXqLI9KOfsRQypqkN5b:Mq7quswmD3/aXqLI9KOfsRJp
                                        MD5:DF3CD12824C1F296878681F0B475F90B
                                        SHA1:6ED2A8FCEAB914F3F353FF87BD9AF0E939C7FADD
                                        SHA-256:E4BE80B1B9E06571552E651D9F3C4A15662B7BA3266B134D62CDF7CC856E2D2D
                                        SHA-512:48C2C6755D2090C28694851E824A5988B42403538105329C58D921CA85FF9A63F7A8A683366E18A9CA1126C05EDD3049C11A8E613754A3CEB3CC1CC7BDFA286C
                                        Malicious:false
                                        Preview:2...>...........v...~...................................................................................................................................2...>...f.......v................................I.......I.qk..B.....LZ............tV$...$1.......tV$...$1........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............T....(.?".?y.W{....N...^...............].sm...D...A...........f...................................:....I.qk..B.....LZ............T....(.?".?y.W{........T....(.?".?y.W{........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
                                        Category:dropped
                                        Size (bytes):242903
                                        Entropy (8bit):7.944495275553473
                                        Encrypted:false
                                        SSDEEP:6144:YVxOYlZX2kCWfYoFMXC/sBFC9r+4iEGM4rrcPoWmwkU6FJ:+OwZ2kbFMC/L99ifvokU6/
                                        MD5:C594A4AA7234EF91E6C2714CFE1410F1
                                        SHA1:C0F720D4CE3196852814D0B7347F0CAA0C6FD526
                                        SHA-256:10C833E47BE1C8496F949A6B059C2D79212A4DD66BDE62116EA337FA4FE0B654
                                        SHA-512:7313F6545A334F9E2DE5430B2DB5C419C4C8A40E075338DAFCD74970BCC6309786946E5DFB57531612BF4C6269495655706D920FD99922FDACFF9796710DA9C0
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:10:32.............................R.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...v&.F;-v;}FH..Z...N..)Y.......h;C....G.0W..ww...MI..Z+..\.........c..4.1.~.Yo.Y6.&. q...............l.A#.~s?yYg..7ky...r
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.327510964666234
                                        Encrypted:false
                                        SSDEEP:48:YuO/sWxchPPjgauSLtAHjeAxEXMRLYLXGrL9+volrdQqruVWTBXvRkP4aeUO5F:YZ/sWazLqH3EXMRIXGP9+vcRQyuV8B
                                        MD5:A6C4B47A106F3200403A98DC460C4C31
                                        SHA1:79E339D9850522DADB4BB3B696184D48C03F5C7D
                                        SHA-256:FFF14FCBDD0A7BA3CCB8E26198B5C4307230638E64375F12D08FA1298623A4AA
                                        SHA-512:B78D74FC94BA700C3CFB90BEA7C0B888F31CF749CF049CC4398A64753F622DBEABA8657E8F7F8722B789C1409990008E04E112318D385CCD19698737296E3A77
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZp{......p{....b..Y<rt..1p{....b..Y<rt..1p{...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................p...?.H.]......N...^...............{%.o...A.c.!}.........f........................................I.qk..B.....LZ...............p...?.H.].............p...?.H.]...........p{......p{......p{..........................................p{.j....p{.T.]..p{......p{...B..p{.H....p{...B..p{...>.)p{...J...................;........4...4...4.."..............p{..p{..p{...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........p{......p{.....#p{.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
                                        Category:dropped
                                        Size (bytes):70028
                                        Entropy (8bit):7.742089280742944
                                        Encrypted:false
                                        SSDEEP:1536:ub4bgbB7g9cKCmSzaNF0jAdAzQKTEFBQqUp/i0yG1pidLHTVX:ub4bIB7Qg2OjbzjgWp/i0yGCZx
                                        MD5:EC7811912ACA47F6AEB912469761D70D
                                        SHA1:C759BC2D908705D599B03BDB366C951B11F99A4E
                                        SHA-256:FBB4573E3BEE1B337077691BEBAE15D6FAC52432405D31396D526D7694A8283D
                                        SHA-512:881828150993A8C56E36CDA2051D89C1F6E0322643902C9506392C163E8734A2933A46486F40E5BC8C8D0164E180605E52620EF22FE14540AEA787A38B22E98E
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....7Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:12:29.............................V.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................}.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....H.yM..? .Z.. .^.x..p.8.A...K.... .\{..)..y....t..=.^y)..v.@.W>. .h.. ..p.:.\)(.$....$.I).....!....E..Z.....&.5.).
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.357678780996109
                                        Encrypted:false
                                        SSDEEP:48:2sUsHGH/tCq8E5VLPCX0S9yWoFrdQqrASFBXkEsVGYBkFsXvTh:2shG/4/E5VWXb9yW8RQyVTsc+kFsXvT
                                        MD5:0A018365B0DBC5533E98D3C8222E56FC
                                        SHA1:8AEE9B5827DD84B4247678629054BB6CC33D8661
                                        SHA-256:62A3B83741E01195624D11B3A0C417B4F9B1C27A1FF1C30831047ED51D82A5CA
                                        SHA-512:C0F78BCF41398CD609E5F2D3ACA46D7D3AEE46BFF2FB8ADBFB9C970C942DD2B23BBB8FF1B8026F0674FF4C399432E0D6DE3D349777E89B5740EB5C9919250161
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ%......%...Qv.:3KS.N|%...Qv.:3KS.N|%...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............2..->....{....i....N...^................\....J..k. ..Y........f........................................I.qk..B.....LZ............2..->....{....i........2..->....{....i.........%......%......%..........................................%.j....%.T.]..%......%...B..%.H....%...B..%...>.)%...J...................;........4...4...4.."..............%..%..%...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........%......%.....#%.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                        Category:dropped
                                        Size (bytes):24268
                                        Entropy (8bit):6.946124661664625
                                        Encrypted:false
                                        SSDEEP:384:d2wiieoHTRh5a1HAteZCWOZIM+L7WhNjYn:8wHFHJ+/OZIKhNO
                                        MD5:3CD906D179F59DDFA112510C7E996351
                                        SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                        SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                        SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.339808951787543
                                        Encrypted:false
                                        SSDEEP:96:CsgIIiruQVK/EjKXuZK9+ncRQyfVNzwo:CsIirlKsjKXuZK9+ncRJtNz
                                        MD5:82D256048A60C0518EC016253C902782
                                        SHA1:0CDD2E71793EE37BA45E4D8DDC3367A5DDF4D555
                                        SHA-256:EE3B88A4C61AD7ADEEC6B570AD39FB0FCBFF042F959A206E3464FCA304998E64
                                        SHA-512:29DCC127E7AF10680339C4DD7AF758B0F29039C21C3EE847EF6F7173F5BC31A7299211C52B4A5F646B0558B32F618AB5BFF47702CDD316EAAE59C4325DC4D800
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ>w......>w......'.2.U...>w......'.2.U...>w...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................SW...6...'F......N...^...............+7:..j.E..=.sD2........f........................................I.qk..B.....LZ...............SW...6...'F.............SW...6...'F...........>w......>w......>w..........................................>w.j....>w.T.]..>w......>w...B..>w.H....>w...B..>w...>.)>w...J...................;........4...4...4.."..............>w..>w..>w...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........>w......>w.....#>w.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):47294
                                        Entropy (8bit):7.497888607667405
                                        Encrypted:false
                                        SSDEEP:768:aQ10VrIBdBvDpQrQ7P9/FUOLG2vTSeG9lkCsMKzXeMBk3CBp:aC0JIBL+QsOLG2+ZAC1KqM2I
                                        MD5:7A450E086AD14BA7D89BA5DB3D3AE6C7
                                        SHA1:E7AEAFCFCE476390E18C19456BDF6529D863D518
                                        SHA-256:BDD997068701ED3A00A224EB694B003C01AC69B857FE7B4147D6C34875B1632B
                                        SHA-512:9B6D50A6CDB6081DA107A2CDDB1BD2811A5764994C8E3F67D56CA81084BE0D068C27435154E867199F38688EA65E8DE02A56DCAC47D0F5E55F0FBB6598814938
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..A..Qa"..q..2.......B#...R%.r...$&b...3Ss.4dU6F.cE..'GC..t..5eufW......................!.1..AQ.aq..".....2BR......r.#3.d...b..Ccs.t......$4T...SD%5Ue&Vf............?..M.7(..).:.a.q.......>..[:O...afQ.uCO..U.....go.l..p..YqVklQ.{i.w&.]Z.\+JQw._.n.'.h..,.bj..X.].k&.Q.>gU..f...1|....[...jQ.%Zb.......t..........*..V..j.6....Vj..i.....?...IY.P.....$.j........[l.....S.4.J9.U\.......7I..[..=*N5....xW..../...=?n....uG.D..S.>...8..3........n.S....]k.*...4.>.R.o..{..l.H.#.^....<amG.m&.......,....wDY.W.m.X....We.IR.Nu...y..Z.l.._S.mr.m...y.]m.R.MT...6.5.5}.K..#%..k].7.Y.q]...%.r.7.R^jR..z.K.T[t.a..d.)glW.r.v,.`....O..^..o:.Uc.\..D....f..D......yt.Q...Y.....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.489751321940057
                                        Encrypted:false
                                        SSDEEP:48:IYEsgK+rL9Fpjt1xEwL5hFLQUXFU9OloxrdQqr8te/BXLxqksLen4yUS1:IYEsuFpj5Ew1JXe9OlgRQyfX
                                        MD5:683B1DA1639DC89DF3EF6074688ECB92
                                        SHA1:6C4654559B1B41EACD89A797F50D4E312FFB9FF1
                                        SHA-256:76160F99D2272DF1B5B39FACED0889E6E581FD38B8C590323E4FE869035E75A9
                                        SHA-512:2FC671F3DA343EEB25C541AB900F1F0E453D5EC83CBE9C85B3496757802DBFF00337E557740574B4C1E78027BEFCF510380FC085DBDE28468007F8343474FE50
                                        Malicious:false
                                        Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.sJ......sJ1.o..5..Z@7C..sJ1.o..5..Z@7C..sJ..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................\{.3.7"$...*!....N...^.................k..9.O...<...4........f........................................I.qk..B.....LZ...............\{.3.7"$...*!...........\{.3.7"$...*!..........sJ......sJ......sJ..........................................sJj.....sJT.]...sJ......sJ..B...sJH.....sJ..B...sJ..>.).sJ..J...................;........4...4...4.."...............sJ..sJ..sJ..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........sJ......sJ....#.sJ............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 60 x 336, 4-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):347
                                        Entropy (8bit):6.85024426015615
                                        Encrypted:false
                                        SSDEEP:6:6v/lhPtnlx/QulkWNY2V18A6Akp7eee1VDjMHCyLezyKUX5Gp:6v/7RrIubiA6AkpNhiyKe+
                                        MD5:78762C169F8B104CB57DFF5A1669D2DF
                                        SHA1:9638B71B584CD636834016A635ABF8D9C0887711
                                        SHA-256:E64FDCD0B108737D8B8F7B677029F924031D6BBAA50585D9C3DEF7C7E92ECAF2
                                        SHA-512:5ED899AAF73B72DEC32E171FFA112382667D5BF3FBA98C92E313E66C0A6975EA97068F4CD32B62283F18DBD5345C11E3610F7EEAC2F2DE71FC44593180B9CEAC
                                        Malicious:false
                                        Preview:.PNG........IHDR...<...P.............PLTE......................=l......bKGD....H....cmPPJCmp0712....Om......IDATh......@..aI...B..C..l...^.%.`....>.]..|0.....a...hb...0......q.......p"....;...K..x=...p...y.yy~J....|...\.......y..X.......'...>1...Ky..f....&........N`..f0..b...3.......`Z.3..3.....o.......4.&........SV...4.....IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341277387111535
                                        Encrypted:false
                                        SSDEEP:96:8srENjO0B8wEeXc90zRgRQy8ywNj0JMug:8s4A0B6eXc9aRgRJzw
                                        MD5:C0628DC1809AD21A2711C1CB6EFCFC78
                                        SHA1:E71B6DFF24950D8B342CEB00DF5BEACE620A982C
                                        SHA-256:94C1367394825A84612E74F31FE67A0E517DBA55B72F22A31477741C1146DDDD
                                        SHA-512:D622B95D9C28A6C7A2799164A30646C5B048702E65E5D73E7596E43AB2C93B7616A90AE17749EC11F048E94EB548361B62D65C627D6BE4657F2C9ED44A12A99C
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ...........oyX..4..z......oyX..4..z........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............`.p./..K....k.....N...^................3.!..&N....C..........f........................................I.qk..B.....LZ..............`.p./..K....k...........`.p./..K....k.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 617, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):827
                                        Entropy (8bit):7.23139555596658
                                        Encrypted:false
                                        SSDEEP:12:6v/7Hs2NwBW1mtjeSfaTHHy05riYUtr8y8PQvPYzzg979Reip0QPqc:oOsotazy4rStr8y8PQIzWea0Qv
                                        MD5:3E675D61F588462FB452342B14BCF9C0
                                        SHA1:86B62019BC3C5BE48B654256B5D10293FC8C842A
                                        SHA-256:639EADAD468B6B32B9124B1F4395A8DA3027FF7258D102173BA070AE2ED541AE
                                        SHA-512:E6EA855B642ED36FA82F8E469A826DC57EB0C36E307045FF8D166F67AF9242C87840833BE31FBE4706DC54100E999D6A3D3A78D0633A3114735818874AD34758
                                        Malicious:false
                                        Preview:.PNG........IHDR...(...i..........`PLTE...................................................................................................bKGD....H....cmPPJCmp0712....H.s....qIDATx^...0.Cg.;......@j..2c.=~KP.[H~..@..8...?U.g.n.a=.=.).....3..u^(.....L....5..........8.}..T.f.n.a=.=.).....3..u^(.....L..r....s..8.....W]....,..9..G?.a..`c.z...E.p...)Y.P.....#....@9.7].....,..9..G?.a..`c.z...E.p...)Y.P...`b....0.b.+~{.Pu...1..<..0._.l.@O.y.(...V3%..J....s... .(g.+.qyWu...1..<..0._.l.@O.y.(...V3%...%R.L.Q..x..R.<t.o......7.............:/.E..j.da@i..`b..Z......u.>.?...7.............:/.E..j.da@.Dj..9.W....s. .....:.......L...">w..7... .....:..."...L..."..a....D..Ya.l....E.{.@&.|.._...7..D..Ya.l.....{.@&.|....0.J.."z.0s..s....=g ..>........"z.0s..s....=g ..>..l..1...y..g......IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.32289491883179
                                        Encrypted:false
                                        SSDEEP:96:Ss/ItXGBSwIKpEXn4Xh6k9p8/cRQysptOQE:Ss/IhGBSNKWXn4Xh6k9O/cRJKtO
                                        MD5:E4831ED47858C316BCADC47A4B9CE928
                                        SHA1:05B833F6D5B2B7804C5B47BD04C83BA5A7484EDA
                                        SHA-256:97BEC01C77F970EE1C39A10040D62D482A7185DF54846B0875A1629004A448B5
                                        SHA-512:523A168520FE0BF95CC7927089161E415FB578A764F4745DCBB5FC9B12EDF0E6B58608ACCCDAB02B17675D0975FAE5AF0FF8C66D474A83FD2DAAB508FD4F24D7
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.k.......k.w........Gj.m.k.w........Gj.m.k...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............._....;..+C.2.?m.....N...^...............8...aFB...jc..[........f........................................I.qk..B.....LZ............_....;..+C.2.?m........._....;..+C.2.?m...........k.......k.......k...........................................k.j.....k.T.]...k.......k...B...k.H.....k...B...k...>.).k...J...................;........4...4...4.."...............k...k...k...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........k.......k.....#.k.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 600, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):4410
                                        Entropy (8bit):7.857636973514526
                                        Encrypted:false
                                        SSDEEP:96:E/pQuIhKZ7u06dICH3AroiTe8DGTl55poBUmLNjpH7MvDHjfm:MpdZtPbknnRPpkLNVMvu
                                        MD5:2494381A1ACDC83843B912CFCDE5643B
                                        SHA1:98F9D1CC140076D1AE5A9EA19F47658FD5DF0D66
                                        SHA-256:5EEBE803E434A845D19BC600DF3C75E98BB69BD0DE473CEEC410D1B3A9154E28
                                        SHA-512:0E64CC3723DC41D94910F7ADFB6A0DFB5049350FD15A873695614E4A89ABD78B166BA4E9C8CB95E275FB56981539DECD2A7F28FBC25E80DD5E2DEA8077CC9489
                                        Malicious:false
                                        Preview:.PNG........IHDR...2...X.......E.....PLTE...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................B..(....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.].\TU.?3"...(..L........q.Q...H.*j......W..Xd.ie.f..%.XT...em..m.m.vkik...>.}..}|..{'.U..~......}....s.............,CVu.x.:C..5...;.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.339966257634038
                                        Encrypted:false
                                        SSDEEP:48:YuN3D1DOsB8Vv2pQdWtOtEZUncf0L5X6w9u5oXRrdQqr59qABXZd+LG4f+DwE9+K:YElOsodWEEZnf0tXR9u5iRRQynr
                                        MD5:9241EFBBCE2AC30A2C3637A66F630419
                                        SHA1:9DA10E9009ADF5C48A222BB85852E639088EF950
                                        SHA-256:9CD7CDAE4FD5D974C15E65C0725AD39E44E0E79F2B9A17047C729B64E4DDF8D5
                                        SHA-512:57F9A795F9BE1EC1AA52B1817DC16643DE4D69917B65484EBCB682B9E5E7B63B369ED853B9A38732CECD9AA12437526F9C986B3B22046DD929B2BF6D76725FAB
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..M.......M6.fY.!#..l.l...M6.fY.!#..l.l...M..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................................N...^.................>...D.x..n..........f........................................I.qk..B.....LZ.............................................................M.......M.......M...........................................Mj......MT.]....M.......M..B....MH......M..B....M..>.)..M..J...................;........4...4...4.."................M...M...M..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........M.......M....#..M............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):136726
                                        Entropy (8bit):7.973487854173386
                                        Encrypted:false
                                        SSDEEP:3072:SIXmy5Tl704vW2ZKkvV8UU0ZWUF0BJwySIdgz816YzDc1+opecYPn:Sny5Tl704fZFV8UU6LGXwyS4xohpQPn
                                        MD5:4A2472AC2A9434E35701362D1C56EDDF
                                        SHA1:16FA2EA2D2808D75445896E03B67A93000EEDDD8
                                        SHA-256:505F731CB7707EFAB2EB06685B392DC7E59265A40B55AAE43E5DC15C0A86CBA4
                                        SHA-512:5E28D8FB2AC62ED270968072A30013334461F7CAE96058AF9EAA6E10912989DC47112D2133892BF61F7A516B77C6FF71BA2A000B750A9F95C787E538B09595C2
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQaq".....2B....R#..b3...r...C$...X.....Sc...9.%'.(Hs4Dgw..T..5GW.x.)......................!.1..AQa"2.q.......B..#c........b6.Rr.3s$.&..S...C4.%5............?.........(......(......(......(......(......(......(......(.G/.GE&...)..P.x..B.({i2Y;.z?G...Yfc.)H..^....#.....}3..Sc^.H..+...M.a.P.....GS.....H_.3..<....1f........1.<.\..nn-..s.s.\9Y....=.......S.0.......N..cA..Io..r.3..........ay.....K.....,.;9..Q......xO.Fa.2..>........{4k.....|....?U....3.8..._/3....#.. t.y......yY.......e.<........#.....B.....Z.%.Y..S.ye.W4...l.......X...%.@y}>....l.yi..D..W......L..._D.Q....)...E....n.%...*..K.4#.8`..I....h..h.o..I......-...hB...3..u.(5..........n...,.@....a.t.9.....@.s.>.&...@
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.329037490799956
                                        Encrypted:false
                                        SSDEEP:48:ysl3IpMxf08vt8sFEKHLujpX/Vp9axDo9rdQqrS08BXdZvX19N:ysEMxrv+wEKHaXz9a1sRQyUNl9
                                        MD5:8128D1B6B861B0292E2B8B3927C21313
                                        SHA1:A4FA99E22C9C751E0666C4577414744F76B33CAA
                                        SHA-256:513A5A29029936EDE8CE6B81BF8711F20D6EFD9CA6FAEF3557ACA12E5AEE85E1
                                        SHA-512:CDA20594E4F27CB80F39A5965DC1D416720C7E75DFA49114269CC656882B6E88EF948F376F2918E5D75DB236F6DA77E2155CB29115A257C2E290B327EF10234F
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.B.......B..O.....z.'OM..B..O.....z.'OM..B...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............k..Ni[.!C..dG.....N...^...............o.n4. ML.R....U.........f........................................I.qk..B.....LZ.............k..Ni[.!C..dG..........k..Ni[.!C..dG...........B.......B.......B...........................................B.j.....B.T.]...B.......B...B...B.H.....B...B...B...>.).B...J...................;........4...4...4.."...............B...B...B...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........B.......B.....#.B.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 77 x 627, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):5136
                                        Entropy (8bit):7.622045262603241
                                        Encrypted:false
                                        SSDEEP:96:djzuNKb3XHco17p2wolIxIx7lpskdsC/ddWNKeabJbMojpxLDTu1:VzuNKb397pwlIxKp7qs3bJb5FBTw
                                        MD5:FA38AFA965141EA3F17863EE8DCCDE61
                                        SHA1:2B4611E651AF7549C1AA73932B1136B561A7602F
                                        SHA-256:E1CB1A0EC9BE62D5445C73AA84DF38234002A7E164EE830C9DF24997802CB5D2
                                        SHA-512:A372674F5CA343321BA9C413D346070709F7685706C9C6C3DC7F61846B59253A5E6FE800DBA10AE870FD3887439B2AA106FBBB51751E92A163938A4393C43E28
                                        Malicious:false
                                        Preview:.PNG........IHDR...M...s.....}8nv....PLTE.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................z`.....tRNS...................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.442198019387247
                                        Encrypted:false
                                        SSDEEP:48:zWOnsueAHtR3TUhVatitEByXiV9MthoBrdQqryFaTCBXps2QtR43ARk6Od:tsaTUhVaMEcX89Mth4RQyy9IO
                                        MD5:F636E82313C0F5E0F97D915FF1542D59
                                        SHA1:E6EF0C41F0A119F05D7B56BAF188408E1ED396F8
                                        SHA-256:84FE02DD912659FA3B7961FCFFDA6DB7B431F15F5DAC49CFFE1D0250926A7DD1
                                        SHA-512:3221AAFDA16369C6BDB295A39DEA2536FD1E1C66763F7DC0ED1BD73DE105B727921828EC824E309AA1450AACE6FD7BA9D326D335478104121DB5CBEEADFACD03
                                        Malicious:false
                                        Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZ..|.......|&.............|&.............|..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................g6.9.|...H(....N...^...............:....<QH..k..C.~........f........................................I.qk..B.....LZ................g6.9.|...H(............g6.9.|...H(...........|.......|.......|...........................................|j......|T.]....|.......|..B....|H......|..B....|..>.)..|..J...................;........4...4...4.."................|...|...|..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........|.......|....#..|............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):52945
                                        Entropy (8bit):7.6490972666456765
                                        Encrypted:false
                                        SSDEEP:768:cjvqR0XvFaGCTJffi0tgybmWDoTw71kHUAnjvawrlp2+NUO8dWSNl3PF2PjK/q09:cyRffflgybmWoTw1UUADHUbU21MjpAD
                                        MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                        SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                        SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                        SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.414952670473202
                                        Encrypted:false
                                        SSDEEP:96:JskgVgYgRzPGkmEbtrcXwFrc9+ERRy537yLgYgqyghgHgMJ:JsVWJRzOkDbmXw+9+ERRy537yUJqTSA
                                        MD5:8A3E19B900561A439E35FFFA6E2DFC4B
                                        SHA1:F7F471E802967A980552F526AC36803175826FFC
                                        SHA-256:C0EFFECF2E49B3B99FDAF31F9408019D3A650852A45A868274DEE759B0C4106E
                                        SHA-512:27B0A1C2F739988296959F62CFB6F1E3D82BC77D8BF31869D1DA7DED75B3D8B96AF1D521E1EC23217141B7E021846BEAFBB891225FF82211E9693AE4ACDDC410
                                        Malicious:false
                                        Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZ.=......=O....(ha.R..<.=O....(ha.R..<.=..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............... X.i.............N...^...............3.M>.$.G....#..........f........................................I.qk..B.....LZ.............. X.i................... X.i...................=......=......=..........................................=j.....=T.]...=......=..B...=H.....=..B...=..>.).=..J...................;........4...4...4.."...............=..=..=..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........=......=....#.=............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):79656
                                        Entropy (8bit):7.966459570826366
                                        Encrypted:false
                                        SSDEEP:1536:2kuUliOeU4os8ii3nF3Hxro/qxXD9u/kjYgMZqoEs6ZUldm:3uUsOXYIAixR2k7WAZV
                                        MD5:39FF3ACAE544EAC172B1269F825B9E9F
                                        SHA1:2D40DE8D90BD21D56314D3F99CEF4FBAE3712C0F
                                        SHA-256:70475431CCA3C91A4EFA3B8F04864371D2D3A45696674A1A0562FE9CD8DB287C
                                        SHA-512:3B9F3B32696AB7779864E83DC0C45960114A130BEE0CF4D0643DE57FF952171E5D775AA49141EE31A28A9B5D052B26EB421F26EA736D7EF4B3A7EC812CA411CB
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1A.Qa"..q.....2#..BRb..r3$.Cc..Ss.4...D%5&..T...'7....................!1.A..Q.aq..."2.....B3.r.#..R...bc$4..D.s%............?..Y..T.o.\......=.a..j..'^..s..[../........Y.......<...(..4.....7y..Ln.[9.cK.ilN...u@$.V.9.V?3..s.KL.z..w.jW.C.............@.~+.o?o8...k....,.m..9.".....q.....d....z.W...q...~...'..e..>..f#...S.....F....pU.......7..N.vfK......S..G.#.....}.c.........RXt.bq1.`.....[+8\.*.N..:......}.....r..........')......Na...&...m......c...a4_%d.............co..0.n.L.Q..E.Lt..y.|..F..4.i(>.._..\.eNL8..?z9I:hLgC.@.p....g.t......'.I!d..?1f..R..........|..4.wJ*..%g..~0bt.....*...v.......O...:.~.>~..o.x...9.@>...s.&.E.0/G.c..t.<..F.t.A.z. ......;.........Gp.P
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.475781649136731
                                        Encrypted:false
                                        SSDEEP:48:yzxslqjGGbV05do3BI+tvueUEWnyqlfZXy7dZ9787oYsrdqr2x8ZJRXw0DbSgtLf:yzxs1o3BI+TUEcXy7T9787rsRy2cucX
                                        MD5:24464CE1EB17464DB9BC2868A54E99C4
                                        SHA1:C9C6D3CC8A97FBEC7510D076508C74DE796B2A29
                                        SHA-256:8AFACDA5807100722B925292EC077F86EB5B9D457E0A20CE5671B991617955C6
                                        SHA-512:D68FA68C197DCB8867A1C5B3C8FE27552B72CB2F48A6E8AF9A2602571D704809D04D5D653B93DBCACC599186FBA84FBCA70B0872166C39E6FC303CAB280A3827
                                        Malicious:false
                                        Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ............z....!.........z....!........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...................G.+.8m........N...^...............m.../..M..n.M.b.........f................................... ....I.qk..B.....LZ..................G.+.8m..................G.+.8m........................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40884
                                        Entropy (8bit):7.545929039957292
                                        Encrypted:false
                                        SSDEEP:768:MCBOA4d+ElOXJ/3pI7cRBiL7L6qERqGz65WXzZqJsKQSbIsTT6XB:hIAU+2cGdLX6qBG4WDZl4Ihx
                                        MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                        SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                        SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                        SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.3574538560931755
                                        Encrypted:false
                                        SSDEEP:48:YuasH4LC2EBtwk0ZWEfE+TXV3+9ksN1oVDrdqrTGeM2RXobKSnulKXB:Y9sY9EB+IE8+TX9+9TN1ARyTGURs
                                        MD5:C6AB094D451F6F1C9CD56EE62838FD91
                                        SHA1:5DCAFDC388D8091B18F7EFCFBA8C8DF32B78BEBD
                                        SHA-256:82E25B27DA07E86873B83FE3071442DF2FB0C7F96ACFBEF357BE89404EF72CB0
                                        SHA-512:A992588FEED43C15B36D13812FB3F1C9F6EDE97D0A6EBEB9E1F8F4E895E209D4482F84D5D9757B0D46E4BE868947D24845E224FEE59E3FF48B30F063E51B7AC1
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ................:..u...........:..u........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............|A..'.E..E$.Fh.....N...^....................J...M1O.4........f........................................I.qk..B.....LZ............|A..'.E..E$.Fh.........|A..'.E..E$.Fh.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                        Category:dropped
                                        Size (bytes):68633
                                        Entropy (8bit):7.709776384921022
                                        Encrypted:false
                                        SSDEEP:1536:tapXpSTJDOkFGdJdBk/slsbfsw1imaapnbvD8:U2OjJr6b07m1bvD8
                                        MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                        SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                        SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                        SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.425585822772448
                                        Encrypted:false
                                        SSDEEP:96:5VdEDs3nWOR7Eg3XbmXFX9u9n1kRyKSwKgc/:5VdKs3nWTg3rmXFX89n1kRyKSwKL
                                        MD5:94822FCAB3BAAAD3F850AADB5F8F9517
                                        SHA1:B739F09BDFB145CDC9097C644E3BDE6D0A1BE0AC
                                        SHA-256:727D0E58F0B91FB015A1680E9A4BB693F93F61DFDE669B6F840EB920405DDCFA
                                        SHA-512:D78C88D8EF6AB361044FD952C5C937AF4ABAA8404C8C379C69C5525618E788323F2B0015CAFC256731A82BEBAC04DDA2276D3856F12F1190807BB402DE9EEA3D
                                        Malicious:false
                                        Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZza......za.+.<...-...$.1za.+.<...-...$.1za...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............w....D.$'f5..?.....N...^.................h.&Q.D.e.Ap!a:........f...................................$....I.qk..B.....LZ............w....D.$'f5..?.........w....D.$'f5..?..........za......za......za..........................................za.j....za.T.]..za......za..B..za.H....za...B..za...>.)za...J...................;........4...4...4.."..............za..za..za...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........za......za.....#za.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 176 x 513, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):11043
                                        Entropy (8bit):7.96811228801767
                                        Encrypted:false
                                        SSDEEP:192:YyroOCsBI9pkCFsHHX2RE6VOlPuIqmBtJNBfAr+ADP1IATaNeTyZ4GF+WQQ6Qwq2:BUOCsB2kCGH32RiPDtDBfArPDP1I/eyM
                                        MD5:8E9AB9C28B155A66BC5C0DA5E2A4EFB5
                                        SHA1:972E61F162D48F1CEE21963ECBB2FE439105DB55
                                        SHA-256:B243A24FA13BC8523450E22F408F9EFF15301C938F8CA52A57018B58CE6785DE
                                        SHA-512:12062D69E676B3B34AFCEF25AC17B40294282D5BAB6C0110680293D7CC96EC17EBCFE104C284E64A30EE3C483E319E9C37C03F6EE82C79632180E45C7A684E8C
                                        Malicious:false
                                        Preview:.PNG........IHDR..............`....`PLTE............................................................................................... .......bKGD....H....cmPPJCmp0712....H.s...*YIDATx^.]...,.N.8.i......0..e..y.......8.6....Fo.........=...F..._..........O..{..............3.|.L.|.............>.....v..n.1J...k...."....7........J._.5LQ`..k...._Z.W.x:..k...g..._.....u<.Q{...1...q6.cs...l............30.g...< W...a.5..>O....9}..c..........s|I.).>.fo4.<q......>...c.:.u..co.#.7,.O..G./.K.|..q.p...(.(....iH.......m..+.7...../..{W.l....b....?.`^.q.9L&.>.hN2`1..m...]$.0J....rBy......{.._...G....;.r.Q..;..,...9..F...t;.+..2.Ub......V...8.k..5.........'[..s.H..).......%j._.&.....BN..V..q...T...#..........0.E&.o7....$..m..8g.f._$..k.8...5......HgQ...L..\.........)B.I.r.(..8.a..$N.9.=..o..Q..(.e.a..O.....c.= .......$0..X.S,..(p......$..l.c.I...=."......g....^..#~,&.a9iK..ZNE`...pFJ.@Wd?.<..Bt.E.......e...i.%d...}.!..B......9.........B}.....5...;..hL.D.....4z.....|.)
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.340146184390358
                                        Encrypted:false
                                        SSDEEP:48:4BsNFWzkYltA9mrEQLWuXwn9vroFrdqrPFxjRXKoiGiW9BniK9PitiGidtiLiz:Qs+kYlzrEQ9XQ9vrURydxjpp
                                        MD5:E2A0418F55E8569D1017FD6185A21F2F
                                        SHA1:1EDB6D08394C6DA656CFB8DE40E45C74B5CF6C4B
                                        SHA-256:9DCAFFF28E52DD3A34E956196E5081DCB895AA4E031F218865A5BF287BE757E0
                                        SHA-512:99B91F70D200F15EE5BA55F93974F622039654A36868604DFD01E12489D038DFA1C7FF34FB2F89095ECBE946C45F3A85F62B7A22DE1DFD7F8904B2B97818F6DB
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.&.......&......'.d.}.]..&......'.d.}.]..&...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............v...5z}.... .m5.....N...^..................Vw..O..D.5...........f........................................I.qk..B.....LZ............v...5z}.... .m5.........v...5z}.... .m5...........&.......&.......&...........................................&.j.....&.T.]...&.......&...B...&.H.....&...B...&...>.).&...J...................;........4...4...4.."...............&...&...&...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........&.......&.....#.&.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 650, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):647
                                        Entropy (8bit):6.854433034679255
                                        Encrypted:false
                                        SSDEEP:12:6v/71rwqZMXVs99W1YvpLp/Fvl+f43ocLtuplb+CrGotLRd:+wqWXVs99rpLpNvr3pIx3b
                                        MD5:DD876AA103BEC3AC83C769D768AD39FB
                                        SHA1:1833603AA9B6A7E53F9AD8A336F96CCE33088234
                                        SHA-256:1262DD23AD54E935CFA10FEB1BE56648E43BEF1116696CA71D87E6E033B1CA7D
                                        SHA-512:946DB2277213104A3B29EC4388578B05027B974A3093B4CCAD8847397AA51AE308BC6A199E5705E1F901D6E4B1BA34D8DECFD6E5B6685184A307D749D7CFAEDD
                                        Malicious:false
                                        Preview:.PNG........IHDR...(.........xk....`PLTE.........................................................................................>.S.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.)..1..7w....6.*.H`T6.ha.k.............b!....Ba..C..P.4K..@.....h.E..X....PX+.P.-.....@@"...o.O4....xZ<...B...B..,A..y.s<......b!....Ba..C..0_p. .......=..,...i. ...=.j..N...........{4+...xZ<...B....|.....$.K<.vyE..X....PX+.P.-.:... .'p......\,...i. ...=.j........K.....%J..S+.....q..k.H.@DD.s...:..J.K.DDL.\.@`,.DD.:.(]..N....KD....A M.....F..S+.....1.sq........\.t..;..../...~k...4.DD.:..]..N....KD........@DD.s...:..J.K..[...Q....V......IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341763106083594
                                        Encrypted:false
                                        SSDEEP:48:WsSCgYUTtg5EtDqEjFLwPXvR9vnolrdqrKzH5RXDCxV7VuvVqRVAV7V9gVyV6g:WsYhUE0EjF0PXp9vnkRyKT5JI
                                        MD5:3F57CF2959284701D8348BDC6A2FCAB5
                                        SHA1:76620CBF964C2EB315253CD2AE2F1C3DE733BFB9
                                        SHA-256:6E9F2CEC3AE2FBAC725DD9FC8AF73E22D70F86464D5D5747B7DB2DC0A496657D
                                        SHA-512:7CF06A4B22D82CDA232F577E66D5E9C6CF11B12560F032CBD60BA8C53FEF3593868859351DB238F1B5DD82BEC6BEA1DB242851864D0F350F942A694D92390645
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.>.......>.....)...]/...>.....)...]/...>...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............0_n...6..C...1....N...^................f..wB.C......3.........f........................................I.qk..B.....LZ..............0_n...6..C...1..........0_n...6..C...1..........>.......>.......>...........................................>.j.....>.T.]...>.......>...B...>.H.....>...B...>...>.).>...J...................;........4...4...4.."...............>...>...>...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........>.......>.....#.>.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
                                        Category:dropped
                                        Size (bytes):52912
                                        Entropy (8bit):7.679147474806877
                                        Encrypted:false
                                        SSDEEP:1536:DB/nIviNJD9C8kfJj6TkVr4q24FsUpjPc021si:DdnIvi3D9C8Cl6Dq24ayPCz
                                        MD5:1122BF4C2A42B4FA7F29D3C94954A7C9
                                        SHA1:3750077A830FE21735A43ABD35C63BA9A4D4B0DE
                                        SHA-256:423B0DD1A93B391D15B1DC8D8757C3BF5725FF2E7A59E6E3140033E2876B67F6
                                        SHA-512:4626EFE2EDED2361D6296B57F994DC434CC9D02357A8A6A67D84A544FB8A1CFE0005EA98F846AB963BED7F2B6CE96BC9181182C9459843A52A98D3A731A4FE73
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:27:10............................f.........................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....]+\.9.9.P.d..Z.?~>.-...]6=....*.......S.9G...b<$..Z..........>.v.o:.o%.e...z.F`...[.wo..z.....k..E...5....G..7.......c2..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.305012648287012
                                        Encrypted:false
                                        SSDEEP:96:esIb1p2cU34FLTEkdXWmLr9P/8Ry/G2Efl:esm1McLAkdXLr9P/8Ry/xE
                                        MD5:77F28BAB7337BF4A26933A1E5F8B1A6C
                                        SHA1:702E88EF6CC32835982223B339AD165F57A8B091
                                        SHA-256:88281E7E0FDA7B4A7FCFDF3F9A34E0A0C05D92D6DD4881AB21CDA472E5ACCB81
                                        SHA-512:CE19247A07BC77A6BD372CAB692BB1810A5C8AB935853B3D8E5CA6A6988ADAF4E37A630D30398962BFD7838B5CC09CE63D3A40893FDF04287745BE9D0B61F947
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.. ....... .~;....`.rv!^.. .~;....`.rv!^.. ..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............Wm-.....a...<.....N...^................%A.o,.I..5...%}........f........................................I.qk..B.....LZ..............Wm-.....a...<...........Wm-.....a...<............ ....... ....... ........................................... j...... T.].... ....... ..B.... H...... ..B.... ..>.).. ..J...................;........4...4...4.."................ ... ... ..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........... ....... ....#.. ............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                        Category:dropped
                                        Size (bytes):27862
                                        Entropy (8bit):7.238903610770013
                                        Encrypted:false
                                        SSDEEP:384:LTawAZvhbrXzDc6LERLQ/b5vXOl6pXQ/wD5OUMrdRUUhCplQg0ESSz:6wm/vT/b4wxoqbdUhWnSs
                                        MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                        SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                        SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                        SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.501374394288001
                                        Encrypted:false
                                        SSDEEP:48:R9+s+9xVrEmJ/MtdkE5z+ttwXyFw9FdJoFrdqr/s7RXEiN+aZX9:CsWUmJE8E5ataXyy9FdJkRy079t
                                        MD5:D65C18AAD44081AB94D2F65B0982D424
                                        SHA1:144262918B969FE71919AF4C302DE56ECB861DA3
                                        SHA-256:EFB1F7CB9470496EBACD14A3EDF7FAD3803A38385ACF201615D1AAE9AADD0246
                                        SHA-512:D17844E85F1DB1B8D2C93C45A7968E41099810BAD18C68ECFA365A9A4DB1961B8936E6B89A7F55DD67642FB533D4CAD1DC00D611E419EEA2018AFB42791E20ED
                                        Malicious:false
                                        Preview:2...>.......r...v...f...................................................................................................................................2...>...N.......v................................I.......I.qk..B.....LZ.........../.i.+.e......../.i.+.e..........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............VM.#8..._Y.......N...^...............iv.7.\.J......G.........f..................................."....I.qk..B.....LZ.............VM.#8..._Y............VM.#8..._Y...........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 556, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):977
                                        Entropy (8bit):7.231269197132181
                                        Encrypted:false
                                        SSDEEP:12:6v/7QiFJaY/z+obuqFA4fypjQSbtBK+lcqNGSbb7XTJArRRzN5DjNRkPmu5cCbR2:x0QY7xbjy9pY0JPXLTWroeuCCbX0
                                        MD5:B7F74C18002A81A578A4EE60C407A8D3
                                        SHA1:70A7D4BB1B3ADF4397D168AD0D81B286F88EBDE0
                                        SHA-256:95F59A0433050180D4C0E8858B83363D51BEA6752A8B7CA516A8677854D8F5B6
                                        SHA-512:13186A7CDCE80BCA9D2238666D6D7A989FA1887EABFA5D8A9A63EEC304DFD4BE8EFF652205FA56E1D1CEE7D3680AF8C70A952AF73AB3C246400E8D4EBECBDBA9
                                        Malicious:false
                                        Preview:.PNG........IHDR...2...,........A....PLTE...................................................................................................................................................................................$.y.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^...0.D_.......cck.....%a...X.a0Y...-..!.G...[....(.r.H.$...1 .zq.4V.e|a.6.X..4..kl.%....=w....6..TN.....{.4..T/.z...../.....3..!~..t.#b..^.....E!.SFb ...-.....^...,..C.!.b...i._c...s.X.w.. lsQH..H.gKc@@...i. ....m...;Ci....@G.; V{..lO..\.R9e$..{.....P...E.+.2.0D.B,..P...56.?......K.6..TN....^z.4..T/.z...../.....3..!~..t.]b........E!.SFb ...-.....^...,..C.!.b...i._c..Y.O...?.9k2.M.?5 .n.P...,...d._..%M?....6....,.1..R.4.a.R.+..U.Q..P...vd..T........j .]@....."..lJ../.90.4...Y. ...9.%...{......Hc%.....i..%M?aG..H....o.q.......4.......X.d9.r..CI.O.5.Ri0?.s\b....w...>/k..4V.)Y....P...vd..T........j .]@....."..lJ../.90..2..MP..l..?....K.X.....IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.313227576333751
                                        Encrypted:false
                                        SSDEEP:96:0sz1+1q1CGnSK8E3TfXY9+q2kRypU1q1iA1P1H1V1i:0soGSQjfXY9n2kRypM
                                        MD5:03AEF57C476015AA2325CF24EF0D2ADF
                                        SHA1:6754E882BB0BADA4C15DF295CA75549DC956225A
                                        SHA-256:C309C9073743E43D914DA83F472708DE7AD58A007A4EF552D02399B9AC93601D
                                        SHA-512:570F1761810535FB458336C090540E4C444C5BC9D708250C14F1F7E6247ACDB0AC06FC3BA78A7850963ECA2D69C0CB29D9FCCFB22703FDCD7749E8649AB69CB8
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ1.......1..2v.......e1..2v.......e1....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............I..u...Gl.........N...^...............l.]".2.B..u.ClM<........f........................................I.qk..B.....LZ..............I..u...Gl...............I..u...Gl..............1.......1.......1...........................................1..j....1..T.]..1.......1....B..1..H....1....B..1....>.)1....J...................;........4...4...4.."..............1...1...1....z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........1.......1......#1..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):34299
                                        Entropy (8bit):7.247541176493898
                                        Encrypted:false
                                        SSDEEP:768:BrSX4V3P8AIc4KLkHeXRUer0zrhOmXfvG0yH82I:tSXuIc4K2eBtswKsHg
                                        MD5:E9C52A7381075E4EBC59296F96C79399
                                        SHA1:BE295AD24D46E2420D7163642B658BF3234A27EA
                                        SHA-256:D56CEFE9EE2FAE72E31BDBA7DD2AA4426EA22E3CEB22EF68C8F63F9F24D5A8BC
                                        SHA-512:95CC96DD4459EBAE623176033BA204CCDC50681A768F8CBAE94C16927D140224E49D5197CAE669C83C77010C5C04C1346CF126BEF49DB686F636C5480342A77F
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.......................................................................................!.1..A..Qaq......".#4.2r3.$.%...B.5U&6....Rb.Cs.7..cDTEFVf'...S..dtevw.u.........Gg.....................!1..AQ.aq.2....."#3.4....r..BRb$CS.D............?..5..............#....v.q.m.}\..{....;...r....h.....J..q|..'.;\..6..v......e...../.k..|.8..i..|..]..3e.m....n..Z.GS..n".y..w.-...[a...7A.....i.4.)9\..~C...=.........s..\V]c.D1<./.g.l.&v..~.h..]....zb>G..y:vNS.\......LU....t.{*..Z#.?..v-...wn.rR...P.....y\=.v....../..9_...m4...V.|.+.o.#.......xj....}..>.s.>C...m.[;.>.p...=^.i.X.(..1...{.F#N.W...xi.z...4..u[{...yO.....8..}\..2...KlX.nbya...2.&.F...R.b.k.7.GV.x.h.y\.Q..O<\>......-...=...r......\......Z.Z...Jf.'....z..Y.q>.p....o..K....h..R..c.lg?......A.Z...Y.q3.L|.'5...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.32266487728465
                                        Encrypted:false
                                        SSDEEP:48:kVseVZTQxGmdt+JafkEHSFLtX+OJa69eqPxolrdqre4GRX8fdCQ/XAmD2SHd:OsTGmdWVEyFpXZh9HJcRycuqW
                                        MD5:523E414092835064E7594D937C1E75E6
                                        SHA1:5E2077F78E9E7DF1B636E10B6F9B88062D06FF00
                                        SHA-256:9803E7A42D1979CBDA3A00556485E29A6A111D67D11DFBF7EC7B5A80C2F67305
                                        SHA-512:2E284FD6FB326E5A912033BFB5CD0065F632B2C53E50594DC41FCC37B28F56A907DA184CA2FD169310CDB609F9162DAE8453B88B8BAC22C55A45D05F31EEC846
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ..r.......r...K.$I..l?....r...K.$I..l?....r..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................A\..,6:....q....N...^.....................M.r.T............f........................................I.qk..B.....LZ...............A\..,6:....q...........A\..,6:....q...........r.......r.......r...........................................rj......rT.]....r.......r..B....rH......r..B....r..>.)..r..J...................;........4...4...4.."................r...r...r..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4...........r.......r....#..r............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 171 x 552, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):10056
                                        Entropy (8bit):7.956064700093514
                                        Encrypted:false
                                        SSDEEP:192:edmu1fpj5DVHuooK4EpGLbAdT+dBXYBR8D1V2p6KwoPR6KUX9ojwRpgA:2Pp/B4LbAF+dBo/1E3S6JScpgA
                                        MD5:E1B57A8851177DD25DC05B50B904656A
                                        SHA1:96D2E31A325322F2720722973814D2CAED23D546
                                        SHA-256:2035407A0540E1C4F7934DB08BA4ADD750FCB9A62863DDD9553E7871C81A99E3
                                        SHA-512:BC7DC1201884E6DAFDC1F9D8E32656BFAEE0BB4905835E09B65299FE2D7C064B27EAA10B531F9BECF970C986E89A5FD8A0B83F508BBA34EB4E38B3F7F5FC623A
                                        Malicious:false
                                        Preview:.PNG........IHDR.......(.....!..t....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................4.....bKGD....H....cmPPJCmp0712....H.s...#.IDATx^.w`......$..B....... ....fz5..6`l\.8...Nsz{.//y./....{.7}g.....e.....~.......s...f.....%c...6....O.PJ...Y.oi...9..'j.2..6.-
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.316617889326937
                                        Encrypted:false
                                        SSDEEP:48:WshGHzlrntGSjtEXh2aLdXpTh9Lmo1rdqrQHJuRXltG5lyR:Ws+lDdEfRXr9Lm0RyQpuGy
                                        MD5:8904CB04FC42211806DD48826137F73F
                                        SHA1:45C8C003C7CADAF588CC838C7D0F1FB0744FB07A
                                        SHA-256:3832570E7551BF035EF76E1FB0983815F244AD665C997B6BF0AB911811B66535
                                        SHA-512:5FA9814122E41AF291DDAFD32C56CF233B19F2202079538F9CFF7F4043FD380A51930BA13D3039A0163DEB7B12921B46FFC5281575D8D9001B08ABCCF24C825D
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.}.......}..#...2.0.....}..#...2.0.....}...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............9w.,\...3...&9......N...^...............pO..n..@.s'o...1........f........................................I.qk..B.....LZ............9w.,\...3...&9..........9w.,\...3...&9............}.......}.......}...........................................}.j.....}.T.]...}.......}..B...}.H.....}...B...}...>.).}...J...................;........4...4...4.."...............}...}...}...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........}.......}.....#.}.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
                                        Category:dropped
                                        Size (bytes):84097
                                        Entropy (8bit):7.78862495530604
                                        Encrypted:false
                                        SSDEEP:1536:cgHTEuD99rHwA5MSadIV2MApVmfJkAKOQ/Z1I7ngpDDyHfKFVITrU:HHjXidIhApV88/jIEmrU
                                        MD5:37EED97290E8ECB46A576C84F0810568
                                        SHA1:18D9FACB4CFA3CBF63B882CABCF30B203EDF4126
                                        SHA-256:140DD943D0F0CFE6AAA98470B7D1A7CB62CA02CB1D8F522DD2AC77433232EF41
                                        SHA-512:E0F57314C136211B8253EB2AC0093DED82198E7170D4F97C40D82FD4EC4123D2AAFE3EB4EBC3E7523C4DF4D77619408773871BDE15B6DC6C4049C71D5B9D4222
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....hExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:11:38.............................A.......................................................&.(.................................2.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................z.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....b.xH......T..I...S.q.~..../s.R.x.....8.a..vE.5...-.G.A.4...._......$K..d.@NC.q....J.....>e".I.%...I0).R.I$........M3.F .
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330067472514566
                                        Encrypted:false
                                        SSDEEP:48:fsnLSCsow9E8Gt1ZEMxfscXnU+sc9feDoNrdqrxuZkoBRXBz8hvnbl:fs6u8GhEkscXU+sc9feDMRy2I
                                        MD5:49AF47D363986BC44083C58B6B9C1C38
                                        SHA1:80656E3402B03918DB889F35AF6988EA402141AD
                                        SHA-256:9B3DD57FDFAEC02464E0A36F1EFA5EE83430909DA8BEE0DF6E28FCE14BEF7439
                                        SHA-512:6F441E667718885B8E83E1C7B45F7304C05A8C3E40073575A43D25A9C726839D216023177ADFF28DF8C1E2E098CEE2873F060A943599EE4C77D2FDA6A66A4E28
                                        Malicious:false
                                        Preview:2...>.......L...v...@...................................................................................................................................2...>...(.......v...t............................^.......^...,...t..0...I.......I.qk..B.....LZ.^...,...t..0...^...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............'J5.G~B..g..F.YS....N...^...............*.....B....;..........f........................................I.qk..B.....LZ............'J5.G~B..g..F.YS........'J5.G~B..g..F.YS..........^.......^.......^...........................................^.j.....^.T.]...^.......^...B...^.H.....^...B...^...>.).^...J...................;........4...4...4.."...............^...^...^...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........^.......^.....#.^.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
                                        Category:dropped
                                        Size (bytes):64118
                                        Entropy (8bit):7.742974333356952
                                        Encrypted:false
                                        SSDEEP:1536:ORG4azGOKXzkEmR4bdRSbxONOoz0khbSb4J/5GZK5SWUlRwUYdv1M:ZXzGXzJdhRmgHfIb4J/5GZK5SWUldYdq
                                        MD5:864EEA0336F8628AE4A1ED46D4406807
                                        SHA1:CFCD7A751DFDBE52A20C03EE0C60FDFFA7A45B93
                                        SHA-256:7CE10D1EA660D2F9CF8B704F3FAB2966A4CE2627D9858D32C75D857095012098
                                        SHA-512:0CAA0C54C14571C279A75F0D5922F78A17803CF6EE1724D66819F7F5944C0F5B25CB586BB686A52808CDF2F8FEB3E4864052A914884054EF7DE44124A8CA951E
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:26:15.....................................................................................(.....................&...........s.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................#.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....NC+n....<.=.7..&.8A56..@^.Q..\\...E.>..".&G.......J .'....$.I)........0.../..mv...D....<v0=..ugc+..l.o...=.c.......x.&D..{`8...v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.34285421554775
                                        Encrypted:false
                                        SSDEEP:48:aHsFmsqQeS9GtAI+gREpnLXLL9TO9olrdqrvCTdORXeC13Z9rN:aHsc+t9GqeEpXv9TO9cRyv+IsUPr
                                        MD5:CADD3AF02CB4C8C3EB261757CA78A4B1
                                        SHA1:E3C04F174F0A531F8BF515FC89CC73DD21D293CB
                                        SHA-256:28A2FB1BEFCDAC61CE97D7CAEFD6B91AE736143B2DA1659D69CCED407E26A0C3
                                        SHA-512:0CF4B1493AD9D6473656F946E34BE76320B601B1CBAF298B5C3A9C48C17E2FDA91C3259B4298EB3605FA71C8791648332339C931DE72A30B139762BDEDA54BC5
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZp[,.....p[,!k*....l.H,.zp[,!k*....l.H,.zp[,..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............+W.x.r.!y..}.....N...^................N..<.I.ihy.i.'........f........................................I.qk..B.....LZ............+W.x.r.!y..}.........+W.x.r.!y..}..........p[,.....p[,.....p[,.........................................p[,j....p[,T.]..p[,.....p[,..B..p[,H....p[,..B..p[,..>.)p[,..J...................;........4...4...4.."..............p[,.p[,.p[,..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........p[,.....p[,....#p[,............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
                                        Category:dropped
                                        Size (bytes):65998
                                        Entropy (8bit):7.671031449942883
                                        Encrypted:false
                                        SSDEEP:1536:klZtmExaFrtWgpc+Sg+DKeplHClpHfRtPMbe:VEWWl+SNDKqlH8p/vse
                                        MD5:B4F0A040890EE6F61EF8D9E094893C9C
                                        SHA1:303BCBA1D777B03BFD99CC01A48E0BB493C93E04
                                        SHA-256:1F81DDE3B42F23F0666D92EBF14D62893B31B39D72C07AEE070EAE28C2E6980E
                                        SHA-512:8F07E4D519F2FD001006BB34F7F8274B9AF9EC55367B88D41D24E5824FCE4354FD1290CE4735E43930829702ED53F41DF02C673904A7091E9354C28E029AD4EF
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:09:29.............................a.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..-O..s(...gO..@...[..+....+...H.'m........L.......@.......[k...S..O..p.'{X..3......]W..w.+.V....[.-.....2..i..i$.p.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):3.2554236395585443
                                        Encrypted:false
                                        SSDEEP:96:qsFBsGldb+WEc4qPXhQa9TPqm72lR0zqE/2HaG:qs7sGldKcdXhQa9THYR032
                                        MD5:4EE7BBA568B24F6622BA5E59F1A3ED00
                                        SHA1:B253E6CA06EF85C83B66DA18EA7216188B182A93
                                        SHA-256:28F82A3071ADF1EBB9FCE7141F1A53BDA0CF6A608E41B33DB9955D13F5B5E90D
                                        SHA-512:25EB183466C784049D2E1E7544A4EFC18E2D95B412DFCEC6EC03DD16E2B8CC801BEEA4C44426D65DB6823C44F31D3C4166110BF557409D461F13FD68897CA638
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>...j.......v................................I.......I.qk..B.....LZ'.......'...5U...J...'...5U...J...'....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............L................N...^................W0O9..N....v..?........&...................................>....I.qk..B.....LZ.............L.....................L.....................'.......'.......'...........................................'..j....'..T.a..'.......'....D..'..H....'....N..'....?.#'....9...................;........4...4...4.."..............'...'...'....z...y.. x.. ...........$........4...*..7*..7...........Op.b..F.$..i.................;........4...4...4.........'.......'......#'..............................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330190219493002
                                        Encrypted:false
                                        SSDEEP:48:YuqsuXolcc1ZWt9PIQEya70XrPF9LUjdNrd3rNxPiRXIV/Jh:YVsYc1ZWXPFEyagXrPF9LU3RbviE
                                        MD5:E5AB213692BDF4258B8CCE93DF638E86
                                        SHA1:702206148AE5C7413E9E6377B69E07F80A8763CD
                                        SHA-256:B3B6782B341FECCA30212A9D9950BF05354480BC62216E7B354B5367BB029025
                                        SHA-512:2AB7680B92BD0C9F00B41BD1C169B3167E78FDD757FFEFBF8C22A69A52D7CA6EC925EE1E643248E4A7C65B177BDAF9EA2C6A86A3AB0750D16B712A37B2F479E9
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.........aq7....Q..z..aq7....Q..z....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............0.................N...^...................?..N.>....E.........f........................................I.qk..B.....LZ..............0.......................0.................................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):39010
                                        Entropy (8bit):7.362726513389497
                                        Encrypted:false
                                        SSDEEP:768:6tCjwO+E+KW0ZtOgepcoWW4pAWQ6/KWcR474HOAZaDfK:68j+E+KW0HOgep/72/NKWcRNefK
                                        MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                        SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                        SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                        SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.409553168787375
                                        Encrypted:false
                                        SSDEEP:96:NsEwLOlN08EvlX49utnIdRbGWUFSFL4xAij:NsEwLSNi9X49UnkRbGjFSFL4xAi
                                        MD5:061CB97501F316237C1F8FCD1D1414C4
                                        SHA1:E20FC8627F4A908E4E8A2DB9BFA6D9EC4F606D95
                                        SHA-256:57A5F485C1DB63EB6744E788F4D676463E21CD949BF793A45DC4F0FF2D02D7E1
                                        SHA-512:A6AFE563D12255A752D56EAB96E705CE8A4EDD14DF41B1D53739A73451964C2C96174EEAA4B4C7AB8F3ED838C16BC427D193FCFE52A76F0597F65F5C9D89C653
                                        Malicious:false
                                        Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZHsv.....Hsv.........;{..Hsv.........;{..Hsv..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............{..-.".0...^.|.....N...^...............Tu."e.?E....u.R.........f........................................I.qk..B.....LZ.............{..-.".0...^.|..........{..-.".0...^.|..........Hsv.....Hsv.....Hsv.........................................Hsvj....HsvT.]..Hsv.....Hsv..B..HsvH....Hsv..B..Hsv..>.)Hsv..J...................;........4...4...4.."..............Hsv.Hsv.Hsv..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........Hsv.....Hsv....#Hsv............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):25622
                                        Entropy (8bit):7.058784902089801
                                        Encrypted:false
                                        SSDEEP:384:EhK81gTCyJ/Gf9Aw3t8w8EtdPeGDh6bEi1Ie1u4ZbvgwTwrSRh7ZKNpIGY:IjcRXwdJvtdGsUbEi1IeY8vgwTyC1+Y
                                        MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                        SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                        SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                        SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.302301679478299
                                        Encrypted:false
                                        SSDEEP:48:YuSs6TkaSLzdtcJXMtJEHGKWcXRbRc9MxIzj4Vrd3rU4xOfdXgpjlZ:YNsASLzdGcHEmwXQ9k8YRbWI
                                        MD5:42EAED04FE9BA5D6E7CDA01430A2D25C
                                        SHA1:18FC73B1E85D9A130B1B81A282EC87DD0DB5A017
                                        SHA-256:6E421A6EC13AA5DA6C72D3567EAE1FB30E730D11C0F6E9A8281A70EDAAF780BD
                                        SHA-512:C8D6B8732BA3D48A6F176751D98D1238CDCF8B1A6089C5D5C7C5C89EAF660FEEF7CEC5186421D697CED44AE6D18D14BC70ED04DDFCD5A859FB80909A0843A05A
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZm......m.#.!...6...B..m.#.!...6...B..m...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............At..9.S.....k..u....N...^................D.....B..t.S.G.........f........................................I.qk..B.....LZ............At..9.S.....k..u........At..9.S.....k..u.........m......m......m..........................................m.j....m.T.]..m......m..B..m.H....m...B..m...>.)m...J...................;........4...4...4.."..............m..m..m...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........m......m.....#m.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 500, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):2033
                                        Entropy (8bit):6.8741208714657
                                        Encrypted:false
                                        SSDEEP:48:P37XYSDTz+UUl7DHt7Ah8l1+4ZfFclFUXwobKXlZr:v7j3z+UoDN0h8ugf2AwobMN
                                        MD5:CA7D2BECCBC3741D73453DCF21D846E0
                                        SHA1:E34B7788498E33FFF0CFB00125E6BA9E090F6CED
                                        SHA-256:E9EAD0BFC09D32CB366010CDFEDE1C432A2D1D550CB7332BADAC1BEE9482BC86
                                        SHA-512:7FE2C3654262B1EEBED4F6D83DA7D3450E1BE52500A3964185FC0092041506A237A2728E5D7EEA0A3814E413E822B803B789C49CF744D51816A2E4EDE5B4247B
                                        Malicious:false
                                        Preview:.PNG........IHDR...2.........H'......PLTE........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................[....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.\.W.G...=a.ewA..a.!r( ...%Dc..x.x....N.OO...3=...S...........~.z.D.0...g.2P.7.*M.#'....z.......3TPj.Z.[5....V..z'L3...a.j9..C>..9.z
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.3153533361497205
                                        Encrypted:false
                                        SSDEEP:48:ySmsIsJOKXPGtAe3EkJLeXRV9sVDj4lrd3rg/xA7KndXjVwgPJ/w0d:ySmsfl/GjE8KXRV9sVDwRbxUvwy/w0
                                        MD5:BE5884C26629DA6CC12E49DB7FB40E2D
                                        SHA1:B8F52AA852F540124BA50EEEAA528315E7FD8319
                                        SHA-256:A153363D34ABCE93F80ED05B4CCBCE88EBF704C2F9DD9A115F6AB8089C46A8C9
                                        SHA-512:CF7F3FE003C468A4B37C8DE795D87051C6EE3DDAE348F05488D559E21AFEBED0771B521CE48AFC8FEB9C9F13826DC2A070494EF27D813E96EEB2610100B14F4E
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.b2......b2.).?..T Kr..N.b2.).?..T Kr..N.b2..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............f........;l.J5s<....N...^...............^.....yB... ...`........f........................................I.qk..B.....LZ............f........;l.J5s<........f........;l.J5s<..........b2......b2......b2..........................................b2j.....b2T.]...b2......b2..B...b2H.....b2..B...b2..>.).b2..J...................;........4...4...4.."...............b2..b2..b2..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........b2......b2....#.b2............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):55804
                                        Entropy (8bit):7.433623355028275
                                        Encrypted:false
                                        SSDEEP:1536:gVvci05lhVbfBcWvBLeynluexaWqzww/u5:gVUZhHDljaHww/u5
                                        MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                        SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                        SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                        SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.433911178918189
                                        Encrypted:false
                                        SSDEEP:48:RyBsX134j114tcbZEbzbBX6ZKB961Tj4trdMrLP5dXpB6zkCDWhtw76:MsFIx14KVEbBXAKB9kTARMV969qhtw7
                                        MD5:9B667334DF0F0D05CB6052F05ED95D7F
                                        SHA1:7A1641C4386585B9AF09D7188FF343FC9FB9ACDE
                                        SHA-256:0B0B72B01B2511819FB2A12EB8268F42A4DB4593BA9B975021010613D77AAB61
                                        SHA-512:33D9666F4FA2AD28D44383604D6CBEC68EE4CE62002A55F3D618ED031B5865F85F146640C2386974150F9F34F3D1E6DC308387E2AFD4C5C34A95DD232042C477
                                        Malicious:false
                                        Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ...........f......o5.o+....f......o5.o+......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............>...e@..6....K5.....N...^.................<+...G..6.0..........f........................................I.qk..B.....LZ............>...e@..6....K5.........>...e@..6....K5.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                        Category:dropped
                                        Size (bytes):59832
                                        Entropy (8bit):7.308211468398169
                                        Encrypted:false
                                        SSDEEP:1536:HS9SYFtN0+CRa9mfJy4zBAiIJhzrkHDV2hJK:yAmta+Tyy4zBIJW5WK
                                        MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                        SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                        SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                        SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330335987274526
                                        Encrypted:false
                                        SSDEEP:96:zshXSzlWEQ3X599P4YRM+KvS/wEvobG7:zshXSNuX59R4YRM+KvS4EvyG
                                        MD5:A37101E2D7F629BA2F3823A6594EFE82
                                        SHA1:485CC5D50259026CBB68EFEE0A372DB7B751F2C2
                                        SHA-256:F00222467696B14EC4146A9A1D6D9FC30489B9771BFDF9FF31FE93E282914D17
                                        SHA-512:28961DE460D5D5B80FC69D47A602E1FA38F7CB3D12634327682D758B871AB0EDADD6956A8F943A45E43E10C28A01D9CE21A1BF40671F210449D082085724F3DD
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.m.......m.h..........m.h..........m...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............kd....(.>Q.A..G....N...^................._.U..A.Z...=Xg........H........................................I.qk..B.....LZ............kd....(.>Q.A..G........kd....(.>Q.A..G..........m.......m.......m...........................................m.j.....m.T.^...m.......m...B...m...C...m...>...m...|...m. .3...................;........4...4...4.."...............m...m...m...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........m.......m.....#.m.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):33032
                                        Entropy (8bit):2.941351060644542
                                        Encrypted:false
                                        SSDEEP:384:ofmqvnCfmqsp1Ue5xzMq+Qh0dffUmS0w5xzMq+Qh0di:AGAp1rmSl
                                        MD5:ACF4A9F470281F475EA45E113E9FB009
                                        SHA1:B20698DDA5E5AFDD86BB359A6578C9860D5DF71F
                                        SHA-256:5DC2367A80588A7518DB5014122510BF0FD784711015EF83A8718336584F82D0
                                        SHA-512:998B7DB9DB08FD15A293267E2371052E436E024AF8D34F96D3C8FF04B1316678DFC1674C921CB404121FF381A4FC39DC759E6698F19D42A6261CBD39469B0A08
                                        Malicious:false
                                        Preview:....l...........................Ac...... EMF........$...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC........................F...(.......GDIC............^...........F...........EMF+*@..$..........?...........?.........@..X...L........................."B...B...B...................?...........??.....n............;...<..@<...<...<...<...<...=...=.. =..0=..@=..P=..`=..p=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...>...>...>...>...>...>...>...>.. >..$>..(>..,>..0>..4>..8>..<>..@>..D>..H>..L>..P>..T>..X>..\>..`>..d>..h>..l>..p>..t>..x>..|>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...?...?...?...?...?...?
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12180
                                        Entropy (8bit):5.318266117301791
                                        Encrypted:false
                                        SSDEEP:96:k1bHyG/fKOOOOQJUg+g2S+kEm6alfsfsfn32:+bSG/yOOOOQ+g+gOab32
                                        MD5:5C859FF69B3A271A9AAB08DFA21E8894
                                        SHA1:3156302A7450ADFF4D1B6EC893E955D3764D4DD4
                                        SHA-256:B4A8E9A67EE0B897615AC4CCE388FFC175AB92D9E192E6875C79A4E7C1B5BB6E
                                        SHA-512:4CF518136EEBCA4F400A115D9B7BB0CAC9FA650BF910B99E15F04A259B7D3EFCFFD6796886FE09DB08C37C332B14BC8500845C09C8EAE1F2306F90E98D3C99E0
                                        Malicious:false
                                        Preview:.PNG........IHDR..............;j.....sRGB.........pHYs..........+..../9IDATx^...dW...S=.dL$.............-.`...'...x.7.D...(...$.?cO....9S]=.v...Z.......{..wNuf.&.....a.k5~...._..\.yk..v.....}{._.Q...5...._9o.n.....}7.].1v..t......q....3.<..0<.p.......0....s...... @....... @....... @....... @....... @...X.'..U-..... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%@....... @....... @....... @....... @....... @....../)m.. @....... @....... @....... @....... @....... @ ....`.)....... @....... @....... @....... @....... @....K.0.....J....... @....... @....... @....... @....... @...`.....\.... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.352878405096331
                                        Encrypted:false
                                        SSDEEP:96:1X+sC6RLOmEEqTFEsAowgXoq5y9A7FRM7v536/R2miO07x:QshOmxsAowgXxy9A7FRM7hq
                                        MD5:A7CFA7A34AB58CA1A811CCA9D21C1373
                                        SHA1:909A25CD217277179CC168581815F7D4BFFC1BD1
                                        SHA-256:0C12C4110F1D68D0C795A5A3AFB943A0014A9910AC902D2EB5A882EFBA3230FC
                                        SHA-512:D29E0BDC7BC0FE47CC1FDBE5595EB81F8F53A25BBD62CE71B3D9DDE4EE3981BE99A45200645201E6E8C4B70EA390F837CD0CFF57D2EC432D59FC3A75E3A79D03
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..?.......?.ccb....ER.....?.ccb....ER.....?..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................8U..<.L....N...^...............z....CC..+pL..Q........f........................................I.qk..B.....LZ....................8U..<.L................8U..<.L...........?.......?.......?...........................................?j......?T.]....?.......?..B....?H......?..B....?..>.)..?..J...................;........4...4...4.."................?...?...?..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4...........?.......?....#..?............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 39 x 600, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):2104
                                        Entropy (8bit):7.252780160030615
                                        Encrypted:false
                                        SSDEEP:48:2PPEOtz2P/LJtVRaqBG8qFOPvHlcEXgkuwf+j:2PZFSjJDjqFOPPlXgG+j
                                        MD5:F6C596F505504044DF1E36BA5DA3F09B
                                        SHA1:BCF17EC408899B822492B47E307DE638CC792447
                                        SHA-256:EDBB86F160050FBF1F9860276802BAE292DBFD0BC98E3EA90D43D981E9F0C54A
                                        SHA-512:E8D067A1932CED8746FE7D665EEC34EA92A98AFF3DF26FFA9DD02742DDEA3C5654124A88A649FA33DB596F96A5FC9CB2C693D03132F1C8B254ACB56DB4763BD8
                                        Malicious:false
                                        Preview:.PNG........IHDR...'...X.......:....PLTE.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................{.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^..c.%i.F...m.m.f.m.m.m{&....X...9.....M.WUW.d.N.O...E$...$...)H....n....N.k..v.....v1L[w)w.}..!...Y.X.V.D.......[....;..[..;....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.320760338598787
                                        Encrypted:false
                                        SSDEEP:48:ek0s7paERRo0thRmE2JlZ1ocX5/rqc9dsUpyRrdMrsozxHJFXmNVQ8YuCVXsAEg:ek0s/Ro0UE2scXUc9dpcRMsaJ1Q
                                        MD5:A36AF9BB2F93F24CB9DC3BC1704E2B46
                                        SHA1:B28B3EDB7BEF38E59E23380162B5CABAB2E65C04
                                        SHA-256:48FC0E8B3DE5979B4715081A6FFB55ABA8FC99524FB16CA99DDD61A3D3BAAF27
                                        SHA-512:85D8D70E99F49D2915CB9D7A0F1BE93239F146CBBB3C3AABE5E82F83933D328C8F974ECFEAD7930E2221EEF06C75C38408458FA10561CDEFBE03F9ECEE98AF76
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ".=.....".= ..N.......nc".= ..N.......nc".=..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............=D..`C...^.Z.......N...^.....................D....."[........f........................................I.qk..B.....LZ............=D..`C...^.Z...........=D..`C...^.Z............".=.....".=.....".=.........................................".=j....".=T.]..".=.....".=..B..".=H....".=..B..".=..>.)".=..J...................;........4...4...4.."..............".=.".=.".=..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........".=.....".=....#".=............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):14177
                                        Entropy (8bit):5.705782002886174
                                        Encrypted:false
                                        SSDEEP:192:EbgGcV/hlvpfal7rgYa8S7auAxwfuSTmCSNoFQ6NO7L:EbgGcVnpwimnd38FdQL
                                        MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                        SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                        SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                        SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.337798617034014
                                        Encrypted:false
                                        SSDEEP:48:Us4Tkz46U7EWtK1UEYXL7aK7XQ799nsWxpyrZrdMrlPaoFXWDrM9I4wQZLt31:UsDU4WLEQtX899nfxSZRM8oWO
                                        MD5:FD5C61EA2A81DE19A09D6CD255CA7F95
                                        SHA1:75E60A6CDA8AE9C8F2F44BD4B68A18723E40ABBF
                                        SHA-256:9BC1105C0AFC17763EA6DA7B2783CA888B3CD3F8417C67B71E79EBE13BC09E90
                                        SHA-512:206A14571551580B7089C9003A49131882066473A7AD0C878BC2244357EC311A2D189F5BF5DAC119A6AF12F839D5AAA8B659611A72368677C6DDD7B4982272CE
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ...........Va%....u._......Va%....u._........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............~...........s.y....N...^...............g..q.V.H.D.............f........................................I.qk..B.....LZ............~...........s.y........~...........s.y........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
                                        Category:dropped
                                        Size (bytes):36740
                                        Entropy (8bit):7.48266872907324
                                        Encrypted:false
                                        SSDEEP:768:3nwDxjTvoE0Rjwit4rjucDILWg7/Da0JgGQ8e1S8SA/Khos0:SxjTmZw7nucDILj77a0JgGQvScb
                                        MD5:9C205C8D770516C5AA70D31B2CA00AF3
                                        SHA1:9A1002F0CF7F92F1BE2BB25BAD61CEBFAC282482
                                        SHA-256:E111F96490755C7D71E87C88ACAEA38AFE55BB865B1A14A83C5BD239648D5E2C
                                        SHA-512:A3E105208B32831265428572B0937DD3C17B793D8611B2DA8D4939F1BEC6050999D375E3F6B87D53AD49DFA0EAE737B0141D37597AA42116C310761973D4A134
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:44:07............................c.........................................................(.....................&...........n.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d................................................................................................................................................."...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..o...4.gP.~.c...K{...V.=...].<.........vS.........s....(.t......X......kk7....~-...yF}^c.Z.\.G./.?t...>....:.>......./.ib..).
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.456100895825142
                                        Encrypted:false
                                        SSDEEP:48:DxsyVAQQ/VffdNLEUMtRKELL4ZXjD9lsJqpyBrdMrrc0XFXKs2ktQLHG0g:VsRFEVaELUXjD9l9URMrLf0
                                        MD5:D0A6087EE23F3A087272C916AA134CC8
                                        SHA1:D493CFBE2259DCF83484C58320A032D3C506F4EC
                                        SHA-256:8E9D155789AAFFA064FA4A3EEFED8315ADF00B614D88CC84861A348ED6FF3798
                                        SHA-512:95AEB6C19E84F2873E3F693BF6DD8B251D890E7EC0D2C96267FE571A924CC00CE9D7B1D75BA16E1BC80B86E7CB7F65928C2E3F22861209119DD03462A1801A63
                                        Malicious:false
                                        Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ(.......(.......+.wcI.X.(.......+.wcI.X.(....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............j.FL=.......M+.....N...^................D.../.G.iX..mH........f........................................I.qk..B.....LZ............j.FL=.......M+.........j.FL=.......M+..........(.......(.......(...........................................(..j....(..T.]..(.......(....B..(..H....(....B..(....>.)(....J...................;........4...4...4.."..............(...(...(....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........(.......(......#(..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):53259
                                        Entropy (8bit):7.651662052139301
                                        Encrypted:false
                                        SSDEEP:768:dCiCBBenRYWDBCipMYGTbYGLHbXxoP/qEF+MU50qyJ30h2W474S/Aq/xc4674bi5:dCiIQXBCiwbDLHD0/sFyVel4Pi4UgE
                                        MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                        SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                        SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                        SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330508904389015
                                        Encrypted:false
                                        SSDEEP:48:CsfHHCrkeE4v+6TSAtWSTtEXDJXGX/2m9RsVpyFrdMrBO5FXFB7rBHsohhXZ:CsToG6TSA0SREX4X/2m9R4IRMs5lhN
                                        MD5:55B1EDAB55B2AE0C7229F0185ECE6AE4
                                        SHA1:A9377AA6FEEC7CDB8A9D5B60C693E1D95B76BDCA
                                        SHA-256:1A7FBB164808E5F772C2887779C2B6774EF0C092407D4FCFEB4BD4E723670931
                                        SHA-512:382179C34A4E1E9E0851F2E6684ACB6617DED7515381B5674A728D1531DDDC3A15CCF5320926268FD2D542684E5147B93FDE178BBF505D57C6B3B55CF19919C2
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.5.......5..4.E.4 ..._D..5..4.E.4 ..._D..5...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............3_f.9...X.b.L*....N...^...............y0.i.`H.0..............f........................................I.qk..B.....LZ.............3_f.9...X.b.L*.........3_f.9...X.b.L*..........5.......5.......5...........................................5.j.....5.T.]...5.......5..B...5.H.....5...B...5...>.).5...J...................;........4...4...4.."...............5...5...5...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........5.......5.....#.5.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):60924
                                        Entropy (8bit):7.758472758205366
                                        Encrypted:false
                                        SSDEEP:1536:kU7O7+CFqO6DkxTgPzo2wqggrrX8QvN1I/ZLBttB9+dPFXbc:hVuqJDaTqo2wq1L84N1I/Z1tT9X
                                        MD5:D58C51D2CF586A5E14A9EC8529C3B0A8
                                        SHA1:F4811A353797C29B1E3F5A61B125C46E1534D587
                                        SHA-256:F927C7825851974A2149868146970706523A49165133CEE6027A43E8C9ABDF27
                                        SHA-512:34B963173AFBDF07432F4B983D29F10376E4771FE666E9D50B1A81DA0B9F6001FD86B4A08B9711386DE153BF6E03C8E932E2D181C8EAF94EFF34D20FCA7570E0
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d................................................................................................!1AQ.aq....".....2B...Rbr#.s.4...3$.5u.6v..CSc...DT..f..t..&F........................!1..A.Qaq....."2....B.s....Rbr..#4...35...CSc.$...DTdt..%..............?....O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.........................................................yK..xd...6..|%....\j..e.=...Y..f..I.|-....e...$R.j.......~.W#....{.....V.k.|F..z^..:.~..f......"x.....L..K..r../.;..[..l...;.U...W...X.........8.....y?..B...m.......j..Q.g3..G.K....GL.o..n7a..Y..[.'.........x........\......~...f...0\Wc.n?k.|.....1.ww;..2..?...r4uF.MXdB6..W..mG2NJ.E........u...2.q...Z..=(l)jU.X...U.\X.......O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.......................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.309612216371578
                                        Encrypted:false
                                        SSDEEP:48:xuBsl032TFCtoZBEJt+IBXMDB9hs0apy9rdMrbD69FXRM9Bxd:x+srFC+rEZBXMDB9h5aARMbgK
                                        MD5:DFDDD8B043F0669EBA7D3526A78344FA
                                        SHA1:D2CACBAF2DD520DE3F99B4060D810A6693B1C900
                                        SHA-256:936EA315BB4E92C3A9E7E3A569348E4AA4F1F6F5EAB4D8C8119138F5FC9A89EE
                                        SHA-512:85E5413FE0F9E8A861613B2A10B258446BAE7909CBCB6D419F8EF6C7DC7939B3FB890EBD26BBAB6A2126B937821BA62914EB05C3AF635FAAB2D70DDE02A0CFC9
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZs.......s......!M......s......!M......s....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............m.1..6.q..K......N...^...............x..f.i.O.......O........f........................................I.qk..B.....LZ..............m.1..6.q..K............m.1..6.q..K...........s.......s.......s...........................................s..j....s..T.]..s.......s....B..s..H....s....B..s....>.)s....J...................;........4...4...4.."..............s...s...s....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........s.......s......#s..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 39 x 579, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):515
                                        Entropy (8bit):6.740133870626016
                                        Encrypted:false
                                        SSDEEP:12:6v/7su2/c30mqkg9VgFHe7Ll8UmJX/N+1Zmkk8f3lbtI4:4mc38gFHe18lkk8f3lbth
                                        MD5:E96BE30D892A5412CF262FEE652921CA
                                        SHA1:8190A0BFE21D04BC6F3A406E91B87CA69C03A2DE
                                        SHA-256:0E31DA4DFCFF4A36C64C1CE940362D2309769F36369E4C43C317D5F2FA15658E
                                        SHA-512:D647F51ABBD013226A6ADD0D551D058C633F867F9AF5A9E099B85D6E291D220F7B85958B07381CD4C7C4F72356DBAFE2A86932AE398E28C56CDDF0744E92EE24
                                        Malicious:false
                                        Preview:.PNG........IHDR...'...C........b...`PLTE..................................................................................................bKGD....H....cmPPJCmp0712....H.s....9IDATx^..I..@.C..<..?mo.#C((.J}...~..B...b.I.i.\<.e.....(p.I.EO...q.x.......dRz....K..b0.:.<c.o..0.x\:...F....I&..ap....."P@....DO...q)p*..@Y.CL2)=......1.........4....._.G..^`..lDO...q...X....SL..z....K..#.L#..I6..ap.Ls.,....7&..ap.p..lI...,GO...q.....k.n1..4......3=.f.x.$..4.....o....x.$+..0.x\.,&6...............IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.36237610583704
                                        Encrypted:false
                                        SSDEEP:96:OsP1Ci65zh9EP/XJ9RkARMT66Em9JwgY9EVG3:OsP1Ci6hhaP/XJ9RkARMT66Em9GgY9qG
                                        MD5:E9BD36D9B1EEFF0963E292F180F6DD70
                                        SHA1:301D4F6ACC3968388ACF2F43433A857608FFD446
                                        SHA-256:BE1E6001FDB3EABE9658D26DD2D5DFFE667715D2761CC9D196F707133BD9378F
                                        SHA-512:123F6907E5A6FDCB7818D3B8E22556628F1C992D46674E319B2DBEE594C41A9E83E42865562E27E6AF6381570DAC7D10CCB56FC49C4839A5D2A64AEB540CBA5F
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.Yu......Yu.....>..\.I...Yu.....>..\.I...Yu..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................+..)%...^......N...^...............=b...=.O...I............f........................................I.qk..B.....LZ.................+..)%...^...............+..)%...^............Yu......Yu......Yu..........................................Yuj.....YuT.]...Yu......Yu..B...YuH.....Yu..B...Yu..>.).Yu..J...................;........4...4...4.."...............Yu..Yu..Yu..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........Yu......Yu....#.Yu............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 30 x 700, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):1547
                                        Entropy (8bit):6.4194805172468286
                                        Encrypted:false
                                        SSDEEP:24:dZeDNYbS+238CTUFPA6SXG5qSacX9q73eXu0vC3dU+OB2gbwHRuZ:dykp9FzBBacXQ3uNC3n7xuZ
                                        MD5:0BA36A74DFBF411FAB348404CCEC3348
                                        SHA1:4C619790E517416E178161028987DF1CD3B871CC
                                        SHA-256:2E7AAF26BEC32148B96442E8FFF1BD2CEF2D72630969F23B9A2ABEDB6CFEC93B
                                        SHA-512:90AF53DB7C413E2ADB970AC345F73E4ED8AF626E179C929E6560118F7A9E98DC7C5FF02B2B3F6C98D397E0FE2D85F3427C6928C328872149E176FA8A99E91F54
                                        Malicious:false
                                        Preview:.PNG........IHDR...............\....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................D......bKGD....H....cmPPJCmp0712....H.s.....IDATx^.WSTA........b.0gPPP0..E.9b@L(.c.N.U>..@......;...}..B.(....$......5..XS...I....).!....D^.uE...\..5........F."o..-...m.n. .^.....q= .
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.334969006458965
                                        Encrypted:false
                                        SSDEEP:48:SszDeeFToV6KtBmE05IMjHWXGW9xUWpyFrdMrz7FXa0eDaDpRG+6:SsXhCEKCEkWXGW9yW4RMvjQa1RG+
                                        MD5:E1D9C17844175CDF1A211C511B941D48
                                        SHA1:504912CD316420E3E2C2EC9AD9A43BE6581856E9
                                        SHA-256:D8B9023D75DB47F70C88808B89D3C705532E9DAA2957CCC1DE7613A07F54E7C7
                                        SHA-512:C6441929E064BFB7578E01BEB9DEE70D4D453616966E2A590EB7668501118611A66CCB0B2DBC4D74AD16B123DC9151061471B610CF1D8BE2F6F7A4BF62ABD0F0
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ............#s...X..*B@....#s...X..*B@.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............w.b.^......i........N...^................)...A.G.7O.y..I........f........................................I.qk..B.....LZ............w.b.^......i............w.b.^......i............................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):95763
                                        Entropy (8bit):7.931689087616878
                                        Encrypted:false
                                        SSDEEP:1536:EoES7mhTyzabUaE77xAOmq0zVruQlttNxlipxVWssMU2YhRy2v6pKKYhQzwMc2:zz7mhTyzabUa4b4xuQlttnlGx8x9h02M
                                        MD5:177DD42CA99CAA2CCBF2974221680334
                                        SHA1:35FD86B3DD082A6D4930C67BC0E05D3B5817465A
                                        SHA-256:525A857D0EDA855A64D3619DF58B1C2D013A73E60FA0D49B155ECFCB2C134C7C
                                        SHA-512:6FB6D9A6C97B1115C3246690A2F339CD612899AC25ACBA00296EAEAA0A1D094E7339D670969764FE23EB7C08FCDD01C6F78FBC0735D504D5E02AD342901719B3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!..1AQa...q......."...2..B#Rb3..r$...6..C4....Ss%5...tu.c..Dd.EU7....................!.1.AQ..aq......"r..2...4Rb#3$B.Ss............?..H..dV....U..-..0]Cp.%O.Z.Y.e.=/.q.....j76.w@s...5.&&&5...n..w..>.1....;.vR..[.......=.......KtY]u3.g18...).r....&.IZ'.....g..4kY..X..b.......y<...r1........e.._...X...w....op.m%Jr31...S.Vo.._....OI\]....F..V-....\...2j..X.....y.p.$4.....&#..]..n.V..x..P...F..C.f....])..~..Z\.....,..#..v..v...2V.k.SuaydO../[.*c._..oTV<Z.s.[...o.x..>....-....v...#....-.X..L.Z./#.XG.-.0......%w..H.@aZ....C.}...N~.;..R......5.D......I.... .R........s.>..ks....(...S...9....2=. :^.. p.+?(....$..Q..I.........=|..`2. v..t......U*.8.u.. ...'...*...2;u....& 3..$.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.362812543489661
                                        Encrypted:false
                                        SSDEEP:96:OsBz3wnQ+cXEy02Xj9SZD4RMrT+y3z6/H6OtD8:Osin1c0y1Xj9eD4RMrT+OuzB
                                        MD5:A8CDC0BF6EBC28CFAE00A73794C77CA0
                                        SHA1:5C9C57573306910151911817466DF3836C742ECD
                                        SHA-256:D98032323897D9DB19954FA2D8DA20C4F4F68F309F1A2ED1126DCF9C5A9D1469
                                        SHA-512:10B0B459669F1EBE3302A2E836B77BDD026D81658A9409FDD6E134D6A283B9F7B3AF64692E3BC7223ED5E31047BE5F9F4E7AFA89F9E087295F737B359CF21A84
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ...........o..Q0lN......o..Q0lN......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............}.:...K...8.;......N...^.................]`.{.O.k7............f........................................I.qk..B.....LZ............}.:...K...8.;..........}.:...K...8.;......................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):67991
                                        Entropy (8bit):7.870481231782746
                                        Encrypted:false
                                        SSDEEP:1536:3PC0XJjsmsKuZRG1pXuZ6z3wARnV9AEnieCc7cllJcHJ:qyMBzkUZ0gq25c7Z
                                        MD5:1271B1905D18A40D79A5B9DB27EE97EA
                                        SHA1:9618608FBD7342DE6C71220A36C3F4995BA9C13E
                                        SHA-256:5B321A4D81BD499B289B1755F6450A42047C494DFBC112DBD56DA4CED2C15C1A
                                        SHA-512:C32DD26047F6B8AA061085B38AC2B8335868E1BFD8731DB65544309223A955FA4BF45B06AC8D244408658F51A1775B6F19FF0FFC804989DE706DE8EB36F1436F
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1..AQa..q..".........2...BR#b.r.3...$.'...)..C%7gw..(.S.W89.......................!1.A.Qa.q".....2...#....B.t......rc.$%67Rb3s&'CUu.v....S.d5.V4T.e.............?...?..Wj.e.e.......w/..E..eOw_.....6......u..C6h.,..;.g.D8Z..-)O..jy..e;.u.g..w..[.L""k'w.......'1'.[......=..P...S.9a.V./O....q=8xk]...........9......F...e9'....9.O.... .&.....p......c.4...mr...?.......L..'.....0....+..|_...POM=7.?.2.a....};.Z..y./....>./.C.<...;.....|.1>...........S.8.o.O...+..n2...k../.X..9...Y...:.....\...Dk......q.K..\.Wuh.!Z?.mu...R.5.A.S.h.0..[..v..+M.....aUi*.k..?#..._...X..R.&]..[..;../]L..f..V......*.e...ut&.#.J.5....c%..o.$..v.<K.6..T.IP.....6X.*.uf..t0^..-.)m$.!.q(.j.f;..WB6.b.B..R.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.346108416951143
                                        Encrypted:false
                                        SSDEEP:48:rijOij7srccEfUIEth7ICEvlLu6cXtrRc9pU47pyRrdMr7k/VaLiFXCE9uYN:I77srKsIErEd0Xta9647sRM7EoLiv
                                        MD5:A743A979D1707AEA4F8727C5B1F8249A
                                        SHA1:87E60401B2B8A79EEA7928832B313F6FC7BB3CB6
                                        SHA-256:E852CAC62C2BF97A3A7832222A63781605CDF79B50A4039B7272D4B9987DAE35
                                        SHA-512:1322B7C424653914A00876EA1F22DF16326501609D15BF657CA96986017595D602CCB4493915825486FE10D7222126371776DF5DEA3851FEDDDCF6A5F67E7EED
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.%......%..W......>.j.%..W......>.j.%..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............. .M#"G..4.........N...^................bAMx`.M................f........................................I.qk..B.....LZ............. .M#"G..4.............. .M#"G..4...............%......%......%..........................................%j.....%T.]...%......%..B...%H.....%..B...%..>.).%..J...................;........4...4...4.."...............%..%..%..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........%......%....#.%............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                        Category:dropped
                                        Size (bytes):22203
                                        Entropy (8bit):6.977175130747846
                                        Encrypted:false
                                        SSDEEP:192:5q3R1VBvq3R1Flrk6Q0QPJJrR39joOVMJ25d1NkMhIwobbtAAAqYnLJZMJYZ2AC:xw6Q0WJR3FoOVMJIIlAAAqYnMJdD
                                        MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                        SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                        SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                        SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.444507719134357
                                        Encrypted:false
                                        SSDEEP:48:BsXrs/bYPcuvMtl4E15L0dX/ge9lUcpyrBrdMruUWKeFXQg/3/IkRPOm/5PGMT/X:BsI5uvMMEDQXH92cyBRMeP/vvW/grIT
                                        MD5:BCA3E5CE178D0925ABC7D39B1CDE026D
                                        SHA1:D8299190B5CF3E06A3100465125582A1033E1B1B
                                        SHA-256:BF596846AECA45947284FFFBDA5E6A1C4F0594680EBDF3F9F7B401400E2C6534
                                        SHA-512:ECF81B39C7D86C3668A31AEC17DAEDC9D9B9B05AAC1DB86D09FC686EA14771D0ECE1B19D4D4C0EF2135817DA914E9ADE6DEF59CCB0C64F687C22D14E8B291261
                                        Malicious:false
                                        Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ..........J.P.....b.:....J.P.....b.:.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............0.......K.H.o.....N...^................6... .J..J..{..........f........................................I.qk..B.....LZ............0.......K.H.o.........0.......K.H.o.....................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):15740
                                        Entropy (8bit):6.0674556182683945
                                        Encrypted:false
                                        SSDEEP:192:Elv3GG8/OOs+GouFdxMlxjoPyerzkpuOo2vPMc62PaJseZC+BJoS/:EtNiwdxMlZoPhzkpuOo2PMc6rX8+B6+
                                        MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                        SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                        SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                        SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.332729704189277
                                        Encrypted:false
                                        SSDEEP:48:ys3iR0bLQtRHEAkLBEjBBXy7wB9OyURpyRrdMrEk6Tu5FX/t6M1hJ7X6AOVI:ysdLQDEjiBBXy7wB9CRURMEkB5B1
                                        MD5:59E9F87947DA24ABCCF32FED036DAE36
                                        SHA1:41C475021A839AB76CBC841B9E95E2FE1DBA8F44
                                        SHA-256:E46D54B2987AF1677D862F4CC7F6D6D401605D7F528DE3450326BDACBD742E92
                                        SHA-512:1434831243310C20B0C7260C04A82B8B92A6975630629F6E173D25B3DE4538FB5CBF8EC556D4D3768A8E76326240399CFF799CD94F7104F1A65E27A6E900768C
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ_a......_a..}.D.>.b.i..._a..}.D.>.b.i..._a...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............ZQ.v}M..............N...^................+.m...E.o\.\.7k........f........................................I.qk..B.....LZ............ZQ.v}M..................ZQ.v}M..................._a......_a......_a.........................................._a.j...._a.T.].._a......_a...B.._a.H...._a...B.._a...>.)_a...J...................;........4...4...4..".............._a.._a.._a...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........._a......_a.....#_a.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):86187
                                        Entropy (8bit):7.951356272886186
                                        Encrypted:false
                                        SSDEEP:1536:AbmHwD7za0syWMetp3TdPFzoJamVdAQZCiUit9qbYN6LerhWMzIWgN1EeaYhJM:1QnzsyTeP3TPAdAQZCi5qbYEKrhWWMNO
                                        MD5:FEE4785DF76E93A9DC2F4501CBAEAE12
                                        SHA1:8FB4527BDE05EF208FCDB168098A07707C27501F
                                        SHA-256:F091DED5E283AF6848670A3172E7C43C6099875D39B3FC69C2BDBA914F609602
                                        SHA-512:7E99D33151A0D3873D6A819C98EA8E62D928C087B7BA2080F11C7BCF746AD60A44D4FF6EE3D2D2E8DFA4BF1FC6285ED56BB83F91C2FC6FC4FDFF2000105F10B1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................1.!Aq...Qa."...2..BR#...br......6v.7..3.CSc...$4.s..&dt%u.f.......................!1.AQ..aq........"2.B#....Rb3..t.5u.67.8.r..$....C4.cs.Sd%.DEUe&.............?............w.....c.....i.A.....3...7.......7..P......%.........?Th..l./?.;.....$}..=5Oa...F.c.A/...D.D..]..y..3e.5\%.fo2.X.*]q.5Ee.}..i..md.T....#...-...Mu...9...-+..~w5O.);..G..'.;..).....A_...M.vV..y.q......,<.3.(...._K:..XM.......w.......9..T.......?b..a-%.c;.}..>....|.,lZKCEB.t...fw|.Sw^..Y..:.J.................t._P..v..j.1.R8.R....G..W*H<(Xi........i..xcu...WM.dqM>'W..g....M.q.....+.....b'..~....>..T.~Jc....fj.X.x..9...N.w.6:..>.......&.(h..u...t._...)_k#7Za...cZ....P...Y..;.V.,..xo.....f........Y...\6...M'L._
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.7109693654568225
                                        Encrypted:false
                                        SSDEEP:48:eGSsr0XT006jtrDWmEdzbULpBhrBXoO49IsU5pyiNErdMrshP4U2FX3N8bFhj:Msx06jhZEtUzJBXoO49Ir5puRMW4B3sR
                                        MD5:2F76D1E150138A3EAAA183605C4EAC90
                                        SHA1:5E2A1B1723D5C227C2D129FD84850C24A97107D1
                                        SHA-256:70FB41C60E941E26FEE5495938C0E7CE7678196CE2FDA784ADBD1CF4E8D571A0
                                        SHA-512:21FCD2AA1C7F93286A9EA0ACBC266A8D94A65BD8B5EF92DE82318469BE3FD75BEFA9034797662F2C101B43191DFCFF7A2E1E70DB35954855EC3CA09A816AAE4D
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>...t.......v................................I.......I.qk..B.....LZ.~+......~+.L3B.-......~+.L3B.-......~+..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............vV^q... ....Y3.....N...^...............!Pk.k{O.}z...h........f...................................H....I.qk..B.....LZ.............vV^q... ....Y3..........vV^q... ....Y3...........~+......~+......~+..........................................~+j.....~+T.]...~+......~+..B...~+H.....~+..B...~+..>.).~+..J...................;........4...4...4.."...............~+..~+..~+..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........~+......~+....#.~+............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 85 x 470, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):11197
                                        Entropy (8bit):7.975073010774664
                                        Encrypted:false
                                        SSDEEP:192:p9wNdtRKcVHso6zsqm06xaqZdingVzLZ7/PGSIz/yycRTbChh/JzhbEx15RGb:mdtMcVHqgAqTinMzLZ7/uSIz/yTR/mhF
                                        MD5:DDC3CC30794277500EFE4BC6667EC123
                                        SHA1:EFC9642C1F95B5FC38764476AE481649C016FA0C
                                        SHA-256:7F5B660A1A0BF46C75AAF19B4F77A0E086DE003EC03AFC1F58D871D55AA5BA9E
                                        SHA-512:25232A84604C3959634D33090238FEC8D51E40AD84EB3A08BB8522A81BE1E83378649C014E98E1DFCDF46B7BFAC92D8D2429211CD11D7EE0334C9C3DF7C1B6A6
                                        Malicious:false
                                        Preview:.PNG........IHDR...U.........1x5.....PLTE....................................e........................................................s...............x..........................o..............................................................................................................................................................~.............................m...............................................j...............................................p.......z......................................................x..............|........................................v.......................y..........................................................h...........................................................................P..{....bKGD....H....cmPPJCmp0712....H.s...(SIDATx^.}i@S..N....h...!..)....AI%..p.L."a..)..`U..,h..:O.b.:.j+.Z).b..zN.s..{O...&|..N}...${....~.....k}.[k}{.o^.D_..W:35ly..7rL....6n0.A...b
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.34691612656319
                                        Encrypted:false
                                        SSDEEP:48:2sivAk73Mt9PjElLXXpWXoLW9BUJpymWrdMrOcFXPRec2NAdR:2sG3MrLEldWXoLW9CJFWRM7TQm
                                        MD5:421F9ABCDBF2AF3C9668ABFF6F5443D3
                                        SHA1:7ACF1ED0ACEF3E2C23E6955C97176D7ABDE04F88
                                        SHA-256:653D6C50D3D0A0F3B01BA811E62D206759DF54A3771B2C7914DFB96C9B06E0FD
                                        SHA-512:7C3317D8C099BDEDFC0ABF606C60043D815C69BDEFB53E8997D9A332384CFE34A24BE8448AE77BB22DA04E52C99EBDFCC02369B796634CF0BD799FA4E844FB0A
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.G*......G*%Jm0.,ML.G.c*.G*%Jm0.,ML.G.c*.G*..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............L.....,.dL..I.....N...^...................]C...tO%.........f........................................I.qk..B.....LZ............L.....,.dL..I.........L.....,.dL..I...........G*......G*......G*..........................................G*j.....G*T.]...G*......G*..B...G*H.....G*..B...G*..>.).G*..J...................;........4...4...4.."...............G*..G*..G*..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........G*......G*....#.G*............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 88 x 574, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):19920
                                        Entropy (8bit):7.987696084459766
                                        Encrypted:false
                                        SSDEEP:384:DRSgtAxJx7bzvAsVSqQElOT4uHmpmvNYT9aPU+QtsC2LgfIqJZnbeyRB:DsgaN7bzvAsVdK4uGQFUZ6bU/p3
                                        MD5:1BDAD9B3B6DE549162F9567697389E1C
                                        SHA1:5D9C09159F07A3A9BDCC6C4B9BD9CB72D0184E6F
                                        SHA-256:0908A4CFA23F93011176D47F45843E9CA2973030421996E8E27484781F54B0EC
                                        SHA-512:475040779AC247BB5C3E11862FB55FBDDFA12D759EE86A33E11BC1F3B656D6CD0F9B25146C0113E43E1D8001D8867D3BC3BF7E6FE21F3A0016CB1F8B70B7A15A
                                        Malicious:false
                                        Preview:.PNG........IHDR...X...>......y=h....PLTE..................................t........iw..............................................._n|...Tds...ky......................................................p~.....................................................dr.................v.............................................n{.......ap}..........x.....z...................u......................|..Vfu............r.....w........................................~...................Zjx...................................Yiw............w..|....................Xgv{.....y...........................jx..............\lz.........}..z.....t..[ky........u..y.....gu................................{..........}.....u....................~...........y....r.....bKGD....H....cmPPJCmp0712....H.s...JfIDATx^...\.W./.}....Sy...(..4....D.-.....H...% .$"D.Qr.......`..;...6...N......s...^...L.....Y{.GQU`..~...j....{...-Ax.K..&.....F..I\i..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):2.908768081037636
                                        Encrypted:false
                                        SSDEEP:48:D4Es/sre/uGnt+pE1Lw9NVSL6MhwnLXOrtL9dsqpyVrdMrHLkhFXI1zR2aMx:D4EsbuGnkE1+N0foXSx9djYRMHohJ
                                        MD5:5F2CAB1070C7353DEA7FD14D0985C3FE
                                        SHA1:8657BBA6855969FA37133283B88C060491CCBF5E
                                        SHA-256:78B3537E9A7CC40733332A09B16372720FEC0F7F99298E147011B0FF61FA9A7D
                                        SHA-512:B7B52B2E44371E7FF0C82E20F54DFA6295B561BD8250CE7C590C0D25C73A0D595CE72CF5A4C3B8D4289C06716BC0FC7577F73848AF715143F01B72F255F04EA7
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>.......H...v................................I.......I.qk..B.....LZdH......dH.....)....+'.dH.....)....+'.dH...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............5.:t.o...I...i......N...^...............[r5.vL.J.].IY.2"........f........................................I.qk..B.....LZ............5.:t.o...I...i..........5.:t.o...I...i...........dH......dH......dH..........................................dH.j....dH.T.]..dH......dH...B..dH.H....dH...B..dH...>.)dH...J...................;........4...4...4.."..............dH..dH..dH...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........dH......dH.....#dH.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):179460
                                        Entropy (8bit):7.979020171518325
                                        Encrypted:false
                                        SSDEEP:3072:oiKXvL7lv0am/R1vrdH+9dK6zPQ6bbnGDpcGGDNMIOIMAT8q9Vc02Q57S4A+vMFz:+vlvC/HvgA6fGqGGJlO1qZ71W6CzDn
                                        MD5:4E131DBFEC5C2462273CA7B35675B9D9
                                        SHA1:CA037F444D819A118AC37D7AA3782B9BF94C1616
                                        SHA-256:2A4A3530D652E227DDD5ADC096A95F6034718F7C380B07DB622022D768815059
                                        SHA-512:C333ECEB1439D0238BF44FB7896E62DBA4C645B70413AA0F99C1F10E8DCD20C2EEE5C83F2E9DDE9A2494C85A6D8D13CFFFC4160E2F598E17867015F5244D656A
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1AQ.aq...".....2Rr..Bb..#34.....CSs.$5c.t....%.Dd.6.T..u.U....E.7w........................!.1A.Qaq......2."r.3....BRb.#4......CsSc...$.5..%.DT.t67d..Uu...'............?..c.......p..z..i.....z......kj........F>f......3N...M....RM.&..-.~.Q..'.....q.a..w...-~......g.{..&.......V.n.D....>FS!n.....@..)...W..q..Wr{..J.gf.{.M$.P@m.,..9..&m.D...w.._...-.O........s.....h.k~......(.K...V..l.-...+.9.k......*......#.p#.O..9M..mF...C.......7+.AI....4vw.;..H......e..Q.u[.eUK.....z.....[.Kt...s..Lf.4..l{.....sh.............=..;..iqkj.m.a...NH......v..H..$..q.y......c...U[Mcf.......+...S-...^....4..T..YtL.x.v.;.....<...Ik|B.$.s8......3.+.8.l.. h.:....%B..W..I.QRS..,*x.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.371008287205504
                                        Encrypted:false
                                        SSDEEP:48:Y9llsDnoHlvjtFxWWE4zKXh9Rsppy9rdMr7CposFXs0EQklgg:asQl7EWEjXh9RswRM+osolg
                                        MD5:462EF1123E766A20A1606F3D0E1EB0CE
                                        SHA1:6CF4137A04028CD4AA8F2EC4162FF02F303A91BD
                                        SHA-256:EA0C914DBC085201952FB7F64E945AB45FCBC4C67AEA6989C9876B29F73C6281
                                        SHA-512:87FA8C3B7FD3BA9A483F723F781D2DEB6AD2C5ED03DB06B60D024B7621C8D4FD70C1BB2A276B46FFDDC5539ADFB5984852ACD40111A8CD4BCD0DCA6BDC7DF1E5
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZT.L.....T.L.oov.....[T.T.L.oov.....[T.T.L..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................Ok....!.|m.MC....N...^...............=.....D....C-.M........f........................................I.qk..B.....LZ...............Ok....!.|m.MC...........Ok....!.|m.MC.........T.L.....T.L.....T.L.........................................T.Lj....T.LT.]..T.L.....T.L..B..T.LH....T.L..B..T.L..>.)T.L..J...................;........4...4...4.."..............T.L.T.L.T.L..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........T.L.....T.L....#T.L............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):109698
                                        Entropy (8bit):7.954100577911302
                                        Encrypted:false
                                        SSDEEP:3072:rDlmvIWr0aRtNCfShCWBxyCHMlcVG0Ezy4FR:rDliIfot8ahCWBcCHDVwR
                                        MD5:8D804A60E86627383BED6280ED62F1CF
                                        SHA1:E23FF14B10AD0762DD67FBA3CD6EFC85647C0384
                                        SHA-256:494547E566FB7A63DD429EB0699FE41AA8998F8EA2F758D813FE3D56C3075719
                                        SHA-512:0FB19F3D00159F2748C3A54E952E551B9FEA6910D67A54DECA8D099992E50383EADB92768FF1F75CFFAE82A7A157B1E0F77A2F0BE7EC64FD2324304FDCA46577
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...............................................................................................!"#.123..AQB$..aq.RCS...b..c4%..rs..D&....5E6'..TdUte...u.....FV...7.......................!"..1A2B..QaqR.#.br3.........C%...$5.....c4U..Eeu&SsD.6T..................?.....O.C.....^..R<A.g...[....3.....r.0.....nX.S....}...[.?Z.....A.?..~~I..rY|N.o...9......!...o7r../-.y...'5.3.U.s".-.0.1......SS...&.Q.j.*.$m.e..:x....`}...EP.?.7..~G(so.......O.....z.N..<....~^a.e...........p9.?<._..|......~.<@.D.9..G..?.?z.y?z.C.U.w..[.,..A.+........s......g...G.^....pz.xY.....d8.y.X...P..O(A.O..~:._.......<...o..4s..^.^b..x......_a.....|{c...:..X.....}.._...[?..NK.c...}.<......H.G....+x.Z..|....n...o....`.nk.#.%x......-|...|7......N!=././..w.8x.".8....'x........w...,>....j[w8a..}..lS..?.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.342400101604063
                                        Encrypted:false
                                        SSDEEP:48:AXsUlCo9NNtJLxE3ywmSXaARcS9ZshpydrdMr1ZB7SFXp9horxeJ:AXsmNN7dEQSXJiS9ZEgRMh7SOe
                                        MD5:346106A1E7D9B393DA4AD82A08054943
                                        SHA1:4E98AC3C596D9655C3B31BB9330A67014C47DF56
                                        SHA-256:F594D2B3554EEAADE16D457BC630905D32677B39A27C728F9134ED51D78FB936
                                        SHA-512:13A6E44DF535D4AF46F61CD11ECB68A79F81DCC90F2C49132BF3B2474CCD350203F0EFE301E110FAFADC697C98D468DC116EE9D30DD0910563CB8D683538CAA2
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ+.......+....P....}../.+....P....}../.+....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............H.5.-M.............N...^.................<..u.N.5..............f........................................I.qk..B.....LZ.............H.5.-M..................H.5.-M..................+.......+.......+...........................................+..j....+..T.]..+.......+....B..+..H....+....B..+....>.)+....J...................;........4...4...4.."..............+...+...+....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........+.......+......#+..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):41893
                                        Entropy (8bit):7.52654558351485
                                        Encrypted:false
                                        SSDEEP:768:pZvVQkUbOHxx3pvVmO5rsP5gUdXwFMuv53knzyncaXgRDqPU:pZkijV5wScXwFMYknzucaXgRyU
                                        MD5:F25427EFECFEE786D5A9F630726DD140
                                        SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                        SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                        SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):3.3004316617368703
                                        Encrypted:false
                                        SSDEEP:48:GN2ObOIGa6qC9zH8jqEDbPUErl7yD/Bqw:G4qGa/C9w+EDb8EIDZJ
                                        MD5:5DF932C0EE6F13320DA4440D2F7B8EF3
                                        SHA1:94E57E23E934CA876E963F9BA43CD8FAC772432E
                                        SHA-256:A8E9A1D379C3DBF989F6093A2CBC0611DEB6DE822CAFD2532E7B393F481CFB5F
                                        SHA-512:7033986D27C380510EC0118ED65C70DC035EE8F1CFF6B7382A3CF294D044E15AADC4304F2CDF43DD62D0F6481E32EA103E0F1E13AE619BAF0967ED2718A84319
                                        Malicious:false
                                        Preview:........$...........t......................................?....................................................................................................\.......................................v.......v...!......x.s..................u[.Iv;..cw.C..{W..R}.;.............u[.Iv.....@.%..qF..P.9|..@...........;.......;...................................................Z.ZT&h..G.T(T...@.T.<..;....{..;..X....;....7..;.......;....$................4..(.....x.(.....Z.Z.....Z.Z.._.J.......d;.......;..cw.C..{W..R}.2...v...............................Z.Z..@............................@...........c..,0...e...B4.$........[.-...I.......9......................G......G....N..C..\..@.......@.%..qF..P.9|.kW...i..#...V...kW..v...!......x.sv....@.%..qF..P.9|..@......>.......@.................u[.Iv.@.%..qF..P.9|.................;.......;..cw.C..{W..R}.kW......kW...i..#...V........Z.Z.....kW...c..,0...e...B4.$..............E........................................0...........e....4....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.9123130841984155
                                        Encrypted:false
                                        SSDEEP:192:zBschZJYQwPGXwMTlIbRz2ELPB768Fu7Tp9D1dWNF:zWlK9ARz2FDTrC
                                        MD5:3100F9652CD6BFE547BFAD6A9753FF52
                                        SHA1:B32CBB517A475EDF4F9D384439455915690EB5F5
                                        SHA-256:08BB783E9D57D64A5655D2AAD88CC44EE2C9E5A56DBD4D7B540D3D8A7F155CD9
                                        SHA-512:F432C1E250A88FB88BA26F445AE6BB5C8AD63621898E2E5B373F17C93C227B160D670C3CF9FCB63654AFEFD2072BB966E8D1FF8EAF528C91DFD969BE064E9DA1
                                        Malicious:false
                                        Preview:2...>...........v.......X .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ.M;.;....M;R..{.?.|B.]L.M;R..{.?.|B.]L.M;..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................i..K./..@c!.U....N...^................/D3\..F..O.d..........h...L...............................D....I.qk..B.....LZ...............i..K./..@c!.U..................................M;......M;......M;..........................................M;j.....M;T&n...M;......M;......M;H.....M;..K...M;......M;$.........M;-.M;J.M;..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.5............(.M;#.M;8.M;..z...,4. .......$>........4...4.@..7.....................D..n4..o4..p4...4. .F
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                        Category:dropped
                                        Size (bytes):68633
                                        Entropy (8bit):7.709776384921022
                                        Encrypted:false
                                        SSDEEP:1536:tapXpSTJDOkFGdJdBk/slsbfsw1imaapnbvD8:U2OjJr6b07m1bvD8
                                        MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                        SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                        SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                        SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):4.08888676579926
                                        Encrypted:false
                                        SSDEEP:192:1bYCGMLDUwrwjGagxYh/8vYzdd/6tv32tcDCC2LUV7KX+RM2IFHRJsbfFF3o5GdP:xYCYZd/6dmc7EtRJu3QG1PRM
                                        MD5:CC02B9B74FF9E3490CA35F197DA89190
                                        SHA1:CCA414D6C779AB27D8E7C680B4E26B05CA298230
                                        SHA-256:59C1D11CAD2A5CCDFD40954B21066FBFAEC8A46E045DD5F2D8C25E97A2BE8674
                                        SHA-512:630CFA57C8BD6CCD28D5764DCA41A55FDEE0750E0E6D61D0C61FC0D4EAE2F9BFEAA00A30040BF7294DD0DEAC0DE4BC2EDEDE5F14DB5292FCDA2EA167BC942BEA
                                        Malicious:false
                                        Preview:N...>.......L...d... .... ...9..N...>...........d...h...@...@;...........................................................................................................................................I.......I.qk..B.....LZ#s......#s.\.:.>.8......CG..].%..V[b.|..C.#s.\.:.>.8....#s...I.qk..B.....LZ.I.............C.......C.......C...........................................Cj......CT.7....C..~....C.......CH......C.......C....&..C........'..C2..C..z...,4. ...."......$>........4..`..7......L.o.w. .P.r.i.o.r.i.t.y........................C:..C...C..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.2.3...........#s...z... ..$........................................2..7.........1.h...?.......?...?....rA\.-?>...o.u.t.l.i.n.e.L.o.c.I.D...o.u.t.l.i.n.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.4........?ff.A......'..C%..C...C..z...,4. .......$>........4.@.4..`..7.....................D..n4..o4..p4...4. ..1.........C*......C....%..C#...'..C&...9..C....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                        Category:dropped
                                        Size (bytes):59832
                                        Entropy (8bit):7.308211468398169
                                        Encrypted:false
                                        SSDEEP:1536:HS9SYFtN0+CRa9mfJy4zBAiIJhzrkHDV2hJK:yAmta+Tyy4zBIJW5WK
                                        MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                        SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                        SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                        SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):3.2424067819931106
                                        Encrypted:false
                                        SSDEEP:384:jdK2Oq0CMHFpHu8Q+sXW/XRJmAB6uIWAn8:jw2Oq0CMlpHu8Q+WoXRIAB6uIWAn
                                        MD5:8CA2639CF7EEACA29C01C029FEEA944C
                                        SHA1:9586E33FAE700DA028236CDD9C2CA463FEB4CEDE
                                        SHA-256:C03BBACDC526DAA8DABD50F29DF6E1C759195EDBC2D2DD50C8BB721690DD610D
                                        SHA-512:BB4C88A0A52A26DE5A0A106E295487FA12B1F185BEF50E32EED9AAAB52FA7F9C1DDD75B819F87D6563FCB8145847CC5AB17CDD0AC4D0E83CD20C83343EF6B1B8
                                        Malicious:false
                                        Preview:2...>...........v........ ...-..2...>...B.......v.......@....,...........................................................................................................................................I.......I.qk..B.....LZ..%.P.....%fW.....K.H.....%fW.....K.H.....%..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............I...Sy..,...;.]:....N...^...............3(....GE.....e.]............................3(....GE.....e.]........3(....GE.....e.]........I...Sy..,...;.]:...................................%.......%.......%...........................................%j.^....%T'.....%.......%.......%..-....%.......%.......% .L........%3..%I..%..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.6...............%3..%9..%..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):53259
                                        Entropy (8bit):7.651662052139301
                                        Encrypted:false
                                        SSDEEP:768:dCiCBBenRYWDBCipMYGTbYGLHbXxoP/qEF+MU50qyJ30h2W474S/Aq/xc4674bi5:dCiIQXBCiwbDLHD0/sFyVel4Pi4UgE
                                        MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                        SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                        SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                        SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):2.5431475937072454
                                        Encrypted:false
                                        SSDEEP:24:dHWKKZZZ2VH47iedCDJRUlbw36J0UlSWTdcw4xeWUlBjVlesJTeE3UliuEJeESUx:5WhddCElbS6J1lf1lBNBElPEt3lCWiU
                                        MD5:13D7E8D4AD4091B9554314DCECFF0BCC
                                        SHA1:1621FE74DD0490C0A68D2C4415F4433850A3CD0B
                                        SHA-256:F065C47B749274C485F6773394F4035B6AE5EFDEFD9FEE06179A00DC00BA7F0F
                                        SHA-512:8EA79EB696019AF5F81A4364E50F3717AE2B29C790CC8E1E9CE924688C624853574806B8070B5418DDCEBAD1F7CAB17A50C42FD2A9AF2CEAA7EF9FDFB77907C2
                                        Malicious:false
                                        Preview:........................................................................................................................................................................................................<.6.....<.6..x..>.JZ..o..;.......;.....jus..]..;.....jus..]..;..*.!.(.....1.....*..6.{)..RJ..r...6.{....................................................................6.{..8..6.{..Q..6.{..[..6.{..b..6.{..o......k....`......................4..~...1...(...(.......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.\.r.o.o.t.\.T.e.m.p.l.a.t.e.s.\.1.0.3.3.\.O.N.E.N.O.T.E.\.1.6.\.S.t.a.t.i.o.n.e.r.y.......S.t.a.t.i.o.n.e.r.y.........1.......S.t.a.t.i.o.n.e.r.y............6.{..1... ..$....S.t.a.t.i.o.n.e.r.y........L......Lf.yy.)..[.1l.6.{.....6.{)..RJ..r...2.................................;.6.{..*.................................;..c..,.........................;..c..,0.............F...pJ....ay.................6.{.6.{..1... ..$....S.t.a.t.i.o.n.e.r.y...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):72
                                        Entropy (8bit):2.2302078877014586
                                        Encrypted:false
                                        SSDEEP:3:bMTaaHt+lRRDlyaRatl:bqHt+pL8X
                                        MD5:C6316532058371F7415AE4E38FFB963A
                                        SHA1:5AF288141DC0BD1959DA261023B5C200B682251B
                                        SHA-256:807C3E9CD486D3F3044ECE07F0501A69AED4BF12C31573ED556143A827D903DE
                                        SHA-512:5DD0FE753EE8344DA7B52E0684D0CBBBA3BDEC86A731A1BFE59FE894EB819AE6A286DE78486C967054428B1F1033DCF75E3F0EAC2BA297B3334A0F1F88F39136
                                        Malicious:false
                                        Preview:...... :............................................4..../..............
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):0.04401584019170665
                                        Encrypted:false
                                        SSDEEP:3:RRk//:Lk
                                        MD5:CD74ABACE8A00B17BD8107BC5982C21E
                                        SHA1:D53193CF8A43D766FBFA52976192F44D6B0F79B2
                                        SHA-256:B670BC07C9CB554511180DCF3F6A2C7818E8CE6E67B84784F0EA4D35EC61D516
                                        SHA-512:1B48A37FCF0F9FB9ED9B31A8F3E36596689BF1EEC6F41F5EFA3C728121944919CE7A81F0379A108D80AA051CFEF07DC296F9C0691FC8855983B2F29EC15C7FEF
                                        Malicious:false
                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):0.49317414713099117
                                        Encrypted:false
                                        SSDEEP:6:NTc0C+l2em6UgPD1S5t/GwJdL+Kw1EVNy:Vc0CaSfG85IiL+KQE/y
                                        MD5:8BF76D71ED14E95741D38B9D36533ABE
                                        SHA1:1D5C94663CF79F64327D499BBAFB2C37EE763066
                                        SHA-256:7025CD1CCDB8E2895BBCDA9D1A67DD8EE0348E37712F88EFD265042BA0728AA6
                                        SHA-512:C46E23C7BE9CF351727BFB67FD5EB7CA9AE8740D7E3A2F2BD733F4EC52AD0832A513B3DB6480223C247DF1333FD2D3B09FE2657B498EAA97C685420030BAC6E2
                                        Malicious:false
                                        Preview:2...>...........~.......................................................................................................................................................................................[&......[&.....O..[m...a........................[&.....O..[m...a[&...................................................[&..........................................................[&.P..............................................................................5........m;.H....7.5N........k.G...........w.../3.D.. .4.-.....N...^...........................................................................................................w.../3.D.. .4.-.............................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.727400654239059
                                        Encrypted:false
                                        SSDEEP:48:wS7Fd5FfWAxz3LCxyw0Lq7cBlkw0LNpruECL33wEwLMrKdDwz:1PxjexyLucgLZpruECsEworK
                                        MD5:2222DEACEBEEBC084F126EC528AFCCE9
                                        SHA1:CDD09E2EB8C7EACD782F26001A86BA22AB92D864
                                        SHA-256:ED44AC052FE944A6BB6E9306E9EBC23775BE5F8E77C61AE88B486E725E8720F6
                                        SHA-512:42A5525F412056B501DA2F6572E6D2EDA0940D72D95D51CC90C87546F2E924D72E2374F562303DA675B25E48A44352767B568C2D6C9ECE9665495D2F564E6236
                                        Malicious:false
                                        Preview:j.......`.......L..................................................................?....................................................................j...............L.................................0.......0V.D..$$.!gRM...2.......2&..{..m/..|.vyQ.5T`.....z9.9vyQ...2&..{..m/..|...2....|R.q.!...#.................2.......2..................................................9.......9<. >.........g.......g^R..N..fBB...2...^.............................2...9.vyQ...g..%.................2.......2X......2..2....2.......2.."...a.T$...9..T%m..G..T.N........g..........c..,0...e...B4.$..........C@RQ.H..B......Y.....................%.......%.....M..L....y...........|R.q.!...#....9<. >.........9.9..2#..A..n.]*l.9...G...5b.C..8.....G.......>.................2&..{..m/..|.9..2#..A..n.]*l.G...5b.C..8..........9........_]..c..,0...e...B4.$...........I...M.....0...............................0...........e....4..................T.i.t.l.e.......|{....B.l...R......(....Y......(...D...L.e.c.t.u.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):4.730882673432808
                                        Encrypted:false
                                        SSDEEP:192:DswWox18tIhAwbX/+PgLRi5E+1HqLSgLla9UggDgvdx8IkG:4wbxjewTbLRi2A0liUzs1x8IkG
                                        MD5:C817DD9C6864576965C656191E0105AC
                                        SHA1:8A9257B2EB98CF516EA86E90F0C3A525B8BCA7E6
                                        SHA-256:B3AA8A9111F76E5E829FEADDB7E4B1FBD36EFB774768601AA11C83C715D9E641
                                        SHA-512:90962A1339562A9D21220DD0E814F363F9B5335E8E9ADDA7A1E26C98E9103D85E4C26EDA8A361F56CECED0D09DE9B23DEDB46375E64E70BC11BCA0CC7D24B123
                                        Malicious:false
                                        Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZ%3..4...%3.8.Cf....'c..}%3.8.Cf....'c..}%3...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............:w._.~.$..z&.D.....N...^.....................L....{..I............>...............................$....I.qk..B.....LZ.............:w._.~.$..z&.D..........:w._.~.$..z&.D..........%3......%3......%3..........................................%3.j....%3.T%;..%3......%3...W..%3.H....%3...+..%3...S..%3...........Z4...........................................4../4......p...............C.a.l.i.b.r.i..................%3.:%3.k%3...z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40884
                                        Entropy (8bit):7.545929039957292
                                        Encrypted:false
                                        SSDEEP:768:MCBOA4d+ElOXJ/3pI7cRBiL7L6qERqGz65WXzZqJsKQSbIsTT6XB:hIAU+2cGdLX6qBG4WDZl4Ihx
                                        MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                        SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                        SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                        SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.439801143042936
                                        Encrypted:false
                                        SSDEEP:192:DspT+8s3VIRAQu8LSorh88caV3+RhEjvwXyKjRk3sghewzNSqj9XI6T:4c3qAF4SoKzaV4hEjyyURk3s8ewzzx
                                        MD5:4F0E03793FB0E3C449207A114036F3C7
                                        SHA1:F0A6CAE3BEEDF5DFA1758BFDEEDB286CDA96DB29
                                        SHA-256:4358B73476CD64C62FF1980B75003731E2BEEADAFFC50F14066CC9609C41C9CF
                                        SHA-512:7105B0C714F227E09B8539B06BC88CE24BBE60ADF9D4A07F9EEF5EB998FA6F749115BF59AB7A58E8EA179D4A52895B11645B103218847F48138015965B541CE7
                                        Malicious:false
                                        Preview:2...>...........v........ ...)..2...>...B.......v.......@....(...........................................................................................................................................I.......I.qk..B.....LZ....H......qA...:+. .......qA...:+. .........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............=V.d.y_.-e...}......N...^...............jT....%B..(KD.............................................."....I.qk..B.....LZ............=V.d.y_.-e...}..................................................................................................j.".....T.................T............. .A............. ...........3...:...8.....z...y.. x.. ........ ..$...$........D..........7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.5........................Z4...........................................4../4......p.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                        Category:dropped
                                        Size (bytes):24268
                                        Entropy (8bit):6.946124661664625
                                        Encrypted:false
                                        SSDEEP:384:d2wiieoHTRh5a1HAteZCWOZIM+L7WhNjYn:8wHFHJ+/OZIKhNO
                                        MD5:3CD906D179F59DDFA112510C7E996351
                                        SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                        SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                        SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.670851473554114
                                        Encrypted:false
                                        SSDEEP:192:jsTksIPNSYhZxMupiIIL/hjbG4/42oQj23g7D+bRiXuP+sRpg0IDx9DqAWp5WLl2:YTJuNSYBAI+5jC4A373gG1cuPTRpzIa3
                                        MD5:60817CFAB30BDBE37138565139624FB4
                                        SHA1:B04E3CB8B6808923B080C78CDF3CB96985FE7154
                                        SHA-256:86515E6BB1145C05DDD9784B671F7F60DBCC363EC33B4AE2B7F962A3D84052BB
                                        SHA-512:9EC3B39C24DCFB883511172018FA46BAB0C981AD6248E7DB49C20C559F4C0438424D02E831DEB9E70AAD6E5F9293B267994526EBB44EFA9B9366616BDC144005
                                        Malicious:false
                                        Preview:2...>...6...z...v...N.... ..X,..2...>...........v.......@...H+...........................................................................................................................................I.......I.qk..B.....LZ....N........1..$.d........1..$.d........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................#6......%.."=....N...^....................M.N.w.E..M.............P....................................I.qk..B.....LZ...............#6......%.."=................................................................................................j.9.....T.................s.....H.........0.......`.&...............3...:...A...8.....z...y.. x.. ........ ..$...$...............7...7.........*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.1.1................Z4...........................................4../4......p.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):39010
                                        Entropy (8bit):7.362726513389497
                                        Encrypted:false
                                        SSDEEP:768:6tCjwO+E+KW0ZtOgepcoWW4pAWQ6/KWcR474HOAZaDfK:68j+E+KW0HOgep/72/NKWcRNefK
                                        MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                        SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                        SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                        SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.954987659592667
                                        Encrypted:false
                                        SSDEEP:192:QnP8sDs9X9JsNCSB26GReNDcK4vRcfgBfct483wq8LC4YkmDWr6vXqyl2M:qPBDwXns3BxGReqnOUct4Wwq8+4P/oq4
                                        MD5:990B3BA14016DFEE614B4480CE0BCDA2
                                        SHA1:7BCF84FC034D0B924C39ABF55B415162F98DE666
                                        SHA-256:BFB3490F1FA5E210A52FE65FE6B02828CA898E93FF06848BA9884494615836A3
                                        SHA-512:366EDDBE014EFD98E9E789443DDD7200488D6A4717D78BDCC420EDDB0E5E6FBED035193B6955939CD7CDBEAF274ADC9DD81CF507E13E09512F200872776F1367
                                        Malicious:false
                                        Preview:....>.......B...v.......0 ..x#......>...........v...^...@...h"...........................................................................................................................................I.......I.qk..B.....LZ.Pq......Pq...v..'QN.U~.S...w.G.1.......S....Pq...v..'QN.U~..Pq..I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'................@Z....[.7......N...^...............]td....@..D.............b...8....................................I.qk..B.....LZ...............@Z....[.7....................................Pq......Pq......Pq.........................................Pq......Pq...v..'QN.U~.S...8...S...w.G.1.......2................................I................................Pqj.#...PqT.G...Pq......Pq..Q..S..H....S.......S..$.7..S..........S..!S....z...,4. ............................"......$...7...............T.u.e.s.d.a.y.,. .J.u.l.y. .2.8.,.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):59707
                                        Entropy (8bit):7.858445368171059
                                        Encrypted:false
                                        SSDEEP:1536:k76rvGc8WKC2/UX1uEgVRY/jvv9CblyL/T:k77Z5C2/Ow1e9CblCT
                                        MD5:47ADB0DF6FDA756920225A099B722322
                                        SHA1:851946B8C2BD0BB351BAEECA9E5BB6648A87D7CA
                                        SHA-256:EC8CD7250F3D82E900E99114869777EE859EC73EFFABED108815F65742078C3A
                                        SHA-512:85A9920E1CE4A2FCCEBAFA425C925DF33580FA3C3C00178F058539B2FBC0163866DB8A41B320E2EF2CD217F00FFA06A1A831C728D3F9F910C9EAC58B5DA76E2D
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..A..Qaq"....2........B#..R.b3$..8xrC4&'W.%e.(.c.d.5E6Ff..h..SsTt..u...Gg..H.....................!.1..AQ.aq.".......2..st.BR..56.r#3.b.S.4c%...$d.CT............?....3.7...G:../P....z..K.:6..w......6....... .z7...~.....{gdF60...9....{...'[N....m.........z...g{.......7...4..1..=.z...._..p...m..Icd.~.v..9.P..0Z(.<j.......R6zm.....v.z...>x..)=g........zo{..w..f..y.t.....%.D..#.}.I.>).H.QM..cLD..x.../.^y.{.............y.=^.......I.T.......U..0_?...u..og..3.ky..K....6w...Dc......~........ik.z....N...en......_.....x....._u...4.{..P...>.....}.......>.R.....m.....[mt.....}.........|.....m......~....B.F.]C.36..q....yg...{]...+.DZv.9<.o..;..N.n&im.,....w.3...V.s...Y..e#$.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.840341144925149
                                        Encrypted:false
                                        SSDEEP:192:ksXWrGW6IAgqaEZGX1qRlRd2Cp5BSMq9Yf36oXMLRp:5XDP3aEZY1qRlCClyYPqLRp
                                        MD5:A4E2114A9304228C747ABF5B9CF9B20B
                                        SHA1:5CB7A645F9586F51D2522E374FD67B29A64DE9A3
                                        SHA-256:10CBC6DC42DDB45AC69874AFB13E5EC992E51D8D67793F55955BC3B1A3EC2E67
                                        SHA-512:D352E67FB500E5630A8EB85986B0B7383250E8BA2FFCAB368B0254D99D469309C4198FAADE8C0733E75E7CFD56ED67B2181FF1FE0E845B9E3247C973F05CEF0E
                                        Malicious:false
                                        Preview:2...>...........v........ .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ..$.<.....$7]]C..^..9....$7]]C..^..9....$..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............pM./.q.4.zeE9.0....N...^.................x+.WB.c.N.B!R............................................D....I.qk..B.....LZ.............pM./.q.4.zeE9.0...................................$.......$.......$...........................................$j......$T.T....$.......$..|....$..;....$..h....$.......$ .W.....'..$2..$..z...,4. ...."......$>........4..p..7......S.u.m.m.a.r.y..........................$3..$8..$..z...y.. x.. ...........$...........7...7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.9...............$
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                        Category:dropped
                                        Size (bytes):27862
                                        Entropy (8bit):7.238903610770013
                                        Encrypted:false
                                        SSDEEP:384:LTawAZvhbrXzDc6LERLQ/b5vXOl6pXQ/wD5OUMrdRUUhCplQg0ESSz:6wm/vT/b4wxoqbdUhWnSs
                                        MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                        SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                        SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                        SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):5.407557509723266
                                        Encrypted:false
                                        SSDEEP:384:Vu1VgNtsKEK68+KWxMqXGMtb1dnEWTuyhAVpwYQVjGEAA2EqP5d8ysElNDlEjdmS:VfYVAV5NkvNS
                                        MD5:E40FC234C3BD68ED065F2A657932AF0C
                                        SHA1:66E811DFA782280777369F17197415891D6C245F
                                        SHA-256:9F6899F197190356451C1AD3406A3ABAF50C15725DE87421AB05AE2B846CAEDE
                                        SHA-512:CEADCA07A4B5ECA5EB1D1D4D72142A0371A96F5FBD66D8D985717DA4AE90EDE20E033F07CE28D52F84E1C41661DCDB4BBEDE46128D45042400C424286070A6CE
                                        Malicious:false
                                        Preview:...@...@.................A..( ...M.........@...@0................K..( ..@L.................................................................................@...@H............... L..( ...L..........................n.w....M.,.w0.......0..:..SF....B4..<..'e?h.........<.....yE.Z.. .\...>...y...u&&..).....z............v......v.....................................................T.^..0..T....K..T...... T.....!+T!d..'.nT!.....pT%B...zT"8...........0...........e....4.........................A..:4E.2..p1......(...`.i.....(...(...B.a.c.k.g.r.o.u.n.d. .-. .Y.e.l.l.o.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.1.9...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e...:t......:t..SDu.'.4....(.!+......!+W&.hC..%r....2...............4.......D...$.......4...0...:t.......!+..+................0...........e....4........................yf.....F.Q.........(...pO;.....(.......S.t.a.t.e.m.e.n.t...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.077114171794445
                                        Encrypted:false
                                        SSDEEP:48:bSTsHwdjgxt8KtcEau8DXHG9HG1hKToOrdHrrEIydXLC4iu1:Is2jgxTcEauiXm9gKTbRL8Jb
                                        MD5:1414921AE656B9EBACEED8F77D45B296
                                        SHA1:07DAB42F86A38EFD36E6CD2BA355E9D5D523053E
                                        SHA-256:2ED53F1418DA71E7F83238482E40C24D47116E7819492EF9BC08B562A405A71F
                                        SHA-512:B3BA6F5B61EA87B47664B1D64F9DAF26098681C41047E7CBC80BE17FE03FCE4CFA7004E6A0E6675B51B4364D16C8A2722616F19A6AE46303D2CFCD798D81BEE8
                                        Malicious:false
                                        Preview:2...>....... ...v....................................................?....?.............................................................................2...>.......|...v...H............................I.......I.qk..B.....LZ..,.......,...y..../../..,...y..../../..,..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............f..`......&..l......N...^................p..m."K.6;6y..@........f........................................I.qk..B.....LZ............f..`......&..l..........f..`......&..l.............,.......,.......,...........................................,j......,T.]....,.......,..B....,H......,..B....,..>.)..,..J...................;........4...4...4.."................,...,...,..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........,.......,....#..,............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.099262552216668
                                        Encrypted:false
                                        SSDEEP:48:7Rs8TY71//UtFt4Efm6cXHc9mnZToArdqrGItdXTikDjCaUa:ds8SN/UN4EDcXHc9CZTlRylE3aU
                                        MD5:86B2D8E025DFF30291584F6710035E7A
                                        SHA1:C53464EF1B21B24B53D862A0A6F1AB9F7DFD5A87
                                        SHA-256:01F5D10F4C12E6CF28EA2B29CC098D3715C1E5DC7E0AC531C9DA9960751A66DA
                                        SHA-512:41DE6FDD590D66360C19EB008BF5B4AA6490EF37A1C601F98828278D68EC9182E2D79EAC94E07F345E8BC53DDE897991EA061612F07310B6DB2750A8544490EE
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZw.......w.....?.<.z...'.w.....?.<.z...'.w....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............E.y..=u....j,......N...^...............?.^/'..J. .............f........................................I.qk..B.....LZ............E.y..=u....j,..........E.y..=u....j,...........w.......w.......w...........................................w..j....w..T.]..w.......w....B..w..H....w....B..w....>.)w....J...................;........4...4...4.."..............w...w...w....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........w.......w......#w..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.071691709619119
                                        Encrypted:false
                                        SSDEEP:48:psHxqffu3ttEfgE3phcXbc99u91pTocrd6rWEIldXLrrxsg:psMffu3LbE3YXY9491pTJRiKPs
                                        MD5:FC0C67FB5368E9028BEC77A27C669408
                                        SHA1:8C2535149A7E9C92312D341C22E891BB8F1F4BEA
                                        SHA-256:449D332AA5DF2C48968471A31BE27C42B3FB77917C3BF9278C7DECC2075DDE08
                                        SHA-512:D759B51D854DE1653E9DA4C19439EED479FE95FC444831155F741EA8664DF1C382372C95712B947877D40816EA0878BEB6B61BCC77478A5661D5DA46FF724F7B
                                        Malicious:false
                                        Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZR......R.t....8]..L.(R.t....8]..L.(R...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............j.......,..R.L....N...^.................K.t..D.j...".........f........................................I.qk..B.....LZ..............j.......,..R.L..........j.......,..R.L.........R......R......R..........................................R.j....R.T.]..R......R..B..R.H....R...B..R...>.)R...J...................;........4...4...4.."..............R..R..R...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........R......R.....#R.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.103557229351409
                                        Encrypted:false
                                        SSDEEP:48:VXs5m3/As4V8t8wElBX89YnToyrdnrgIDdXdHO2Qg:lsiwV87E7X89YnTTRrFBQ
                                        MD5:8E3F3A40F70528B52D640B41393615B8
                                        SHA1:028F683B76F66770B16606DD08EE910E61E2DD4A
                                        SHA-256:C3A359DAD390EC187100D1BAEF7530587040C9DEFEDF28ACCD465DC146EDFE0C
                                        SHA-512:D15F023AE6DF5B75E7FD666155E058C97C4D654FCFCF7A301C8D205AABDBB9E59AE6B13348652027FB913143DBD91F14F6EC57ED5D6612BB7256935A97F51848
                                        Malicious:false
                                        Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZ..`.......`....#eJi[....`....#eJi[....`..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............4..............N...^.................=...>O..sL%.X.........f........................................I.qk..B.....LZ..............4....................4.....................`.......`.......`...........................................`j......`T.]....`.......`..B....`H......`..B....`..>.)..`..J...................;........4...4...4.."................`...`...`..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........`.......`....#..`............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.078796899934866
                                        Encrypted:false
                                        SSDEEP:96:BDsIxNZ4aa44ecEH6X49EqTcRyrjUsZcbRUDSCxUlpbS:BDsIxNZna4nH6X49Eq4RyrjUsZcbRUeL
                                        MD5:E954C0EAE40139772FD6F3AC359F97A1
                                        SHA1:2345253833F89E61B3DCF62E5C7FDCB49D290E58
                                        SHA-256:9A2CE18BCCECD48BBB39B10EDD4879B889E752FD3896C650226F33AEAAC8AB02
                                        SHA-512:957DA0C5DE67A82EB16934D7F55C9F498670282CD73EEBF6FC6BADC5E884388C1B52D79D9E68195362B3000A22A8C9587375F572A100F0BD5DC497F3B994C9FC
                                        Malicious:false
                                        Preview:2...>.......$...v.......................................................................................................................................2...>...........v...L............................I.......I.qk..B.....LZh.......h...5.T.0..V:..h...5.T.0..V:..h....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................k..@.9.b2......N...^................v...y.H.ri~{[.8........f........................................I.qk..B.....LZ...............k..@.9.b2.............k..@.9.b2...........h.......h.......h...........................................h..j....h..T.]..h.......h....B..h..H....h....B..h....>.)h....J...................;........4...4...4.."..............h...h...h....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........h.......h......#h..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.0810584965302965
                                        Encrypted:false
                                        SSDEEP:48:YdssaYlVFsL6e+toJmEErX09RfsTojrdDraIM5dXQAkRsVXE+o31:2ssVVFsL6/TE6X09RsT2RPY5PnVU+o3
                                        MD5:8EB1657245C326CD76007A5DD2FA9429
                                        SHA1:B0DC3B49E6145F698B6F4B63C6755E99DEAF1EA3
                                        SHA-256:EB727FACF099925FC64929EC6B449F5A8747C772111560E746B8DD9C6C115EAD
                                        SHA-512:80C5B2A00CF676146E50119D3ED0DEA66BDDDC5D0D1E5614B2A22F3A7C2B43F952AEEB48D93E4169B1336C31D79B3E2AD668C72DA1B658E00A080AA0889DD148
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.B.......B.(;......g...B.(;......g...B...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............f.A..2.(..D.H......N...^.................SR.h.M....&I.........f........................................I.qk..B.....LZ.............f.A..2.(..D.H...........f.A..2.(..D.H............B.......B.......B...........................................B.j.....B.T.]...B.......B..B...B.H.....B...B...B...>.).B...J...................;........4...4...4.."...............B...B...B...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........B.......B.....#.B.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):3.989841477651738
                                        Encrypted:false
                                        SSDEEP:48:YC7esScMuoj5twtR0EYwFYXrY94mpToMrdmrL/ItdXrz9uQRR+zcF:beshoj560EYfXs9JpTlR2LqOvzc
                                        MD5:BE92061BA87FB00CCCC430983BEAC279
                                        SHA1:A6AB08F1C1B5D8C093C90F55F508AD653D03A199
                                        SHA-256:648A52FF7A3F26CFD7C505BBEF0AE13762F379F91AEFE9EA9926C61E6A2D69F1
                                        SHA-512:CA41F592309D21CBDCC5A61DDB6FF850CD217FCC54D2FD768EEF702DE9EAAF9321EE6047B84411CFFA0DE806D96B92C3031330B9BC92263E5B008BEC6A180038
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................?.......?...O..=.3.vy...I.......I.qk..B.....LZ.?...O..=.3.vy...?...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............9+.(.......KPU:....N...^..................].MyL...4z..........f........................................I.qk..B.....LZ............9+.(.......KPU:........9+.(.......KPU:..........?.......?.......?...........................................?.j.....?.T.]...?.......?...B...?.H.....?...B...?...>.).?...J...................;........4...4...4.."...............?...?...?...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........?.......?.....#.?.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.0658216203795465
                                        Encrypted:false
                                        SSDEEP:48:YlTsiUF396qLtSftyEn6rJXY9VATonrdvlxrsIV6dX8dxlRRN1:8TsSqLsfkEEXY9VATaRHaa7
                                        MD5:E81DA33E977CF9307000C71BCDAA9979
                                        SHA1:77486146213B703ECE0DA0C03E91C867019F9971
                                        SHA-256:A939D43E404FF809C160654C8BF3EC04FF6CC27712CA6CA5943DC768F8479423
                                        SHA-512:060CF20FA6DB32AD3C65D7EC3C06E50B51D533F881D95FDB3AFAE3DC6ABEAE6A85E7A10673623C27A2030AEEF0D1624C6E960C5E9A8ED0B83FFCD28E6E927187
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J......................................O^...?........I.......I.qk..B.....LZ...O^...?............I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............-dOi.{[.3m..*.3.....N...^................/.`j.zF..7@L~..........f........................................I.qk..B.....LZ............-dOi.{[.3m..*.3.........-dOi.{[.3m..*.3.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.04471293985102
                                        Encrypted:false
                                        SSDEEP:48:Y5stXO5U6tPNsKEXgZbcXrc9H0ycToN9rdPr1IwdXERRrjd:qsE5U61hEXgZcXrc91cTORjNQ
                                        MD5:8578929E81288A91B5D8F9A060DF54DD
                                        SHA1:6FE9B27FFB3529045C8034905F35B26D32979505
                                        SHA-256:8D1E22917DF3CCA4A99838D3FFE12DE14BAA70E1103327123B1873CCC4E41394
                                        SHA-512:4F005AF33B81CB57A7CB2974EA3F32DED77F55B17CF8ED57F98C056669417C59C7D104578FECB3A9796609A4B0867110CD880A424ED9D103C7BD387043EEEC06
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J...........................4.......4........K4...S..I.......I.qk..B.....LZ4........K4...S.4....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................K...."H..........N...^.................8..M.M.It..+.(........f........................................I.qk..B.....LZ...............K...."H.................K...."H...............4.......4.......4...........................................4..j....4..T.]..4.......4....B..4..H....4....B..4....>.)4....J...................;........4...4...4.."..............4...4...4....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........4.......4......#4..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.049381364169831
                                        Encrypted:false
                                        SSDEEP:96:uspw0t6elREXXs9fFyTcRIB006Tp4j6Ie5:usp7MquXXs99yARIW06Tp4j6t5
                                        MD5:EAE61373363C05F77EF1922F25A11C31
                                        SHA1:561C010C417DDCBC0D5779FC76B427FE1C345568
                                        SHA-256:3CB1D8FF99F7DD27892CCB37EC118B7D160BFDC457C554393369B87BBA854858
                                        SHA-512:6127E843A0BD3E575BDCE4CBF39BB48D61288560FC791587902B932B37C52B258F029ADE6D75C7DD0DC274E6A69D4D09E1862308A7CE53ABC60F7ADACB91669B
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.........`....%*Yu_'....`....%*Yu_'......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............V.:..E.9.E.#m......N...^...............soM!.d.B......,.........f........................................I.qk..B.....LZ............V.:..E.9.E.#m..........V.:..E.9.E.#m......................................................................j......T.].............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.076672882066051
                                        Encrypted:false
                                        SSDEEP:48:YJfsqccC9fhF5mMP+tY5/tLL2ELh93BXcB9N9tWToNrdP7r8IadXihREJiUK9:ysL5fh3mMP+ORKEfRXY9N9tWTQRf8RQ
                                        MD5:CB1806D2DEED9DC7B4FA536755505D65
                                        SHA1:5128E2C49C330EF153DC32EE22372E4A3D8BCB32
                                        SHA-256:71F38970D572C39D2F924EFA68CF46071F5251F321FC0A1E628BC25E619EDD26
                                        SHA-512:83BF94F00D07B8EBB0FF30DE17457230D8F054F5AB6FF55BEFF966A65D244AE6CF5CD4658DB265EA0A85A7C2693EF4D402FFD573901FA027337097936EA9A16C
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZbu......bu..Q..02....bu..Q..02....bu...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............(..P.7.+..PvqY.....N...^...............C.n...I...'..!O........f........................................I.qk..B.....LZ.............(..P.7.+..PvqY..........(..P.7.+..PvqY..........bu......bu......bu..........................................bu.j....bu.T.]..bu......bu...B..bu.H....bu...B..bu...>.)bu...J...................;........4...4...4.."..............bu..bu..bu...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........bu......bu.....#bu.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.052958661374192
                                        Encrypted:false
                                        SSDEEP:96:zeBsfrrrwr6FKR3OSEFwXE9moITWRemtbqrwrjrXjrrrNrMUbOxu:SsTP26FWAOXE9moIKRem623HPZ
                                        MD5:C52ACDD0720DDA06246E78407D06CEC3
                                        SHA1:69CA179F2C654E7D67A9E3911F9188CDC05E345D
                                        SHA-256:31509345F16DDB0F016DB04B82B5491CF7BCC40661DD378E82BE9D088EAA0BE8
                                        SHA-512:F3DB8EFBF2AB1F40756A6752ADDB10DA112016F735390322098B99A24DF920046A1A58240C1580F010D4EA5BAA5472C16CB2A69291FF7DBF15EF9B683AD29BFD
                                        Malicious:false
                                        Preview:2...>......."...v.......................................................................................................................................2...>.......~...v...J............................I.......I.qk..B.....LZ.k......k...M... ...R/.k...M... ...R/.k..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............Y.=....:..x.D......N...^....................*.N.....C.V........f........................................I.qk..B.....LZ.............Y.=....:..x.D...........Y.=....:..x.D............k......k......k..........................................kj.....kT.]...k......k..B...kH.....k..B...k..>.).k..J...................;........4...4...4.."...............k..k..k..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........k......k....#.k............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.048903631280613
                                        Encrypted:false
                                        SSDEEP:96:5sxVdM7ofFMEjX89VPwqTCJRfHznqMxfZf0I:5sbkotpjX89qqWJRvzb
                                        MD5:B97919DF97B5DB96E3D57FFEC1EE80DD
                                        SHA1:4A082344881568449AE22EEA8AC9C500D1E0C5E3
                                        SHA-256:4FDE914F6D506BC6A6111ACD61369EB5C7FA751D42506323E575E14C80F2C196
                                        SHA-512:A89724C18A4517D008D1BA7C2DB92B4FAA5E1338803D26A274A2AFB0617BDE0EE85DD8055A28A644325EDF4869A11D05D045228751516F6890326C77741578B4
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ4Z^.....4Z^.`.........F4Z^.`.........F4Z^..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............Blw^...... Y.....N...^...............m..I6..@....\A3?........f........................................I.qk..B.....LZ..............Blw^...... Y...........Blw^...... Y..........4Z^.....4Z^.....4Z^.........................................4Z^j....4Z^T.]..4Z^.....4Z^..B..4Z^H....4Z^..B..4Z^..>.)4Z^..J...................;........4...4...4.."..............4Z^.4Z^.4Z^..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........4Z^.....4Z^....#4Z^............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.077753189741639
                                        Encrypted:false
                                        SSDEEP:48:7i6dsnsXIat0gNytDptcEno36XU9Ito0ToRKxrdlrHaIndXZ+kbaf1PXRY8a:7psU0gNyFcEdXU9eDT5xRpry28
                                        MD5:9E4336482AD453AB0EF7AF06E7C01221
                                        SHA1:AE19A7F6050D4606045FDEEC46456627DDC4C884
                                        SHA-256:5989F66522DF587D8A475296D08070A469BB885E642D2BFEBF698F2CB44751DD
                                        SHA-512:9E65FB3DE39FA41AFC971C82F7CDEC088310F546BA75E2DCBA39770C4E02BE7F8DA31C526E3A3B473F31EE09F755F2248970023F1D3171C2CBA34EA87E52E3C5
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZZ.......Z.........:.e...Z.........:.e...Z....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............~Rd..0..fAe.....N...^...............0....C.t.D?..\........f........................................I.qk..B.....LZ..............~Rd..0..fAe...........~Rd..0..fAe..........Z.......Z.......Z...........................................Z..j....Z..T.]..Z.......Z....B..Z..H....Z....B..Z....>.)Z....J...................;........4...4...4.."..............Z...Z...Z....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........Z.......Z......#Z..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.064965064824384
                                        Encrypted:false
                                        SSDEEP:96:BsgYD3GcommYs/AElXo9t8gT6RR7TBxDbgM0Gqk:BsDVoYEdlXo9t8guRRPr9
                                        MD5:7BF269A9F272155FC7F70F7BD0E2FA30
                                        SHA1:FDBF3C1F94E07FA36B295F1F6C2F8E9B0E5F3444
                                        SHA-256:06C1F2D4F4819EB95178FB4AABA67ED06CD7C2BC9677ED41E44164EF18D9142B
                                        SHA-512:99C8C965F1316418F2EAF63EC6FFDDF2CC56D2429F6FC43B9DA4D022444788FB36C6F9025D149064283843BABEA6B4B75C11D118948589E45DD9AE925C4C4EED
                                        Malicious:false
                                        Preview:2...>.......&...v.......................................................................................................................................2...>...........v...N............................I.......I.qk..B.....LZ...........N.A=.+...>G.g...N.A=.+...>G.g.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............-......0LT.".>.....N...^.....................`I....o.%.........f........................................I.qk..B.....LZ............-......0LT.".>.........-......0LT.".>.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.162178488104287
                                        Encrypted:false
                                        SSDEEP:48:zR0xsnm//S2120tEmkEtYXc9zBXToY9FrdjrmIc2dX9D7T6GHdig:ms812023EyXc99XT3RvbzB
                                        MD5:4FD0F45B090F6A0E15800B9F4BCF533E
                                        SHA1:CD895132D04BB13F6B86C7EDBB5DB84ED749CA29
                                        SHA-256:8E21E42B7646B3F4F1640309ACEBFF89626708F39055CA21D72395DD9EC8E054
                                        SHA-512:6B04C83B110E3D0DF0876F9A9230EB0C1F10E23D33910AB9C1D0546FA5842CA06737C9775563ECD69D97BDDCC70FB4656712EFE3EC4C665518AD195003906B7B
                                        Malicious:false
                                        Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZ..............&.3.X.......&.3.X......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................,z|..5.V-.......N...^................1$dAswC.T..............f........................................I.qk..B.....LZ...............,z|..5.V-..............,z|..5.V-...........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.178390585954608
                                        Encrypted:false
                                        SSDEEP:96:WsTkVcw8QzKdAEPcXs9XTcRInMcwc70mh:WsTFezAdkXs9XoRInf
                                        MD5:2400DE23BC922D7B11EBCBA88A05BE66
                                        SHA1:A68790918957C1616E1FB832016906800D1B9506
                                        SHA-256:A831ABEE7836615A0D6CC1EEDAF2B91D3F28879A6014E260816FD87B9958F2C4
                                        SHA-512:11CCA27527276B9195D6B0D43E094AD22BCF6E90C67AA5550F63D5FE28553C383D14D340AA5268E5FDFA7EE8FA36196A1E50C4729DBA478E75FCC21B3BAA871C
                                        Malicious:false
                                        Preview:2...>.......0...v...$.................................................?....?............................................................................2...>...........v...X............................I.......I.qk..B.....LZam......am..Ae.....h..am..Ae.....h..am...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................3...2....H,}....N...^...............z@.\4dH.E.k............f........................................I.qk..B.....LZ................3...2....H,}............3...2....H,}.........am......am......am..........................................am.j....am.T.]..am......am..B..am.H....am...B..am...>.)am...J...................;........4...4...4.."..............am..am..am...z...y.. x.. ...........$........4......7...7........................;........4...4...4.........am......am.....#am.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.137505493732325
                                        Encrypted:false
                                        SSDEEP:48:Gf2sPrmVvKHtgdWBKeEBAC+rCX89ICD2ToTrdSr0IwdXkSJMKJ:Rs6VvKHKdsdEBA7WX896TKRKC+K
                                        MD5:06C3F072170063A244E9E613BAA0E075
                                        SHA1:723BF60A8739A9DABF30375709DBF9C8EE3242DD
                                        SHA-256:F63E28E40DE9B659CBEFC6067A663BB20890D375C5EED201CB55BF9DE1D7A028
                                        SHA-512:7390054A115C5ADAC7D60FBFACD6CFEE4D68F964708BF17312CB8C5266317C37EF5E763894C6B0E07A2E270DC194B2235BBB899435EB990954C286ABCAE8FD72
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.............5.(....v.....5.(....v.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............9../.7.m.......N...^...............dRkz...A...8&k..........f........................................I.qk..B.....LZ..............9../.7.m.............9../.7.m...........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.124274531231
                                        Encrypted:false
                                        SSDEEP:48:FtgksGXADqtduDyE7CWnXc963+nToMrdSrmIRdXfOigh:FtgkslDqvu+E7dXc968TpRKZ6
                                        MD5:1CBDCAC1C750B80B66943FB24EB4E2B2
                                        SHA1:5A56B26B1F6CEAF397173A5CF4445AB49097B0DE
                                        SHA-256:FDFB5C0862687A689DD546BD1DB75A3A8A32D7592A7E7173A4724FBC4096BE58
                                        SHA-512:659ED60FEA586D69C402BA15C5D45687AF97EDD11C90FE66F2E58858094A5A49158EF9CFC3D1B4853AFD318BEA2D8A1329A30BE67D5CEE127A4496B3360B4A71
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..............{j..!........{j..!.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............./G.~SA...Z.dq......N...^.................,..@...&.Zd$........f........................................I.qk..B.....LZ............/G.~SA...Z.dq........../G.~SA...Z.dq......................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4......7...7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.129322471264205
                                        Encrypted:false
                                        SSDEEP:48:tsxGTj63lstT82EEC/VX89cP8gmNHToCrdSrrIfdX56kg7O/zk5/Jf:tsN3lsNjEEoX89cP8fTHRKcc
                                        MD5:FED023B6945539C025F8375090B1680A
                                        SHA1:6ECF15371F776BE5B82121B67DEFAFF4DFBE4366
                                        SHA-256:235807C46C4A372A8243CD319D1950131752A8748164A413CB15BF4DC525562D
                                        SHA-512:42BD7BC6ABF26C3277108AD46E5CDA36A2F42E21C4B266B6A427C38389ED7B2C4CBA698BC45E34A652C3EEC974C5C945D0999C102F2D6C309A0B7F191C18F4ED
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ9.......9...!R..4B....a.9...!R..4B....a.9....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............>.&.?...).H.........N...^................l.R6.rM..o\.h..........f........................................I.qk..B.....LZ............>.&.?...).H.............>.&.?...).H..............9.......9.......9...........................................9..j....9..T.]..9.......9....B..9..H....9....B..9....>.)9....J...................;........4...4...4.."..............9...9...9....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........9.......9......#9..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.11656594589611
                                        Encrypted:false
                                        SSDEEP:48:1sUeA9HbuRVktIKE2CHEXk9F9bCwdToSrdSrKIzdXtn2sba2smkVPh:1sUNbcVkZE2RXk96gT7RK3XRbaFmkVP
                                        MD5:4D816E7BC31BF9EB689597A9EC21BE21
                                        SHA1:8A045C9631BE2F679A29EDF098D588AA76A4B402
                                        SHA-256:D4AA1CA48E509AFB82C2ADE385D583F5D031C42C24C0EDE4CC8F5BD52C1248D8
                                        SHA-512:C5BBF60F10266E70F0BED43741C2A756BFBD2B03A8160220D9B52BBEC4F6316D8D1EB8AB0C6854011F9B573BFD417674835A6995191C033172177D13BE7E86C3
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..~.......~......4...`L...~......4...`L...~..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............~!..{.N....q........N...^................"5....O....F.U.........f........................................I.qk..B.....LZ............~!..{.N....q............~!..{.N....q...............~.......~.......~...........................................~j......~T.]....~.......~..B....~H......~..B....~..>.)..~..J...................;........4...4...4.."................~...~...~..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........~.......~....#..~............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.1133963789518875
                                        Encrypted:false
                                        SSDEEP:48:ls1IKtJSGvt4DSEG9CCZ3XkrR97N1/ToexrdSr1IRdXRxyI2EyHVr:lsDTSGvmOEinXQR9nTfxRKc2fHV
                                        MD5:2A8EAC5DB72717AB93EADF1237AD2A42
                                        SHA1:B91E063CAD20D5B23194ACF24679899B39475A9F
                                        SHA-256:35F6BEF2EDD8865CF99BA08672EA8902A340A3AD514D6FBB3E3114DF951AB58B
                                        SHA-512:2E3C4AE8B8FE1C0AAF9C0658A1F6A06A0CE6DB6D2AC45322D1E77805FA78BDBFD66B35C9884FCBE6211461997348CDC91788A92B448A652AA21FD61A59E45E79
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ............NQ......./......NQ......./.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............|..Qn........WK....N...^.................c.:h.D..-.............f........................................I.qk..B.....LZ............|..Qn........WK........|..Qn........WK........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.129003269432336
                                        Encrypted:false
                                        SSDEEP:48:aIsNB65GXIC5tkGEnpDCZPCXY9PZUm0ToprdSrBIedX+m6Zit:ds3bIC5JE1JXY9B10TkRKDV
                                        MD5:93EFEA607D27EBE63F1C82A955CB1D61
                                        SHA1:7748E9802C28E8FD7F7C5836F6680F88B3E200AB
                                        SHA-256:CA0FC933F59842E7B4293FBBCA93397EDE91139FD3CF76386F5B75AC4DC2E17D
                                        SHA-512:0D7B4D8AF94E1061DB358D9687ADCE45D9467DFCBF386E7C5E15F6604688BBF3D0A5CB66E78E6BC11BCC11458AA789AB914AE4BD15CB7ED88C1D328A0F7A91DC
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ-.......-.........9v.4..-.........9v.4..-....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............A..Ts.q....BO.......N...^................5.M..*M.P...O#.........f........................................I.qk..B.....LZ............A..Ts.q....BO...........A..Ts.q....BO............-.......-.......-...........................................-..j....-..T.]..-.......-....B..-..H....-....B..-....>.)-....J...................;........4...4...4.."..............-...-...-....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........-.......-......#-..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.110281473215743
                                        Encrypted:false
                                        SSDEEP:48:9iGsov9zlcoHNtAMUeEmCKyqXRq9wwgToNrdSrDQIEI+dXuy7sSp:9vsEGotqkEmTX894TIRKDDcl
                                        MD5:11F979140D8040C8076380BC89716A4E
                                        SHA1:99EE05BB438745113EE11E655E4BB2AD20D8D462
                                        SHA-256:D81300FE4155AE761DCD06CB43C4AE9B80CF57DEA328119BB34572B6DC977BEE
                                        SHA-512:6DEEE030CFC04278E34A312AE634CB064BA704C77868A340CC50EAC13563E90394B18A1F38F07E63AB577E71412FD52B0689E14C4CA1341224BFFF21DB23D895
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ0.n.....0.n...e.....?.0.n...e.....?.0.n..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............`...C.,.'.....R....N...^.................f.=.jJ...C."..........f........................................I.qk..B.....LZ............`...C.,.'.....R........`...C.,.'.....R.........0.n.....0.n.....0.n.........................................0.nj....0.nT.]..0.n.....0.n..B..0.nH....0.n..B..0.n..>.)0.n..J...................;........4...4...4.."..............0.n.0.n.0.n..z...y.. x.. ...........$........4......7...7........................;........4...4...4.........0.n.....0.n....#0.n............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.12555936796589
                                        Encrypted:false
                                        SSDEEP:96:K0sMiVE3XpUcOWgbElCPXI9ZAHTHRKHm41EtU5lHrD4NTh:bsZMp9gYuXI9SjRKHm4vnD4Bh
                                        MD5:3C108E337613EA3EDA9E69B0C3EFB8CE
                                        SHA1:D6BCD1B188C35690A66E753A160F266B152505E4
                                        SHA-256:AE11E73D7D67716D1104E42ED52A60F179325D36B486B3E2C7F7787FF5CE8E9F
                                        SHA-512:9A70E21172F1DCD55076D5F461D43491B527B368D2D543AE8CAD8974E1113D2234342B595052613A00EA566417F471D10DFE4102746ECCE51D8037F8B3240297
                                        Malicious:false
                                        Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ.(w......(wK..D....;...(wK..D....;...(w..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............pN:.......s.a3......N...^...............?{..Kz.A..~............f........................................I.qk..B.....LZ............pN:.......s.a3..........pN:.......s.a3............(w......(w......(w..........................................(wj.....(wT.]...(w......(w..B...(wH.....(w..B...(w..>.).(w..J...................;........4...4...4.."...............(w..(w..(w..z...y.. x.. ...........$........4......7...7........................;........4...4...4..........(w......(w....#.(w............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.09141609708951
                                        Encrypted:false
                                        SSDEEP:48:K0szsG2OYjtuXME6tiC+GfXY9B6JN0ToxrdSrsgIGdXgDJ0Q3yjN:K0sj/YjlE6c7IXY9B6UTsRKs0T
                                        MD5:740C33FF63C21CC32D0C8F64DD27328C
                                        SHA1:8B9AB670FF59D52F5F7B31ED500671DD09B870C6
                                        SHA-256:EEB50C96C1EB4077D91C44525CBB6630EBBFF31BA762863AE66B91420E4EC06F
                                        SHA-512:47A5FB590C6C777145B05CF3A3528B1F4291690100A5A62FC6F862556ED8C0ED0EA0CAEE42AF1188BF4D3AA9C3DB01F40B7D3ED2E9385E3670AC879AD094B01E
                                        Malicious:false
                                        Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ.............C..2....`.\.....C..2....`.\.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................'4_...`..N=K....N...^...................m1-K...............f........................................I.qk..B.....LZ................'4_...`..N=K............'4_...`..N=K........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.106986687580678
                                        Encrypted:false
                                        SSDEEP:48:QICsLTcOs2jktf2EIWCCYVUXzU9tMlzTo56rdSrqIW2dX3lRJU+d:QPszDjkQEPyUXzU9tcTU6RK1vt
                                        MD5:BCCD07A1434FF550B6B0CDC69694043B
                                        SHA1:44DEA4F0CE5E5CD1CF6C48350D053F923F438243
                                        SHA-256:D64DB0865B998316C888B4D410996868D2A06CF02D0800207D7995231BB0EECB
                                        SHA-512:1E938AFE9A9D8AB30742CAE804058E5AE981D3B7C6A0C7AB1ED1C86100EA83D3B786CE9684C15C887B98B557DFAA1D2D45D879A0AF1D9C84A0E5E46C4F09C15A
                                        Malicious:false
                                        Preview:2...>...........v..."...................................................................................................................................2...>...........v...V............................I.......I.qk..B.....LZ...........O#S...&...R.....O#S...&...R.......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............n.D.......2zR....N...^................u.z.. I..h.fk)........f........................................I.qk..B.....LZ.............n.D.......2zR.........n.D.......2zR........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.118924767101091
                                        Encrypted:false
                                        SSDEEP:48:TQ0sfhg42Bt46EVC/tXw9Bs2OTo/rdSrbeIkdXUlajM5U3aoeV4:Bsr2BBEVoXw9BgTWRKgr
                                        MD5:6D5246B63EF586656D4A42337003407C
                                        SHA1:988C54FDA90C2C956C8457E81C87710D809B6065
                                        SHA-256:6B015925E7139DB77E3BA6FDAD936CE10DA07A80259FF11691B782252B6DC1A5
                                        SHA-512:FD06EBAD5F5A41BC264C3C049630A51C5C1F879270DE3A216ADB3864AE3CD3B819896E0B16FDC7733336DA13218ED6612D6842ECF47A74502986FE4BE359925F
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..1.......1....!.Kn|...1....!.Kn|...1..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............hV.*.n......t......N...^.....................UC.Z..K..........f........................................I.qk..B.....LZ.............hV.*.n......t...........hV.*.n......t.............1.......1.......1...........................................1j......1T.]....1.......1..B....1H......1..B....1..>.)..1..J...................;........4...4...4.."................1...1...1..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........1.......1....#..1............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.102608002939301
                                        Encrypted:false
                                        SSDEEP:48:5sFQuKwDxeJtSN+EsWCjtgXY9rrwToNrdSrZIydX6K8C1:5snxeJsYEsWMSXY9gTARK31
                                        MD5:8E1321BEE14145676DFA20A0C658A444
                                        SHA1:653136011449411C8BECC77B12661573AE367F8F
                                        SHA-256:20DBA010946CDB64BABE24ABDD9D4F08893EF6C6463AD3898EF9FBCB8C2AC9EF
                                        SHA-512:CCA86D456A6EB36965534BD2C8E73A02EE0025D252DE8549CF11C77D04619BBAF98A7126B5F4D0B61B95C537056180A53AC14AFDDB21DAF26DAFFF8FA281FFB2
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ.y.......y.M......!km...y.M......!km...y...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................3.......{!......N...^...................o..M.7)............f........................................I.qk..B.....LZ...............3.......{!.............3.......{!............y.......y.......y...........................................y.j.....y.T.]...y.......y...B...y.H.....y...B...y...>.).y...J...................;........4...4...4.."...............y...y...y...z...y.. x.. ...........$........4......7...7........................;........4...4...4..........y.......y.....#.y.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.137195836417298
                                        Encrypted:false
                                        SSDEEP:96:psnQ/gT274/LJER3caXo9ppT9RKK2eh/lGwv:psRT27eSxDXo9jpRKK2e
                                        MD5:140432783C43F1BFAB133B57EE0B3176
                                        SHA1:3131C1BD8273FD95184F1D9D701AC06A31220CD8
                                        SHA-256:4B692EA1C756572D6AE11F863CFD6A97259356B565B89E740E626154D18DEDA5
                                        SHA-512:041427509DB69EC94837698BFDC3A6ADBE66A74006B18C40D3C4E3935188C22EE9A83CACB0FCAABD09CDFAC74AD8EE5E421A1E50AB6950764274486C8B2C2571
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..P.......P.I.Z.....F.Y ..P.I.Z.....F.Y ..P..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............\#.....?.....[....N...^....................D.'..9Ya.........f........................................I.qk..B.....LZ.............\#.....?.....[.........\#.....?.....[...........P.......P.......P...........................................Pj......PT.]....P.......P..B....PH......P..B....P..>.)..P..J...................;........4...4...4.."................P...P...P..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........P.......P....#..P............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.100925409765434
                                        Encrypted:false
                                        SSDEEP:96:dNps0et5hENA1s2rXc9ZKGTN9RKsxf6r:Zs0etsyrXc9QGPRKsx
                                        MD5:E7B918F87F0A429CA3653E58ECE9E819
                                        SHA1:68B17D7F8816327D6C7CFBE5D01A51FF6FC4B341
                                        SHA-256:331E7FD4F64BA1A2CFAAC33CE7A1F3A6F93D39A3E1D87BFC1174A6E64F1FDC5F
                                        SHA-512:E686B75369C70D96E6E9218B474E008C1396638D6D5A6177955A153C403B201A334CA94FB093CBE8401677D0421C2B5033BA98B88946A20A0A8B020471907C93
                                        Malicious:false
                                        Preview:2...>.......*...v.......................................................................................................................................2...>...........v...R............................I.......I.qk..B.....LZ..{.......{..v..2.k.IA...{..v..2.k.IA...{..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............D...5.....=.......N...^................-q.f4.B.....L1.........f........................................I.qk..B.....LZ..............D...5.....=.............D...5.....=..............{.......{.......{...........................................{j......{T.]....{.......{..B....{H......{..B....{..>.)..{..J...................;........4...4...4.."................{...{...{..z...y.. x.. ...........$........4......7...7........................;........4...4...4...........{.......{....#..{............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.1494917095775055
                                        Encrypted:false
                                        SSDEEP:48:KC1sBKXyfTjZZ9tUcMEEyrCQGXw9poEoSk3ToYrdSrHhI9dXD2uN0QpmouQpunLF:KIsmWTjT9f1Eyr2Xw9pz2TxRKHEPk
                                        MD5:0CBBA41760A6954B8B8532094C27055F
                                        SHA1:9FD49A38DDC5D782027CA572C5B6C342D5353CB2
                                        SHA-256:A3FAD901F6340561E7955530AB908F92782C5DB873B193AF1B4AF2FB570573FB
                                        SHA-512:FAC67E7339EE713565BDCE2FD6A32ACBBC93A6ABAB8D941E8BDE2EA3350C7EE289EC6A0550E15CEE408F4D769647EFC8949F6975822835D8410E273BC64A316A
                                        Malicious:false
                                        Preview:2...>.......,...v... ...................................................................................................................................2...>...........v...T............................I.......I.qk..B.....LZ...........+]...s@Wq.tz...+]...s@Wq.tz.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................)T..1L.t..".....N...^...............z.N.=T4O......j.........f........................................I.qk..B.....LZ................)T..1L.t..".............)T..1L.t..".........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4......7...7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.097837369470074
                                        Encrypted:false
                                        SSDEEP:96:7s3NnncaEXhXO9tCRTpRKkD4VT9LET4As5W:7spn0xXO9t0dRKk2B
                                        MD5:1E12F10F78568C513C3C986A731AD1BF
                                        SHA1:6A0E246DDC455BB6991B19DF3BA69A5FF8E62E7E
                                        SHA-256:BBECDF0B6F18CE5F5BE4F4743606524A18E60FAA2D6E46E7FE9999311F445351
                                        SHA-512:E6B5A2092E0ADE23FCC0EDDC956149B941A1858C9CA9123312F539AF45993FC1BC454FB9D6E42938032E305801147F463DA5A5354880BA3267042352CECEF690
                                        Malicious:false
                                        Preview:2...>.......(...v.......................................................................................................................................2...>...........v...P............................I.......I.qk..B.....LZ#.......#...s'....-.....#...s'....-.....#....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............{U.:..)..0.......N...^................x..%.!H.[...*.m........f........................................I.qk..B.....LZ.............{U.:..)..0............{U.:..)..0............#.......#.......#...........................................#..j....#..T.]..#.......#...B..#..H....#....B..#....>.)#....J...................;........4...4...4.."..............#...#...#....z...y.. x.. ...........$........4......7...7........................;........4...4...4.........#.......#......##..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):3.5471449948187765
                                        Encrypted:false
                                        SSDEEP:96:6So9yfc5zLC5qwryieLEG4IgE8usMFc4IrH4I8XglA:69RRmqJ1IO9zsGUrX8Q+
                                        MD5:722BAFA2D55EAAFF257119317A11D16B
                                        SHA1:E8B64CC7B5CA7E30D0C93C28D49BEB6DA5CBBC26
                                        SHA-256:FEFC970F1BEFBC64593066E28142A0DDBAFFA101D64C9B85AA4640207DA2A5BE
                                        SHA-512:520C542FA876166924EBB39D4C64EEE8A48192D9A5894BF1BBC32D70C5EF81430B65020EA209A3938A1929F8B869AAE6003EBDDC483346E9A74921A553391078
                                        Malicious:false
                                        Preview:<...,...............................................................................................?...................................................<...,...............,...............................................C].0.............3.M....`.... -.q;...f.txUC.. ..9.....$.{....>.9..&..i.......#:s6&............&.......&.................................................... ....... -.q;...f.txUC..m.......m...IG...8....2.......^...p...............P............. ...m..&......9........d.T)......T.....l2T.s....mT.2...V.T.....&.T)O..&...."..&....n..................c..,0...e...B4.$...........GP..A..}.....J....................F_x.....F_x....3..$q..t.&.......&.=.NM.....y..............C].0.....V...G.C...q.\`..V....m...IG...8......m.....>...|............9.....$.{....>&..i.......#:s6.&.=.NM.....y............0...........e....4.............."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w.......B.^....F...r.QH.....(...........(..."...P.r.o.j.e.c.t. .O.v.e.r.v.i.e.w...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):4.616452128356718
                                        Encrypted:false
                                        SSDEEP:384:epcRkbrUX8fT07FAizeM8xRtz/nBiula7ud06FSkguw4xPWNwjvGELxEz/mG:epc6brUX8fTSFAge7xRp/ng8ayd06FSd
                                        MD5:EC3D5A894E587ECEA4365DCC55AD3F2E
                                        SHA1:18C967A4A40F0EBC7A7D8DF7CA6110AD2F027623
                                        SHA-256:8D0DE4AF6753493336AB3C114150E115B3B400AF6270A90E1BFFF966D5B1F92D
                                        SHA-512:CE9E578DB38430E4273DFD2015E63576481E686D3155818AE634EBBA6D6558AAF42F29FF384448473F745DFFCF779D53BDF19211670632ADEE536FECB0193C16
                                        Malicious:false
                                        Preview:....>...........v........@..( ..`J..........>...t...8...v........H..( ..PI..................................................................................>...........v........I..( ...I...............I.......I.qk..B.....LZ.&.......&........~@....&........~@...&....I...~.....u..o..I..I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'.................q...:.g..ajw....N...^................4A..AWD...................J...............................4....I.qk..B.....LZ................q...:.g..ajw..................................&.......&.......&............................................I(.6....I(.z....I ......I$......I ......I(.5....I ......I$.........&.3.&.8.&...z...y.. x.. ...........$........!..7!..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.3..............Z4...........................................4../4......p...............C.a.l.i.b.r.i.....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                        Category:dropped
                                        Size (bytes):22203
                                        Entropy (8bit):6.977175130747846
                                        Encrypted:false
                                        SSDEEP:192:5q3R1VBvq3R1Flrk6Q0QPJJrR39joOVMJ25d1NkMhIwobbtAAAqYnLJZMJYZ2AC:xw6Q0WJR3FoOVMJIIlAAAqYnMJdD
                                        MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                        SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                        SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                        SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):3.966008462578475
                                        Encrypted:false
                                        SSDEEP:96:/ssZK7MgYXfNP3YR/pxyKyuepdWE8d9tJkfqJ3JkfCynzw:/s4K7MgYXFP3YR/pRKp8d9tmfq3mfPz
                                        MD5:A8E279ECF1E65530B3EBEBD35E67216D
                                        SHA1:4F9FF354688F111D40D720D5E3FCD268C496AC5D
                                        SHA-256:2BB9E631EB4543E36F5C6855F758D03225C9551A6F05F14F2770667CD6ABF418
                                        SHA-512:96311242D7E1F1C61C70508A53ECD849E9F4ABD0470D08F04951F93C83B36253CA6B3CA5AF5B5A227A504D61186D31D74B4C25CB520786B034E77E80741C747F
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>.......Z...v...&............................I.......I.qk..B.....LZ....)....../...).k......../...).k..........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............9Ss...=...?.4.~....N...^...............>.P....D.E.;q...................................................I.qk..B.....LZ............9Ss...=...?.4.~........9Ss...=...?.4.~........................................................................j.h.....T)................L.....H.]...............H.......}.......Z4...........................................4../4......p...............C.a.l.i.b.r.i...............................z...y.. x.. ...........$........4...!..7!..7..................:...F...G.....z...y.. x.. ...........$..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):52945
                                        Entropy (8bit):7.6490972666456765
                                        Encrypted:false
                                        SSDEEP:768:cjvqR0XvFaGCTJffi0tgybmWDoTw71kHUAnjvawrlp2+NUO8dWSNl3PF2PjK/q09:cyRffflgybmWoTw1UUADHUbU21MjpAD
                                        MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                        SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                        SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                        SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.533305612496011
                                        Encrypted:false
                                        SSDEEP:192:8xsgWjq3RTv15LP4/HTNUicXzkJs4OEcRtZ3jRA4YWI0daoe10tAxc9kNHfoHDUM:v0v34/HTNUfIs/dRtl/ji10tAGkNHgYM
                                        MD5:FAF62599DEDFDB56FECD0A3CE0E98CEA
                                        SHA1:E7A634E712166105C971E9F73AF67646CBBD7563
                                        SHA-256:B14198D8BB4C802544F9D904C2A81A016C00E4278D119AE12EA0CCBEF807D882
                                        SHA-512:BAC82D8CBEA7C6FBF6D8313EBCE2BDE30379FDE71435C13122C58433F2E6C3EDD7229B37F260E39FF6C1D247608A36AF0F01F7175715C6195C2CD3CC80F7DC5C
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>.......@...v................................I.......I.qk..B.....LZ.Zm.9....Zm...|.3.z.....Zm...|.3.z.....Zm..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................F...4..?ClR....N...^...............`.u..&{A..[................................................r....I.qk..B.....LZ................F...4..?ClR............F...4..?ClR..........Zm......Zm......Zm..........................................Zmj.....ZmT.H...Zm......Zm..\...ZmH.....Zm..3...Zm..O...Zm..........Z4...........................................4../4......p...............C.a.l.i.b.r.i...................Zm..Zm..Zm..z...y.. x.. ...........$........4...!..7!..7................Zm:.ZmF.Zm..z...y.. x.. ...........$......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):25622
                                        Entropy (8bit):7.058784902089801
                                        Encrypted:false
                                        SSDEEP:384:EhK81gTCyJ/Gf9Aw3t8w8EtdPeGDh6bEi1Ie1u4ZbvgwTwrSRh7ZKNpIGY:IjcRXwdJvtdGsUbEi1IeY8vgwTyC1+Y
                                        MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                        SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                        SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                        SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):3.196909638775678
                                        Encrypted:false
                                        SSDEEP:384:VYfhZAb85bVgeO+Y5yVzyMlq2RS3KihfnWa/BLP2DTCD4s:VYfm85bVgoY5yVzDlq2RkKihfnWaZLP
                                        MD5:F8CABFB88A95CAF9361F2C2AFE468890
                                        SHA1:90C948BA73B3C7E2FECC8F37716C99BA5F851E2D
                                        SHA-256:D32B75D0B00A750E3223EA126E7F01B38AD6771FBD95CF49ABBA73FD896B525B
                                        SHA-512:3CEC2C80B949ED49A48011E694B1B9D7317727701274E2804A88EAB1AEF41C806600215A9D0AEA258D772120F86F767A5E9243CA2734DDCDF2F804286526BEE2
                                        Malicious:false
                                        Preview:2...>...........v.......0 .../..........3g...G.q.In............3g...G.q.In.....I.qk..B.....LZ................................2...>.......B...v........-..............v........-..8....................I.......I.qk..B.....LZ.}..T....}..R..........}..R..........}...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................3g...G.q.In....N...^.................3...5E.yA>Ag.(............................3g...G.q.In..........3...5E.yA>Ag.(................3g...G.q.In..................................}.......}.......}...........................................}.j.e...}.T.....}.......}......}...a...}.......}.......}. .H.......z.......R...................!..7......}.....W.i.n.g.d.i.n.g.s. .3.......................Z4...........................................4../4......p...............C.a.l.i.b.r.i...................}...z... ..$..............
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):15740
                                        Entropy (8bit):6.0674556182683945
                                        Encrypted:false
                                        SSDEEP:192:Elv3GG8/OOs+GouFdxMlxjoPyerzkpuOo2vPMc62PaJseZC+BJoS/:EtNiwdxMlZoPhzkpuOo2PMc6rX8+B6+
                                        MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                        SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                        SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                        SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.7654199325489284
                                        Encrypted:false
                                        SSDEEP:192:dsxJvdev00rSudnSBF8WXjgZUk8RtV6yG2wxD2sO4XeNl9Ug6knhOvn:ixJsc0rSgmfjgmk8Rt0yVwE6XeNHd6kQ
                                        MD5:3F993C1E803F83DE5718EFF41AE77A6A
                                        SHA1:8B5BEA60A86F0603EA6B544F36F6840EA0860953
                                        SHA-256:25260E55CE2C518A16954D43ED59B2204B27F26B21D3B5D03CAA90F29693731A
                                        SHA-512:2CEA08FDC219EB40ED6D41D94BDF00894AA122EB66F34E9B257B379D6065EB630FBD319077E5AAA0315FF392AC2B2045ADEC3979703730DCC464FD5E11689B3B
                                        Malicious:false
                                        Preview:2...>...x.......v........ ..`!..2...>...........v.......@................................................................................................................................................I.......I.qk..B.....LZK...9...K...x.....$...bK...x.....$...bK....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............B.T.T'0......$'....N...^................[.\C..@.....D'j.................................................I.qk..B.....LZ............B.T.T'0......$'.................................K.......K.......K...........................................K..j....K..T.Q..K.......K....n..K..H....K....9..K....V..K............Z4...........................................4../4......p...............C.a.l.i.b.r.i..................K...K...K....z...y.. x.. ...........$........4...!..7!..7..............'K..%K...K....z...,4. ...........$>........4
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):55804
                                        Entropy (8bit):7.433623355028275
                                        Encrypted:false
                                        SSDEEP:1536:gVvci05lhVbfBcWvBLeynluexaWqzww/u5:gVUZhHDljaHww/u5
                                        MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                        SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                        SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                        SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.711693632604244
                                        Encrypted:false
                                        SSDEEP:192:usaFrOxP6/ohZ7IQUwqo4PIxe+0aP7SZHCPT/aXTom/3kRtl0f/9PzF4PQ7P09ey:baZOh6/or7MwqoCf/EwMj0eRtifdzFCv
                                        MD5:5AE8E7A0BD684AE809DF8D0650B3D36F
                                        SHA1:002B5B6B60198EAA6F1E076514C3C668FB8DF14E
                                        SHA-256:E98CD0ADCF32C1542DC012588597A1CE29F8623BF8C77389655988C2938457BF
                                        SHA-512:6AED44BFB9B1A700D35B0AA67B482E9FE3F67CDAA2E005AEF2EFE4BB1DC9F5E7E1992CF1DB52ED42E8B45E633BCAC9C4728E5C8FBC2F8E32DFC2B1D6CFC875CE
                                        Malicious:false
                                        Preview:....>.......^...v...2...0 ...+......>...........v...z...@....*...........................................................................................................................................I.......I.qk..B.....LZB.......B....|...N-.M.Q.B....|...N-.M.Q.B.....A(.@..{....W....I.qk..B.....LZ.I............I.......I...................................................I.t.....I................................................................4..'...'.............Y..g...B..ZqD.\...........................N..&.M..M.5.@.....N...^........................................I.qk..B.....LZ..............N..&.M..M.5.@..................................B.......B.......B...........................................B..j.N..B..T)...B.......B...f..B.......B.. .<..B......B.. .......'B..8B....z...,4. ...."......$>........4.."..7......A.g.e.n.d.a.:.........................Z4...........................................4../4......p...............C.a.l.i.b.r.i..................B...B...B....z...y.. x.. ..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):41893
                                        Entropy (8bit):7.52654558351485
                                        Encrypted:false
                                        SSDEEP:768:pZvVQkUbOHxx3pvVmO5rsP5gUdXwFMuv53knzyncaXgRDqPU:pZkijV5wScXwFMYknzucaXgRyU
                                        MD5:F25427EFECFEE786D5A9F630726DD140
                                        SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                        SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                        SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):4.573016741618155
                                        Encrypted:false
                                        SSDEEP:192:DsrSs/XqhgXPBF9KQB/uBmFdU9ppadf3OBvBWHWD0wXuxa/YEgSs+RttHBtVpFBa:4msmgXPBH9B/uB2U9+t3OBvB2WnzNXsD
                                        MD5:2A5B5619070A7AB9AD97988A85BDA681
                                        SHA1:780849B12545FBB26603B97D35DBDED622F69B1D
                                        SHA-256:643836D5E196B56997FA08662FD2A8029755B88B635315A15C71FF7B542F32FF
                                        SHA-512:C45F56B11B0D846CD588BD0F691785267872F1DB670DF0881AFFF7C45721BB3630595106E6FD90782BDB1C5BB4D17AD85FCCF8899E558924B8E9F962E97CD607
                                        Malicious:false
                                        Preview:2...>.......,...v....... .. +..2...>.......|...v...H...@....*...........................................................................................................................................I.......I.qk..B.....LZ..t.G.....tC.7%.7F..M7....tC.7%.7F..M7....t..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............!......4....Lp#....N...^................M....E..E.bm.........V...x....................................I.qk..B.....LZ.............!......4....Lp#...................................t.......t.......t...........................................tj.A....tT......t.......t..r....t.......t .7....t.......t .........Z4...........................................4../4......p...............C.a.l.i.b.r.i....................t...t...t..z...y.. x.. ...........$........4...!..7!..7.................t;..t...t..z...y.. x.. ...........$......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):14177
                                        Entropy (8bit):5.705782002886174
                                        Encrypted:false
                                        SSDEEP:192:EbgGcV/hlvpfal7rgYa8S7auAxwfuSTmCSNoFQ6NO7L:EbgGcVnpwimnd38FdQL
                                        MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                        SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                        SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                        SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49152
                                        Entropy (8bit):4.63228295739128
                                        Encrypted:false
                                        SSDEEP:768:UaNEZvx5tEZ7yDngcFOBDMSHJ3LhiuCzeA:9Ehx56lyDgBDXHJ3LMn
                                        MD5:94BBC64DDA05FC3856032A40AFD961C5
                                        SHA1:17E8320EC32A84FD7A58C4C9372AA9B19AE9CF66
                                        SHA-256:A565FFC6771AFF70C82A477DD592F61659DDC34E0A52A368C21FCBF6ED5B6A5C
                                        SHA-512:57C59A3493947D117D38681C316A5161381A0C62D2790F0BF6B078B45AAD093FA1A53B9519187079B3B092325C55D9757A3789E49149B7A12B33BEC283AF8A32
                                        Malicious:false
                                        Preview:....r....&......f%.."&..8... ..H@..@`..............r....%......f%..>&..... ..H@..@`..h...................................................................r....%......f%......H... ..H@..@`.........X.......X....7....=b..+.PM......PM.Q.R...j....ntC.V.<7.. ..-.l.NC.V...I.z.p..{.O.....I..p..tW...+f.0oL.p...........n.a.....n.a....................................................T$......T....rT.T%......T"...%..T.....4(T.....f-T%....<5T.............0...........e....4........................u.^s.Q.@.).~b.......(...@kO.....(..."...P.l.a.i.n. .a.n.d. .S.i.m.p.l.e...j...P.a.g.e.L.o.c.I.D...L.o.c.V.e.r...P.a.g.e.V.e.r.C.o.m.m.e.n.t...P.a.g.e.O.v.e.r.i.d.e...P.a.g.e.N.a.m.e...2...0.0.0.5.2...1.....0...U.n.t.i.t.l.e.d. .p.a.g.e..........}+......}+.O.....@..#..f-......f-...}D.d...PA.2.......N........$..............PM..........p0......m...rT...........Z(......k.*..c..,0...e...B4.$........{p.....G...^...?@kO...................;/i.....;/i....G.A..S30!/.p...../.p..^..02/A/x..........m.y........'
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.354006764632179
                                        Encrypted:false
                                        SSDEEP:48:xWsoNC+ZgwOwUOYt5mgVE8oGXnyi9KuCcLrdhSro4tXKR7S9pVuD+7Zqcf:xWsIZLUB3xVE8nXyi9JCGRAlBN
                                        MD5:DC94D6BA231A5EE83B5D77C4FDC539EC
                                        SHA1:C236B1CE02017729BCC0C817018A7406B98B97EE
                                        SHA-256:084956719AAE8F367042726337B0F9C42DE2164F3910E3E8333DE086D03AD629
                                        SHA-512:55D42EF8E80C58437D90E9F85BA921B03A4A33AAA04F9E3238D71974F3A930D650A6A2272A741CB51540AF88E47064E004CE18DAB6380E8B832596A6B5B25883
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZry......ry...!....rE...ry...!....rE...ry...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............x.2<yZ#....Zxt.0....N...^...............B&/.A..J..W..h.t........f........................................I.qk..B.....LZ............x.2<yZ#....Zxt.0........x.2<yZ#....Zxt.0.........ry......ry......ry..........................................ry.j....ry.T.]..ry......ry..B..ry.H....ry...B..ry...>.)ry...J...................;........4...4...4.."..............ry..ry..ry...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4.........ry......ry.....#ry.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
                                        Category:dropped
                                        Size (bytes):12654
                                        Entropy (8bit):7.745439197485533
                                        Encrypted:false
                                        SSDEEP:384:JheN2cq6MLu6MLGu54cHeNzhcmhcDu53eNE3UPkhrxvu:Ji2Wix7fzVsbE3Zm
                                        MD5:4BCCCDBB4273ECEBE216C84930A8D0B2
                                        SHA1:FFBF617787E27BC94D9BAF89F2FE34A2BD42794B
                                        SHA-256:474F9A8C25D5E21192315397EA995B1E11E2C1608157C6E0277688091BFD136A
                                        SHA-512:DAD73A8C0E293B88685C0C71EF15E0DC95EE39B7FC9F849DE5D634173FD9FA0AF0AA96742D9E94BE03556AA4A817D5001C95A6736EAD5D5DF03661876785EB74
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................i..............................................E.....................U....V...f..ASTc.......de.1Qq...!Rb....Ca."r.................................B....................b....Ra.....!Qc.....AS.1U.."C...2Bq...$#3%&.............?......3.....~......:..g..s"......:..g..s"..ic..Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. ..0...Q_..X..V5E~..c..X...@u...cTW...0...Q_..;.m.....@w...Q.+....*.4W...lUFh....v..._..wn...dW....y._..v..E~...*...@wn...dW....y._...v..U..@wn...d..{`;.|U.2g...*.3...:.0?ViN.z.@w...4.M.:m..`~..i7...q...I....J.`l...W..n..PQTiB...6....+..sj.*."...6....+..WA...x..A........(.N6`..AD.q.....'S...t.Q:.l.......f.]..N..0.. .u8..A........_W..Y...}.C...~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~.v..?U..^.r..}..Bep
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.358524431750295
                                        Encrypted:false
                                        SSDEEP:48:QsSNJzy10Uvpat3uDEp8TcXnc996c1rdhSrHkZlStX5pztUtr9eohtbUtA+Rg:Qsl0UvUmEp9Xc996YRA+lSU6e
                                        MD5:7112C86895D178BA7897E362A4E3F792
                                        SHA1:817897F1B3F3580724CC20B15D835C0A3EC112EB
                                        SHA-256:0D9A4EBA5444E6173E88B0808B5490513599DCF1C00BEB487E105FDE6DAF79ED
                                        SHA-512:E2339F0C97E53861283B97D507094AD6BD552671B6614FF4A6A0239DB415E22388A62DB29BBA4798B10D1559588A3AC2F6E0D1F66E3B714181F0B1A83EAC1C24
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.f.......f..........N..f..........N..f...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............G....N..!...T.zC....N...^....................RJ.Gd%..\.........f........................................I.qk..B.....LZ............G....N..!...T.zC........G....N..!...T.zC..........f.......f.......f...........................................f.j.....f.T.]...f.......f...B...f.H.....f...B...f...>.).f...J...................;........4...4...4.."...............f...f...f...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........f.......f.....#.f.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
                                        Category:dropped
                                        Size (bytes):2695
                                        Entropy (8bit):7.434963358385164
                                        Encrypted:false
                                        SSDEEP:48:N9YMsguOZgKAz2vcaQU4R8r4BU0/Rc4nbIQdsohw13ZmFLY6KsVvMdBL2mr:/hsEgNz2v5T/rQC67SoWniHK4EdBH
                                        MD5:B23DE98D5B4AFC269ED7EBFDDECE9716
                                        SHA1:10AF507A8079293A9AE0E3B96CF63A949B4588AA
                                        SHA-256:646586CB71742A2369A529876B41AF6A472C35CC508D1AE5D8395D55784814F2
                                        SHA-512:BBACBE205EC0A4F4E3AB7E2B1DEE36FCF087DDF77C7D18B53AEA4B15984A47C64E19F9B8D8FA568620619CEA0361D94FE7ABEA6E502EC6ECAEFE957F42ED7EE8
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......M....".......................................,.......................1....!ABQRq.2a."CbS.......................................................Qa1A............?....{............i........l..-D.q.~..|cS.S...R\..d.8,!.....]f$....Q..di.;~5......vj......MqCe..=.*.f^..=.}.Cm]qCd..s=..u.e..v..t'.,.....S.s..N...>.d4'.,..k...N...d..9....G...y....6J.Y.l.{Vf...^B..i.3.z....:5W#4@.S\fj.%..Mb.5.v.5......S.E..#.v.I.....I......m..H....D..|.Y|...W.Wf..o..U.0.E..@.T.....................................'.S../...Z......!J..1K..rI...T.f.>.+.N..o.....\..^u........e..q.qK.GXP..-...F8".;5J...]Y......j.a.,R.......J.N........z}<qu..J.)`.}X:..}.............B...[. ......,B.).b.......(Y.O....c\.o.e&.W.#Bo..N|..N8.#J.>1D.1..b.&....q.#..UT%,.d.....m&..^...VXA..b.nbTV~.....^........q..#./.I..=Q..=..Y.*.Ib...VZ+......Y.........'.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.344195876153121
                                        Encrypted:false
                                        SSDEEP:96:4sh3iTJQ6zRSv/KE/AmXQZ9ld0SBRAmP6i5AxX/:4sh3i1QMAH/AmXg9lC4RAmSi5AxX
                                        MD5:E5C25F10F5E01AECADF0884C8C0F4664
                                        SHA1:2703BA060D17AA9DB1AFCA26B4B2A80745400AE5
                                        SHA-256:730832C57EDE569A96DCDBB8B1661BB928B6D8C411B772DE78D41CB9275C7B1D
                                        SHA-512:8E901068B0DFFCB90E080119832F11CC2908A3EE71EF947B34B5FC82C75E95517106B99CB63B8162B2D4169775D010D8F8A34A5B9A21A3C44CE0308B062DD61A
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.S.......S.@..k...HZ...,.S.@..k...HZ...,.S...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................&...7}.L....N...^..................k.X^A....B..|........f........................................I.qk..B.....LZ....................&...7}.L................&...7}.L..........S.......S.......S...........................................S.j.....S.T.]...S.......S...B...S.H.....S...B...S...>.).S...J...................;........4...4...4.."...............S...S...S...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........S.......S.....#.S.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
                                        Category:dropped
                                        Size (bytes):11040
                                        Entropy (8bit):7.929583162638891
                                        Encrypted:false
                                        SSDEEP:192:u99+91V42ho91V42ho91V42ho91V4235z9pUkDCyixxo4PS6b8tEy3BcWWhhSy0b:ubKD4/D4/D4/D4uzX38u4PNYJ2zhhmb
                                        MD5:02775A1E41CF53AC771D820003903913
                                        SHA1:2951A94A05ECF65E86D44C3C663B9B44BAD2BC9D
                                        SHA-256:83245F217DEAE4A4143B565E13C045DBB32A9063E8C6B2E43BB15CD76C5F9219
                                        SHA-512:5A1FCC24BDD5EE16BC2C9BACF45BCECF35ED895EAC22D2C4EE99C1B7E79C8E8B9E5186E3D026BA08FF70E08113F0A88FBF5E61C57AF4F3EA9BA80CE9F33410E9
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................v.E.............................................S..........................Aa..!12Qqw.....3568rv........".....4Btu.....#Rs.(W..bg.................................D.....................1..2.!4Aqrs....Qa......t..."3BRb....#.$S.Cc..............?...K/h._+.N6.-.a...5...;.r....,...0B.s(..zp..4.%r|q..E.Q^.../...C.R..?u.q8XN.>.e..:..gJ...._.n>.70G,..(........3b.&.5m...Q../...7Ie..k....e.l6..&..`Gt.P.Y^r...=..Y.e...N.B...O.#..J+........u.V;G.'.....V.]8..C.]..........E.....c..w&lX..f..\T.J?...F.,..m|..93........,.....+.R..WG...%.....(@.....p].iEz<.8.^...J.h.....a8P.1......(z..y~.........H.Z^.>..<.....L.k..IG...R.(.%..m....&u...B|.....@]ey.W.J...!d..R.8...[..>8....(.G......!.)X.....,'..F2.Z.t..Aw./..Z..#..i.kK.......b.i...qR.(....RE.............O.XP.#..(...9J..]...,.2.[w....KrW'...tY.......{~.:.+..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.498631065773949
                                        Encrypted:false
                                        SSDEEP:48:ghieBsX3fby3b3LBhlv4ztUEP3F7YXC9C0colrdHrDptXRvjR3b343/f3A3EN3qB:gDBsMBhB4zWEP3FkXC9C0RlRL9mY
                                        MD5:B0D9C34ADD81597C325BBB11BD09DE72
                                        SHA1:FF7D60CB27C79FE9A133E59BBCF8B4F0CBED8ED9
                                        SHA-256:0F3439EE7488A1138D7950211704437C17545623B5CBA05973AD8C65B44630FB
                                        SHA-512:FC8DD34CA91D3A9E8479FAD3E9A59246F53566C5B8E07F0F989EC91FA2C35D66AB5A7A52DCFF42A63027D40DF52D426E8007BD3C7B473AC3973540DA549C9278
                                        Malicious:false
                                        Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ..k.......k........ftA....k........ftA....k..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................../....Bi.....N...^................0....N.^#............Z................................... ....I.qk..B.....LZ................../....Bi.............../....Bi............k.......k.......k...........................................kj......kT%c....k.......k..G....k..H....k..>....k.......k .3...................;........4...4...4.."................k...k...k..z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4...........k.......k....#..k............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
                                        Category:dropped
                                        Size (bytes):2268
                                        Entropy (8bit):7.384274251000273
                                        Encrypted:false
                                        SSDEEP:48:N9YMn9H5gXlM26vroVXWxyNnl1LmLR+rn4FOeewGhDbby:/h9SlMdgm09ll8R2/rby
                                        MD5:09A7AE94AA8E517298A9618A13D6E0E2
                                        SHA1:FA5181A7414BA32F816BF0C4278EC20C615E8B1A
                                        SHA-256:3C68C7EE798E62A4A99C740153F3980D7DF029605C843410942C7F85E794823B
                                        SHA-512:074E9A2BE2039D0AFEAD360157550B934FABD0CB86B5AF476C1FBC885EE60331F5A68EAF70BF76E23C8248A20FB900346839F4AA8892370B5889E64948DCC6E2
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222........i..".......................................3......................!.A..1Q."q.2BRa.b...#$................................... .......................!12AqQ.............?..D.z.4....;.....7...3.t<!..d.O.....+O+.;.z6.4cz7E.........U.Z)-..@..y...........}(W...<.xv/...5.ew......yN....n.Tk.Tm.Ty.vA=...T..U....h...e.8.5%....'......e^......L.g.$.~e..O.._...... .F`.....xnL.<.......]jfv...}..\G..c.......-%...#.C.|.].`..^..W..c..B..5D.QSTaZ.5A=....BU..z%.4.h.6..=..U...W.$..l...7.:...........IPQT_...~..i..x....~.l.|.n.J..TV.21.Tg.....................j.z!+.-............"j.j...)*..TT...."....T.Tc.**j..............j.z!*.h...&.&.&..e.%..TksTW%G.?".l+$..c._9..[x...TU..........i~X..#'.qm?ttO.....}*.i...q.....9..r..?..W..d.w...f;..q...tZh..0.....2.......OD%Q-.......$......56.K.O...y._..*_C.k..p9.p..O..vu...'........0v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
                                        Category:dropped
                                        Size (bytes):784
                                        Entropy (8bit):6.962539208465222
                                        Encrypted:false
                                        SSDEEP:12:869YM8fij0W/xfuCp7ovv1bidiMn3bGi6AETQcdH8SADjoZgV6v9jUEvS3/g:N9YMWeI424diMn3yinsQeHvADu9QEvJ
                                        MD5:14105A831FE32590E52C2E2E41879624
                                        SHA1:078FA63FC7DB5830E9059DF02D56882240429D90
                                        SHA-256:D0A3A1C3CD63C4023FE5716CBE2C211307D0E277E444D9EF76C7FC097A845FD4
                                        SHA-512:8FC0ED24E8EC14C46EA523D9265DE28F85C5FC57AA54AD5B9CA162E95F79221E2AD3DD67D1293CF756B67F3D3DECAE122254134EA8D4D00DDED02114B5383947
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......a.L..".......................................-........................!A."1.Qbq....2Ba.........................................................1............?.....3.Ty\......vs....>.>..a.W..s89.d...Z}......rz...`...Z.r.do....u.W.%....gf.>.L..xz....B8=w...g.~g."HD...$..IKJ......nn..*ly..I....L...\q...Q;6.KrxZ.,...j$..ZQ..)f...q`.*..C1..cZ2]-..\.~..J.....^..(.f..9m?..C.NI.UL..X.fy.Z.........+n....r."Z...d..R./\.#...kd.D.5.!...h.3*s-+.......Xjt..}i..rK..y.../>u..]N.....Y..J......1.x./.....F6.......I...._3...k.sM.+..v;.%|.f.~.......:y....S....UKovh...W'........lF... .................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):2.7399986602086757
                                        Encrypted:false
                                        SSDEEP:192:VsnNNPTR2NlSXmizXL9fANgRCG4PCkqoH:KnLPNMl3Q5fAKRCTPCkqo
                                        MD5:5396E57BA07777BAEF1008DBD24B94D7
                                        SHA1:50434A9D900FD998BCEBF9499A0A4DD208DCC8B4
                                        SHA-256:B6056BD6129385CBA954E135A2D2B873046B104DD683773FCB604406F48997A2
                                        SHA-512:207396FBF44C9BD1F1E8876637C9678A75289253A5B7D2C6C2A0427D91B6C0A31B1AF5099E94B918460D2801D6AC2967BCB59E204A69B831E4E2FC184413D2AA
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>...........v................................I.......I.qk..B.....LZ.>.......>....T./.g......>....T./.g......>...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............,\5/1...='..-.m.....N...^...............KS"..mH../.X..u............................................^....I.qk..B.....LZ............,\5/1...='..-.m.........,\5/1...='..-.m...........>.......>.......>...........................................>.j.....>.T.l...>.......>...Q...>...Q...>...>...>.......>. .3...................;........4...4...4.."...............>...>...>...z...y.. x.. ...........$........4...(..7(..7........................;........4...4...4..........>.......>.....#.>.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
                                        Category:dropped
                                        Size (bytes):3009
                                        Entropy (8bit):7.493528353751471
                                        Encrypted:false
                                        SSDEEP:48:aRCTf+0hagMrbAZMJShPdvF/5OzlQFlDF7npkDdWvVBTEnBLT6NrgCX0:D+0YgMrApL553JtEdEVcL2NcX
                                        MD5:D9BD80D40B458EDB2A318F639561579A
                                        SHA1:83BA01519F3C7C1525C2EA4C2D9B40F28B2F2E5E
                                        SHA-256:509A6945FACFB3DDC7BE6EE8B82797AD0C72DB5755486EE878125A959CC09B59
                                        SHA-512:C368499667028180A922DD015980C29865AEF4A890C83E87AE29F6A27DC323DD729E6FB1C34A2168A148E6A7A972F65A5FC8ACE6981AF1D4E7057D99681CB366
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666........_.........................................:.......................r.!12BQ...3Aaq.."CRb.....#4$c.S.....................................................1A............?..p..-.....u0$.......l......)..o.FTd..DG....... .t*e..jO..Z.U......r..j.O.,..VD./.....V5D.&......A..Zi....E.N....*..........#..M<|.2.Y.../QO.x.cTM4......+.F;V.x.de*....]e..O.x.c\Y........r..j.O.,..T...hw..k.^.[B..J.sEl.w.x.m.5%zzt0..T.......b..<\.3Q..W</..!.xh6..Z..\.+M.o.Y..1............#.........|.a.l.KR>..U......e....@...\.1Z...Y...[....F.6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....Uh....FkYm.m`P...W .V.g..FjVj.\..1Q6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
                                        Category:dropped
                                        Size (bytes):2266
                                        Entropy (8bit):5.563021222358941
                                        Encrypted:false
                                        SSDEEP:24:TuRCTP9rSTfIEe1HbcVY1YbDXq8eCI0bf2QQe0GVDQAzZw:aRCTN7HbcW1YbDXq+I07Ien0AVw
                                        MD5:DB8A181E3F0EAD4A9472099E42ED6BE3
                                        SHA1:92096AF05CC6167B1AA816811A1160B809393FA2
                                        SHA-256:E9746B4E9AE9CE7B3B0068779DB3E113E2DFC9880F25373D745D0E700E69A906
                                        SHA-512:A9E246E10E28D057090BA9F034ECE6131780D7F794C5C9421523388997C7EDFBB49BC32B863B6C6668911B359C304AA54969B48CB9234950D5CECD2A6F3EFFF8
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666......r...........................................5.......................!1AQ..2a...."Rq..#3BSr..C..................................................................?...X.....U...j...F.W.V]'KV.uWt.iT...{.......`.(.....V%..=.....z......V..ct+.U.B...@.............................................{.....5.........0...x4....c..;...........+......|.7E.%.9.1+}..d.........+.V#.P.HUL.E...g.li...8.>U.";0pi.]5.\..zo..."@.........................................y.6.mLN..S.....@...i..A..p.......~|V9.+.Xy.........+,L.....7Z7..p...-X...\.....:-...i....v.1...-..H....9.zk....l....^.......:.."^.t.Q.F...X..B..$............................................a.%f&3..1.5+.X..'b7bwr.).e.x....!...H...aa_..kD...b..g..p..K^.k..qX.[,.........Q...U..x...YMvj...w..:k.....j.W.8..4....c.u.}m.....o.=@.......j.S.t.|.....5h.y.%.~...G
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.351910531931645
                                        Encrypted:false
                                        SSDEEP:48:YuUDsXNJA9iIR8itnTd1WLCxEg0XVy9KeW0oBrdQqriOrBX+hmSxuPetmKELS:YNDsk9iIR8ixd1JERXM9KeBwRQybrK
                                        MD5:9B2F4C0E1CAA3DD1EDDD3C6A491ACCFA
                                        SHA1:3A2EF771457465AD4DE1B0621C1D54F868D0AEF6
                                        SHA-256:F470521FC4D1AC6FDC9BDC3F6BEEAA5AF662E2AE5C5D2BDF3511300C7E95ED53
                                        SHA-512:67CD62BB4837CCD5E03EEDEE4B4A99F422C6C0484F174B65AA2EF1BE9037C648AB15C52C040565D6D539EC5FA96BDEC2EAA2CAC14A01A2174A42BBAA0D6EE903
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZQ.j.....Q.j=.i..8i.....Q.j=.i..8i.....Q.j..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............C..Z....{t~V.......N...^................s...E.O&a..N.........f........................................I.qk..B.....LZ............C..Z....{t~V...........C..Z....{t~V............Q.j.....Q.j.....Q.j.........................................Q.jj....Q.jT.]..Q.j.....Q.j..B..Q.jH....Q.j..B..Q.j..>.)Q.j..J...................;........4...4...4.."..............Q.j.Q.j.Q.j..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........Q.j.....Q.j....#Q.j............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):99293
                                        Entropy (8bit):7.9690121496708555
                                        Encrypted:false
                                        SSDEEP:1536:Moq1jVORV5NO5xLCBaaNk4vhpCr1CH/DATOQlWvHMHojiaAMrxArLFRZPj19AWFz:eVEbouBaIk4T8uDGOQlVHvaAMkhDh95V
                                        MD5:EA45266A770EEA27A24A5BB3BE688B14
                                        SHA1:9F0B23B3C8EBA4FC3C521E875EF876FBE018F3C8
                                        SHA-256:EDAD0F03E6FF99FEF9EF8E8B834CE74F26CD23C5F8C067F5CEE66F304181E64D
                                        SHA-512:D4EE36BDA897BBD643A699A0332DD00DE9CDCC6F46D861789BAD259A4BF87868AE3B4CFAAB6DFAF29941C7055B77A95D76BAA86A4A0DB2BF3BAF7E3317F03EB9
                                        Malicious:false
                                        Preview:.PNG........IHDR...-...c............sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..[Oh\E...y3kv........`.%m.R..6.1.4).o..Ki...D.......P!.].=..K...C[....f.}o7VPJIg...{3.|....d.....i..=.4.u0...n y......@j..Q..f)..mQ...4-SJ..9.d.?..5\-....:b.W..i...c.5..{..pj#.....B1C/.I.......].Su.k?.2..:.9Q...5.U...UZ...e..U.c],..2.}...1..)W./..Epr.Zt.....K.=..{......e..."...v..B.4.#....A.V1.".V}t..[..2f..Y..V9.".6.......(..gbm.P.....Y%2.c.z.:Q.2.<tYF.....u.@..KJ.;u.q:.].....$.....V....Hqk..DW.l.e.j.Z.YP?:'R..*.<........6...m@..r..j2..HK"|..L.Nc..D..y.9..B4$.......`.3.m1LE....7(OU\+./.O...%6T..w......h....).I.&n...*......#..W.41...5.#.`..I...<.?.|..*+Q.....#i........$,..n...`.s....[..E. T.w..j.,&-.r..;a....#.>(.P......f...MU\3*..;B....)..5....z..(....-...a.....}y.l..E...z>......&..g.$.....*T...N....E:./.>..#...^..E.0..%......(..@..W.X.NDM.<~.]A.>..fW.O.y.'...Z...h..).F..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.335847673885307
                                        Encrypted:false
                                        SSDEEP:96:YtswFQRsKPtW4SX+mEPYXvc9K4ARQyXhRarG0h:WswFQRsWtW4SuDPYXvc9K4ARJXhRarG0
                                        MD5:64691C25396D51474486549DB4A3A564
                                        SHA1:2C30C53B3095053A47AE91F1C05124949C323037
                                        SHA-256:B54248D2C198E4CD684BBE73D208779768A3AA7369B3322A44053EB98DFF0666
                                        SHA-512:12F41BAE0E77D7F4FEA20520683762DEC7597A461AE3FBDDAC4CF4D0118D3F162D8CADE0436619040E811BC0C1C7F5D21A2275DF6A583CA6846A5EC5B3D666B5
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..T.......T....!..z.iT...T....!..z.iT...T..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............#P./...5.JM.@C.....N...^...............{...}{.E..............f........................................I.qk..B.....LZ.............#P./...5.JM.@C..........#P./...5.JM.@C............T.......T.......T...........................................Tj......TT.]....T.......T..B....TH......T..B....T..>.)..T..J...................;........4...4...4.."................T...T...T..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........T.......T....#..T............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
                                        Category:dropped
                                        Size (bytes):2898
                                        Entropy (8bit):7.551512280854713
                                        Encrypted:false
                                        SSDEEP:48:N9YMTXc4gpw+EIWnqQ5G+NE9VTzRFvS4+Xh+AKrNx+JuCluc3Eeky8etajhDCFex:/hDc4rPIoNEzbS4+XhOrGJu1cUHeoVey
                                        MD5:7C7D9922101488124D2E4666709198AC
                                        SHA1:00CC44A1B84D4D94A0ACE8834491EB5F65D04619
                                        SHA-256:20016E5FA1A32DCE5AF4E92872597E36432185A7BB2E61C91F362BD68484529B
                                        SHA-512:882944B2CF040485899128E03B7499C540D481E45FE8017DBF4FE0330157B2D8ABB7334DDB31C112BA0EFE3722A554883917C54155A7F60044D2D7F3D848260F
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......k....".......................................2...........................c.....TUb...Sa...QRqr..............................!.....................Q...R..!..............?...$.)m.1...%%bV.J..H....-.%a[...I"WJ..:.X.:TT.$.......N.-NR.E..-NR.E...9..E....$.k.....B.I,I)..J...kr..+)..I,Yj..YbI..+,J..e..Z..V.e.$V..TV.X..V.YQZ.EQ..U%PY[.[.R.EP............................| F.. ...j*...!m.!j.I%.j.$...YeEYYEEUE..eY[.hEEUeEil.....%..el...V..TUYA.U.UTTUT.Z..UQQUQE...V.,...UlE.U[.lEP.P.@......................................R1...AR1m.....#..$:.T.p..IJ.t.....A..AH.,5..]F!a.XJFaa. ..a.!*.aa. X.e.......bB.b..,HX[,!..,,.c0.,..U..X..(,,...B(.,..4..B.`..".a..-......"...........................>D..IKEb...t.....)u.....)K.%+L\.J]i)*b.JR.IIL\i)u....T............T.....qs.it.iJ...])ZJb.....X....U.A...V1..B.R1....X...,.c...,%X...,%#0...,H
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341400086372359
                                        Encrypted:false
                                        SSDEEP:96:WslshEtZTAVOEShHXFb9wARQyR7NnMRCHN5CSAX1:Wsl/ZUb4Xd9wARJRZM
                                        MD5:E6B09D76651F6F56CF40A855175F2E0F
                                        SHA1:10C449743C69C27DBF3C1FB92BE06B2C090ED453
                                        SHA-256:980E900E139E2E3F9598FBB88D50830225E2D805242A2F17B80AB3B2D88D3904
                                        SHA-512:6356780F82FAAE4139B1F813B3081E4FAB2392B79953519F2F05735DD2A62B063F2FB81B1101AB953843E2A0497E8CF463DDF56CD28F54261E78E3BEB123D081
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ ....... ...........:, ...........:, ....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............Y..V.[...a.........N...^.................F...(N.....r.........f........................................I.qk..B.....LZ.............Y..V.[...a..............Y..V.[...a.............. ....... ....... ........................................... ..j.... ..T.].. ....... ....B.. ..H.... ....B.. ....>.) ....J...................;........4...4...4..".............. ... ... ....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4......... ....... ......# ..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
                                        Category:dropped
                                        Size (bytes):29187
                                        Entropy (8bit):7.971308326749753
                                        Encrypted:false
                                        SSDEEP:768:RwjBOlCk+nYnGagKJWJhwMJiRO22ZIm4VXvXx1tA6BQs:i8snY3JW7uROlEfbtVL
                                        MD5:DF99CAAAB9A7DE97B63343E60A699AB6
                                        SHA1:B84334135CFB73BC6EF55F85926770D5AC6DFEA8
                                        SHA-256:74C131777E7C437FD654427417097BC01B0813BA8E1E50E4B937BD50A1BEBCDB
                                        SHA-512:5D15AAAA8B71DDFE01A7C0ADE16D9E1F5E9AAE484BCD711B38CCB103ED9564CAAC23A0031471167B660E15972D70179C2A387509B213C05D60261042A0456025
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.........................................................................e..............................................`.............................!1Qq...2ARa..."#.....3BSbr...$4C...Tcs......%&DUd...E....56Fe....................................H........................!1Qa..Aq..."b....2R...BSr..#...3..Cc....$%4...............?...b.d.8T1.;#.S.DO...~.R.......3.xe...z.6..."m..k...;*.'.f.5^.....m..<$....8.R.j.D.v..>...*dT..vGbt...I......sEWp.r3.. ..G...6.....w...l.S..q...b.....-R....^Zu5+u6...A..Z].:...5..Uzn.,l.L.....?%.*.S.+zVg7.=.s.Q.....8..:,c.......ZE...>'IF..W.0.d.......c.e.d.V.t..S$.DNR.[....g..#i.$. .U.SK2.....k...J5u u\R.....T.[4..A.O..,.T..................] .i...B.m.^f....._...{S.....<......:..|D...+...NA....Y.^f.1|..%K~1..B..^...S..v=.c..g.tX[..kTJ..t.gr....R..@.F....5j..2.K.9..g.1N.....*.U...^w......>+.l.v...@N....%Qd...t.Ni.....0;lggm...K".+!.,.....[J...>..?f.]._;
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.3571588485586155
                                        Encrypted:false
                                        SSDEEP:96:Msy9UqIF+qjiEYY61XUZ39TcRQy9r71Rd:MsUUqmxqXY39TcRJFxf
                                        MD5:D3EF13F20F42075A963E05D00CC70A02
                                        SHA1:974201BE172B5A098FAF9A616DAD457F6622A09D
                                        SHA-256:B38091317C01EF3759ECB7AE4AE484B5514B7338BEEBBC0896FD9AB90716B20A
                                        SHA-512:685FC928AEB9230A9B26BBE6CA4E61267B6400D546C3262B9A2641CB01BC0862A301A7C0768E1422E92F2BC63B329D387027DB332D0B9D92C2FDB14BABA3A4BE
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZd.M.....d.M.G.|.&.t..d Wd.M.G.|.&.t..d Wd.M..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............&Ut.E....3.Ev......N...^...............<n._...K...j..y"........f........................................I.qk..B.....LZ.............&Ut.E....3.Ev...........&Ut.E....3.Ev...........d.M.....d.M.....d.M.........................................d.Mj....d.MT.]..d.M.....d.M..B..d.MH....d.M..B..d.M..>.)d.M..J...................;........4...4...4.."..............d.M.d.M.d.M..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........d.M.....d.M....#d.M............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
                                        Category:dropped
                                        Size (bytes):4819
                                        Entropy (8bit):7.874649683222419
                                        Encrypted:false
                                        SSDEEP:96:/hnQiz+ET2/hDi+tv34VtpWfowTHgegb6hhLT1NTS:5nQ6TAhLtvIzMvbi6hhF0
                                        MD5:5D6C1F361BC04403555BE945E28E53FC
                                        SHA1:00C254F7B3BC0289590C2BBDBB39C8EC2E2B2821
                                        SHA-256:131D637CDC5D0B094FB9FAD17F4D2A1ACE0D03613588155AACAA2D1CB4E16DA9
                                        SHA-512:34D2C0929FCC3CC10D0A2121BD55BFA9A07062C2A7B8F101071164C946895DBCB2777641E79DE4193D57A3F0778DD4F1351FAF333B7E4B4DBE31A32DD69C51F9
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................<........................!1..AQaq"...2B...#Rb..r..$3CS.cs..................................................!1A............?.............u....p.p($.Y...9,j...V.*..S86yh.G.#m.5..9...6Y.."C.R:.[..-.7U3c:..].;.....f.?%..<T...&F.Lh.N...m]..x.D.g<B.....k..S........>j.K....#U..Z....<e.:..8....o..xq.[..4v..U..y...k... k....A#..A...pn.jJ.I.7:..{.b..ns.t,...8.Td.I....m.I.5Z.).-.. ]..X.Do%.....?..4jV.`llt.E...5...u.|..\F.=.F.r<...5dV....xc.%..&...4,...f...3..H.<......eQ...P.J....7...lLc..?..-.fR..7.#.6.......}:.]'.ny..........e;u.Y..$0...i..-....f..9(....}..T,.Inb...+=Cca7....WULA1@.s...4uY5.N.f.c..].ks.....3v..~..k..m)...f gNE`S......#.....Z..6.uc.m...#k.s.f*.l.$6..?..xC.Cm.`...N2..&H...._.&.E...[....f.Z./...!.a{K..#.V.5..v.B....1...9..B.&....%s.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.35574553564949
                                        Encrypted:false
                                        SSDEEP:96:ysabibNbR4RtmazdEVUNXZ/v9xERQyQQ2pbNbcbvb4b+bp/:ysQ4JR4RtB6KNXtv9xERJZ21JqDWk
                                        MD5:FFC4504BD1D2C59807294788AFB23A80
                                        SHA1:CF10550E28DF0C51922BE5B287D28A74830AFBB3
                                        SHA-256:BD21C54A64C9659E772AFD6B992E8286C25F5630B2F23D16CB62EDB7215CCE6A
                                        SHA-512:DA03B2BAE06EEF80E5C08126907407EEAF5C862E16BF19ADB896B1D2B2461B040EDD482077DB00C454BE211B2ED63C0025CC3CBBB8A504B200C1EA44849C7B70
                                        Malicious:false
                                        Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ...............$...4.k.......$...4.k.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Z.. L..>..OY.n.....N...^.................4..8rG.2....:........f........................................I.qk..B.....LZ............Z.. L..>..OY.n.........Z.. L..>..OY.n.........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
                                        Category:dropped
                                        Size (bytes):1717
                                        Entropy (8bit):7.154087739587035
                                        Encrypted:false
                                        SSDEEP:48:N9YMzO6BOfqH/dAIWpdAIWpdAIWpdAIWUtr/SD:/hzJgfqHaPYPYPYPUt/i
                                        MD5:943371B39CA847674998535110462220
                                        SHA1:5CA79B7BD7E0E93271463FAEF3280F1644CBA073
                                        SHA-256:9C552717E8D5079BBB226948641FF13532DF3D7BE434C6CE545F1692FA57D45A
                                        SHA-512:812541836C8B6F356A4D530E5CCF1CFDCC4CA54AF048CAC19FE86707CE5EA0F41D73C501821AC627AD330291EF58C040DFC017923A7886CEEC308048DA2CE7C9
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......-...."........................................&.....................U.....1T..S.R.Q.................................................R....Q.a............?..d.. ...............................................+A...Z+E...V+E...U..R.....}........Q..Ah....Ah..b.AX..b.PZ+A...V+E...V..J*....Q...b.Q..Ah....Ah..b.Ah..b.PZ*.(.@z.?.`;2.......................................................Q...b.Q..EZ*.(..Z>.G.....`Z+E......J*....F+D...F+E.......b.Q...h....PZ+E...V+E......J*....F+D...F+E..............[u#...a-...f<.9^[...l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m..0.....l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.338056064512297
                                        Encrypted:false
                                        SSDEEP:48:ZkiWs9Ya6qNv3ntm4XEKd79KBXnB9uBoRrdQqr1qeBXvjN+vl9N0g:CsrvXlEKd5qXB9SARQyoeVA0
                                        MD5:E4DF8A7FD7BC3B66AAE60CFD0F7DB935
                                        SHA1:4FF1F9D46C0F25432B5ABCF1DAD6D369FC34F407
                                        SHA-256:BA10FD2FF27D82E00C7445E5D588799A54399BF44129B191BE34D8FCDC89B210
                                        SHA-512:D69A057CF6DCA564DD4E987A87E68F744DF92EAE0D530C0E4A786D65F984600D3A89BDF2BBC6C99732934BCD8DABCF527B29A5A8DCF07FD903EAC5924FE79D8F
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ...............-.H./Js........-.H./Js......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............S..Y.....<.@s....N...^...............G..]k.D......%i........f........................................I.qk..B.....LZ.............S..Y.....<.@s.........S..Y.....<.@s........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
                                        Category:dropped
                                        Size (bytes):3555
                                        Entropy (8bit):7.686253071499049
                                        Encrypted:false
                                        SSDEEP:96:/h3JeYCQV5Hn++9HBdAjU78S/mjLLwqnqahJD:53Je8b+EBdAjm8S/mjLLRnphJD
                                        MD5:8A5444524F467A45A5A10245F89C855A
                                        SHA1:ACE68D567B02B68275E0345C86DB1139C0EC1386
                                        SHA-256:7D2B01F17354D9237A6AB99D5B9AFDF0E1CC43687125848B0C2DEDFB44CE3843
                                        SHA-512:8151B447B60D110C32EC1EF286B941FFC09B99140F41BBACF5A1650A385FF4D13C0DDB2878E9A470FC7CFCC95A1AB6E44F6DE72562B0FFE093DC8A3C3C7FCC14
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................2........................!1AQ.a."2q.B..#R...3C................................ .......................!1.AQBq............?........)&vD.)3Hn*..X+....r...tmL.k..(.E...R. .Z..&...,fJ...!...6..S\t3.=...g&..Bqe.)_U.....1......-..fl.................J...u.i.mU..K..v.w.0O..E.h..D~K.(..9.,8..E.}.............i.\.....t."v..q..C............<..|3.........................*Q..../c.....f.}8....D..|k..Z......0..~..c..e..m(...|.c..'.5.5............==bx.5x.8...T;....=.--.pc...I;.V.m..,(....}...NH.ho....Q..U.E$.~...w.t>.S\....'f.{.+.g._.t....;>.....P...........-..G.h..2...J.% !.E97Ir.D..N....j...oE._...._...".?.......#".S.........Q.Tc.I..*I..k.......=$.........sk1Jp.\K.....F.3.Q..q..J....N..[l.&....OR4bB|..2ul....J...B.$&H..9#j.f.n./........?R~....B.I.@..........m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.350161208590484
                                        Encrypted:false
                                        SSDEEP:48:n92ssQNHr29YGXMPteuxElOX9a9yeoZrdQqrbw+piBXuUN9N99KNnD6N0N9gfNiA:n92sWMPjEEXo9x4RQyEDL
                                        MD5:9D7ED6A2DC8DCA59CC5913A174F3659E
                                        SHA1:EF50E5E8182D73AB2D6C8887071E5BDBC38D53E6
                                        SHA-256:F7D6959067DCA7FBE4FD91D4BC7B41D390BEDDEF19C8A2A3843C73AEB8967586
                                        SHA-512:860F5A0FC101CCAECA7F91664624FD4DFB86C2B9F3F2B8F535400103EAC915DD4E7CFF1EE4C133C2DB387A688FCA9E6216941F337D19588D551EE3C64ECC7B1D
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.$......$...A....Ng.0..$...A....Ng.0..$..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Tf......9....p......N...^................._.kL3D..o............f........................................I.qk..B.....LZ............Tf......9....p..........Tf......9....p............$......$......$..........................................$j.....$T.]...$......$..B...$H.....$..B...$..>.).$..J...................;........4...4...4.."...............$..$..$..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........$......$....#.$............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
                                        Category:dropped
                                        Size (bytes):3428
                                        Entropy (8bit):7.766473352510893
                                        Encrypted:false
                                        SSDEEP:96:/hdu7isPwAp7zesusUyYAatNG87llTONQYS:5di5tfuQ9atNZlaC
                                        MD5:EE9E2DF458733B61333E8A82F7A2613D
                                        SHA1:A86704C969F51B86D6A05ED51C6C60214ED9FA89
                                        SHA-256:BE4F0E6C89FCE91B9EBD2623567F7DFC259E0E3C77C9158742B8F64B724DF673
                                        SHA-512:BFB5D6DD6B66EE21E946E90D1E482384CD10244308562DDA814189602681DADDE5752B80519E5B8515F115A71BD6BB4317A59BE65B8B5E3474AED119F8303569
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......r.F.."........................................H............................!Qaq.."12.....#3ARbr...$B...cd...&CSu.....................................+.......................12..aAQ.!#q.."................?...#...3.Za......rV.5&...../"..i.t...j..W........d.FL.V.2K....]t.f.d.NK..:.....f...... ......2.[...#..D...ZK....p.z.E.N..T..L.-....1....2.\.6FIr2..zS\U#..........fB\t..5J..~q...D....A.......!....MY..../.HY..../e.M.Y.n.~..,....'..Pc...l...d2..m.f.it$..qx-z*...._..].cOO....n..&.....FIA.....2J2..d:<qc..6.I.G.N....f.K..Dx.-.......`....2.FZ."K7.r}..<.P.Z.da.Y.....8..s....G.....b.e..g .S.......FL.Z,&..q.MG.J+..x\..m...qN=.....)..`...&Y...S....u6{.z.g.....@......FL.ZL&.Iv.w..8....U..v...*.q.B.v_./A..#.#.g.j........*J;...u...W.Ao...%....#$.....M..^\{W.SO...s,.N.....c).,.B.Gv...."k..z."..S]H.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.351609661722639
                                        Encrypted:false
                                        SSDEEP:48:ss4GVrOSUhZtQSgNEXNrx7qXs9C7oJrdQqrp/1BXR1u9iMMgFl:ssh6J73oEXNrxWXs9cQRQyV15DMtF
                                        MD5:B87D3DBD7732C661D74E6B0EF63E9544
                                        SHA1:14899903AA410668654227F684793A1485A93DDB
                                        SHA-256:C6B38D96CA5205F7539A8B19E20C8287340E78E92981B80671B2D4A107C8A16C
                                        SHA-512:E39ED6D9B8E6C5A1CEF01843693B7B776037F7BDF47B24347F70E3B881080537AB3F1234836ACE8AA68DEB233292922F50C6808D33D451CB273CBAFC7036A094
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ`<......`<.v..:.;..;C.eV`<.v..:.;..;C.eV`<...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............]Hk.(....H...._....N...^...............F...../D.E...8..........f........................................I.qk..B.....LZ............]Hk.(....H...._........]Hk.(....H...._.........`<......`<......`<..........................................`<.j....`<.T.]..`<......`<..B..`<.H....`<...B..`<...>.)`<...J...................;........4...4...4.."..............`<..`<..`<...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........`<......`<.....#`<.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):65589
                                        Entropy (8bit):7.960181939300061
                                        Encrypted:false
                                        SSDEEP:1536:2Hlrjw3xL//DPgff+9j6yPWvHMHjkbfnwHO3AW3GL:2H2zDUU+yPVHITwNfL
                                        MD5:8B48DA9F89264D14B83FF9969F869577
                                        SHA1:E1BD58E2D80FEEF56DC514F3F0B3AB9669F22F95
                                        SHA-256:62AD3C277E54F03F1ADB44062407346F789E63859B7AFABFD64BE6AF5E9F66EC
                                        SHA-512:03B783EC968DF3F648504D068D64DD1AE110E28110FE5B3401C9D04F44897DBE0CBB5680D42CA4C665FA94A6CED4B559106EB3C06C9BF2C5B14951ECBFFAC8AE
                                        Malicious:false
                                        Preview:.PNG........IHDR.......{.....;Za.....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..Y=.+I....t.y...,^vv....;. "|. .i7.....$.2g..']pH@p..]b....H.H.......d'@ B...U.xm..3{3k?..5n.._}U...3......~..>...g.....f..t...t:...p>..Si..d:..k:.Lf..t6.K.i....d<...x.8\.8.+lc...)i.$.r.....x.t.BG.R.cm.c...p.:&.6.4..K.......^...~b].0....oBYv..u.'.=.K.Q.g)6.....4.!.M......4.=....G.%.Sr........nxC.F..t.U........1...J.t..eQ....".... |...81.$D.!.>...........$...^.vY..EY8tb..'.P.g#O....S*..0'.V....x.W..........k.......s.C.S...J%.iVb..].........3....j.}*.z....+.s..@..K.....\x.C..e.Qq.....;N.....;....,....^.*..$F..{G...8.#....8'..&....8..5.....3(P._....S......|".....u.cr....+a-....&V..x...iI-<|a.{E.c.X.......?..&.C....'........(.x....>...M.?.9..#X......l...0...Z.F..<.z.0}Q..Z1..........?h..`E$K.2o.A*c^.......*..D..uL=.}.#*0.. M!.A.C......|_..(.Y........!E... .O...`;....M+..x.u~g...q>...N."D^..K..x..D.`.!.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.361516175299188
                                        Encrypted:false
                                        SSDEEP:96:esXQQUYezdEmd3Xz99m68RQyr6nE+ntiTTa9:esXNUj6mJXx998RJrIE+ntiTu9
                                        MD5:40520BC08F65DB24DE53F85B93210965
                                        SHA1:2F8765F7C89BFA6887C2442F275F361429D423B4
                                        SHA-256:71A8C022B0E96CEC858FFA7CD42A4913A29B27727AE48F96CC60DE29F2206016
                                        SHA-512:5303ED7F87A532C60F38CD5C902CE99EE580926C254502C7BB714F265179B11E6650043E311CCD8B046DE1A1BA2E15DE6E560B77AA6103C327CA43650F175AEB
                                        Malicious:false
                                        Preview:2...>.......V...v...J...................................................................................................................................2...>...2.......v...~............................I.......I.qk..B.....LZ.P.......P.....$.9"G.Nk.P.....$.9"G.Nk.P...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............Hq5.q..>g..........N...^.................O...@.>w1.D.+........f........................................I.qk..B.....LZ............Hq5.q..>g..............Hq5.q..>g................P.......P.......P...........................................P.j.....P.T.]...P.......P...B...P.H.....P...B...P...>.).P...J...................;........4...4...4.."...............P...P...P...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........P.......P.....#.P.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
                                        Category:dropped
                                        Size (bytes):1873
                                        Entropy (8bit):7.534961703340853
                                        Encrypted:false
                                        SSDEEP:48:N9YMw9kGzE4xTdow1C3kyIkyM66KeJY3fOxJ:/h8HzE4xTdoUCUyxyD6LCvSJ
                                        MD5:4FC8500BD304AD127AF4B5E269DFF59B
                                        SHA1:9A5E3432358A0FCDECE86AEB967319B93A65D14A
                                        SHA-256:B4DAA90D5A53FCBC85119050B5B76962443C4DD18D7F42CDC6D4E0AD8EFAD872
                                        SHA-512:E5E07054A522EB91EFD39722AFB3776389632B8F5F923C1D29796716D68CEC93BE5E44F79913804CEC7ED631FF520CBBBAAB841E01FB90AF8E8ADF84DCD47481
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......`...."........................................>.......................tu.....45.!#$%1s."fr...2Fq..AQe.Eav............................... .........................!AQR.............?..e4.bbu."m.G......u.S.-Qq.b.a..'#..E.......u.|:.f[O..jS.S.&....=.....[.....S...N.~~...'...q....N.T.Oyf..a.6..%.I.1j.e~.4..[5.WW.Y..Xp.gn...u.......Gb.O.W..k.!mJgfq....~.F.......m..}bn4.5........s,F...z.b)..O..*...5).-.-\....=`.fP....%...A..Q.&..9.....QQbD.%.:u.f...r$.10..W.F.T..MI...9...ZQH._..).....D..n.F].........*.:.j...!6Z..S....0...B.6..Ga..S.O.....U8S_.J.>...i..?..<.P..........M..F.T.C..7.E...`.4BKcMh1j....4y...+.|.^......2[.WG.W..+......E..r/V^".R...."..6..hht..f...........;E..Kx....)}Le.A.x.>..$/).._S.n.L......}..H^Sw...2. .v.io...../.........x.>..$/).._S.n.t^;O.....n...[.S...h.v.io...../....:/...[..7yK.c-
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.487521630500666
                                        Encrypted:false
                                        SSDEEP:48:ysoRRysTa+3hbtUEeWXW90GQ7o0vlrdQVruWKBXFDWksaTnwXRO9:ysoaga2hbWE9XW90GOPRQ5kIaTwXRO
                                        MD5:6B87905173B899AA90D4E15122CBB56C
                                        SHA1:3346CF18A222FFC584AD3358F13D0395301EBCEB
                                        SHA-256:D2A9B2025DF65416C8F9C7B37A314B22C483BED4B9A0076FDDA19C0BBDD8E533
                                        SHA-512:EBFC1E6282965F063B1B7933C053658B7DD3E69DF0187752C58D65F265B361F2B096FAD933F9C69E005910F26923F6960DEE8C3088F2F4D455CEFAAFC5D8B543
                                        Malicious:false
                                        Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.+9......+9.....;0.[.f...+9.....;0.[.f...+9..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............."Z.M.Id...O.........N...^....................7FN.....v..........Z........................................I.qk..B.....LZ............"Z.M.Id...O............."Z.M.Id...O...............+9......+9......+9..........................................+9j.....+9T$c...+9......+9..G...+9..H...+9..>...+9......+9 .3...................;........4...4...4.."...............+9..+9..+9..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........+9......+9....#.+9............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
                                        Category:dropped
                                        Size (bytes):5465
                                        Entropy (8bit):7.79401348966645
                                        Encrypted:false
                                        SSDEEP:96:X0cZneDWlIKmXwxacOHHI6EhzNlSSDDgafbofgt7mGrw:XleDWlIJwQHihRdgu8imGk
                                        MD5:8470F9A96B6C6CAD9EE60961E96D19B2
                                        SHA1:AFE1F01FFA4E4CB06B1D770C9C59DA75B434D1AC
                                        SHA-256:2DF453410796AEC7B9EFEC00059B6CE64BCF67313A95AE458BA600EA5DE14811
                                        SHA-512:CAE5C2ED091BA49761F0348516D53491E578FB165F32F93AC7DAD927383E9A398B06229FAC6A8233777DF708E5001AE0037A1FA960293BDA49892C40B37F2240
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................E.e.............................................8...............................!"1...2A#Qa.$34bBDSqt..........................................................?.....`0.....O...3Sd..@..5.0....Q.pw....;....!pN.DR....`0......N^...k.=.u.e.7{.b........?z....zV...M.....P:a.SPj.....WRK.=x.2.h..2..AS..s..A..|.Z/f$D.YX1pr......}G6._.~..)j...+.s.r".{..q..-.^@...#w|.H..*.K)....g...y..`0......2.w@.Ro.d....@...K....}...&... y..f.y.0.|DC..>p.[E.2......v..N.)Z..4.RF.D.8]..Z.|f/..+\ID.r/.o........0i..*.G.O..uj..RN. ....j...xnF...Q.Ls.U.c.D0m....z.k.P;f...b.=..L.hH.,./;.U..`sa.I...?*...I....M.0<.u....!..C..U.T.....s.Q......_..7K..*.....?....R\&=.<.u..oQ}WZ..Yu...{Fe3.h...@.s..mW.G..^....1.W.#[.q2.&u.c.G......`J./..X.C....M;.....3k$}.i.3...#/x.m.Oh.}FH]. ..5NNDIS.-.M~...6..w.d....P.;..k...........v*..T..L.P...s.!B.4..w
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
                                        Category:dropped
                                        Size (bytes):3361
                                        Entropy (8bit):7.619405839796034
                                        Encrypted:false
                                        SSDEEP:96:zDqnxqMt6gGr/Nln5ANln5ANln5ANln5ANln5ANln5ANln5ANllHN6:CxqMQr/rn5Arn5Arn5Arn5Arn5Arn5AN
                                        MD5:A994063FF2ABEB78917C5382B2F5FA8C
                                        SHA1:BD5C4D816B04A2B6596DFE38DB01228F553FACCC
                                        SHA-256:D72900E8DA72D1A7F3729971AA558E1E9B6E9CF9A0D51E83852E567256DBBFEF
                                        SHA-512:CF2279033DD3EDFE6F6F9E5C517BEBD9A52863EEFD90F57F7A5AE0E0485E705254BE7ED6B50E6CA142669687727AE85E2E6035F69930B75F2E6D3EEFA961EF88
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................U..........................................>...............................8H........59...$%&7F#'Ddf.....................................>.................................58EG........!#124$%&ACFbcde............?...n.p..v..a.~.._.>......#....8.....w.G...&.W...i...%6m..K;...4."...=..?.~......P..O...j.l..AW.jo..,..=d.h.ta..../.."...z|).J.......Ww._..<Wp.3+8...-5...G:..2.D..I>o..K.F;-.....#...`...6..T...M.....OOgV~..5...np...P..TYr...........b..{r.2.9..].DA.%C....=.v.z......CK."..R..l..y}.i..;.{....JzS.....~.?..Z....=c.h~*..p.@(@..G.....O.]...Hsd.xf".V]..S"..w...4e>....3*U.7..|M.x...|\......FD./.cIe.;.bId..+=...w.......[.k>....}.u...j.xZ.....Q4..+.....B....1O~\......I..h....LaXJ%&.w.<C...n/`.W..U.W.U.}~...}>..^.0.J.....@....LN.b.......5W...m].Eu...:....G..:4.=4ixx..@_0=.mab.T.U.....w..~.V.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.30677586083873
                                        Encrypted:false
                                        SSDEEP:48:esoAZ5OwdOutE+KED5KXRX9eN6olrdQqrP76hBXWh/SihfFF:es/5OwEu2tEwXRX9eN68RQyP2hm6YfF
                                        MD5:EB4FC5D79A15AB77DE713EC02005D025
                                        SHA1:F15D33DDFAF0B1DAD6453E2A5B49F9771C31577D
                                        SHA-256:1517D95D54BED6D49F189AFC1B208B2A617FA34720B39947820E6F9702C7C7CC
                                        SHA-512:77CC7C42F530E73921D1136354C0B5C3EC215A1CD4AF667E8152549A1E2A5D19DBFB652697320BA536B7450A6670CC91ADEE92F61FFFFC6933F611C729EDAB02
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZsp......sp._..!.8;#.$I.`sp._..!.8;#.$I.`sp...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................u...>&._..ln....N...^.................^.q..H.4.(/Uo.........f........................................I.qk..B.....LZ................u...>&._..ln............u...>&._..ln.........sp......sp......sp..........................................sp.j....sp.T.]..sp......sp..B..sp.H....sp...B..sp...>.)sp...J...................;........4...4...4.."..............sp..sp..sp...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........sp......sp.....#sp.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
                                        Category:dropped
                                        Size (bytes):140755
                                        Entropy (8bit):7.9013245181576695
                                        Encrypted:false
                                        SSDEEP:3072:i/aDiblRsFcOco8dofE5Zx1+NQI8Wh9aiOe5NTO:mnbM+TxaAi98W3aiOwTO
                                        MD5:CC087700C07D674D69AFDFDA0FA9825C
                                        SHA1:F11113DF69DACDB255C6CBCFB29C1D1CCE40B346
                                        SHA-256:A7FA7F092EFF43030A56342C39A765F8D5CC48C7DB815DDFC8C1E5EC40117FAE
                                        SHA-512:843202D975EFA91E73287052A893584B6E5AE601F91612B56539AA2F73D1AD3F997FCAD1E711E0F483A2E91D46D9643D0B026B43F4E94116A5D2FB6551536034
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:15:20.............................\.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.......J...\O.,......../$..........OE.m.o......T....Z..l.g.-....m.?...Y....3......"....].j.X.k.S.k.....4..R....{....?F.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.359852861894593
                                        Encrypted:false
                                        SSDEEP:96:YJsdQGPrWshEuVJXU9eytSRQy7TTmGVRDdbMaTY/Y:6snrWduVJXU9eytSRJ7
                                        MD5:7D9978CE2C51EBE452414286E70F1DDA
                                        SHA1:58405A709612A7817219FE26CC13E00C5BFAA456
                                        SHA-256:27AB21184AEB7F67F6BA75B6F472873A7C007AF85FFE9B3FD930DAAE806BF598
                                        SHA-512:57D9B6ACEE94093FAC357EB32CBB21B90AED0249D40F865CFEE045950494A059A8CD3F4D732E50A21EB4377B4B5099B56881087A85749E662A018AFDAC81E257
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZP.......P..%.Q..;9"...wUP..%.Q..;9"...wUP....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............$.....(...~=~q.....N...^................4g.#.QE.9.....!........f........................................I.qk..B.....LZ............$.....(...~=~q.........$.....(...~=~q..........P.......P.......P...........................................P..j....P..T.]..P.......P....B..P..H....P....B..P....>.)P....J...................;........4...4...4.."..............P...P...P....z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........P.......P......#P..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
                                        Category:dropped
                                        Size (bytes):129887
                                        Entropy (8bit):7.8877849553452695
                                        Encrypted:false
                                        SSDEEP:3072:QS1x1rXglsteJ79wHi4vNQR5yBlUdOSILe9hSj9jeWMPjdlOJ:vvglst1HiwWR5yBA2LeS9jd1
                                        MD5:737E96E41D79D3BDACE7AB4F8CBF6274
                                        SHA1:E6202A41A4F86B27D9EBCAEF7670B16C0ED67CF2
                                        SHA-256:7966F3D8A2D61ECB49A35E163781858E052C0B122A18A1238AFE27B57E2850E8
                                        SHA-512:D398C8521DB2FB3F8456FE792CF37472F3B851DD7298DB20E2DB79144F8E846D051878E77E5EF5D00E6840EDB90C6E2D97935BC1023A15FC45038CCE731E9895
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....iExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:13:06.............................:.......................................................&.(.................................3.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................u.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...W..I:..*....a....Aa ...w.T.M.v.........3x.......8Y....$.."-..m.I.0~sxB[@..=...:..\.Y?....@O.L;9i..U....?.5">+9.s\Z..vN
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.351104279473443
                                        Encrypted:false
                                        SSDEEP:48:Yu1PaP3sWcoStVI/96EtqSEr7LsXz49bwdQLoqirdQqrjdSBXOhDN9:Yoyfsxti/cEDEr7AXz49bwd4sRQyhS+
                                        MD5:B1C00C1BBA4AFE2ABFF7B082025D5FD5
                                        SHA1:E4B80A13C578929F5154426D55D7B0CFB393D5BF
                                        SHA-256:D4DB12691D5100934BEB64C0D62EC1F78B60FA42EA613961CF18C0DC3D4E47A5
                                        SHA-512:7FC472C8F715676CDE60A5A5761AE978930BBF93D6D4FD4A5B4175DE93A2FB6D3F84D41C0885F772ABA8CEC7EDD6C8E9F3D8A87138F2095D1BD4DCC79B601BA4
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..............g..H..........g..H.........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............m%........VJ.%....N...^...................3..A....-../........f........................................I.qk..B.....LZ..............m%........VJ.%..........m%........VJ.%........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):84941
                                        Entropy (8bit):7.966881945560921
                                        Encrypted:false
                                        SSDEEP:1536:X3sWfhTVd+xu6rA6SOONM0/YFXnviDwoPCaNSm+z/ze/fWNj7GfigeKyCGzw+QKW:nsOhdDJOwY1voPCaom+z/zeHAfGihCG8
                                        MD5:CB84C108A76C2AFFCAC2551A3C1EAD56
                                        SHA1:8BB7C2A12B056C1ED12EBBAE5BC9F60CCE880FFE
                                        SHA-256:139BB0E79F89C3DDEF79B1716A5FBAB4C07DF5785FB3CDF6B4EEDDBF6C078452
                                        SHA-512:6EF85144E9A7ACD0FF2E52A5FF42093153EFB69127B1C8549EEBC49B6CC196A46B65EE39A2CAD0206F6A41476D8B5B35D29EAC9942B8F84972B32E14CAFEED27
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d....................................................................................!.1A.Qa..q...........".2..BRbr#.T.3C....S$.cs.D..4%5......................!1A..Qaq."2..BR....3...b#.r.C4.............?.......m.q..'O.....r......_.1....8h....?.....O]~..k......GO...''._...!....o........''..g..H?k.......1...?.....z......>...+0..................GO...''._.........}.O.Z|.L?...........?.........[~t.......}......NO.....v.......J.......?..g..H?k......GO,m..r}o.z.....}......dC.9?..g..H_..........?.....O]~...m...C?.z..f....W.=u.B..m..C.-?.a.....3._.?.......o....np.M....g..H_............9?..g..H...../..kO...''._...!~...o.....0.M....g..H.........../......O]~.~...o.......7..+.... ..l?.}........&....3._./....?.........W.=u.C..m..C.+?..o.W.=u.A.^.O....:......_.........}..t
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341248624926927
                                        Encrypted:false
                                        SSDEEP:48:YuzIrsaXU25P6tFPhmCcEe+h4X/89mroFrdQqrjx7RVBXLDtjKY7pB:Y6IrsA5P63Z4EPmXU9mrkRQyFHhZDp
                                        MD5:E44D4FA1A04F0BFB413F38216165564F
                                        SHA1:4AB5C9DB1D283D6F59B8533E017A0FC6CB01182A
                                        SHA-256:AAA3C32CC1EAEF6A031DD707CEDA417F533647BFAA83FF6B96F622DDF161931E
                                        SHA-512:DF99BBCB90D5FE55E9574709AFAF54823FAB2BC5C9B84E94604D6F4D7586D4D43E3E0077DDF66CF4AF73BDAFB2DDD03DD921B53E65BC6A9FDD7B9F24372237E6
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZI.".....I."..t..'J..&...I."..t..'J..&...I."..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............W...5..-.Z..f!.....N...^.............../..o...@...\!$(0........f........................................I.qk..B.....LZ.............W...5..-.Z..f!..........W...5..-.Z..f!..........I.".....I.".....I.".........................................I."j....I."T.]..I.".....I."..B..I."H....I."..B..I."..>.)I."..J...................;........4...4...4.."..............I.".I.".I."..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........I.".....I."....#I."............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 623, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):1569
                                        Entropy (8bit):7.583832946136897
                                        Encrypted:false
                                        SSDEEP:24:KArPoy/sSfmBL0EGEsRgeTLLXFnViAAEslVorlP0i8OmO57EnGAkYelBKMN:9oQPTgeL5ViAe8rQs7HAkrlc+
                                        MD5:07DB3F43DE7C1392C67802E74707DAA6
                                        SHA1:C173ADB1999065C5E1E6DBEF934B4D4D7AF0CC23
                                        SHA-256:51E05999A1C9F17DF28CB474E57DD8E64BDAB824874A532C20A23766A01F8967
                                        SHA-512:E509255519D4E521E82332FF418DD5A6BBBC8476399A0D9C3D81542C1CABA535B2D79E5BC90F73F9EE8468643302137671934ABD600FC696F16161C91FEAC111
                                        Malicious:false
                                        Preview:.PNG........IHDR...(...o.....>.c.....PLTE................................................................................................................................................................................................a.o.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.Y.. ..........}%.../].`<..y....V...m.....<....)..;Ki..'9...2.:.c...t..V..d.t;-y.Z.=K>B.."{Lj.~G..|..ENC.!Sw,....";.p..g....E.B..S.-...k..P."..E......l[./D.-.....Q+.G<>.+..b...#..y(...{a.M..J...<....v.W..F.qm.`.....(.mk.nX....l.Px8.0\Z....7G...$*.....&..Z.VJ.~......J.2|...2H..../...=.)q....ZT" .,%..h.p....Z$.!........r...Hh.f. ....P .d..1d....2.3h....;.A.... ....d..g4...A..^.....2.ew..."h...y/..j.h..B.......%.2.%..{r...+dG.=9h....P1...A...c...^h.]Q0.8x....q .!3....ZW"Z.!3...G.vC.GG..".&..X!3.|xB..V.P!.+zS..NX!3.....Nh.y(.Z.1.h..B...Z+....l8Xcu.B...K...@U..@Q...mB...x...&L C....mB.....@kC...Y.,.... ..e\F.B..........y..e\..:$(....Z.a...yn...f..z.~Q.{o...].ln.r....^.@.{..c.7..{...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.346767481124215
                                        Encrypted:false
                                        SSDEEP:48:H8LsQOfMGMntCDE+YlLnXN29+boxrdQqrrkQBXjCL9kxgR:UsbMDn6EplLXN29+bwRQyoQMUg
                                        MD5:D9646ACC0911E17480822280D69429D5
                                        SHA1:87D3E44547506F06E29BC86949084009551B22CC
                                        SHA-256:BF900668B2F33F977ACAA62E467CDA5C1A4DF72E288B19EF6624174EC4995E32
                                        SHA-512:CD149B0405FF5A09C0493FDE16836B8630AD43759118C1D45EA89CA75BC646FAC5C61B31256C82A57AF23E563E9DFEB046B851BA8A17764A6C42261A1D1E5CFD
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..O.......O..`4...O..l.t..O..`4...O..l.t..O..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............dV..XT.$QR.0KSC....N...^...............k.(..#.L.......`........f........................................I.qk..B.....LZ.............dV..XT.$QR.0KSC.........dV..XT.$QR.0KSC...........O.......O.......O...........................................Oj......OT.]....O.......O..B....OH......O..B....O..>.)..O..J...................;........4...4...4.."................O...O...O..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........O.......O....#..O............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40035
                                        Entropy (8bit):7.360144465307449
                                        Encrypted:false
                                        SSDEEP:768:MQhziQo1RKGlyyzYjlxuxwRUj/BN837xRmwH2uDTCn8qXFQziN:ThzrSzalg6O563l4uTC8q1Ig
                                        MD5:B1DDD365D87605F96D72042CB56572F6
                                        SHA1:ADF71DAD1A62B8A58A657C2EDBDD665A19EB846B
                                        SHA-256:06E09DE80C3F32254DA4FE6B2CBAD7C05EF144DD54B8C65745E195BBF7317A2E
                                        SHA-512:9C686092CC9524F34EA6CEC9AAE936A6225BCC54DE38DE1786EBA8F532959A80FF885E8664A09E4C318D7CA4B278E807D3D1F135BE55F30979B844FF5EC9699A
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!1....AQ.aq.....".3.5...2B#s.$%..Rr.CS4&6...bE'7.c.DTtU...d.eu...VFfv.Gw.....Wg......................!...1AQaq........"2..4..Rbr#3$...B.s5Cc.S%.D............?..^.f....R*.N{.{f.....O.r.V.;U..~...U.(..>M._.yI.{8,..^.t...s`...j.O..U5t.&&..h.G.6Da.;.....J.......E..QD...C...}..N...tR.....~..].J:.V$.*.r......]...W......4.[.)6..Y_.....4...........m._'HR.a......]U=.....n...0.W..]..K..){.+...w...f...<|..1/.|.....b..-..y....]U#Ctn.7m.._.|..2I;|....tM....q.q.}.N)....'...9&...nR...R..}.........m._.LZ}u.../K....9.~..?.{....V.#..dx.Zk.:=..:.j].....E#....E~w%....J..[S..[......gr...vb.r]..<..ut..i...[P.w....:..Gkn>......#..m...9km`......t).up.....w....VOR.{&.nQI..}...wD.7Ey#n....MO.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.619385888008212
                                        Encrypted:false
                                        SSDEEP:96:Mq7quswmDtkE3/aXqLI9KOfsRQypqkN5b:Mq7quswmD3/aXqLI9KOfsRJp
                                        MD5:DF3CD12824C1F296878681F0B475F90B
                                        SHA1:6ED2A8FCEAB914F3F353FF87BD9AF0E939C7FADD
                                        SHA-256:E4BE80B1B9E06571552E651D9F3C4A15662B7BA3266B134D62CDF7CC856E2D2D
                                        SHA-512:48C2C6755D2090C28694851E824A5988B42403538105329C58D921CA85FF9A63F7A8A683366E18A9CA1126C05EDD3049C11A8E613754A3CEB3CC1CC7BDFA286C
                                        Malicious:false
                                        Preview:2...>...........v...~...................................................................................................................................2...>...f.......v................................I.......I.qk..B.....LZ............tV$...$1.......tV$...$1........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............T....(.?".?y.W{....N...^...............].sm...D...A...........f...................................:....I.qk..B.....LZ............T....(.?".?y.W{........T....(.?".?y.W{........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
                                        Category:dropped
                                        Size (bytes):242903
                                        Entropy (8bit):7.944495275553473
                                        Encrypted:false
                                        SSDEEP:6144:YVxOYlZX2kCWfYoFMXC/sBFC9r+4iEGM4rrcPoWmwkU6FJ:+OwZ2kbFMC/L99ifvokU6/
                                        MD5:C594A4AA7234EF91E6C2714CFE1410F1
                                        SHA1:C0F720D4CE3196852814D0B7347F0CAA0C6FD526
                                        SHA-256:10C833E47BE1C8496F949A6B059C2D79212A4DD66BDE62116EA337FA4FE0B654
                                        SHA-512:7313F6545A334F9E2DE5430B2DB5C419C4C8A40E075338DAFCD74970BCC6309786946E5DFB57531612BF4C6269495655706D920FD99922FDACFF9796710DA9C0
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:10:32.............................R.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...v&.F;-v;}FH..Z...N..)Y.......h;C....G.0W..ww...MI..Z+..\.........c..4.1.~.Yo.Y6.&. q...............l.A#.~s?yYg..7ky...r
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.327510964666234
                                        Encrypted:false
                                        SSDEEP:48:YuO/sWxchPPjgauSLtAHjeAxEXMRLYLXGrL9+volrdQqruVWTBXvRkP4aeUO5F:YZ/sWazLqH3EXMRIXGP9+vcRQyuV8B
                                        MD5:A6C4B47A106F3200403A98DC460C4C31
                                        SHA1:79E339D9850522DADB4BB3B696184D48C03F5C7D
                                        SHA-256:FFF14FCBDD0A7BA3CCB8E26198B5C4307230638E64375F12D08FA1298623A4AA
                                        SHA-512:B78D74FC94BA700C3CFB90BEA7C0B888F31CF749CF049CC4398A64753F622DBEABA8657E8F7F8722B789C1409990008E04E112318D385CCD19698737296E3A77
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZp{......p{....b..Y<rt..1p{....b..Y<rt..1p{...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................p...?.H.]......N...^...............{%.o...A.c.!}.........f........................................I.qk..B.....LZ...............p...?.H.].............p...?.H.]...........p{......p{......p{..........................................p{.j....p{.T.]..p{......p{...B..p{.H....p{...B..p{...>.)p{...J...................;........4...4...4.."..............p{..p{..p{...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........p{......p{.....#p{.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
                                        Category:dropped
                                        Size (bytes):70028
                                        Entropy (8bit):7.742089280742944
                                        Encrypted:false
                                        SSDEEP:1536:ub4bgbB7g9cKCmSzaNF0jAdAzQKTEFBQqUp/i0yG1pidLHTVX:ub4bIB7Qg2OjbzjgWp/i0yGCZx
                                        MD5:EC7811912ACA47F6AEB912469761D70D
                                        SHA1:C759BC2D908705D599B03BDB366C951B11F99A4E
                                        SHA-256:FBB4573E3BEE1B337077691BEBAE15D6FAC52432405D31396D526D7694A8283D
                                        SHA-512:881828150993A8C56E36CDA2051D89C1F6E0322643902C9506392C163E8734A2933A46486F40E5BC8C8D0164E180605E52620EF22FE14540AEA787A38B22E98E
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....7Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:12:29.............................V.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................}.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....H.yM..? .Z.. .^.x..p.8.A...K.... .\{..)..y....t..=.^y)..v.@.W>. .h.. ..p.:.\)(.$....$.I).....!....E..Z.....&.5.).
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.357678780996109
                                        Encrypted:false
                                        SSDEEP:48:2sUsHGH/tCq8E5VLPCX0S9yWoFrdQqrASFBXkEsVGYBkFsXvTh:2shG/4/E5VWXb9yW8RQyVTsc+kFsXvT
                                        MD5:0A018365B0DBC5533E98D3C8222E56FC
                                        SHA1:8AEE9B5827DD84B4247678629054BB6CC33D8661
                                        SHA-256:62A3B83741E01195624D11B3A0C417B4F9B1C27A1FF1C30831047ED51D82A5CA
                                        SHA-512:C0F78BCF41398CD609E5F2D3ACA46D7D3AEE46BFF2FB8ADBFB9C970C942DD2B23BBB8FF1B8026F0674FF4C399432E0D6DE3D349777E89B5740EB5C9919250161
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ%......%...Qv.:3KS.N|%...Qv.:3KS.N|%...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............2..->....{....i....N...^................\....J..k. ..Y........f........................................I.qk..B.....LZ............2..->....{....i........2..->....{....i.........%......%......%..........................................%.j....%.T.]..%......%...B..%.H....%...B..%...>.)%...J...................;........4...4...4.."..............%..%..%...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........%......%.....#%.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                        Category:dropped
                                        Size (bytes):24268
                                        Entropy (8bit):6.946124661664625
                                        Encrypted:false
                                        SSDEEP:384:d2wiieoHTRh5a1HAteZCWOZIM+L7WhNjYn:8wHFHJ+/OZIKhNO
                                        MD5:3CD906D179F59DDFA112510C7E996351
                                        SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                        SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                        SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.339808951787543
                                        Encrypted:false
                                        SSDEEP:96:CsgIIiruQVK/EjKXuZK9+ncRQyfVNzwo:CsIirlKsjKXuZK9+ncRJtNz
                                        MD5:82D256048A60C0518EC016253C902782
                                        SHA1:0CDD2E71793EE37BA45E4D8DDC3367A5DDF4D555
                                        SHA-256:EE3B88A4C61AD7ADEEC6B570AD39FB0FCBFF042F959A206E3464FCA304998E64
                                        SHA-512:29DCC127E7AF10680339C4DD7AF758B0F29039C21C3EE847EF6F7173F5BC31A7299211C52B4A5F646B0558B32F618AB5BFF47702CDD316EAAE59C4325DC4D800
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ>w......>w......'.2.U...>w......'.2.U...>w...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................SW...6...'F......N...^...............+7:..j.E..=.sD2........f........................................I.qk..B.....LZ...............SW...6...'F.............SW...6...'F...........>w......>w......>w..........................................>w.j....>w.T.]..>w......>w...B..>w.H....>w...B..>w...>.)>w...J...................;........4...4...4.."..............>w..>w..>w...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4.........>w......>w.....#>w.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):47294
                                        Entropy (8bit):7.497888607667405
                                        Encrypted:false
                                        SSDEEP:768:aQ10VrIBdBvDpQrQ7P9/FUOLG2vTSeG9lkCsMKzXeMBk3CBp:aC0JIBL+QsOLG2+ZAC1KqM2I
                                        MD5:7A450E086AD14BA7D89BA5DB3D3AE6C7
                                        SHA1:E7AEAFCFCE476390E18C19456BDF6529D863D518
                                        SHA-256:BDD997068701ED3A00A224EB694B003C01AC69B857FE7B4147D6C34875B1632B
                                        SHA-512:9B6D50A6CDB6081DA107A2CDDB1BD2811A5764994C8E3F67D56CA81084BE0D068C27435154E867199F38688EA65E8DE02A56DCAC47D0F5E55F0FBB6598814938
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..A..Qa"..q..2.......B#...R%.r...$&b...3Ss.4dU6F.cE..'GC..t..5eufW......................!.1..AQ.aq..".....2BR......r.#3.d...b..Ccs.t......$4T...SD%5Ue&Vf............?..M.7(..).:.a.q.......>..[:O...afQ.uCO..U.....go.l..p..YqVklQ.{i.w&.]Z.\+JQw._.n.'.h..,.bj..X.].k&.Q.>gU..f...1|....[...jQ.%Zb.......t..........*..V..j.6....Vj..i.....?...IY.P.....$.j........[l.....S.4.J9.U\.......7I..[..=*N5....xW..../...=?n....uG.D..S.>...8..3........n.S....]k.*...4.>.R.o..{..l.H.#.^....<amG.m&.......,....wDY.W.m.X....We.IR.Nu...y..Z.l.._S.mr.m...y.]m.R.MT...6.5.5}.K..#%..k].7.Y.q]...%.r.7.R^jR..z.K.T[t.a..d.)glW.r.v,.`....O..^..o:.Uc.\..D....f..D......yt.Q...Y.....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.489751321940057
                                        Encrypted:false
                                        SSDEEP:48:IYEsgK+rL9Fpjt1xEwL5hFLQUXFU9OloxrdQqr8te/BXLxqksLen4yUS1:IYEsuFpj5Ew1JXe9OlgRQyfX
                                        MD5:683B1DA1639DC89DF3EF6074688ECB92
                                        SHA1:6C4654559B1B41EACD89A797F50D4E312FFB9FF1
                                        SHA-256:76160F99D2272DF1B5B39FACED0889E6E581FD38B8C590323E4FE869035E75A9
                                        SHA-512:2FC671F3DA343EEB25C541AB900F1F0E453D5EC83CBE9C85B3496757802DBFF00337E557740574B4C1E78027BEFCF510380FC085DBDE28468007F8343474FE50
                                        Malicious:false
                                        Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ.sJ......sJ1.o..5..Z@7C..sJ1.o..5..Z@7C..sJ..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................\{.3.7"$...*!....N...^.................k..9.O...<...4........f........................................I.qk..B.....LZ...............\{.3.7"$...*!...........\{.3.7"$...*!..........sJ......sJ......sJ..........................................sJj.....sJT.]...sJ......sJ..B...sJH.....sJ..B...sJ..>.).sJ..J...................;........4...4...4.."...............sJ..sJ..sJ..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........sJ......sJ....#.sJ............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 60 x 336, 4-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):347
                                        Entropy (8bit):6.85024426015615
                                        Encrypted:false
                                        SSDEEP:6:6v/lhPtnlx/QulkWNY2V18A6Akp7eee1VDjMHCyLezyKUX5Gp:6v/7RrIubiA6AkpNhiyKe+
                                        MD5:78762C169F8B104CB57DFF5A1669D2DF
                                        SHA1:9638B71B584CD636834016A635ABF8D9C0887711
                                        SHA-256:E64FDCD0B108737D8B8F7B677029F924031D6BBAA50585D9C3DEF7C7E92ECAF2
                                        SHA-512:5ED899AAF73B72DEC32E171FFA112382667D5BF3FBA98C92E313E66C0A6975EA97068F4CD32B62283F18DBD5345C11E3610F7EEAC2F2DE71FC44593180B9CEAC
                                        Malicious:false
                                        Preview:.PNG........IHDR...<...P.............PLTE......................=l......bKGD....H....cmPPJCmp0712....Om......IDATh......@..aI...B..C..l...^.%.`....>.]..|0.....a...hb...0......q.......p"....;...K..x=...p...y.yy~J....|...\.......y..X.......'...>1...Ky..f....&........N`..f0..b...3.......`Z.3..3.....o.......4.&........SV...4.....IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341277387111535
                                        Encrypted:false
                                        SSDEEP:96:8srENjO0B8wEeXc90zRgRQy8ywNj0JMug:8s4A0B6eXc9aRgRJzw
                                        MD5:C0628DC1809AD21A2711C1CB6EFCFC78
                                        SHA1:E71B6DFF24950D8B342CEB00DF5BEACE620A982C
                                        SHA-256:94C1367394825A84612E74F31FE67A0E517DBA55B72F22A31477741C1146DDDD
                                        SHA-512:D622B95D9C28A6C7A2799164A30646C5B048702E65E5D73E7596E43AB2C93B7616A90AE17749EC11F048E94EB548361B62D65C627D6BE4657F2C9ED44A12A99C
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ...........oyX..4..z......oyX..4..z........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............`.p./..K....k.....N...^................3.!..&N....C..........f........................................I.qk..B.....LZ..............`.p./..K....k...........`.p./..K....k.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 617, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):827
                                        Entropy (8bit):7.23139555596658
                                        Encrypted:false
                                        SSDEEP:12:6v/7Hs2NwBW1mtjeSfaTHHy05riYUtr8y8PQvPYzzg979Reip0QPqc:oOsotazy4rStr8y8PQIzWea0Qv
                                        MD5:3E675D61F588462FB452342B14BCF9C0
                                        SHA1:86B62019BC3C5BE48B654256B5D10293FC8C842A
                                        SHA-256:639EADAD468B6B32B9124B1F4395A8DA3027FF7258D102173BA070AE2ED541AE
                                        SHA-512:E6EA855B642ED36FA82F8E469A826DC57EB0C36E307045FF8D166F67AF9242C87840833BE31FBE4706DC54100E999D6A3D3A78D0633A3114735818874AD34758
                                        Malicious:false
                                        Preview:.PNG........IHDR...(...i..........`PLTE...................................................................................................bKGD....H....cmPPJCmp0712....H.s....qIDATx^...0.Cg.;......@j..2c.=~KP.[H~..@..8...?U.g.n.a=.=.).....3..u^(.....L....5..........8.}..T.f.n.a=.=.).....3..u^(.....L..r....s..8.....W]....,..9..G?.a..`c.z...E.p...)Y.P.....#....@9.7].....,..9..G?.a..`c.z...E.p...)Y.P...`b....0.b.+~{.Pu...1..<..0._.l.@O.y.(...V3%..J....s... .(g.+.qyWu...1..<..0._.l.@O.y.(...V3%...%R.L.Q..x..R.<t.o......7.............:/.E..j.da@i..`b..Z......u.>.?...7.............:/.E..j.da@.Dj..9.W....s. .....:.......L...">w..7... .....:..."...L..."..a....D..Ya.l....E.{.@&.|.._...7..D..Ya.l.....{.@&.|....0.J.."z.0s..s....=g ..>........"z.0s..s....=g ..>..l..1...y..g......IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.32289491883179
                                        Encrypted:false
                                        SSDEEP:96:Ss/ItXGBSwIKpEXn4Xh6k9p8/cRQysptOQE:Ss/IhGBSNKWXn4Xh6k9O/cRJKtO
                                        MD5:E4831ED47858C316BCADC47A4B9CE928
                                        SHA1:05B833F6D5B2B7804C5B47BD04C83BA5A7484EDA
                                        SHA-256:97BEC01C77F970EE1C39A10040D62D482A7185DF54846B0875A1629004A448B5
                                        SHA-512:523A168520FE0BF95CC7927089161E415FB578A764F4745DCBB5FC9B12EDF0E6B58608ACCCDAB02B17675D0975FAE5AF0FF8C66D474A83FD2DAAB508FD4F24D7
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.k.......k.w........Gj.m.k.w........Gj.m.k...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............._....;..+C.2.?m.....N...^...............8...aFB...jc..[........f........................................I.qk..B.....LZ............_....;..+C.2.?m........._....;..+C.2.?m...........k.......k.......k...........................................k.j.....k.T.]...k.......k...B...k.H.....k...B...k...>.).k...J...................;........4...4...4.."...............k...k...k...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........k.......k.....#.k.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 600, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):4410
                                        Entropy (8bit):7.857636973514526
                                        Encrypted:false
                                        SSDEEP:96:E/pQuIhKZ7u06dICH3AroiTe8DGTl55poBUmLNjpH7MvDHjfm:MpdZtPbknnRPpkLNVMvu
                                        MD5:2494381A1ACDC83843B912CFCDE5643B
                                        SHA1:98F9D1CC140076D1AE5A9EA19F47658FD5DF0D66
                                        SHA-256:5EEBE803E434A845D19BC600DF3C75E98BB69BD0DE473CEEC410D1B3A9154E28
                                        SHA-512:0E64CC3723DC41D94910F7ADFB6A0DFB5049350FD15A873695614E4A89ABD78B166BA4E9C8CB95E275FB56981539DECD2A7F28FBC25E80DD5E2DEA8077CC9489
                                        Malicious:false
                                        Preview:.PNG........IHDR...2...X.......E.....PLTE...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................B..(....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.].\TU.?3"...(..L........q.Q...H.*j......W..Xd.ie.f..%.XT...em..m.m.vkik...>.}..}|..{'.U..~......}....s.............,CVu.x.:C..5...;.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.339966257634038
                                        Encrypted:false
                                        SSDEEP:48:YuN3D1DOsB8Vv2pQdWtOtEZUncf0L5X6w9u5oXRrdQqr59qABXZd+LG4f+DwE9+K:YElOsodWEEZnf0tXR9u5iRRQynr
                                        MD5:9241EFBBCE2AC30A2C3637A66F630419
                                        SHA1:9DA10E9009ADF5C48A222BB85852E639088EF950
                                        SHA-256:9CD7CDAE4FD5D974C15E65C0725AD39E44E0E79F2B9A17047C729B64E4DDF8D5
                                        SHA-512:57F9A795F9BE1EC1AA52B1817DC16643DE4D69917B65484EBCB682B9E5E7B63B369ED853B9A38732CECD9AA12437526F9C986B3B22046DD929B2BF6D76725FAB
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ..M.......M6.fY.!#..l.l...M6.fY.!#..l.l...M..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................................N...^.................>...D.x..n..........f........................................I.qk..B.....LZ.............................................................M.......M.......M...........................................Mj......MT.]....M.......M..B....MH......M..B....M..>.)..M..J...................;........4...4...4.."................M...M...M..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........M.......M....#..M............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):136726
                                        Entropy (8bit):7.973487854173386
                                        Encrypted:false
                                        SSDEEP:3072:SIXmy5Tl704vW2ZKkvV8UU0ZWUF0BJwySIdgz816YzDc1+opecYPn:Sny5Tl704fZFV8UU6LGXwyS4xohpQPn
                                        MD5:4A2472AC2A9434E35701362D1C56EDDF
                                        SHA1:16FA2EA2D2808D75445896E03B67A93000EEDDD8
                                        SHA-256:505F731CB7707EFAB2EB06685B392DC7E59265A40B55AAE43E5DC15C0A86CBA4
                                        SHA-512:5E28D8FB2AC62ED270968072A30013334461F7CAE96058AF9EAA6E10912989DC47112D2133892BF61F7A516B77C6FF71BA2A000B750A9F95C787E538B09595C2
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQaq".....2B....R#..b3...r...C$...X.....Sc...9.%'.(Hs4Dgw..T..5GW.x.)......................!.1..AQa"2.q.......B..#c........b6.Rr.3s$.&..S...C4.%5............?.........(......(......(......(......(......(......(......(.G/.GE&...)..P.x..B.({i2Y;.z?G...Yfc.)H..^....#.....}3..Sc^.H..+...M.a.P.....GS.....H_.3..<....1f........1.<.\..nn-..s.s.\9Y....=.......S.0.......N..cA..Io..r.3..........ay.....K.....,.;9..Q......xO.Fa.2..>........{4k.....|....?U....3.8..._/3....#.. t.y......yY.......e.<........#.....B.....Z.%.Y..S.ye.W4...l.......X...%.@y}>....l.yi..D..W......L..._D.Q....)...E....n.%...*..K.4#.8`..I....h..h.o..I......-...hB...3..u.(5..........n...,.@....a.t.9.....@.s.>.&...@
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.329037490799956
                                        Encrypted:false
                                        SSDEEP:48:ysl3IpMxf08vt8sFEKHLujpX/Vp9axDo9rdQqrS08BXdZvX19N:ysEMxrv+wEKHaXz9a1sRQyUNl9
                                        MD5:8128D1B6B861B0292E2B8B3927C21313
                                        SHA1:A4FA99E22C9C751E0666C4577414744F76B33CAA
                                        SHA-256:513A5A29029936EDE8CE6B81BF8711F20D6EFD9CA6FAEF3557ACA12E5AEE85E1
                                        SHA-512:CDA20594E4F27CB80F39A5965DC1D416720C7E75DFA49114269CC656882B6E88EF948F376F2918E5D75DB236F6DA77E2155CB29115A257C2E290B327EF10234F
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.B.......B..O.....z.'OM..B..O.....z.'OM..B...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............k..Ni[.!C..dG.....N...^...............o.n4. ML.R....U.........f........................................I.qk..B.....LZ.............k..Ni[.!C..dG..........k..Ni[.!C..dG...........B.......B.......B...........................................B.j.....B.T.]...B.......B...B...B.H.....B...B...B...>.).B...J...................;........4...4...4.."...............B...B...B...z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........B.......B.....#.B.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 77 x 627, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):5136
                                        Entropy (8bit):7.622045262603241
                                        Encrypted:false
                                        SSDEEP:96:djzuNKb3XHco17p2wolIxIx7lpskdsC/ddWNKeabJbMojpxLDTu1:VzuNKb397pwlIxKp7qs3bJb5FBTw
                                        MD5:FA38AFA965141EA3F17863EE8DCCDE61
                                        SHA1:2B4611E651AF7549C1AA73932B1136B561A7602F
                                        SHA-256:E1CB1A0EC9BE62D5445C73AA84DF38234002A7E164EE830C9DF24997802CB5D2
                                        SHA-512:A372674F5CA343321BA9C413D346070709F7685706C9C6C3DC7F61846B59253A5E6FE800DBA10AE870FD3887439B2AA106FBBB51751E92A163938A4393C43E28
                                        Malicious:false
                                        Preview:.PNG........IHDR...M...s.....}8nv....PLTE.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................z`.....tRNS...................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.442198019387247
                                        Encrypted:false
                                        SSDEEP:48:zWOnsueAHtR3TUhVatitEByXiV9MthoBrdQqryFaTCBXps2QtR43ARk6Od:tsaTUhVaMEcX89Mth4RQyy9IO
                                        MD5:F636E82313C0F5E0F97D915FF1542D59
                                        SHA1:E6EF0C41F0A119F05D7B56BAF188408E1ED396F8
                                        SHA-256:84FE02DD912659FA3B7961FCFFDA6DB7B431F15F5DAC49CFFE1D0250926A7DD1
                                        SHA-512:3221AAFDA16369C6BDB295A39DEA2536FD1E1C66763F7DC0ED1BD73DE105B727921828EC824E309AA1450AACE6FD7BA9D326D335478104121DB5CBEEADFACD03
                                        Malicious:false
                                        Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZ..|.......|&.............|&.............|..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.................g6.9.|...H(....N...^...............:....<QH..k..C.~........f........................................I.qk..B.....LZ................g6.9.|...H(............g6.9.|...H(...........|.......|.......|...........................................|j......|T.]....|.......|..B....|H......|..B....|..>.)..|..J...................;........4...4...4.."................|...|...|..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4...........|.......|....#..|............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):52945
                                        Entropy (8bit):7.6490972666456765
                                        Encrypted:false
                                        SSDEEP:768:cjvqR0XvFaGCTJffi0tgybmWDoTw71kHUAnjvawrlp2+NUO8dWSNl3PF2PjK/q09:cyRffflgybmWoTw1UUADHUbU21MjpAD
                                        MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                        SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                        SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                        SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.414952670473202
                                        Encrypted:false
                                        SSDEEP:96:JskgVgYgRzPGkmEbtrcXwFrc9+ERRy537yLgYgqyghgHgMJ:JsVWJRzOkDbmXw+9+ERRy537yUJqTSA
                                        MD5:8A3E19B900561A439E35FFFA6E2DFC4B
                                        SHA1:F7F471E802967A980552F526AC36803175826FFC
                                        SHA-256:C0EFFECF2E49B3B99FDAF31F9408019D3A650852A45A868274DEE759B0C4106E
                                        SHA-512:27B0A1C2F739988296959F62CFB6F1E3D82BC77D8BF31869D1DA7DED75B3D8B96AF1D521E1EC23217141B7E021846BEAFBB891225FF82211E9693AE4ACDDC410
                                        Malicious:false
                                        Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZ.=......=O....(ha.R..<.=O....(ha.R..<.=..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'............... X.i.............N...^...............3.M>.$.G....#..........f........................................I.qk..B.....LZ.............. X.i................... X.i...................=......=......=..........................................=j.....=T.]...=......=..B...=H.....=..B...=..>.).=..J...................;........4...4...4.."...............=..=..=..z...y.. x.. ...........$........4...)..7)..7........................;........4...4...4..........=......=....#.=............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):79656
                                        Entropy (8bit):7.966459570826366
                                        Encrypted:false
                                        SSDEEP:1536:2kuUliOeU4os8ii3nF3Hxro/qxXD9u/kjYgMZqoEs6ZUldm:3uUsOXYIAixR2k7WAZV
                                        MD5:39FF3ACAE544EAC172B1269F825B9E9F
                                        SHA1:2D40DE8D90BD21D56314D3F99CEF4FBAE3712C0F
                                        SHA-256:70475431CCA3C91A4EFA3B8F04864371D2D3A45696674A1A0562FE9CD8DB287C
                                        SHA-512:3B9F3B32696AB7779864E83DC0C45960114A130BEE0CF4D0643DE57FF952171E5D775AA49141EE31A28A9B5D052B26EB421F26EA736D7EF4B3A7EC812CA411CB
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1A.Qa"..q.....2#..BRb..r3$.Cc..Ss.4...D%5&..T...'7....................!1.A..Q.aq..."2.....B3.r.#..R...bc$4..D.s%............?..Y..T.o.\......=.a..j..'^..s..[../........Y.......<...(..4.....7y..Ln.[9.cK.ilN...u@$.V.9.V?3..s.KL.z..w.jW.C.............@.~+.o?o8...k....,.m..9.".....q.....d....z.W...q...~...'..e..>..f#...S.....F....pU.......7..N.vfK......S..G.#.....}.c.........RXt.bq1.`.....[+8\.*.N..:......}.....r..........')......Na...&...m......c...a4_%d.............co..0.n.L.Q..E.Lt..y.|..F..4.i(>.._..\.eNL8..?z9I:hLgC.@.p....g.t......'.I!d..?1f..R..........|..4.wJ*..%g..~0bt.....*...v.......O...:.~.>~..o.x...9.@>...s.&.E.0/G.c..t.<..F.t.A.z. ......;.........Gp.P
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.475781649136731
                                        Encrypted:false
                                        SSDEEP:48:yzxslqjGGbV05do3BI+tvueUEWnyqlfZXy7dZ9787oYsrdqr2x8ZJRXw0DbSgtLf:yzxs1o3BI+TUEcXy7T9787rsRy2cucX
                                        MD5:24464CE1EB17464DB9BC2868A54E99C4
                                        SHA1:C9C6D3CC8A97FBEC7510D076508C74DE796B2A29
                                        SHA-256:8AFACDA5807100722B925292EC077F86EB5B9D457E0A20CE5671B991617955C6
                                        SHA-512:D68FA68C197DCB8867A1C5B3C8FE27552B72CB2F48A6E8AF9A2602571D704809D04D5D653B93DBCACC599186FBA84FBCA70B0872166C39E6FC303CAB280A3827
                                        Malicious:false
                                        Preview:2...>.......p...v...d.....................................................?....?........................................................................2...>...L.......v................................I.......I.qk..B.....LZ............z....!.........z....!........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...................G.+.8m........N...^...............m.../..M..n.M.b.........f................................... ....I.qk..B.....LZ..................G.+.8m..................G.+.8m........................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40884
                                        Entropy (8bit):7.545929039957292
                                        Encrypted:false
                                        SSDEEP:768:MCBOA4d+ElOXJ/3pI7cRBiL7L6qERqGz65WXzZqJsKQSbIsTT6XB:hIAU+2cGdLX6qBG4WDZl4Ihx
                                        MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                        SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                        SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                        SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.3574538560931755
                                        Encrypted:false
                                        SSDEEP:48:YuasH4LC2EBtwk0ZWEfE+TXV3+9ksN1oVDrdqrTGeM2RXobKSnulKXB:Y9sY9EB+IE8+TX9+9TN1ARyTGURs
                                        MD5:C6AB094D451F6F1C9CD56EE62838FD91
                                        SHA1:5DCAFDC388D8091B18F7EFCFBA8C8DF32B78BEBD
                                        SHA-256:82E25B27DA07E86873B83FE3071442DF2FB0C7F96ACFBEF357BE89404EF72CB0
                                        SHA-512:A992588FEED43C15B36D13812FB3F1C9F6EDE97D0A6EBEB9E1F8F4E895E209D4482F84D5D9757B0D46E4BE868947D24845E224FEE59E3FF48B30F063E51B7AC1
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ................:..u...........:..u........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............|A..'.E..E$.Fh.....N...^....................J...M1O.4........f........................................I.qk..B.....LZ............|A..'.E..E$.Fh.........|A..'.E..E$.Fh.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                        Category:dropped
                                        Size (bytes):68633
                                        Entropy (8bit):7.709776384921022
                                        Encrypted:false
                                        SSDEEP:1536:tapXpSTJDOkFGdJdBk/slsbfsw1imaapnbvD8:U2OjJr6b07m1bvD8
                                        MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                        SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                        SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                        SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.425585822772448
                                        Encrypted:false
                                        SSDEEP:96:5VdEDs3nWOR7Eg3XbmXFX9u9n1kRyKSwKgc/:5VdKs3nWTg3rmXFX89n1kRyKSwKL
                                        MD5:94822FCAB3BAAAD3F850AADB5F8F9517
                                        SHA1:B739F09BDFB145CDC9097C644E3BDE6D0A1BE0AC
                                        SHA-256:727D0E58F0B91FB015A1680E9A4BB693F93F61DFDE669B6F840EB920405DDCFA
                                        SHA-512:D78C88D8EF6AB361044FD952C5C937AF4ABAA8404C8C379C69C5525618E788323F2B0015CAFC256731A82BEBAC04DDA2276D3856F12F1190807BB402DE9EEA3D
                                        Malicious:false
                                        Preview:2...>.......t...v...h...................................................................................................................................2...>...P.......v................................I.......I.qk..B.....LZza......za.+.<...-...$.1za.+.<...-...$.1za...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............w....D.$'f5..?.....N...^.................h.&Q.D.e.Ap!a:........f...................................$....I.qk..B.....LZ............w....D.$'f5..?.........w....D.$'f5..?..........za......za......za..........................................za.j....za.T.]..za......za..B..za.H....za...B..za...>.)za...J...................;........4...4...4.."..............za..za..za...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........za......za.....#za.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 176 x 513, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):11043
                                        Entropy (8bit):7.96811228801767
                                        Encrypted:false
                                        SSDEEP:192:YyroOCsBI9pkCFsHHX2RE6VOlPuIqmBtJNBfAr+ADP1IATaNeTyZ4GF+WQQ6Qwq2:BUOCsB2kCGH32RiPDtDBfArPDP1I/eyM
                                        MD5:8E9AB9C28B155A66BC5C0DA5E2A4EFB5
                                        SHA1:972E61F162D48F1CEE21963ECBB2FE439105DB55
                                        SHA-256:B243A24FA13BC8523450E22F408F9EFF15301C938F8CA52A57018B58CE6785DE
                                        SHA-512:12062D69E676B3B34AFCEF25AC17B40294282D5BAB6C0110680293D7CC96EC17EBCFE104C284E64A30EE3C483E319E9C37C03F6EE82C79632180E45C7A684E8C
                                        Malicious:false
                                        Preview:.PNG........IHDR..............`....`PLTE............................................................................................... .......bKGD....H....cmPPJCmp0712....H.s...*YIDATx^.]...,.N.8.i......0..e..y.......8.6....Fo.........=...F..._..........O..{..............3.|.L.|.............>.....v..n.1J...k...."....7........J._.5LQ`..k...._Z.W.x:..k...g..._.....u<.Q{...1...q6.cs...l............30.g...< W...a.5..>O....9}..c..........s|I.).>.fo4.<q......>...c.:.u..co.#.7,.O..G./.K.|..q.p...(.(....iH.......m..+.7...../..{W.l....b....?.`^.q.9L&.>.hN2`1..m...]$.0J....rBy......{.._...G....;.r.Q..;..,...9..F...t;.+..2.Ub......V...8.k..5.........'[..s.H..).......%j._.&.....BN..V..q...T...#..........0.E&.o7....$..m..8g.f._$..k.8...5......HgQ...L..\.........)B.I.r.(..8.a..$N.9.=..o..Q..(.e.a..O.....c.= .......$0..X.S,..(p......$..l.c.I...=."......g....^..#~,&.a9iK..ZNE`...pFJ.@Wd?.<..Bt.E.......e...i.%d...}.!..B......9.........B}.....5...;..hL.D.....4z.....|.)
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.340146184390358
                                        Encrypted:false
                                        SSDEEP:48:4BsNFWzkYltA9mrEQLWuXwn9vroFrdqrPFxjRXKoiGiW9BniK9PitiGidtiLiz:Qs+kYlzrEQ9XQ9vrURydxjpp
                                        MD5:E2A0418F55E8569D1017FD6185A21F2F
                                        SHA1:1EDB6D08394C6DA656CFB8DE40E45C74B5CF6C4B
                                        SHA-256:9DCAFFF28E52DD3A34E956196E5081DCB895AA4E031F218865A5BF287BE757E0
                                        SHA-512:99B91F70D200F15EE5BA55F93974F622039654A36868604DFD01E12489D038DFA1C7FF34FB2F89095ECBE946C45F3A85F62B7A22DE1DFD7F8904B2B97818F6DB
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.&.......&......'.d.}.]..&......'.d.}.]..&...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............v...5z}.... .m5.....N...^..................Vw..O..D.5...........f........................................I.qk..B.....LZ............v...5z}.... .m5.........v...5z}.... .m5...........&.......&.......&...........................................&.j.....&.T.]...&.......&...B...&.H.....&...B...&...>.).&...J...................;........4...4...4.."...............&...&...&...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........&.......&.....#.&.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 650, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):647
                                        Entropy (8bit):6.854433034679255
                                        Encrypted:false
                                        SSDEEP:12:6v/71rwqZMXVs99W1YvpLp/Fvl+f43ocLtuplb+CrGotLRd:+wqWXVs99rpLpNvr3pIx3b
                                        MD5:DD876AA103BEC3AC83C769D768AD39FB
                                        SHA1:1833603AA9B6A7E53F9AD8A336F96CCE33088234
                                        SHA-256:1262DD23AD54E935CFA10FEB1BE56648E43BEF1116696CA71D87E6E033B1CA7D
                                        SHA-512:946DB2277213104A3B29EC4388578B05027B974A3093B4CCAD8847397AA51AE308BC6A199E5705E1F901D6E4B1BA34D8DECFD6E5B6685184A307D749D7CFAEDD
                                        Malicious:false
                                        Preview:.PNG........IHDR...(.........xk....`PLTE.........................................................................................>.S.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.)..1..7w....6.*.H`T6.ha.k.............b!....Ba..C..P.4K..@.....h.E..X....PX+.P.-.....@@"...o.O4....xZ<...B...B..,A..y.s<......b!....Ba..C..0_p. .......=..,...i. ...=.j..N...........{4+...xZ<...B....|.....$.K<.vyE..X....PX+.P.-.:... .'p......\,...i. ...=.j........K.....%J..S+.....q..k.H.@DD.s...:..J.K.DDL.\.@`,.DD.:.(]..N....KD....A M.....F..S+.....1.sq........\.t..;..../...~k...4.DD.:..]..N....KD........@DD.s...:..J.K..[...Q....V......IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.341763106083594
                                        Encrypted:false
                                        SSDEEP:48:WsSCgYUTtg5EtDqEjFLwPXvR9vnolrdqrKzH5RXDCxV7VuvVqRVAV7V9gVyV6g:WsYhUE0EjF0PXp9vnkRyKT5JI
                                        MD5:3F57CF2959284701D8348BDC6A2FCAB5
                                        SHA1:76620CBF964C2EB315253CD2AE2F1C3DE733BFB9
                                        SHA-256:6E9F2CEC3AE2FBAC725DD9FC8AF73E22D70F86464D5D5747B7DB2DC0A496657D
                                        SHA-512:7CF06A4B22D82CDA232F577E66D5E9C6CF11B12560F032CBD60BA8C53FEF3593868859351DB238F1B5DD82BEC6BEA1DB242851864D0F350F942A694D92390645
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.>.......>.....)...]/...>.....)...]/...>...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............0_n...6..C...1....N...^................f..wB.C......3.........f........................................I.qk..B.....LZ..............0_n...6..C...1..........0_n...6..C...1..........>.......>.......>...........................................>.j.....>.T.]...>.......>...B...>.H.....>...B...>...>.).>...J...................;........4...4...4.."...............>...>...>...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........>.......>.....#.>.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
                                        Category:dropped
                                        Size (bytes):52912
                                        Entropy (8bit):7.679147474806877
                                        Encrypted:false
                                        SSDEEP:1536:DB/nIviNJD9C8kfJj6TkVr4q24FsUpjPc021si:DdnIvi3D9C8Cl6Dq24ayPCz
                                        MD5:1122BF4C2A42B4FA7F29D3C94954A7C9
                                        SHA1:3750077A830FE21735A43ABD35C63BA9A4D4B0DE
                                        SHA-256:423B0DD1A93B391D15B1DC8D8757C3BF5725FF2E7A59E6E3140033E2876B67F6
                                        SHA-512:4626EFE2EDED2361D6296B57F994DC434CC9D02357A8A6A67D84A544FB8A1CFE0005EA98F846AB963BED7F2B6CE96BC9181182C9459843A52A98D3A731A4FE73
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:27:10............................f.........................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....]+\.9.9.P.d..Z.?~>.-...]6=....*.......S.9G...b<$..Z..........>.v.o:.o%.e...z.F`...[.wo..z.....k..E...5....G..7.......c2..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.305012648287012
                                        Encrypted:false
                                        SSDEEP:96:esIb1p2cU34FLTEkdXWmLr9P/8Ry/G2Efl:esm1McLAkdXLr9P/8Ry/xE
                                        MD5:77F28BAB7337BF4A26933A1E5F8B1A6C
                                        SHA1:702E88EF6CC32835982223B339AD165F57A8B091
                                        SHA-256:88281E7E0FDA7B4A7FCFDF3F9A34E0A0C05D92D6DD4881AB21CDA472E5ACCB81
                                        SHA-512:CE19247A07BC77A6BD372CAB692BB1810A5C8AB935853B3D8E5CA6A6988ADAF4E37A630D30398962BFD7838B5CC09CE63D3A40893FDF04287745BE9D0B61F947
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.. ....... .~;....`.rv!^.. .~;....`.rv!^.. ..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............Wm-.....a...<.....N...^................%A.o,.I..5...%}........f........................................I.qk..B.....LZ..............Wm-.....a...<...........Wm-.....a...<............ ....... ....... ........................................... j...... T.].... ....... ..B.... H...... ..B.... ..>.).. ..J...................;........4...4...4.."................ ... ... ..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........... ....... ....#.. ............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                        Category:dropped
                                        Size (bytes):27862
                                        Entropy (8bit):7.238903610770013
                                        Encrypted:false
                                        SSDEEP:384:LTawAZvhbrXzDc6LERLQ/b5vXOl6pXQ/wD5OUMrdRUUhCplQg0ESSz:6wm/vT/b4wxoqbdUhWnSs
                                        MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                        SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                        SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                        SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.501374394288001
                                        Encrypted:false
                                        SSDEEP:48:R9+s+9xVrEmJ/MtdkE5z+ttwXyFw9FdJoFrdqr/s7RXEiN+aZX9:CsWUmJE8E5ataXyy9FdJkRy079t
                                        MD5:D65C18AAD44081AB94D2F65B0982D424
                                        SHA1:144262918B969FE71919AF4C302DE56ECB861DA3
                                        SHA-256:EFB1F7CB9470496EBACD14A3EDF7FAD3803A38385ACF201615D1AAE9AADD0246
                                        SHA-512:D17844E85F1DB1B8D2C93C45A7968E41099810BAD18C68ECFA365A9A4DB1961B8936E6B89A7F55DD67642FB533D4CAD1DC00D611E419EEA2018AFB42791E20ED
                                        Malicious:false
                                        Preview:2...>.......r...v...f...................................................................................................................................2...>...N.......v................................I.......I.qk..B.....LZ.........../.i.+.e......../.i.+.e..........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............VM.#8..._Y.......N...^...............iv.7.\.J......G.........f..................................."....I.qk..B.....LZ.............VM.#8..._Y............VM.#8..._Y...........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 556, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):977
                                        Entropy (8bit):7.231269197132181
                                        Encrypted:false
                                        SSDEEP:12:6v/7QiFJaY/z+obuqFA4fypjQSbtBK+lcqNGSbb7XTJArRRzN5DjNRkPmu5cCbR2:x0QY7xbjy9pY0JPXLTWroeuCCbX0
                                        MD5:B7F74C18002A81A578A4EE60C407A8D3
                                        SHA1:70A7D4BB1B3ADF4397D168AD0D81B286F88EBDE0
                                        SHA-256:95F59A0433050180D4C0E8858B83363D51BEA6752A8B7CA516A8677854D8F5B6
                                        SHA-512:13186A7CDCE80BCA9D2238666D6D7A989FA1887EABFA5D8A9A63EEC304DFD4BE8EFF652205FA56E1D1CEE7D3680AF8C70A952AF73AB3C246400E8D4EBECBDBA9
                                        Malicious:false
                                        Preview:.PNG........IHDR...2...,........A....PLTE...................................................................................................................................................................................$.y.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^...0.D_.......cck.....%a...X.a0Y...-..!.G...[....(.r.H.$...1 .zq.4V.e|a.6.X..4..kl.%....=w....6..TN.....{.4..T/.z...../.....3..!~..t.#b..^.....E!.SFb ...-.....^...,..C.!.b...i._c...s.X.w.. lsQH..H.gKc@@...i. ....m...;Ci....@G.; V{..lO..\.R9e$..{.....P...E.+.2.0D.B,..P...56.?......K.6..TN....^z.4..T/.z...../.....3..!~..t.]b........E!.SFb ...-.....^...,..C.!.b...i._c..Y.O...?.9k2.M.?5 .n.P...,...d._..%M?....6....,.1..R.4.a.R.+..U.Q..P...vd..T........j .]@....."..lJ../.90.4...Y. ...9.%...{......Hc%.....i..%M?aG..H....o.q.......4.......X.d9.r..CI.O.5.Ri0?.s\b....w...>/k..4V.)Y....P...vd..T........j .]@....."..lJ../.90..2..MP..l..?....K.X.....IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.313227576333751
                                        Encrypted:false
                                        SSDEEP:96:0sz1+1q1CGnSK8E3TfXY9+q2kRypU1q1iA1P1H1V1i:0soGSQjfXY9n2kRypM
                                        MD5:03AEF57C476015AA2325CF24EF0D2ADF
                                        SHA1:6754E882BB0BADA4C15DF295CA75549DC956225A
                                        SHA-256:C309C9073743E43D914DA83F472708DE7AD58A007A4EF552D02399B9AC93601D
                                        SHA-512:570F1761810535FB458336C090540E4C444C5BC9D708250C14F1F7E6247ACDB0AC06FC3BA78A7850963ECA2D69C0CB29D9FCCFB22703FDCD7749E8649AB69CB8
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ1.......1..2v.......e1..2v.......e1....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............I..u...Gl.........N...^...............l.]".2.B..u.ClM<........f........................................I.qk..B.....LZ..............I..u...Gl...............I..u...Gl..............1.......1.......1...........................................1..j....1..T.]..1.......1....B..1..H....1....B..1....>.)1....J...................;........4...4...4.."..............1...1...1....z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........1.......1......#1..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):34299
                                        Entropy (8bit):7.247541176493898
                                        Encrypted:false
                                        SSDEEP:768:BrSX4V3P8AIc4KLkHeXRUer0zrhOmXfvG0yH82I:tSXuIc4K2eBtswKsHg
                                        MD5:E9C52A7381075E4EBC59296F96C79399
                                        SHA1:BE295AD24D46E2420D7163642B658BF3234A27EA
                                        SHA-256:D56CEFE9EE2FAE72E31BDBA7DD2AA4426EA22E3CEB22EF68C8F63F9F24D5A8BC
                                        SHA-512:95CC96DD4459EBAE623176033BA204CCDC50681A768F8CBAE94C16927D140224E49D5197CAE669C83C77010C5C04C1346CF126BEF49DB686F636C5480342A77F
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.......................................................................................!.1..A..Qaq......".#4.2r3.$.%...B.5U&6....Rb.Cs.7..cDTEFVf'...S..dtevw.u.........Gg.....................!1..AQ.aq.2....."#3.4....r..BRb$CS.D............?..5..............#....v.q.m.}\..{....;...r....h.....J..q|..'.;\..6..v......e...../.k..|.8..i..|..]..3e.m....n..Z.GS..n".y..w.-...[a...7A.....i.4.)9\..~C...=.........s..\V]c.D1<./.g.l.&v..~.h..]....zb>G..y:vNS.\......LU....t.{*..Z#.?..v-...wn.rR...P.....y\=.v....../..9_...m4...V.|.+.o.#.......xj....}..>.s.>C...m.[;.>.p...=^.i.X.(..1...{.F#N.W...xi.z...4..u[{...yO.....8..}\..2...KlX.nbya...2.&.F...R.b.k.7.GV.x.h.y\.Q..O<\>......-...=...r......\......Z.Z...Jf.'....z..Y.q>.p....o..K....h..R..c.lg?......A.Z...Y.q3.L|.'5...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.32266487728465
                                        Encrypted:false
                                        SSDEEP:48:kVseVZTQxGmdt+JafkEHSFLtX+OJa69eqPxolrdqre4GRX8fdCQ/XAmD2SHd:OsTGmdWVEyFpXZh9HJcRycuqW
                                        MD5:523E414092835064E7594D937C1E75E6
                                        SHA1:5E2077F78E9E7DF1B636E10B6F9B88062D06FF00
                                        SHA-256:9803E7A42D1979CBDA3A00556485E29A6A111D67D11DFBF7EC7B5A80C2F67305
                                        SHA-512:2E284FD6FB326E5A912033BFB5CD0065F632B2C53E50594DC41FCC37B28F56A907DA184CA2FD169310CDB609F9162DAE8453B88B8BAC22C55A45D05F31EEC846
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ..r.......r...K.$I..l?....r...K.$I..l?....r..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................A\..,6:....q....N...^.....................M.r.T............f........................................I.qk..B.....LZ...............A\..,6:....q...........A\..,6:....q...........r.......r.......r...........................................rj......rT.]....r.......r..B....rH......r..B....r..>.)..r..J...................;........4...4...4.."................r...r...r..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4...........r.......r....#..r............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 171 x 552, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):10056
                                        Entropy (8bit):7.956064700093514
                                        Encrypted:false
                                        SSDEEP:192:edmu1fpj5DVHuooK4EpGLbAdT+dBXYBR8D1V2p6KwoPR6KUX9ojwRpgA:2Pp/B4LbAF+dBo/1E3S6JScpgA
                                        MD5:E1B57A8851177DD25DC05B50B904656A
                                        SHA1:96D2E31A325322F2720722973814D2CAED23D546
                                        SHA-256:2035407A0540E1C4F7934DB08BA4ADD750FCB9A62863DDD9553E7871C81A99E3
                                        SHA-512:BC7DC1201884E6DAFDC1F9D8E32656BFAEE0BB4905835E09B65299FE2D7C064B27EAA10B531F9BECF970C986E89A5FD8A0B83F508BBA34EB4E38B3F7F5FC623A
                                        Malicious:false
                                        Preview:.PNG........IHDR.......(.....!..t....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................4.....bKGD....H....cmPPJCmp0712....H.s...#.IDATx^.w`......$..B....... ....fz5..6`l\.8...Nsz{.//y./....{.7}g.....e.....~.......s...f.....%c...6....O.PJ...Y.oi...9..'j.2..6.-
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.316617889326937
                                        Encrypted:false
                                        SSDEEP:48:WshGHzlrntGSjtEXh2aLdXpTh9Lmo1rdqrQHJuRXltG5lyR:Ws+lDdEfRXr9Lm0RyQpuGy
                                        MD5:8904CB04FC42211806DD48826137F73F
                                        SHA1:45C8C003C7CADAF588CC838C7D0F1FB0744FB07A
                                        SHA-256:3832570E7551BF035EF76E1FB0983815F244AD665C997B6BF0AB911811B66535
                                        SHA-512:5FA9814122E41AF291DDAFD32C56CF233B19F2202079538F9CFF7F4043FD380A51930BA13D3039A0163DEB7B12921B46FFC5281575D8D9001B08ABCCF24C825D
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.}.......}..#...2.0.....}..#...2.0.....}...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............9w.,\...3...&9......N...^...............pO..n..@.s'o...1........f........................................I.qk..B.....LZ............9w.,\...3...&9..........9w.,\...3...&9............}.......}.......}...........................................}.j.....}.T.]...}.......}..B...}.H.....}...B...}...>.).}...J...................;........4...4...4.."...............}...}...}...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........}.......}.....#.}.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
                                        Category:dropped
                                        Size (bytes):84097
                                        Entropy (8bit):7.78862495530604
                                        Encrypted:false
                                        SSDEEP:1536:cgHTEuD99rHwA5MSadIV2MApVmfJkAKOQ/Z1I7ngpDDyHfKFVITrU:HHjXidIhApV88/jIEmrU
                                        MD5:37EED97290E8ECB46A576C84F0810568
                                        SHA1:18D9FACB4CFA3CBF63B882CABCF30B203EDF4126
                                        SHA-256:140DD943D0F0CFE6AAA98470B7D1A7CB62CA02CB1D8F522DD2AC77433232EF41
                                        SHA-512:E0F57314C136211B8253EB2AC0093DED82198E7170D4F97C40D82FD4EC4123D2AAFE3EB4EBC3E7523C4DF4D77619408773871BDE15B6DC6C4049C71D5B9D4222
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....hExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:11:38.............................A.......................................................&.(.................................2.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................z.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....b.xH......T..I...S.q.~..../s.R.x.....8.a..vE.5...-.G.A.4...._......$K..d.@NC.q....J.....>e".I.%...I0).R.I$........M3.F .
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330067472514566
                                        Encrypted:false
                                        SSDEEP:48:fsnLSCsow9E8Gt1ZEMxfscXnU+sc9feDoNrdqrxuZkoBRXBz8hvnbl:fs6u8GhEkscXU+sc9feDMRy2I
                                        MD5:49AF47D363986BC44083C58B6B9C1C38
                                        SHA1:80656E3402B03918DB889F35AF6988EA402141AD
                                        SHA-256:9B3DD57FDFAEC02464E0A36F1EFA5EE83430909DA8BEE0DF6E28FCE14BEF7439
                                        SHA-512:6F441E667718885B8E83E1C7B45F7304C05A8C3E40073575A43D25A9C726839D216023177ADFF28DF8C1E2E098CEE2873F060A943599EE4C77D2FDA6A66A4E28
                                        Malicious:false
                                        Preview:2...>.......L...v...@...................................................................................................................................2...>...(.......v...t............................^.......^...,...t..0...I.......I.qk..B.....LZ.^...,...t..0...^...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............'J5.G~B..g..F.YS....N...^...............*.....B....;..........f........................................I.qk..B.....LZ............'J5.G~B..g..F.YS........'J5.G~B..g..F.YS..........^.......^.......^...........................................^.j.....^.T.]...^.......^...B...^.H.....^...B...^...>.).^...J...................;........4...4...4.."...............^...^...^...z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4..........^.......^.....#.^.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
                                        Category:dropped
                                        Size (bytes):64118
                                        Entropy (8bit):7.742974333356952
                                        Encrypted:false
                                        SSDEEP:1536:ORG4azGOKXzkEmR4bdRSbxONOoz0khbSb4J/5GZK5SWUlRwUYdv1M:ZXzGXzJdhRmgHfIb4J/5GZK5SWUldYdq
                                        MD5:864EEA0336F8628AE4A1ED46D4406807
                                        SHA1:CFCD7A751DFDBE52A20C03EE0C60FDFFA7A45B93
                                        SHA-256:7CE10D1EA660D2F9CF8B704F3FAB2966A4CE2627D9858D32C75D857095012098
                                        SHA-512:0CAA0C54C14571C279A75F0D5922F78A17803CF6EE1724D66819F7F5944C0F5B25CB586BB686A52808CDF2F8FEB3E4864052A914884054EF7DE44124A8CA951E
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:26:15.....................................................................................(.....................&...........s.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................#.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....NC+n....<.=.7..&.8A56..@^.Q..\\...E.>..".&G.......J .'....$.I)........0.../..mv...D....<v0=..ugc+..l.o...=.c.......x.&D..{`8...v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.34285421554775
                                        Encrypted:false
                                        SSDEEP:48:aHsFmsqQeS9GtAI+gREpnLXLL9TO9olrdqrvCTdORXeC13Z9rN:aHsc+t9GqeEpXv9TO9cRyv+IsUPr
                                        MD5:CADD3AF02CB4C8C3EB261757CA78A4B1
                                        SHA1:E3C04F174F0A531F8BF515FC89CC73DD21D293CB
                                        SHA-256:28A2FB1BEFCDAC61CE97D7CAEFD6B91AE736143B2DA1659D69CCED407E26A0C3
                                        SHA-512:0CF4B1493AD9D6473656F946E34BE76320B601B1CBAF298B5C3A9C48C17E2FDA91C3259B4298EB3605FA71C8791648332339C931DE72A30B139762BDEDA54BC5
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZp[,.....p[,!k*....l.H,.zp[,!k*....l.H,.zp[,..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............+W.x.r.!y..}.....N...^................N..<.I.ihy.i.'........f........................................I.qk..B.....LZ............+W.x.r.!y..}.........+W.x.r.!y..}..........p[,.....p[,.....p[,.........................................p[,j....p[,T.]..p[,.....p[,..B..p[,H....p[,..B..p[,..>.)p[,..J...................;........4...4...4.."..............p[,.p[,.p[,..z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4.........p[,.....p[,....#p[,............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
                                        Category:dropped
                                        Size (bytes):65998
                                        Entropy (8bit):7.671031449942883
                                        Encrypted:false
                                        SSDEEP:1536:klZtmExaFrtWgpc+Sg+DKeplHClpHfRtPMbe:VEWWl+SNDKqlH8p/vse
                                        MD5:B4F0A040890EE6F61EF8D9E094893C9C
                                        SHA1:303BCBA1D777B03BFD99CC01A48E0BB493C93E04
                                        SHA-256:1F81DDE3B42F23F0666D92EBF14D62893B31B39D72C07AEE070EAE28C2E6980E
                                        SHA-512:8F07E4D519F2FD001006BB34F7F8274B9AF9EC55367B88D41D24E5824FCE4354FD1290CE4735E43930829702ED53F41DF02C673904A7091E9354C28E029AD4EF
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:09:29.............................a.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..-O..s(...gO..@...[..+....+...H.'m........L.......@.......[k...S..O..p.'{X..3......]W..w.+.V....[.-.....2..i..i$.p.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):3.2554236395585443
                                        Encrypted:false
                                        SSDEEP:96:qsFBsGldb+WEc4qPXhQa9TPqm72lR0zqE/2HaG:qs7sGldKcdXhQa9THYR032
                                        MD5:4EE7BBA568B24F6622BA5E59F1A3ED00
                                        SHA1:B253E6CA06EF85C83B66DA18EA7216188B182A93
                                        SHA-256:28F82A3071ADF1EBB9FCE7141F1A53BDA0CF6A608E41B33DB9955D13F5B5E90D
                                        SHA-512:25EB183466C784049D2E1E7544A4EFC18E2D95B412DFCEC6EC03DD16E2B8CC801BEEA4C44426D65DB6823C44F31D3C4166110BF557409D461F13FD68897CA638
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>...j.......v................................I.......I.qk..B.....LZ'.......'...5U...J...'...5U...J...'....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............L................N...^................W0O9..N....v..?........&...................................>....I.qk..B.....LZ.............L.....................L.....................'.......'.......'...........................................'..j....'..T.a..'.......'....D..'..H....'....N..'....?.#'....9...................;........4...4...4.."..............'...'...'....z...y.. x.. ...........$........4...*..7*..7...........Op.b..F.$..i.................;........4...4...4.........'.......'......#'..............................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330190219493002
                                        Encrypted:false
                                        SSDEEP:48:YuqsuXolcc1ZWt9PIQEya70XrPF9LUjdNrd3rNxPiRXIV/Jh:YVsYc1ZWXPFEyagXrPF9LU3RbviE
                                        MD5:E5AB213692BDF4258B8CCE93DF638E86
                                        SHA1:702206148AE5C7413E9E6377B69E07F80A8763CD
                                        SHA-256:B3B6782B341FECCA30212A9D9950BF05354480BC62216E7B354B5367BB029025
                                        SHA-512:2AB7680B92BD0C9F00B41BD1C169B3167E78FDD757FFEFBF8C22A69A52D7CA6EC925EE1E643248E4A7C65B177BDAF9EA2C6A86A3AB0750D16B712A37B2F479E9
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZ.........aq7....Q..z..aq7....Q..z....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............0.................N...^...................?..N.>....E.........f........................................I.qk..B.....LZ..............0.......................0.................................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...*..7*..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):39010
                                        Entropy (8bit):7.362726513389497
                                        Encrypted:false
                                        SSDEEP:768:6tCjwO+E+KW0ZtOgepcoWW4pAWQ6/KWcR474HOAZaDfK:68j+E+KW0HOgep/72/NKWcRNefK
                                        MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                        SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                        SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                        SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.409553168787375
                                        Encrypted:false
                                        SSDEEP:96:NsEwLOlN08EvlX49utnIdRbGWUFSFL4xAij:NsEwLSNi9X49UnkRbGjFSFL4xAi
                                        MD5:061CB97501F316237C1F8FCD1D1414C4
                                        SHA1:E20FC8627F4A908E4E8A2DB9BFA6D9EC4F606D95
                                        SHA-256:57A5F485C1DB63EB6744E788F4D676463E21CD949BF793A45DC4F0FF2D02D7E1
                                        SHA-512:A6AFE563D12255A752D56EAB96E705CE8A4EDD14DF41B1D53739A73451964C2C96174EEAA4B4C7AB8F3ED838C16BC427D193FCFE52A76F0597F65F5C9D89C653
                                        Malicious:false
                                        Preview:2...>.......h...v...\...................................................................................................................................2...>...D.......v................................I.......I.qk..B.....LZHsv.....Hsv.........;{..Hsv.........;{..Hsv..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............{..-.".0...^.|.....N...^...............Tu."e.?E....u.R.........f........................................I.qk..B.....LZ.............{..-.".0...^.|..........{..-.".0...^.|..........Hsv.....Hsv.....Hsv.........................................Hsvj....HsvT.]..Hsv.....Hsv..B..HsvH....Hsv..B..Hsv..>.)Hsv..J...................;........4...4...4.."..............Hsv.Hsv.Hsv..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........Hsv.....Hsv....#Hsv............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):25622
                                        Entropy (8bit):7.058784902089801
                                        Encrypted:false
                                        SSDEEP:384:EhK81gTCyJ/Gf9Aw3t8w8EtdPeGDh6bEi1Ie1u4ZbvgwTwrSRh7ZKNpIGY:IjcRXwdJvtdGsUbEi1IeY8vgwTyC1+Y
                                        MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                        SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                        SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                        SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.302301679478299
                                        Encrypted:false
                                        SSDEEP:48:YuSs6TkaSLzdtcJXMtJEHGKWcXRbRc9MxIzj4Vrd3rU4xOfdXgpjlZ:YNsASLzdGcHEmwXQ9k8YRbWI
                                        MD5:42EAED04FE9BA5D6E7CDA01430A2D25C
                                        SHA1:18FC73B1E85D9A130B1B81A282EC87DD0DB5A017
                                        SHA-256:6E421A6EC13AA5DA6C72D3567EAE1FB30E730D11C0F6E9A8281A70EDAAF780BD
                                        SHA-512:C8D6B8732BA3D48A6F176751D98D1238CDCF8B1A6089C5D5C7C5C89EAF660FEEF7CEC5186421D697CED44AE6D18D14BC70ED04DDFCD5A859FB80909A0843A05A
                                        Malicious:false
                                        Preview:2...>.......P...v...D...................................................?....?..........................................................................2...>...,.......v...x............................I.......I.qk..B.....LZm......m.#.!...6...B..m.#.!...6...B..m...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............At..9.S.....k..u....N...^................D.....B..t.S.G.........f........................................I.qk..B.....LZ............At..9.S.....k..u........At..9.S.....k..u.........m......m......m..........................................m.j....m.T.]..m......m..B..m.H....m...B..m...>.)m...J...................;........4...4...4.."..............m..m..m...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4.........m......m.....#m.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 500, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):2033
                                        Entropy (8bit):6.8741208714657
                                        Encrypted:false
                                        SSDEEP:48:P37XYSDTz+UUl7DHt7Ah8l1+4ZfFclFUXwobKXlZr:v7j3z+UoDN0h8ugf2AwobMN
                                        MD5:CA7D2BECCBC3741D73453DCF21D846E0
                                        SHA1:E34B7788498E33FFF0CFB00125E6BA9E090F6CED
                                        SHA-256:E9EAD0BFC09D32CB366010CDFEDE1C432A2D1D550CB7332BADAC1BEE9482BC86
                                        SHA-512:7FE2C3654262B1EEBED4F6D83DA7D3450E1BE52500A3964185FC0092041506A237A2728E5D7EEA0A3814E413E822B803B789C49CF744D51816A2E4EDE5B4247B
                                        Malicious:false
                                        Preview:.PNG........IHDR...2.........H'......PLTE........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................[....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.\.W.G...=a.ewA..a.!r( ...%Dc..x.x....N.OO...3=...S...........~.z.D.0...g.2P.7.*M.#'....z.......3TPj.Z.[5....V..z'L3...a.j9..C>..9.z
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.3153533361497205
                                        Encrypted:false
                                        SSDEEP:48:ySmsIsJOKXPGtAe3EkJLeXRV9sVDj4lrd3rg/xA7KndXjVwgPJ/w0d:ySmsfl/GjE8KXRV9sVDwRbxUvwy/w0
                                        MD5:BE5884C26629DA6CC12E49DB7FB40E2D
                                        SHA1:B8F52AA852F540124BA50EEEAA528315E7FD8319
                                        SHA-256:A153363D34ABCE93F80ED05B4CCBCE88EBF704C2F9DD9A115F6AB8089C46A8C9
                                        SHA-512:CF7F3FE003C468A4B37C8DE795D87051C6EE3DDAE348F05488D559E21AFEBED0771B521CE48AFC8FEB9C9F13826DC2A070494EF27D813E96EEB2610100B14F4E
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.b2......b2.).?..T Kr..N.b2.).?..T Kr..N.b2..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............f........;l.J5s<....N...^...............^.....yB... ...`........f........................................I.qk..B.....LZ............f........;l.J5s<........f........;l.J5s<..........b2......b2......b2..........................................b2j.....b2T.]...b2......b2..B...b2H.....b2..B...b2..>.).b2..J...................;........4...4...4.."...............b2..b2..b2..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........b2......b2....#.b2............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):55804
                                        Entropy (8bit):7.433623355028275
                                        Encrypted:false
                                        SSDEEP:1536:gVvci05lhVbfBcWvBLeynluexaWqzww/u5:gVUZhHDljaHww/u5
                                        MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                        SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                        SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                        SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.433911178918189
                                        Encrypted:false
                                        SSDEEP:48:RyBsX134j114tcbZEbzbBX6ZKB961Tj4trdMrLP5dXpB6zkCDWhtw76:MsFIx14KVEbBXAKB9kTARMV969qhtw7
                                        MD5:9B667334DF0F0D05CB6052F05ED95D7F
                                        SHA1:7A1641C4386585B9AF09D7188FF343FC9FB9ACDE
                                        SHA-256:0B0B72B01B2511819FB2A12EB8268F42A4DB4593BA9B975021010613D77AAB61
                                        SHA-512:33D9666F4FA2AD28D44383604D6CBEC68EE4CE62002A55F3D618ED031B5865F85F146640C2386974150F9F34F3D1E6DC308387E2AFD4C5C34A95DD232042C477
                                        Malicious:false
                                        Preview:2...>.......n...v...b...................................................................................................................................2...>...J.......v................................I.......I.qk..B.....LZ...........f......o5.o+....f......o5.o+......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............>...e@..6....K5.....N...^.................<+...G..6.0..........f........................................I.qk..B.....LZ............>...e@..6....K5.........>...e@..6....K5.........................................................................j.......T.]...............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                        Category:dropped
                                        Size (bytes):59832
                                        Entropy (8bit):7.308211468398169
                                        Encrypted:false
                                        SSDEEP:1536:HS9SYFtN0+CRa9mfJy4zBAiIJhzrkHDV2hJK:yAmta+Tyy4zBIJW5WK
                                        MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                        SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                        SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                        SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330335987274526
                                        Encrypted:false
                                        SSDEEP:96:zshXSzlWEQ3X599P4YRM+KvS/wEvobG7:zshXSNuX59R4YRM+KvS4EvyG
                                        MD5:A37101E2D7F629BA2F3823A6594EFE82
                                        SHA1:485CC5D50259026CBB68EFEE0A372DB7B751F2C2
                                        SHA-256:F00222467696B14EC4146A9A1D6D9FC30489B9771BFDF9FF31FE93E282914D17
                                        SHA-512:28961DE460D5D5B80FC69D47A602E1FA38F7CB3D12634327682D758B871AB0EDADD6956A8F943A45E43E10C28A01D9CE21A1BF40671F210449D082085724F3DD
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.m.......m.h..........m.h..........m...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............kd....(.>Q.A..G....N...^................._.U..A.Z...=Xg........H........................................I.qk..B.....LZ............kd....(.>Q.A..G........kd....(.>Q.A..G..........m.......m.......m...........................................m.j.....m.T.^...m.......m...B...m...C...m...>...m...|...m. .3...................;........4...4...4.."...............m...m...m...z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4..........m.......m.....#.m.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):33032
                                        Entropy (8bit):2.941351060644542
                                        Encrypted:false
                                        SSDEEP:384:ofmqvnCfmqsp1Ue5xzMq+Qh0dffUmS0w5xzMq+Qh0di:AGAp1rmSl
                                        MD5:ACF4A9F470281F475EA45E113E9FB009
                                        SHA1:B20698DDA5E5AFDD86BB359A6578C9860D5DF71F
                                        SHA-256:5DC2367A80588A7518DB5014122510BF0FD784711015EF83A8718336584F82D0
                                        SHA-512:998B7DB9DB08FD15A293267E2371052E436E024AF8D34F96D3C8FF04B1316678DFC1674C921CB404121FF381A4FC39DC759E6698F19D42A6261CBD39469B0A08
                                        Malicious:false
                                        Preview:....l...........................Ac...... EMF........$...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC........................F...(.......GDIC............^...........F...........EMF+*@..$..........?...........?.........@..X...L........................."B...B...B...................?...........??.....n............;...<..@<...<...<...<...<...=...=.. =..0=..@=..P=..`=..p=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...>...>...>...>...>...>...>...>.. >..$>..(>..,>..0>..4>..8>..<>..@>..D>..H>..L>..P>..T>..X>..\>..`>..d>..h>..l>..p>..t>..x>..|>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...?...?...?...?...?...?
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12180
                                        Entropy (8bit):5.318266117301791
                                        Encrypted:false
                                        SSDEEP:96:k1bHyG/fKOOOOQJUg+g2S+kEm6alfsfsfn32:+bSG/yOOOOQ+g+gOab32
                                        MD5:5C859FF69B3A271A9AAB08DFA21E8894
                                        SHA1:3156302A7450ADFF4D1B6EC893E955D3764D4DD4
                                        SHA-256:B4A8E9A67EE0B897615AC4CCE388FFC175AB92D9E192E6875C79A4E7C1B5BB6E
                                        SHA-512:4CF518136EEBCA4F400A115D9B7BB0CAC9FA650BF910B99E15F04A259B7D3EFCFFD6796886FE09DB08C37C332B14BC8500845C09C8EAE1F2306F90E98D3C99E0
                                        Malicious:false
                                        Preview:.PNG........IHDR..............;j.....sRGB.........pHYs..........+..../9IDATx^...dW...S=.dL$.............-.`...'...x.7.D...(...$.?cO....9S]=.v...Z.......{..wNuf.&.....a.k5~...._..\.yk..v.....}{._.Q...5...._9o.n.....}7.].1v..t......q....3.<..0<.p.......0....s...... @....... @....... @....... @....... @...X.'..U-..... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%@....... @....... @....... @....... @....... @....../)m.. @....... @....... @....... @....... @....... @ ....`.)....... @....... @....... @....... @....... @....K.0.....J....... @....... @....... @....... @....... @...`.....\.... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.352878405096331
                                        Encrypted:false
                                        SSDEEP:96:1X+sC6RLOmEEqTFEsAowgXoq5y9A7FRM7v536/R2miO07x:QshOmxsAowgXxy9A7FRM7hq
                                        MD5:A7CFA7A34AB58CA1A811CCA9D21C1373
                                        SHA1:909A25CD217277179CC168581815F7D4BFFC1BD1
                                        SHA-256:0C12C4110F1D68D0C795A5A3AFB943A0014A9910AC902D2EB5A882EFBA3230FC
                                        SHA-512:D29E0BDC7BC0FE47CC1FDBE5595EB81F8F53A25BBD62CE71B3D9DDE4EE3981BE99A45200645201E6E8C4B70EA390F837CD0CFF57D2EC432D59FC3A75E3A79D03
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ..?.......?.ccb....ER.....?.ccb....ER.....?..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.....................8U..<.L....N...^...............z....CC..+pL..Q........f........................................I.qk..B.....LZ....................8U..<.L................8U..<.L...........?.......?.......?...........................................?j......?T.]....?.......?..B....?H......?..B....?..>.)..?..J...................;........4...4...4.."................?...?...?..z...y.. x.. ...........$........4...+..7+..7........................;........4...4...4...........?.......?....#..?............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 39 x 600, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):2104
                                        Entropy (8bit):7.252780160030615
                                        Encrypted:false
                                        SSDEEP:48:2PPEOtz2P/LJtVRaqBG8qFOPvHlcEXgkuwf+j:2PZFSjJDjqFOPPlXgG+j
                                        MD5:F6C596F505504044DF1E36BA5DA3F09B
                                        SHA1:BCF17EC408899B822492B47E307DE638CC792447
                                        SHA-256:EDBB86F160050FBF1F9860276802BAE292DBFD0BC98E3EA90D43D981E9F0C54A
                                        SHA-512:E8D067A1932CED8746FE7D665EEC34EA92A98AFF3DF26FFA9DD02742DDEA3C5654124A88A649FA33DB596F96A5FC9CB2C693D03132F1C8B254ACB56DB4763BD8
                                        Malicious:false
                                        Preview:.PNG........IHDR...'...X.......:....PLTE.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................{.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^..c.%i.F...m.m.f.m.m.m{&....X...9.....M.WUW.d.N.O...E$...$...)H....n....N.k..v.....v1L[w)w.}..!...Y.X.V.D.......[....;..[..;....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.320760338598787
                                        Encrypted:false
                                        SSDEEP:48:ek0s7paERRo0thRmE2JlZ1ocX5/rqc9dsUpyRrdMrsozxHJFXmNVQ8YuCVXsAEg:ek0s/Ro0UE2scXUc9dpcRMsaJ1Q
                                        MD5:A36AF9BB2F93F24CB9DC3BC1704E2B46
                                        SHA1:B28B3EDB7BEF38E59E23380162B5CABAB2E65C04
                                        SHA-256:48FC0E8B3DE5979B4715081A6FFB55ABA8FC99524FB16CA99DDD61A3D3BAAF27
                                        SHA-512:85D8D70E99F49D2915CB9D7A0F1BE93239F146CBBB3C3AABE5E82F83933D328C8F974ECFEAD7930E2221EEF06C75C38408458FA10561CDEFBE03F9ECEE98AF76
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ".=.....".= ..N.......nc".= ..N.......nc".=..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............=D..`C...^.Z.......N...^.....................D....."[........f........................................I.qk..B.....LZ............=D..`C...^.Z...........=D..`C...^.Z............".=.....".=.....".=.........................................".=j....".=T.]..".=.....".=..B..".=H....".=..B..".=..>.)".=..J...................;........4...4...4.."..............".=.".=.".=..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........".=.....".=....#".=............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):14177
                                        Entropy (8bit):5.705782002886174
                                        Encrypted:false
                                        SSDEEP:192:EbgGcV/hlvpfal7rgYa8S7auAxwfuSTmCSNoFQ6NO7L:EbgGcVnpwimnd38FdQL
                                        MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                        SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                        SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                        SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.337798617034014
                                        Encrypted:false
                                        SSDEEP:48:Us4Tkz46U7EWtK1UEYXL7aK7XQ799nsWxpyrZrdMrlPaoFXWDrM9I4wQZLt31:UsDU4WLEQtX899nfxSZRM8oWO
                                        MD5:FD5C61EA2A81DE19A09D6CD255CA7F95
                                        SHA1:75E60A6CDA8AE9C8F2F44BD4B68A18723E40ABBF
                                        SHA-256:9BC1105C0AFC17763EA6DA7B2783CA888B3CD3F8417C67B71E79EBE13BC09E90
                                        SHA-512:206A14571551580B7089C9003A49131882066473A7AD0C878BC2244357EC311A2D189F5BF5DAC119A6AF12F839D5AAA8B659611A72368677C6DDD7B4982272CE
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ...........Va%....u._......Va%....u._........I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............~...........s.y....N...^...............g..q.V.H.D.............f........................................I.qk..B.....LZ............~...........s.y........~...........s.y........................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
                                        Category:dropped
                                        Size (bytes):36740
                                        Entropy (8bit):7.48266872907324
                                        Encrypted:false
                                        SSDEEP:768:3nwDxjTvoE0Rjwit4rjucDILWg7/Da0JgGQ8e1S8SA/Khos0:SxjTmZw7nucDILj77a0JgGQvScb
                                        MD5:9C205C8D770516C5AA70D31B2CA00AF3
                                        SHA1:9A1002F0CF7F92F1BE2BB25BAD61CEBFAC282482
                                        SHA-256:E111F96490755C7D71E87C88ACAEA38AFE55BB865B1A14A83C5BD239648D5E2C
                                        SHA-512:A3E105208B32831265428572B0937DD3C17B793D8611B2DA8D4939F1BEC6050999D375E3F6B87D53AD49DFA0EAE737B0141D37597AA42116C310761973D4A134
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:44:07............................c.........................................................(.....................&...........n.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d................................................................................................................................................."...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..o...4.gP.~.c...K{...V.=...].<.........vS.........s....(.t......X......kk7....~-...yF}^c.Z.\.G./.?t...>....:.>......./.ib..).
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.456100895825142
                                        Encrypted:false
                                        SSDEEP:48:DxsyVAQQ/VffdNLEUMtRKELL4ZXjD9lsJqpyBrdMrrc0XFXKs2ktQLHG0g:VsRFEVaELUXjD9l9URMrLf0
                                        MD5:D0A6087EE23F3A087272C916AA134CC8
                                        SHA1:D493CFBE2259DCF83484C58320A032D3C506F4EC
                                        SHA-256:8E9D155789AAFFA064FA4A3EEFED8315ADF00B614D88CC84861A348ED6FF3798
                                        SHA-512:95AEB6C19E84F2873E3F693BF6DD8B251D890E7EC0D2C96267FE571A924CC00CE9D7B1D75BA16E1BC80B86E7CB7F65928C2E3F22861209119DD03462A1801A63
                                        Malicious:false
                                        Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ(.......(.......+.wcI.X.(.......+.wcI.X.(....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............j.FL=.......M+.....N...^................D.../.G.iX..mH........f........................................I.qk..B.....LZ............j.FL=.......M+.........j.FL=.......M+..........(.......(.......(...........................................(..j....(..T.]..(.......(....B..(..H....(....B..(....>.)(....J...................;........4...4...4.."..............(...(...(....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........(.......(......#(..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):53259
                                        Entropy (8bit):7.651662052139301
                                        Encrypted:false
                                        SSDEEP:768:dCiCBBenRYWDBCipMYGTbYGLHbXxoP/qEF+MU50qyJ30h2W474S/Aq/xc4674bi5:dCiIQXBCiwbDLHD0/sFyVel4Pi4UgE
                                        MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                        SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                        SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                        SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.330508904389015
                                        Encrypted:false
                                        SSDEEP:48:CsfHHCrkeE4v+6TSAtWSTtEXDJXGX/2m9RsVpyFrdMrBO5FXFB7rBHsohhXZ:CsToG6TSA0SREX4X/2m9R4IRMs5lhN
                                        MD5:55B1EDAB55B2AE0C7229F0185ECE6AE4
                                        SHA1:A9377AA6FEEC7CDB8A9D5B60C693E1D95B76BDCA
                                        SHA-256:1A7FBB164808E5F772C2887779C2B6774EF0C092407D4FCFEB4BD4E723670931
                                        SHA-512:382179C34A4E1E9E0851F2E6684ACB6617DED7515381B5674A728D1531DDDC3A15CCF5320926268FD2D542684E5147B93FDE178BBF505D57C6B3B55CF19919C2
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.5.......5..4.E.4 ..._D..5..4.E.4 ..._D..5...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............3_f.9...X.b.L*....N...^...............y0.i.`H.0..............f........................................I.qk..B.....LZ.............3_f.9...X.b.L*.........3_f.9...X.b.L*..........5.......5.......5...........................................5.j.....5.T.]...5.......5..B...5.H.....5...B...5...>.).5...J...................;........4...4...4.."...............5...5...5...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........5.......5.....#.5.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):60924
                                        Entropy (8bit):7.758472758205366
                                        Encrypted:false
                                        SSDEEP:1536:kU7O7+CFqO6DkxTgPzo2wqggrrX8QvN1I/ZLBttB9+dPFXbc:hVuqJDaTqo2wq1L84N1I/Z1tT9X
                                        MD5:D58C51D2CF586A5E14A9EC8529C3B0A8
                                        SHA1:F4811A353797C29B1E3F5A61B125C46E1534D587
                                        SHA-256:F927C7825851974A2149868146970706523A49165133CEE6027A43E8C9ABDF27
                                        SHA-512:34B963173AFBDF07432F4B983D29F10376E4771FE666E9D50B1A81DA0B9F6001FD86B4A08B9711386DE153BF6E03C8E932E2D181C8EAF94EFF34D20FCA7570E0
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d................................................................................................!1AQ.aq....".....2B...Rbr#.s.4...3$.5u.6v..CSc...DT..f..t..&F........................!1..A.Qaq....."2....B.s....Rbr..#4...35...CSc.$...DTdt..%..............?....O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.........................................................yK..xd...6..|%....\j..e.=...Y..f..I.|-....e...$R.j.......~.W#....{.....V.k.|F..z^..:.~..f......"x.....L..K..r../.;..[..l...;.U...W...X.........8.....y?..B...m.......j..Q.g3..G.K....GL.o..n7a..Y..[.'.........x........\......~...f...0\Wc.n?k.|.....1.ww;..2..?...r4uF.MXdB6..W..mG2NJ.E........u...2.q...Z..=(l)jU.X...U.\X.......O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.......................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.309612216371578
                                        Encrypted:false
                                        SSDEEP:48:xuBsl032TFCtoZBEJt+IBXMDB9hs0apy9rdMrbD69FXRM9Bxd:x+srFC+rEZBXMDB9h5aARMbgK
                                        MD5:DFDDD8B043F0669EBA7D3526A78344FA
                                        SHA1:D2CACBAF2DD520DE3F99B4060D810A6693B1C900
                                        SHA-256:936EA315BB4E92C3A9E7E3A569348E4AA4F1F6F5EAB4D8C8119138F5FC9A89EE
                                        SHA-512:85E5413FE0F9E8A861613B2A10B258446BAE7909CBCB6D419F8EF6C7DC7939B3FB890EBD26BBAB6A2126B937821BA62914EB05C3AF635FAAB2D70DDE02A0CFC9
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZs.......s......!M......s......!M......s....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'...............m.1..6.q..K......N...^...............x..f.i.O.......O........f........................................I.qk..B.....LZ..............m.1..6.q..K............m.1..6.q..K...........s.......s.......s...........................................s..j....s..T.]..s.......s....B..s..H....s....B..s....>.)s....J...................;........4...4...4.."..............s...s...s....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........s.......s......#s..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 39 x 579, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):515
                                        Entropy (8bit):6.740133870626016
                                        Encrypted:false
                                        SSDEEP:12:6v/7su2/c30mqkg9VgFHe7Ll8UmJX/N+1Zmkk8f3lbtI4:4mc38gFHe18lkk8f3lbth
                                        MD5:E96BE30D892A5412CF262FEE652921CA
                                        SHA1:8190A0BFE21D04BC6F3A406E91B87CA69C03A2DE
                                        SHA-256:0E31DA4DFCFF4A36C64C1CE940362D2309769F36369E4C43C317D5F2FA15658E
                                        SHA-512:D647F51ABBD013226A6ADD0D551D058C633F867F9AF5A9E099B85D6E291D220F7B85958B07381CD4C7C4F72356DBAFE2A86932AE398E28C56CDDF0744E92EE24
                                        Malicious:false
                                        Preview:.PNG........IHDR...'...C........b...`PLTE..................................................................................................bKGD....H....cmPPJCmp0712....H.s....9IDATx^..I..@.C..<..?mo.#C((.J}...~..B...b.I.i.\<.e.....(p.I.EO...q.x.......dRz....K..b0.:.<c.o..0.x\:...F....I&..ap....."P@....DO...q)p*..@Y.CL2)=......1.........4....._.G..^`..lDO...q...X....SL..z....K..#.L#..I6..ap.Ls.,....7&..ap.p..lI...,GO...q.....k.n1..4......3=.f.x.$..4.....o....x.$+..0.x\.,&6...............IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.36237610583704
                                        Encrypted:false
                                        SSDEEP:96:OsP1Ci65zh9EP/XJ9RkARMT66Em9JwgY9EVG3:OsP1Ci6hhaP/XJ9RkARMT66Em9GgY9qG
                                        MD5:E9BD36D9B1EEFF0963E292F180F6DD70
                                        SHA1:301D4F6ACC3968388ACF2F43433A857608FFD446
                                        SHA-256:BE1E6001FDB3EABE9658D26DD2D5DFFE667715D2761CC9D196F707133BD9378F
                                        SHA-512:123F6907E5A6FDCB7818D3B8E22556628F1C992D46674E319B2DBEE594C41A9E83E42865562E27E6AF6381570DAC7D10CCB56FC49C4839A5D2A64AEB540CBA5F
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZ.Yu......Yu.....>..\.I...Yu.....>..\.I...Yu..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..................+..)%...^......N...^...............=b...=.O...I............f........................................I.qk..B.....LZ.................+..)%...^...............+..)%...^............Yu......Yu......Yu..........................................Yuj.....YuT.]...Yu......Yu..B...YuH.....Yu..B...Yu..>.).Yu..J...................;........4...4...4.."...............Yu..Yu..Yu..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........Yu......Yu....#.Yu............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 30 x 700, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):1547
                                        Entropy (8bit):6.4194805172468286
                                        Encrypted:false
                                        SSDEEP:24:dZeDNYbS+238CTUFPA6SXG5qSacX9q73eXu0vC3dU+OB2gbwHRuZ:dykp9FzBBacXQ3uNC3n7xuZ
                                        MD5:0BA36A74DFBF411FAB348404CCEC3348
                                        SHA1:4C619790E517416E178161028987DF1CD3B871CC
                                        SHA-256:2E7AAF26BEC32148B96442E8FFF1BD2CEF2D72630969F23B9A2ABEDB6CFEC93B
                                        SHA-512:90AF53DB7C413E2ADB970AC345F73E4ED8AF626E179C929E6560118F7A9E98DC7C5FF02B2B3F6C98D397E0FE2D85F3427C6928C328872149E176FA8A99E91F54
                                        Malicious:false
                                        Preview:.PNG........IHDR...............\....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................D......bKGD....H....cmPPJCmp0712....H.s.....IDATx^.WSTA........b.0gPPP0..E.9b@L(.c.N.U>..@......;...}..B.(....$......5..XS...I....).!....D^.uE...\..5........F."o..-...m.n. .^.....q= .
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.334969006458965
                                        Encrypted:false
                                        SSDEEP:48:SszDeeFToV6KtBmE05IMjHWXGW9xUWpyFrdMrz7FXa0eDaDpRG+6:SsXhCEKCEkWXGW9yW4RMvjQa1RG+
                                        MD5:E1D9C17844175CDF1A211C511B941D48
                                        SHA1:504912CD316420E3E2C2EC9AD9A43BE6581856E9
                                        SHA-256:D8B9023D75DB47F70C88808B89D3C705532E9DAA2957CCC1DE7613A07F54E7C7
                                        SHA-512:C6441929E064BFB7578E01BEB9DEE70D4D453616966E2A590EB7668501118611A66CCB0B2DBC4D74AD16B123DC9151061471B610CF1D8BE2F6F7A4BF62ABD0F0
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ............#s...X..*B@....#s...X..*B@.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............w.b.^......i........N...^................)...A.G.7O.y..I........f........................................I.qk..B.....LZ............w.b.^......i............w.b.^......i............................................................................j.......T.]..............B.....H.........B.......>.).....J...................;........4...4...4.."...........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........................#...............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):95763
                                        Entropy (8bit):7.931689087616878
                                        Encrypted:false
                                        SSDEEP:1536:EoES7mhTyzabUaE77xAOmq0zVruQlttNxlipxVWssMU2YhRy2v6pKKYhQzwMc2:zz7mhTyzabUa4b4xuQlttnlGx8x9h02M
                                        MD5:177DD42CA99CAA2CCBF2974221680334
                                        SHA1:35FD86B3DD082A6D4930C67BC0E05D3B5817465A
                                        SHA-256:525A857D0EDA855A64D3619DF58B1C2D013A73E60FA0D49B155ECFCB2C134C7C
                                        SHA-512:6FB6D9A6C97B1115C3246690A2F339CD612899AC25ACBA00296EAEAA0A1D094E7339D670969764FE23EB7C08FCDD01C6F78FBC0735D504D5E02AD342901719B3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!..1AQa...q......."...2..B#Rb3..r$...6..C4....Ss%5...tu.c..Dd.EU7....................!.1.AQ..aq......"r..2...4Rb#3$B.Ss............?..H..dV....U..-..0]Cp.%O.Z.Y.e.=/.q.....j76.w@s...5.&&&5...n..w..>.1....;.vR..[.......=.......KtY]u3.g18...).r....&.IZ'.....g..4kY..X..b.......y<...r1........e.._...X...w....op.m%Jr31...S.Vo.._....OI\]....F..V-....\...2j..X.....y.p.$4.....&#..]..n.V..x..P...F..C.f....])..~..Z\.....,..#..v..v...2V.k.SuaydO../[.*c._..oTV<Z.s.[...o.x..>....-....v...#....-.X..L.Z./#.XG.-.0......%w..H.@aZ....C.}...N~.;..R......5.D......I.... .R........s.>..ks....(...S...9....2=. :^.. p.+?(....$..Q..I.........=|..`2. v..t......U*.8.u.. ...'...*...2;u....& 3..$.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.362812543489661
                                        Encrypted:false
                                        SSDEEP:96:OsBz3wnQ+cXEy02Xj9SZD4RMrT+y3z6/H6OtD8:Osin1c0y1Xj9eD4RMrT+OuzB
                                        MD5:A8CDC0BF6EBC28CFAE00A73794C77CA0
                                        SHA1:5C9C57573306910151911817466DF3836C742ECD
                                        SHA-256:D98032323897D9DB19954FA2D8DA20C4F4F68F309F1A2ED1126DCF9C5A9D1469
                                        SHA-512:10B0B459669F1EBE3302A2E836B77BDD026D81658A9409FDD6E134D6A283B9F7B3AF64692E3BC7223ED5E31047BE5F9F4E7AFA89F9E087295F737B359CF21A84
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ...........o..Q0lN......o..Q0lN......I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............}.:...K...8.;......N...^.................]`.{.O.k7............f........................................I.qk..B.....LZ............}.:...K...8.;..........}.:...K...8.;......................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):67991
                                        Entropy (8bit):7.870481231782746
                                        Encrypted:false
                                        SSDEEP:1536:3PC0XJjsmsKuZRG1pXuZ6z3wARnV9AEnieCc7cllJcHJ:qyMBzkUZ0gq25c7Z
                                        MD5:1271B1905D18A40D79A5B9DB27EE97EA
                                        SHA1:9618608FBD7342DE6C71220A36C3F4995BA9C13E
                                        SHA-256:5B321A4D81BD499B289B1755F6450A42047C494DFBC112DBD56DA4CED2C15C1A
                                        SHA-512:C32DD26047F6B8AA061085B38AC2B8335868E1BFD8731DB65544309223A955FA4BF45B06AC8D244408658F51A1775B6F19FF0FFC804989DE706DE8EB36F1436F
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1..AQa..q..".........2...BR#b.r.3...$.'...)..C%7gw..(.S.W89.......................!1.A.Qa.q".....2...#....B.t......rc.$%67Rb3s&'CUu.v....S.d5.V4T.e.............?...?..Wj.e.e.......w/..E..eOw_.....6......u..C6h.,..;.g.D8Z..-)O..jy..e;.u.g..w..[.L""k'w.......'1'.[......=..P...S.9a.V./O....q=8xk]...........9......F...e9'....9.O.... .&.....p......c.4...mr...?.......L..'.....0....+..|_...POM=7.?.2.a....};.Z..y./....>./.C.<...;.....|.1>...........S.8.o.O...+..n2...k../.X..9...Y...:.....\...Dk......q.K..\.Wuh.!Z?.mu...R.5.A.S.h.0..[..v..+M.....aUi*.k..?#..._...X..R.&]..[..;../]L..f..V......*.e...ut&.#.J.5....c%..o.$..v.<K.6..T.IP.....6X.*.uf..t0^..-.)m$.!.q(.j.f;..WB6.b.B..R.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.346108416951143
                                        Encrypted:false
                                        SSDEEP:48:rijOij7srccEfUIEth7ICEvlLu6cXtrRc9pU47pyRrdMr7k/VaLiFXCE9uYN:I77srKsIErEd0Xta9647sRM7EoLiv
                                        MD5:A743A979D1707AEA4F8727C5B1F8249A
                                        SHA1:87E60401B2B8A79EEA7928832B313F6FC7BB3CB6
                                        SHA-256:E852CAC62C2BF97A3A7832222A63781605CDF79B50A4039B7272D4B9987DAE35
                                        SHA-512:1322B7C424653914A00876EA1F22DF16326501609D15BF657CA96986017595D602CCB4493915825486FE10D7222126371776DF5DEA3851FEDDDCF6A5F67E7EED
                                        Malicious:false
                                        Preview:2...>.......R...v...F...................................................................................................................................2...>...........v...z............................I.......I.qk..B.....LZ.%......%..W......>.j.%..W......>.j.%..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............. .M#"G..4.........N...^................bAMx`.M................f........................................I.qk..B.....LZ............. .M#"G..4.............. .M#"G..4...............%......%......%..........................................%j.....%T.]...%......%..B...%H.....%..B...%..>.).%..J...................;........4...4...4.."...............%..%..%..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........%......%....#.%............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                        Category:dropped
                                        Size (bytes):22203
                                        Entropy (8bit):6.977175130747846
                                        Encrypted:false
                                        SSDEEP:192:5q3R1VBvq3R1Flrk6Q0QPJJrR39joOVMJ25d1NkMhIwobbtAAAqYnLJZMJYZ2AC:xw6Q0WJR3FoOVMJIIlAAAqYnMJdD
                                        MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                        SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                        SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                        SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.444507719134357
                                        Encrypted:false
                                        SSDEEP:48:BsXrs/bYPcuvMtl4E15L0dX/ge9lUcpyrBrdMruUWKeFXQg/3/IkRPOm/5PGMT/X:BsI5uvMMEDQXH92cyBRMeP/vvW/grIT
                                        MD5:BCA3E5CE178D0925ABC7D39B1CDE026D
                                        SHA1:D8299190B5CF3E06A3100465125582A1033E1B1B
                                        SHA-256:BF596846AECA45947284FFFBDA5E6A1C4F0594680EBDF3F9F7B401400E2C6534
                                        SHA-512:ECF81B39C7D86C3668A31AEC17DAEDC9D9B9B05AAC1DB86D09FC686EA14771D0ECE1B19D4D4C0EF2135817DA914E9ADE6DEF59CCB0C64F687C22D14E8B291261
                                        Malicious:false
                                        Preview:2...>.......l...v...`...................................................................................................................................2...>...H.......v................................I.......I.qk..B.....LZ..........J.P.....b.:....J.P.....b.:.....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............0.......K.H.o.....N...^................6... .J..J..{..........f........................................I.qk..B.....LZ............0.......K.H.o.........0.......K.H.o.....................................................................j......T.]............B....H........B......>.)....J...................;........4...4...4.."........................z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4......................#..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):15740
                                        Entropy (8bit):6.0674556182683945
                                        Encrypted:false
                                        SSDEEP:192:Elv3GG8/OOs+GouFdxMlxjoPyerzkpuOo2vPMc62PaJseZC+BJoS/:EtNiwdxMlZoPhzkpuOo2PMc6rX8+B6+
                                        MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                        SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                        SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                        SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.332729704189277
                                        Encrypted:false
                                        SSDEEP:48:ys3iR0bLQtRHEAkLBEjBBXy7wB9OyURpyRrdMrEk6Tu5FX/t6M1hJ7X6AOVI:ysdLQDEjiBBXy7wB9CRURMEkB5B1
                                        MD5:59E9F87947DA24ABCCF32FED036DAE36
                                        SHA1:41C475021A839AB76CBC841B9E95E2FE1DBA8F44
                                        SHA-256:E46D54B2987AF1677D862F4CC7F6D6D401605D7F528DE3450326BDACBD742E92
                                        SHA-512:1434831243310C20B0C7260C04A82B8B92A6975630629F6E173D25B3DE4538FB5CBF8EC556D4D3768A8E76326240399CFF799CD94F7104F1A65E27A6E900768C
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ_a......_a..}.D.>.b.i..._a..}.D.>.b.i..._a...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............ZQ.v}M..............N...^................+.m...E.o\.\.7k........f........................................I.qk..B.....LZ............ZQ.v}M..................ZQ.v}M..................._a......_a......_a.........................................._a.j...._a.T.].._a......_a...B.._a.H...._a...B.._a...>.)_a...J...................;........4...4...4..".............._a.._a.._a...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4........._a......_a.....#_a.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):86187
                                        Entropy (8bit):7.951356272886186
                                        Encrypted:false
                                        SSDEEP:1536:AbmHwD7za0syWMetp3TdPFzoJamVdAQZCiUit9qbYN6LerhWMzIWgN1EeaYhJM:1QnzsyTeP3TPAdAQZCi5qbYEKrhWWMNO
                                        MD5:FEE4785DF76E93A9DC2F4501CBAEAE12
                                        SHA1:8FB4527BDE05EF208FCDB168098A07707C27501F
                                        SHA-256:F091DED5E283AF6848670A3172E7C43C6099875D39B3FC69C2BDBA914F609602
                                        SHA-512:7E99D33151A0D3873D6A819C98EA8E62D928C087B7BA2080F11C7BCF746AD60A44D4FF6EE3D2D2E8DFA4BF1FC6285ED56BB83F91C2FC6FC4FDFF2000105F10B1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................1.!Aq...Qa."...2..BR#...br......6v.7..3.CSc...$4.s..&dt%u.f.......................!1.AQ..aq........"2.B#....Rb3..t.5u.67.8.r..$....C4.cs.Sd%.DEUe&.............?............w.....c.....i.A.....3...7.......7..P......%.........?Th..l./?.;.....$}..=5Oa...F.c.A/...D.D..]..y..3e.5\%.fo2.X.*]q.5Ee.}..i..md.T....#...-...Mu...9...-+..~w5O.);..G..'.;..).....A_...M.vV..y.q......,<.3.(...._K:..XM.......w.......9..T.......?b..a-%.c;.}..>....|.,lZKCEB.t...fw|.Sw^..Y..:.J.................t._P..v..j.1.R8.R....G..W*H<(Xi........i..xcu...WM.dqM>'W..g....M.q.....+.....b'..~....>..T.~Jc....fj.X.x..9...N.w.6:..>.......&.(h..u...t._...)_k#7Za...cZ....P...Y..;.V.,..xo.....f........Y...\6...M'L._
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.7109693654568225
                                        Encrypted:false
                                        SSDEEP:48:eGSsr0XT006jtrDWmEdzbULpBhrBXoO49IsU5pyiNErdMrshP4U2FX3N8bFhj:Msx06jhZEtUzJBXoO49Ir5puRMW4B3sR
                                        MD5:2F76D1E150138A3EAAA183605C4EAC90
                                        SHA1:5E2A1B1723D5C227C2D129FD84850C24A97107D1
                                        SHA-256:70FB41C60E941E26FEE5495938C0E7CE7678196CE2FDA784ADBD1CF4E8D571A0
                                        SHA-512:21FCD2AA1C7F93286A9EA0ACBC266A8D94A65BD8B5EF92DE82318469BE3FD75BEFA9034797662F2C101B43191DFCFF7A2E1E70DB35954855EC3CA09A816AAE4D
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>...t.......v................................I.......I.qk..B.....LZ.~+......~+.L3B.-......~+.L3B.-......~+..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............vV^q... ....Y3.....N...^...............!Pk.k{O.}z...h........f...................................H....I.qk..B.....LZ.............vV^q... ....Y3..........vV^q... ....Y3...........~+......~+......~+..........................................~+j.....~+T.]...~+......~+..B...~+H.....~+..B...~+..>.).~+..J...................;........4...4...4.."...............~+..~+..~+..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........~+......~+....#.~+............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 85 x 470, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):11197
                                        Entropy (8bit):7.975073010774664
                                        Encrypted:false
                                        SSDEEP:192:p9wNdtRKcVHso6zsqm06xaqZdingVzLZ7/PGSIz/yycRTbChh/JzhbEx15RGb:mdtMcVHqgAqTinMzLZ7/uSIz/yTR/mhF
                                        MD5:DDC3CC30794277500EFE4BC6667EC123
                                        SHA1:EFC9642C1F95B5FC38764476AE481649C016FA0C
                                        SHA-256:7F5B660A1A0BF46C75AAF19B4F77A0E086DE003EC03AFC1F58D871D55AA5BA9E
                                        SHA-512:25232A84604C3959634D33090238FEC8D51E40AD84EB3A08BB8522A81BE1E83378649C014E98E1DFCDF46B7BFAC92D8D2429211CD11D7EE0334C9C3DF7C1B6A6
                                        Malicious:false
                                        Preview:.PNG........IHDR...U.........1x5.....PLTE....................................e........................................................s...............x..........................o..............................................................................................................................................................~.............................m...............................................j...............................................p.......z......................................................x..............|........................................v.......................y..........................................................h...........................................................................P..{....bKGD....H....cmPPJCmp0712....H.s...(SIDATx^.}i@S..N....h...!..)....AI%..p.L."a..)..`U..,h..:O.b.:.j+.Z).b..zN.s..{O...&|..N}...${....~.....k}.[k}{.o^.D_..W:35ly..7rL....6n0.A...b
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.34691612656319
                                        Encrypted:false
                                        SSDEEP:48:2sivAk73Mt9PjElLXXpWXoLW9BUJpymWrdMrOcFXPRec2NAdR:2sG3MrLEldWXoLW9CJFWRM7TQm
                                        MD5:421F9ABCDBF2AF3C9668ABFF6F5443D3
                                        SHA1:7ACF1ED0ACEF3E2C23E6955C97176D7ABDE04F88
                                        SHA-256:653D6C50D3D0A0F3B01BA811E62D206759DF54A3771B2C7914DFB96C9B06E0FD
                                        SHA-512:7C3317D8C099BDEDFC0ABF606C60043D815C69BDEFB53E8997D9A332384CFE34A24BE8448AE77BB22DA04E52C99EBDFCC02369B796634CF0BD799FA4E844FB0A
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ.G*......G*%Jm0.,ML.G.c*.G*%Jm0.,ML.G.c*.G*..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............L.....,.dL..I.....N...^...................]C...tO%.........f........................................I.qk..B.....LZ............L.....,.dL..I.........L.....,.dL..I...........G*......G*......G*..........................................G*j.....G*T.]...G*......G*..B...G*H.....G*..B...G*..>.).G*..J...................;........4...4...4.."...............G*..G*..G*..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4..........G*......G*....#.G*............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 88 x 574, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):19920
                                        Entropy (8bit):7.987696084459766
                                        Encrypted:false
                                        SSDEEP:384:DRSgtAxJx7bzvAsVSqQElOT4uHmpmvNYT9aPU+QtsC2LgfIqJZnbeyRB:DsgaN7bzvAsVdK4uGQFUZ6bU/p3
                                        MD5:1BDAD9B3B6DE549162F9567697389E1C
                                        SHA1:5D9C09159F07A3A9BDCC6C4B9BD9CB72D0184E6F
                                        SHA-256:0908A4CFA23F93011176D47F45843E9CA2973030421996E8E27484781F54B0EC
                                        SHA-512:475040779AC247BB5C3E11862FB55FBDDFA12D759EE86A33E11BC1F3B656D6CD0F9B25146C0113E43E1D8001D8867D3BC3BF7E6FE21F3A0016CB1F8B70B7A15A
                                        Malicious:false
                                        Preview:.PNG........IHDR...X...>......y=h....PLTE..................................t........iw..............................................._n|...Tds...ky......................................................p~.....................................................dr.................v.............................................n{.......ap}..........x.....z...................u......................|..Vfu............r.....w........................................~...................Zjx...................................Yiw............w..|....................Xgv{.....y...........................jx..............\lz.........}..z.....t..[ky........u..y.....gu................................{..........}.....u....................~...........y....r.....bKGD....H....cmPPJCmp0712....H.s...JfIDATx^...\.W./.}....Sy...(..4....D.-.....H...% .$"D.Qr.......`..;...6...N......s...^...L.....Y{.GQU`..~...j....{...-Ax.K..&.....F..I\i..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):2.908768081037636
                                        Encrypted:false
                                        SSDEEP:48:D4Es/sre/uGnt+pE1Lw9NVSL6MhwnLXOrtL9dsqpyVrdMrHLkhFXI1zR2aMx:D4EsbuGnkE1+N0foXSx9djYRMHohJ
                                        MD5:5F2CAB1070C7353DEA7FD14D0985C3FE
                                        SHA1:8657BBA6855969FA37133283B88C060491CCBF5E
                                        SHA-256:78B3537E9A7CC40733332A09B16372720FEC0F7F99298E147011B0FF61FA9A7D
                                        SHA-512:B7B52B2E44371E7FF0C82E20F54DFA6295B561BD8250CE7C590C0D25C73A0D595CE72CF5A4C3B8D4289C06716BC0FC7577F73848AF715143F01B72F255F04EA7
                                        Malicious:false
                                        Preview:2...>...........v.......................................................................................................................................2...>.......H...v................................I.......I.qk..B.....LZdH......dH.....)....+'.dH.....)....+'.dH...I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............5.:t.o...I...i......N...^...............[r5.vL.J.].IY.2"........f........................................I.qk..B.....LZ............5.:t.o...I...i..........5.:t.o...I...i...........dH......dH......dH..........................................dH.j....dH.T.]..dH......dH...B..dH.H....dH...B..dH...>.)dH...J...................;........4...4...4.."..............dH..dH..dH...z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........dH......dH.....#dH.............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):179460
                                        Entropy (8bit):7.979020171518325
                                        Encrypted:false
                                        SSDEEP:3072:oiKXvL7lv0am/R1vrdH+9dK6zPQ6bbnGDpcGGDNMIOIMAT8q9Vc02Q57S4A+vMFz:+vlvC/HvgA6fGqGGJlO1qZ71W6CzDn
                                        MD5:4E131DBFEC5C2462273CA7B35675B9D9
                                        SHA1:CA037F444D819A118AC37D7AA3782B9BF94C1616
                                        SHA-256:2A4A3530D652E227DDD5ADC096A95F6034718F7C380B07DB622022D768815059
                                        SHA-512:C333ECEB1439D0238BF44FB7896E62DBA4C645B70413AA0F99C1F10E8DCD20C2EEE5C83F2E9DDE9A2494C85A6D8D13CFFFC4160E2F598E17867015F5244D656A
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1AQ.aq...".....2Rr..Bb..#34.....CSs.$5c.t....%.Dd.6.T..u.U....E.7w........................!.1A.Qaq......2."r.3....BRb.#4......CsSc...$.5..%.DT.t67d..Uu...'............?..c.......p..z..i.....z......kj........F>f......3N...M....RM.&..-.~.Q..'.....q.a..w...-~......g.{..&.......V.n.D....>FS!n.....@..)...W..q..Wr{..J.gf.{.M$.P@m.,..9..&m.D...w.._...-.O........s.....h.k~......(.K...V..l.-...+.9.k......*......#.p#.O..9M..mF...C.......7+.AI....4vw.;..H......e..Q.u[.eUK.....z.....[.Kt...s..Lf.4..l{.....sh.............=..;..iqkj.m.a...NH......v..H..$..q.y......c...U[Mcf.......+...S-...^....4..T..YtL.x.v.;.....<...Ik|B.$.s8......3.+.8.l.. h.:....%B..W..I.QRS..,*x.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.371008287205504
                                        Encrypted:false
                                        SSDEEP:48:Y9llsDnoHlvjtFxWWE4zKXh9Rsppy9rdMr7CposFXs0EQklgg:asQl7EWEjXh9RswRM+osolg
                                        MD5:462EF1123E766A20A1606F3D0E1EB0CE
                                        SHA1:6CF4137A04028CD4AA8F2EC4162FF02F303A91BD
                                        SHA-256:EA0C914DBC085201952FB7F64E945AB45FCBC4C67AEA6989C9876B29F73C6281
                                        SHA-512:87FA8C3B7FD3BA9A483F723F781D2DEB6AD2C5ED03DB06B60D024B7621C8D4FD70C1BB2A276B46FFDDC5539ADFB5984852ACD40111A8CD4BCD0DCA6BDC7DF1E5
                                        Malicious:false
                                        Preview:2...>.......T...v...H...................................................................................................................................2...>...0.......v...|............................I.......I.qk..B.....LZT.L.....T.L.oov.....[T.T.L.oov.....[T.T.L..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................Ok....!.|m.MC....N...^...............=.....D....C-.M........f........................................I.qk..B.....LZ...............Ok....!.|m.MC...........Ok....!.|m.MC.........T.L.....T.L.....T.L.........................................T.Lj....T.LT.]..T.L.....T.L..B..T.LH....T.L..B..T.L..>.)T.L..J...................;........4...4...4.."..............T.L.T.L.T.L..z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........T.L.....T.L....#T.L............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):109698
                                        Entropy (8bit):7.954100577911302
                                        Encrypted:false
                                        SSDEEP:3072:rDlmvIWr0aRtNCfShCWBxyCHMlcVG0Ezy4FR:rDliIfot8ahCWBcCHDVwR
                                        MD5:8D804A60E86627383BED6280ED62F1CF
                                        SHA1:E23FF14B10AD0762DD67FBA3CD6EFC85647C0384
                                        SHA-256:494547E566FB7A63DD429EB0699FE41AA8998F8EA2F758D813FE3D56C3075719
                                        SHA-512:0FB19F3D00159F2748C3A54E952E551B9FEA6910D67A54DECA8D099992E50383EADB92768FF1F75CFFAE82A7A157B1E0F77A2F0BE7EC64FD2324304FDCA46577
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...............................................................................................!"#.123..AQB$..aq.RCS...b..c4%..rs..D&....5E6'..TdUte...u.....FV...7.......................!"..1A2B..QaqR.#.br3.........C%...$5.....c4U..Eeu&SsD.6T..................?.....O.C.....^..R<A.g...[....3.....r.0.....nX.S....}...[.?Z.....A.?..~~I..rY|N.o...9......!...o7r../-.y...'5.3.U.s".-.0.1......SS...&.Q.j.*.$m.e..:x....`}...EP.?.7..~G(so.......O.....z.N..<....~^a.e...........p9.?<._..|......~.<@.D.9..G..?.?z.y?z.C.U.w..[.,..A.+........s......g...G.^....pz.xY.....d8.y.X...P..O(A.O..~:._.......<...o..4s..^.^b..x......_a.....|{c...:..X.....}.._...[?..NK.c...}.<......H.G....+x.Z..|....n...o....`.nk.#.%x......-|...|7......N!=././..w.8x.".8....'x........w...,>....j[w8a..}..lS..?.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):4.342400101604063
                                        Encrypted:false
                                        SSDEEP:48:AXsUlCo9NNtJLxE3ywmSXaARcS9ZshpydrdMr1ZB7SFXp9horxeJ:AXsmNN7dEQSXJiS9ZEgRMh7SOe
                                        MD5:346106A1E7D9B393DA4AD82A08054943
                                        SHA1:4E98AC3C596D9655C3B31BB9330A67014C47DF56
                                        SHA-256:F594D2B3554EEAADE16D457BC630905D32677B39A27C728F9134ED51D78FB936
                                        SHA-512:13A6E44DF535D4AF46F61CD11ECB68A79F81DCC90F2C49132BF3B2474CCD350203F0EFE301E110FAFADC697C98D468DC116EE9D30DD0910563CB8D683538CAA2
                                        Malicious:false
                                        Preview:2...>.......N...v...B...................................................................................................................................2...>...*.......v...v............................I.......I.qk..B.....LZ+.......+....P....}../.+....P....}../.+....I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'..............H.5.-M.............N...^.................<..u.N.5..............f........................................I.qk..B.....LZ.............H.5.-M..................H.5.-M..................+.......+.......+...........................................+..j....+..T.]..+.......+....B..+..H....+....B..+....>.)+....J...................;........4...4...4.."..............+...+...+....z...y.. x.. ...........$........4...,..7,..7........................;........4...4...4.........+.......+......#+..............................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):41893
                                        Entropy (8bit):7.52654558351485
                                        Encrypted:false
                                        SSDEEP:768:pZvVQkUbOHxx3pvVmO5rsP5gUdXwFMuv53knzyncaXgRDqPU:pZkijV5wScXwFMYknzucaXgRyU
                                        MD5:F25427EFECFEE786D5A9F630726DD140
                                        SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                        SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                        SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):3.3004316617368703
                                        Encrypted:false
                                        SSDEEP:48:GN2ObOIGa6qC9zH8jqEDbPUErl7yD/Bqw:G4qGa/C9w+EDb8EIDZJ
                                        MD5:5DF932C0EE6F13320DA4440D2F7B8EF3
                                        SHA1:94E57E23E934CA876E963F9BA43CD8FAC772432E
                                        SHA-256:A8E9A1D379C3DBF989F6093A2CBC0611DEB6DE822CAFD2532E7B393F481CFB5F
                                        SHA-512:7033986D27C380510EC0118ED65C70DC035EE8F1CFF6B7382A3CF294D044E15AADC4304F2CDF43DD62D0F6481E32EA103E0F1E13AE619BAF0967ED2718A84319
                                        Malicious:false
                                        Preview:........$...........t......................................?....................................................................................................\.......................................v.......v...!......x.s..................u[.Iv;..cw.C..{W..R}.;.............u[.Iv.....@.%..qF..P.9|..@...........;.......;...................................................Z.ZT&h..G.T(T...@.T.<..;....{..;..X....;....7..;.......;....$................4..(.....x.(.....Z.Z.....Z.Z.._.J.......d;.......;..cw.C..{W..R}.2...v...............................Z.Z..@............................@...........c..,0...e...B4.$........[.-...I.......9......................G......G....N..C..\..@.......@.%..qF..P.9|.kW...i..#...V...kW..v...!......x.sv....@.%..qF..P.9|..@......>.......@.................u[.Iv.@.%..qF..P.9|.................;.......;..cw.C..{W..R}.kW......kW...i..#...V........Z.Z.....kW...c..,0...e...B4.$..............E........................................0...........e....4....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12288
                                        Entropy (8bit):3.9123130841984155
                                        Encrypted:false
                                        SSDEEP:192:zBschZJYQwPGXwMTlIbRz2ELPB768Fu7Tp9D1dWNF:zWlK9ARz2FDTrC
                                        MD5:3100F9652CD6BFE547BFAD6A9753FF52
                                        SHA1:B32CBB517A475EDF4F9D384439455915690EB5F5
                                        SHA-256:08BB783E9D57D64A5655D2AAD88CC44EE2C9E5A56DBD4D7B540D3D8A7F155CD9
                                        SHA-512:F432C1E250A88FB88BA26F445AE6BB5C8AD63621898E2E5B373F17C93C227B160D670C3CF9FCB63654AFEFD2072BB966E8D1FF8EAF528C91DFD969BE064E9DA1
                                        Malicious:false
                                        Preview:2...>...........v.......X .. "..2...>...d...<...v.......@....!...........................................................................................................................................I.......I.qk..B.....LZ.M;.;....M;R..{.?.|B.]L.M;R..{.?.|B.]L.M;..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'................i..K./..@c!.U....N...^................/D3\..F..O.d..........h...L...............................D....I.qk..B.....LZ...............i..K./..@c!.U..................................M;......M;......M;..........................................M;j.....M;T&n...M;......M;......M;H.....M;..K...M;......M;$.........M;-.M;J.M;..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.5............(.M;#.M;8.M;..z...,4. .......$>........4...4.@..7.....................D..n4..o4..p4...4. .F
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                        Category:dropped
                                        Size (bytes):68633
                                        Entropy (8bit):7.709776384921022
                                        Encrypted:false
                                        SSDEEP:1536:tapXpSTJDOkFGdJdBk/slsbfsw1imaapnbvD8:U2OjJr6b07m1bvD8
                                        MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                        SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                        SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                        SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):4.08888676579926
                                        Encrypted:false
                                        SSDEEP:192:1bYCGMLDUwrwjGagxYh/8vYzdd/6tv32tcDCC2LUV7KX+RM2IFHRJsbfFF3o5GdP:xYCYZd/6dmc7EtRJu3QG1PRM
                                        MD5:CC02B9B74FF9E3490CA35F197DA89190
                                        SHA1:CCA414D6C779AB27D8E7C680B4E26B05CA298230
                                        SHA-256:59C1D11CAD2A5CCDFD40954B21066FBFAEC8A46E045DD5F2D8C25E97A2BE8674
                                        SHA-512:630CFA57C8BD6CCD28D5764DCA41A55FDEE0750E0E6D61D0C61FC0D4EAE2F9BFEAA00A30040BF7294DD0DEAC0DE4BC2EDEDE5F14DB5292FCDA2EA167BC942BEA
                                        Malicious:false
                                        Preview:N...>.......L...d... .... ...9..N...>...........d...h...@...@;...........................................................................................................................................I.......I.qk..B.....LZ#s......#s.\.:.>.8......CG..].%..V[b.|..C.#s.\.:.>.8....#s...I.qk..B.....LZ.I.............C.......C.......C...........................................Cj......CT.7....C..~....C.......CH......C.......C....&..C........'..C2..C..z...,4. ...."......$>........4..`..7......L.o.w. .P.r.i.o.r.i.t.y........................C:..C...C..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.2.3...........#s...z... ..$........................................2..7.........1.h...?.......?...?....rA\.-?>...o.u.t.l.i.n.e.L.o.c.I.D...o.u.t.l.i.n.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.4........?ff.A......'..C%..C...C..z...,4. .......$>........4.@.4..`..7.....................D..n4..o4..p4...4. ..1.........C*......C....%..C#...'..C&...9..C....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                        Category:dropped
                                        Size (bytes):59832
                                        Entropy (8bit):7.308211468398169
                                        Encrypted:false
                                        SSDEEP:1536:HS9SYFtN0+CRa9mfJy4zBAiIJhzrkHDV2hJK:yAmta+Tyy4zBIJW5WK
                                        MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                        SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                        SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                        SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20480
                                        Entropy (8bit):3.2424067819931106
                                        Encrypted:false
                                        SSDEEP:384:jdK2Oq0CMHFpHu8Q+sXW/XRJmAB6uIWAn8:jw2Oq0CMlpHu8Q+WoXRIAB6uIWAn
                                        MD5:8CA2639CF7EEACA29C01C029FEEA944C
                                        SHA1:9586E33FAE700DA028236CDD9C2CA463FEB4CEDE
                                        SHA-256:C03BBACDC526DAA8DABD50F29DF6E1C759195EDBC2D2DD50C8BB721690DD610D
                                        SHA-512:BB4C88A0A52A26DE5A0A106E295487FA12B1F185BEF50E32EED9AAAB52FA7F9C1DDD75B819F87D6563FCB8145847CC5AB17CDD0AC4D0E83CD20C83343EF6B1B8
                                        Malicious:false
                                        Preview:2...>...........v........ ...-..2...>...B.......v.......@....,...........................................................................................................................................I.......I.qk..B.....LZ..%.P.....%fW.....K.H.....%fW.....K.H.....%..I.qk..B.....LZ.I................................I.......I...................................................I.t.....I................................................................4..'...'.............I...Sy..,...;.]:....N...^...............3(....GE.....e.]............................3(....GE.....e.]........3(....GE.....e.]........I...Sy..,...;.]:...................................%.......%.......%...........................................%j.^....%T'.....%.......%.......%..-....%.......%.......% .L........%3..%I..%..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o.m.m.e.n.t.......0.0.0.6...............%3..%9..%..z...y.. x.. ...........$........2..72..7.....*...o.e.L.o.c.I.D...o.e.L.o.c.C.o
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:modified
                                        Size (bytes):53259
                                        Entropy (8bit):7.651662052139301
                                        Encrypted:false
                                        SSDEEP:768:dCiCBBenRYWDBCipMYGTbYGLHbXxoP/qEF+MU50qyJ30h2W474S/Aq/xc4674bi5:dCiIQXBCiwbDLHD0/sFyVel4Pi4UgE
                                        MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                        SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                        SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                        SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):2.5431475937072454
                                        Encrypted:false
                                        SSDEEP:24:dHWKKZZZ2VH47iedCDJRUlbw36J0UlSWTdcw4xeWUlBjVlesJTeE3UliuEJeESUx:5WhddCElbS6J1lf1lBNBElPEt3lCWiU
                                        MD5:13D7E8D4AD4091B9554314DCECFF0BCC
                                        SHA1:1621FE74DD0490C0A68D2C4415F4433850A3CD0B
                                        SHA-256:F065C47B749274C485F6773394F4035B6AE5EFDEFD9FEE06179A00DC00BA7F0F
                                        SHA-512:8EA79EB696019AF5F81A4364E50F3717AE2B29C790CC8E1E9CE924688C624853574806B8070B5418DDCEBAD1F7CAB17A50C42FD2A9AF2CEAA7EF9FDFB77907C2
                                        Malicious:false
                                        Preview:........................................................................................................................................................................................................<.6.....<.6..x..>.JZ..o..;.......;.....jus..]..;.....jus..]..;..*.!.(.....1.....*..6.{)..RJ..r...6.{....................................................................6.{..8..6.{..Q..6.{..[..6.{..b..6.{..o......k....`......................4..~...1...(...(.......C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.\.r.o.o.t.\.T.e.m.p.l.a.t.e.s.\.1.0.3.3.\.O.N.E.N.O.T.E.\.1.6.\.S.t.a.t.i.o.n.e.r.y.......S.t.a.t.i.o.n.e.r.y.........1.......S.t.a.t.i.o.n.e.r.y............6.{..1... ..$....S.t.a.t.i.o.n.e.r.y........L......Lf.yy.)..[.1l.6.{.....6.{)..RJ..r...2.................................;.6.{..*.................................;..c..,.........................;..c..,0.............F...pJ....ay.................6.{.6.{..1... ..$....S.t.a.t.i.o.n.e.r.y...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2278
                                        Entropy (8bit):3.855443000169642
                                        Encrypted:false
                                        SSDEEP:48:uiTrlKxsxxPxl9Il8um/PxCjBvrsHHtOzwn4fTrYkKWNA3mud1rc:vbYWpCFIHnV6NAmF
                                        MD5:FD1932E149ED3A0F982065EE377F3163
                                        SHA1:B23565707F2F026AD9A43C51FD80700BA8247478
                                        SHA-256:2A9E1AF55D31BEA1CECC12A7E196AA17D8B3D1DFEB2E656400E9307EA71EDF66
                                        SHA-512:07CEEFFE0C00D9A6622D76C68096C739D96E4790247BC86FB8B631B6996C9077E796E969863B2FF79D0A821BABE786A9FE3A4417E21413395C57205E04F3FB9D
                                        Malicious:false
                                        Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".C.J.1.m.u.g.S.o.z.s.S.9.x.S.Z./.Q.v.O.c.+.E.J.4.u.2.c.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".g.L.t.r.G.c.e.W.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.S.U.t.H.8.M.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4542
                                        Entropy (8bit):3.9970343461118616
                                        Encrypted:false
                                        SSDEEP:96:gLYI+SvBUn6OMVBbsyw6rfJ9ZLIYqeuCN5rR4HKIrr0OfZjO:gL3+SpLOa9HfJbk6RkrYWw
                                        MD5:C3B5D7F9D2ECABCFF15DA369475D799D
                                        SHA1:1B0A1F7C26F50B64A610D75AFCBE04401E3A18FA
                                        SHA-256:3E628706BB4C89CE8123AB5A9BC4D3FBA7D8D841BC67A67CA640C54A0AF259AE
                                        SHA-512:F900A2342E517B5B8EA8BCBC198BF8BB88803B671957975F94D6DE2333D1A356D62FE03918C1E39BABFD3110F452081D637251411E5346B1C94659FCC8BED9BB
                                        Malicious:false
                                        Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".V.q.Y.a.6.3.X.Y.9.b.4.Y.b.C.Z.g.f.0.u.y.E.6.v.n.x.e.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".q.u.H.i./.r.6.W.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.S.U.t.H.8.M.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):38896
                                        Entropy (8bit):7.994512755481974
                                        Encrypted:true
                                        SSDEEP:768:TG/iU8NNjRoJ8xHKgiKlGQdYgJ//203LtCCe1HXocJPrsd4XcWdOuj9EQAb+rVsI:TZnNNjRWS5ieXdr207tLaHXocpsd85MO
                                        MD5:F375639141631BBE3D48E92FA6920552
                                        SHA1:9656FB5A07D129AD136A1FDF7277E1DC0628FD0E
                                        SHA-256:D614ACA0BEFD6BFCCC6344E688CEFECF4D41A757952183DC31C2837D05D36F15
                                        SHA-512:233197A3E4A4E48FCD924E6930EDA71605E9C665AF56471C69429699F8058049500E5959C604874D88E920CC7F771A4D28F5F7FB501CC6CBFED8C55D44FBB824
                                        Malicious:true
                                        Preview:..b.:.).}&..J.U......!.?..g...e...3....P.......mrJ..&...;,......h.3..=".*P+.u...P......3....K+....].-Bg.H..sJ.(.....a.^...wz.......2....I..m.?.e+j..V..y.v.8.%^.rK.....:.1.@....~.e8.[.....\...+@f'...H.d...o...oe..J.J..... Cs..az.."w..}....4]....(.Y.=.......U<. _|....4......./.W./...-.L.u.O;........XL.kJwa......5...U.i.....e.pn[.?.A\....].v..i?...n...l....w..t..". W.8........<zi.q..c..ZW...y.+3....`..G#.._....K.{....=V4%.....].q..=S..[.}..:...9|..FX'...c..x...N...t..................K..q-R........(...?..W...z_.l..d.f.B.=...+z...e...j{.D.....\.M..n..5-..{o.m9..D.&=./.|e.$...J..S. ....ze....}......6....2d_+wh)..q.(b...;.=A....!...9......:a...*.k...).t.m.2Uy.*.I.....R.s.N.......!...S.P.FLr..I.....O.i...3.W..Z/.5.D.3.RC..wT8..u'8.u...0.........q...@;..%.`I W...5.....4.7.......6........Z..v...2...V....T{k.v5..F...|....j.I....l0@...Ola6.....Vg.e..F....X...k..h.4.$..xw....3.........^b.C#.3...l.m.{...x..._.%I..?...."...S...'S....u..=."........N...8..*
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10040
                                        Entropy (8bit):7.98103385033283
                                        Encrypted:false
                                        SSDEEP:192:+578w02mAUX83nTsZy2oAtSyANzvyALwOlMOntyBcazFI6CLrhKpS:+57b0/AUXanQY2DUnNbyJOLtyBc+C7gS
                                        MD5:2637265986706A0C5763121CE52BBBBB
                                        SHA1:41D353BC9DD0212D03217642B053AE9142BA29C2
                                        SHA-256:3E967E7989F413E95B7BE129EE3A16BCB17DD658915CAD82499D095C1942C196
                                        SHA-512:FA0B07D32BFFB1CB035FFDDEF339BA9A02C2F435EF2107F7E907E6CBB7387C9CD4D9730C868BFBB3D32FA3CDCAB5EB3AE23FE6BDE5406B0CE6B7947BB7637BBD
                                        Malicious:false
                                        Preview:.6..u...f..#2.x.&./..eU..v.O1..y.'.k.*..!..Dj.......R.`.8.......5n......>.>.<...w*5.>E!...R..~..VwMX..)eC&...Y5.Z..P.zi.C.V...'E;..Y..(@S.*h\.}...>7..c.c..o<.6(_.Sc....ym.Cs*.#.]..Xqn...w..,.P.U....2..c.m.0+.4..TO&{a.rB..e.l..)N.....e...a(.iL(.xbFM......g....O...i.(q......P?...F...=..CVk`.\..m.{..H=....l.){...8=p0......jo&....e.......].../.5.,..K...%.V[0].......?...r...l-...v-....+zz.-....9....>I..[..f.<.WsT...>]..*}.x.~Z......d...%P..A...e.1.3.{D...!..X.'....ATP.E..=...Y..A&...$p.ay^4.:.'3...?I.....[^oz...).%..TA...Bz{...3F,1}..4 ..'\...PB.^./ ....g...v....6.d.i.....$+..}.Y.......8..*.."!.Q....&S.......6Eo...l...l~..o.Q......HN.G.....;..rT...N.`.*....\.]<.Q{.*..Bd.....?...n3q..~....@*...P....Z2.xsw_.W..Z<..q.....lIr_...........d..#+7O.pU.....X/p?u.I..o...=..mi!.....ek.;.....}icBV..@f..K-.]jO.*G.%.1..cyKvY......U....:/.O...|.m.*H..~|[.....fViIO..\v..U.=.rB...QhUH.P.u.~e......W.Bt....4..7..p..1.Z.).j..A;~.Sutw@...L.N9...S.z....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):14503
                                        Entropy (8bit):7.989546909566185
                                        Encrypted:false
                                        SSDEEP:384:u0YuO+fv00fsantVzZjH1ey2DuuEt322XeLQjtrS:u01PH00kGxLN2iuEE2X+QjY
                                        MD5:A41EC7A2B746A45F7109B3868494B9C2
                                        SHA1:2A171B8A3F817E79E7E8EC4D6753959C67F74D61
                                        SHA-256:9A671953D188254ECB39479F5AFDC2490A14D9440DF2161545B0B1441DB41561
                                        SHA-512:5CB608596AD945FB9CBCEC6289B05C450B5C7D2B5C903A97972692F27A7C294D82A00541EF861ED28375364FFF16FA35DB96FD9E371E8F25539F28DD971B220E
                                        Malicious:false
                                        Preview:..N@..M.fs0.p.M ...A-.....o........ ..[Z}~....g....s.E.....m8R.Z.U..RI.....9..{U..tE...1. d..L..K2.<,wG.C>...k...Z.I.; &u....+.p....b..Ew...fW.D....".$..qU..?Q..9.....'......%0.}..y..*.F.5.8.y"..oM.....6.e.Y.1.^.....F.6I...Q..=.u.K...~....X.e.Jt.E............A..0.z........4.w.g.&.2..3...3..N.,..7..J.r.B.I.3o.R.....k..m.....@............|.p.Vq}...x....*.@.L..g......... ..HG"..........n.....dUv....76.Z.o .H.~.o..7...j...mh...J)(.a....h.I...'I........2}.7...f&.7/..........n...p.CX.e.,.8c.@<QY6r.^.vU...a8.l..i.MJ..Q.E..~....KF...S..k#}.t..?.......hb.f...*..FA.6....@...m..B..3w...J%.....3...B....d".b...B`j(....19.H...*J.y..u&r.~""......AI...(.2Ze....Px....Ru...a.W;..E.R.!."c.d..T..!`........&j.....I..NIz,.=K....Qx.SX.zi.-.B...6NA.2...n...../...A.&...Q..x.}.F...6.B.....1...v.qCj...r..4..5.x....9...#.0.*_.~........W..7bs...|...4...Oi..X......G.[|....$..N.W|=.!... f..:}-..;/..).....;...B.p...Y..C..T:.G...<..1.e.^0.'....~o!..=g<:..~.#.qB.p..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9595
                                        Entropy (8bit):7.983095626593998
                                        Encrypted:false
                                        SSDEEP:192:XFHwgK0c0F/RoE8qimyqy00lca2onUcYgnsFIHopS:mgK0rsE8iryyovYw0S
                                        MD5:0F227CD76B928D4FAF5C1AD908FA1620
                                        SHA1:156A043266AD9CAB2AAC92C2EB204E6DCE2A5D61
                                        SHA-256:37BCDA56DA3908E1B0D2C805A19DD85DBE93160D1905E15092D8A61828761F46
                                        SHA-512:69246A5045F806E13A7B0A456B496461021BE76829DC3508891087513ECA5E87919C67A62DC6B9D5BBD214057775F75B6D4BCBDD28DA0BF1C325C0A9CD9E87C4
                                        Malicious:false
                                        Preview:..~L.......m+.BHz>..(.>..Cd...i......7[..%^..b....1.*.<.6kg{2.tv1.*A9X.H..2..^.y....T......._\..#e./W.......4f.Q...X0....f.6....9........%...".........k...2..F........)<.../X....(.....F..^...S.t......a.y..~...C..E..z&f5C....H...)As!E_._...kI..UQ.w.e.5..../..!d'.....Q...'BJN....a...xN[;5..5...o.~s.d8.Y.L..........f.5. ....D`.....7O?i.?....960..M.I..;.^_.....l`W.R.F.6ca.w.P...F.A....W...,X..Y......Z}.?!..R.v........M....p..q_..r.\w{C.%iJ..j....C..oA.$.8.0on.........2...M..{...._..)b.._.st.=....%..L.{>.....e.zK...X......2.8.y...,.M.....$.........J....Bz....54.I..0.,......+.Ky......<....Y..a....P..\L.....=9...*_~x=..|=.q..sGU.j.F..W..P...pL.\....V.t....a..G...+].KC^..)m}fg..7R...5........y+k...~w.'.K0.bW..g$.......h@.,Y..!....,.|L..g..n/..=.q.....Of.I..}.I,.S.....:...`N...~~.......&#.c......f.+~d:...$.....,#q...xZ....q1&Z..wQ5..]...8...N......P)\.q..........qN..0...u.....v.b....]}O.<.7.^$..*...rC.J..=_...A...|.Y....9.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):28042
                                        Entropy (8bit):7.9930407563060974
                                        Encrypted:true
                                        SSDEEP:768:RGjJLVxB+n+T2n7rzg+z1nkgz3jVW0a17yPKBHJowukFQMf7ruL:oj1nB+q2n7rzg+z1trU0KmPKBHJoRk9w
                                        MD5:715A3F18BFB7371803F9251A5E2D94B3
                                        SHA1:5FCFC930B6B0C49FD16E507B95411E84EDE14B13
                                        SHA-256:98D604E525A145B03A67D93D31BA146CCE9784D1811650C456EF7CAB818E5557
                                        SHA-512:8B21DF728C2685B50303929497BC01CE2DFD3803E25BB42AF3250641AF235D241CEF448259438A7990B8C45C26508E921DCEE8A46C142887281616387C7CF5CE
                                        Malicious:true
                                        Preview:..DN'#...y.0z...?#......*A.T....y.d..T.4..........F..|..3.+....S....U..:.Y.{T'>;..}..d...(.!....^;D.$....2@.s..x#...3..?...L.i..R........i.I...h...n\g...W....)E....-$.z...|[5s....#..%.......r5....K.....yZ.P..zu]....p.gS/,..E..?u..n..q...cPTHS_8.m.63...^....0...@.....'X....c..4...~.....w.)x...._..r..7.MS5.31z..t..m..e.5x.......G.j..:.H.xCOf.t....&.S.n..C....._x.|../0.........B..+..>.......q...hj.v[S..}&..P........F...X7...&rd=.p.3.A]O..k;...}..N.Hu...g.oM.9.."...pQ.....?..x...5...3../G.N!....S....]y......U.p..[W.R..r.......R...F..[?v..`....@a@.z...z..T.-l.Ti..........i?...60H..S...>.."A=.a.}.b>P?..}Z.`Q..S....e.I.P.....x..]r.....T.T..<.3.R...+..8..09.a...(.e.M.i.b.laL.,p..-.V..U.[....?....3.jh*...L.|x.`g..C.x7.X.F|::...S..O.r..G:...U^`FRk..[.-E'db..9....F....(.d........N(.F....}.W....ZL.[Q...,.d.I ..H.n&A..z..N..7f...p.........h......~nCkh.!.e...0;.m..u...6../b....(..=W.Uj#..l.e.....<.C#..4.$.....T.w.m...%....^...\.........F........k1n.z]...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10098
                                        Entropy (8bit):7.980822295524365
                                        Encrypted:false
                                        SSDEEP:192:cI80My14bCThFJh1bNrRqiDOH1mvZrCOo3Cf3dhxTvRnxLpLEmolUpS:WIoG15OcCR3CfTbEmouS
                                        MD5:661CFA8F30DC1DA0079B5FB73D1D14B4
                                        SHA1:148E3AC7AC543C28A0424693D319AC89B196C3A7
                                        SHA-256:1424AE9A20623688160B53F281EFBD6319234F9FB6135F0E52E5B0ABD3882655
                                        SHA-512:C1C2DB73B6A46C0ECAC368EC465C3E407D18B78049B233DE70AC28B322F8E07D9F09650612A854361F23EE6BEB1751C2557836709B74BFC69B11D317339D4224
                                        Malicious:false
                                        Preview:..6...G..T....w..0..rL.7..ytZ..x*..\&5O.%r.8...$...d.F.0.....e.,.).3{.N^Y.?5.V.z.u1....o....=l.....3v.O.4.aF.S..W.C..2.W..2.n.m^.6=r..).x).4..d..s......E.'....9....mt.|.j.b.Tl....Y..Ib.....?f....5$.P&t..)~.6.B..w.#...k...P...y."y....I.........9..~<....d_2.O....B.9..Y.\..\...CydLC=[......N....%5.(/1v.......[....6xZ...r.l.V?y^-f?...VQ.qr......~$.........t..nP....j.*AE.....p_b.x.X.I.3t...(...`.;.....m..}.s:.......J.D.2..Du.....V9.XH.._.......h.o%.q'$X)..t..b)V... A@..mQNrZ.N..PFm..=.d....6........$..>f.cA..\......1p......8~..;.q.Fv.eiT..q....'PQ..;...&.+cg...Gud3.*.2...a....#s.EA...W..]"xs....99..D..F..S..&...6..-........Q6LnsMN...%.<.D......0\...C...s^..GO[.8""..^.Z..Y.?....RJ...K...kc.[r9....6.x.....7a.. !.~t+p....,<)...f8.:t.,.]z ..*...:o4..........S~..a.p.(*xM.b,..R6W..M.y..W.N{v..d.+..m...`(...................J.:..D..O.i.....h.Z..X..2#...O....a..M..p.a...'..<?.8...9.~*8.....O..7U.cb.E..@.s.....Z.>.u.h3...%.......N.......'..}.O.hu............
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):11105
                                        Entropy (8bit):7.984255413769599
                                        Encrypted:false
                                        SSDEEP:192:K4BccTLE17wDXScsXj8p5Etb43jnoROls08wpG+qF/IMjnmX5WZpS:KgTEpvcsAiEtl0YMjM5WXS
                                        MD5:845E4ABEAD39E32D099C72C255AC0EC9
                                        SHA1:6693AE863F60A8F7A4C382DAEA6D0E77329BBABC
                                        SHA-256:18A421761B8DA2558F976B9F5C132611CCC406764DEBD4F727E5CCB31CE204D6
                                        SHA-512:8EB95B41A3D351B9DF0483AF198E6F6D8CA95FAB1B9CB712FE714440A16F423E7694CA32427A6944995486B1C4B7EE6E7429CA28DC44E021524614FE53B1C90A
                                        Malicious:false
                                        Preview:tNX...l...v.......,...5.......L...Lu..$.o...._..z.(V4....e.%eg{....)..5..:..Y.w..h.....:.N!@....M...GQ%... gJW.X,.x....#....#.r.1..d..7.......J...lO.P....gN._.'. .;.y........M...#.....<I...w.".\..c7{M...1.g..W...v..5RQ...\/n.OY[M...{.f$..s.}d..J;.XmVc...J..u./...t.+.k.1.....%(..$...z.^...q`.....,h......6....+..9j.....MC..g..fe..aP.@.,E.@.....:.[.1.TR.%n...WLfr'..C.....<.Ki..Z.6M.!..m.}.W..x.........}...u......vB.ZG..Cz....<UM....].~.{]^D....8l........b..n.g..U...+].Nc......l..t..A....Pc."..2~....>.......kx$^o.^...$..8f...I.}.;.)j...[.!.G.9.J.....2...3....A ..q.]. A"+.W....Jkp...c5..)G.b.~aE..tf..t...../..U.)?>.}NV3....)'q~...Jf....u.....{t.._2.\.R...H.*.%lq. ....R..<(..0^....C.Z../#.....f;!2m.7...V..[....M..6N..6..5..).j.....g<.`....1;`%.C!..)sp..V.#...@np.9E..\.%.......j..p'../..g.~..Bz.$n, -Z*.0.a...5.7.d.#.NJC.T1...X.0....Z .Ko.(...g.4.|.G..cC..G......e.|...Cm..cA..a.-.m}D..M..o.6..%.JnM....H..pf.....]#Z.w0yz.$H]..q..F...n.~
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9716
                                        Entropy (8bit):7.978883674873902
                                        Encrypted:false
                                        SSDEEP:192:zNbrrPk4K8oBLzVsJRbHKbcg37Gogjams6ccC3spY+GsoEfU46SgzlpS:jK8gzE9A3ifjaLLlS7pUS
                                        MD5:A5316BB1BBCB5ACA1FED9494492D7BFD
                                        SHA1:605C79232D88FA5501223B3E5A784360F921233A
                                        SHA-256:24E39DF9A7CB0A256BEAC75A0ED90CA3AFA236F6B6BC5BA8EF88C4DDD89E2E4A
                                        SHA-512:DA6E0E6B2A64D50239BB2BB941E2F2FA54361C6C1B5F6DFB3AD4E36D8CA048D506A119B5CDD7941D5C13E113E88793D706370278D5CB09B3386E97310EFDC954
                                        Malicious:false
                                        Preview:.\..H.X.._......XSM..0~..N@g#O'.`..=b...RP..,a,>...yY_...v.#.C..._FI..1.....[........y..........#2j.^k.O7.R..!3.k.......~...ZJ..o.......+i9..I....3.r.L......k....+........zs.P.1V.L..B.....j..).@;.W.1ii....w.5...^.C...u<....R...W..p..E....d....<.O~%.^(.e..q)....J..^.m.J......B.......e..h......E....R$N{....mF2.$x.z4#.L.......:...q...T..Ji..d...;.....& l..&n6.1Q...A..7.2..O~....N./..=.)".a.....C9.......j........}E'...[(..|..."9S.n4.'..!U+.....?.....w1.J'...&E...f=...O.Y..N.-o.kF....=.r..z....7!.!.7Zw.c..t.{U.D..!iG.+p..,...tiK.(H".7....O..d...'77`..y.x.[...T...B.{m......P,5u#..d.P.m...>.wwiU."....H3.`.D..9....z.....`....$^n]u..6/.M%.+..=.G.v.P.\....v..S_...8@b...o.$J.k...)..... ....3 Z.AL...j..>.K..zv...q>...)..s...j...$..8...iQ..52..S.V.6....-...K.hy.......~.....R....Z.w......7[........8.5@.....,..2..N..fk`:.lh.g.yx.t..j.,I.-<..SaY...|.Q..#.h..]iedY8.|.......&V....{..O..."..R...>'. S.@..f....1..........K\.I...gq.s....-/..x@M..A.Am..{@..-
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10337
                                        Entropy (8bit):7.980970053706086
                                        Encrypted:false
                                        SSDEEP:192:h0Kooasbr3kFrFL9ynhcgHiHXljakfSkOXqyPjfr/yBTnKpS:kUkNF+cJ1jak9Ozbr/yAS
                                        MD5:14B32CDB0A172C182C80E20FB42F6DBB
                                        SHA1:58A94288F25D0E0E1DC0A9568B51C61963AF1C3B
                                        SHA-256:3B03ACE6D37F3C8611987524651304F790CDDB12DE11DD1C7DE67670CD555FE4
                                        SHA-512:A626744FFEAC0EE2FDD6A15F0C3DEEE3AEA86B0DD41FC0244E8D53BFB6713BA6DD9CB3D64BB41FD316486653D121382E2EFE1EDFDC4A7A9F8395A22D9DEFEF75
                                        Malicious:false
                                        Preview:.._.'.....4t..`....o.:...O...Qf........b*....sv...I.7@;.....up.......d......80A+0,....K$...7..q.%.......W-X...?.....k*.ujk...$..W.I...?....B...5P... ..G.?'.%?+.#F.e....F..k...!.I...............C.......cm..4@U...`.s[...E{d.....=L.S#..._..9..D..WBI.j....g...;.........RB..`H..p.._N..sz.....~....<.>...\m.Z....~..;T.Nq..1..DF.B....^.bL.{. '.`\|kq@......VJA..v....`.}.....a..k.y...9pQ........ ..2Z.W..T...*@.H\.u.....V..aG...^5d.>.H.G!..T....M.. . .pi..FAR..VX........3..R[..Pb9!........B..E......~q..M.5...rbu(BK`.>...P%Ak....t...O....q.EK.,..E6.E.Eo......*.Z..A.f.JD.^...X..t...(b.Hu68..q.k..GU.P...s.....sO.J.:..Z`......J..N)...!...........).W.....F"*..8....d..M.Z..<Yq:@..}|t..oU|..\I.oi....^..B..........F..5+....i5T....;a...F.PsY.....37..ja.?Xf.$S...c...T.....K..'.......(.e(.Z..KLg...l...,T[.Y......ei.3.i...s..D0.e.g).c..8F[....(.. ........5.........]..e.=....0.2~....4...HwL....]./...MgZ.ID............ei.R.5..e.P...C.i.+....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10042
                                        Entropy (8bit):7.9814236779700325
                                        Encrypted:false
                                        SSDEEP:192:1Lgel7J/TlinKg7jrc4717dOH7yi5/6CcVwGulnI/PcFpS:F5hRTghnrc4xBXiofwGanSiS
                                        MD5:1BAFF4EF2C0B1AF13C2FE9DC17AC6876
                                        SHA1:C9AF01951EE90344A50B0363C4BFDB7B66DFD412
                                        SHA-256:8B072C3FC8028874103A9FFAE685E4C7EDA606720B4716DF7C982450277D5ADB
                                        SHA-512:304A0CF91E2C3117F477D8B4966D64CDC83CF917F37CAAC44E2D5AFEDA74C20BBD6D13D6076871F90E1981E2A04009A66F3B75D51C61EA718408A63B20106DC1
                                        Malicious:false
                                        Preview:u..7\.Ha....*0...J3y..")PAD..4.Yk.{.L.V..\..M....y..<...:.t...N.W....`..<.....EI.Y..w.W].e[.A.b..a..[.+.B ...lf....!!.g.H.o6Y... a....b...a!x...0Q.v...w.aJ..........^...p..4..o.+......$..s...]...iR4....5..w....Z.....SM?..pgz.....-..p...K..m...X..i5.5..M.[.lJ..o...O..,Gz.|..V..Al...4..s.......K.>.A...E.t..rEi=....&.........Z...O.B.99]a.Q|d3m...=.N._......a..........t..S...!....d.....1.o..-2K$..fp._..-.......8.R5.WU..2..C.V....7.<R.[.. .&=..{Ce......OL_r..{=&:......S.5...LdUpd=.6.......@..!..6lB...\%H*I...E.A....:.M.$.u.A.~"B.[R..`*....(.."......$..D..qUsY.2.6..z.&.5s4...~(.3T.o.a...o...L..z..T.L..o...4.n@X....v'...L.....l.....9..&U..?....R..w.N...OWRL...baf.....k...}.....V.<...S...Y.^N..{.3..p....h.a.@.c.:yP.I......`$..GN.....`.:....3Mj.Z. 3...Vr.b....K..8.._.].t..D..u).CC..........D.z............:.N....._....e...u..Kv...:l... o.EjT..}[.......!.R3..nV..4iaN.t.Q'..D....uMuk......z.d'4.....p\'..=..=.....$...R.[{..'....'..h(..V).........4T..$..5.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9435
                                        Entropy (8bit):7.977833037720549
                                        Encrypted:false
                                        SSDEEP:192:WDPZUbRxs84qjlfcrHbkWQ12eRS0yNpf18NM0yVn2s4HgOpS:WDRUtoqjWzxQ12Wof18NM0gGAuS
                                        MD5:610C6E879096C2688B962E8D521DF715
                                        SHA1:C416A3B3C39271657660000DD914E02760770F4D
                                        SHA-256:2EE7E727E6AA52BC5609EC3CD30B91F10D65EE6458530DF79AD7BBF6EA54AB98
                                        SHA-512:593663FDF114CEA3808C36CB75675259CC9501986EA1D6EF63B27BD4ED20525E983DD20A07B2F04D2A10CB3186A8F4BF416DEF6012C2E11A9F6927E948AD57DA
                                        Malicious:false
                                        Preview:n.,<n..#.kOz.....`>.....R..BA.Sy....INW.s.8\(.h..}.V.JG.@.EI#iX..g..;F.^.N..U.....3.v.4.....:Zg.0a.z...e..TD....(..z.....h.v..7.l....Nm.....L..f3..W.../Z...m.....R.A....T.td.<.@..1nu..i.~...|.l..lk~.0p...{.pA..'......gF....W.5....4.C..T.\M.u.)Z....N...."sc[.*d...z-...P........... .Nk......[jrnv.@x.,..}Ef...O.wt..N...3_..0.'.c3. ...].3.9.o...,..m.<7.x..$/}x.!...J...RC:+.. ..V.b..x...:..c[..M.+..}.~F..qg.E..QF>.t.:W.V.........G..H...?..`...f;h.C..D1%..).R.jE....;.+..5....-.}[v9.xIe.Kwj......9..|.....[.\..U./..e./.N.*..\.f..>9w.8N.V.. ..I.W....)Z(.3..M.\....F?.(....M"Q.......4V.N.M....I.v.p.e8#.|Z...K"/...&....l.J>r..f..M.W.m.c........nB:.}.;R..h...kRUt.=.C...pm.:..G......U...c\DK.........:8A$.S.h.-..K..u..*.F...X<..U..c..x...@.t~~o+.X...X....w...v`H.]xZ.....s..x.....^O\.K..-\..sG.E.h..`.).1..,g.&0.._kl.a.......s.o...Z.}.uf.RT..F...(4...E...Sk..6s.9..@T.9....=?...P.H.K.w......6Y..2:...........CX....^.P/..Di.y....%\.2.."/*..URS.....t\._.b.p7.wR.}yx..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10042
                                        Entropy (8bit):7.979846122293459
                                        Encrypted:false
                                        SSDEEP:192:36xXCOCSD8fCWX5rg4E77HYZkjUXWxq+LcNuTYx3sqUE+eJq94BlpS:3gvtgKWXNgJ7zpjUXDMc8a3sh6JqaBDS
                                        MD5:83333BED25F4DDE475C01EB0F96203C5
                                        SHA1:12BF8EC6712164E93887EB336D4E230254731A8F
                                        SHA-256:6BA14A92DDB2EF91754E36C7A9F6917B740DE6B85624970B39857B0B3B3207BB
                                        SHA-512:D2512B185FE2360BF09BD87628E766D77F94D654C7C576F5B992A65C2640D3D97C56FB151750BCEC8D3B4C4AC7DD93FA2F677DE08619CCDF98A89D552F15352E
                                        Malicious:false
                                        Preview:..O...W..K..._k$i....I.l....(J._;[.E<..,.../.U...o...A.E.w.1E]s...@.=...Z.....Q).l.bs7...!...M...R..f....; 5.....m,.a..Y......\.cF.A.(.b.%.^...G.t@w.[.&.G..B.Q..Hm.$...Yu....-.X*c........~N....R..dne.PU...$....Rg.n.....3..ne8~.Hs.n...4.(...Y[..M..H.fo7...T....!..*EX..G..0.|............p.t.q....!.VU...8.B{.....w.S.B..a...D..V.s.S!...O..*.(%13_.%..l.*..y..*..a.,.N.rK..f.....&..M...n...T...0'S1.r.n..,...p.R.?.>...SM9...'.7B....#..w....b84.S...R_.6.tX7.iZ..".......D.{B.......I.\..u.o~cg.N*w...9.>.....j...1..........<...&S.8...9.A.}}G.y.(....X(..D.#...l|_w..Y.a...v*LQ...k$.'....W...;:>.{gs~.;s..........d...g.g...I....C....-..@...f..8.S.P.2f.....5.....[...%dYi....<..e....J..].....p.....{.......Y.D9.l..}.1....hI....J.G.[....S..K.P.+...+......X.!i2V...z`.K..'...p..........M.`V.%R.-...m..>d.d|.C2gq.U[#f.#....zHY.\@I..Xq..'.~Q%.l.S.D"....?.[p`]*.....!./M..E......P....V4.D.@,H...GBE..>......d..j<.O].V.l..Z......d.....xcF"..,.#~...|.;.......M...U.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10043
                                        Entropy (8bit):7.981273892185628
                                        Encrypted:false
                                        SSDEEP:192:VADi4HbH9DSxknIt4ajKBAdZMuH6FKInPk0O/OpS:VADb79DmqIdzdZMnnPk0euS
                                        MD5:F94B226EEC077908E4847A2213B22FA7
                                        SHA1:2426CCB7CE171F1E3377CF8490F7ED9C2AEBD487
                                        SHA-256:5AB9918890F027A632776ADED75E8959E6323CCD88D61AB3116A5B05545EEB27
                                        SHA-512:EA0FBADDA681C9E30A6337575FFC648A0C937B2C136125C03730C723C71162FED833BD8F2D910EB15225600C102C50B2117FEA0FA1C831CF884C11814FC3D1D2
                                        Malicious:false
                                        Preview:..w..$.EZ.e*.z...6.w}.|.Xq.x.>.....t.d&.r...fI.F.f...hK^.]....I....Qfi...2T...Q.o...w.)s..1....Sp.....&.U~\RgS..N8l.R.m.@..9.^v...........y...}.LB+....*p.=...b....Q.....&....*u......n...Q%..A..5...c...A..#b.].3.{f..#CC..7.xJ.`.(g..zht.P...5.G../...c..{.M.U..v..\}.F_.K. R:....9.v..^..t...o.7..p2.N5........_J...QF5......@...A..r.5z.D..p.J....?......%..\F)....+''PQi4&V.......l.O.L.`.i...[n.M.[...~jC....P./.......8.\..!...X;.+X.IZx.K..<3..+.>...WX..x..3".6..2<....Z.../O..Z..sN..bm...m..??.c.X..NN..b...=....B.L^y.0.....lBN..3.(.]...`j.X..K..?.}..qL..4,4.#.9I[f.......1.>#5..&.RHE.t6...X.V.....6..........u..9.i4F.5a........n. y5...|....E.t9..S.o...J5.}...fP.RS1;..&J.d...3Fb.S......A3u_....C..[._K.......u...<..Y.%.{{.u..i...(....Q]....wDf......jK..H&.A.<4.{...6>..cY.E..#.8.c.U..2*^.$.n'..YCS.n.~.....$.`.r...=.ui..!......wsk.9.M.Z.{f.W.>.P.Wx)..A.S...sCg.BJ`|<.v..gJS.. .=.Jd.o.ca.....Y..q..3..\.......@&X..gu....V,..T.`.Qt......ZLw{.].p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10043
                                        Entropy (8bit):7.983526222501591
                                        Encrypted:false
                                        SSDEEP:192:jFp7enbsXqvkGtSp9tVbkORnm6ijYVH2RFBCuHKAXwRNYQeiMvzszaQ/Nc0pS:/4wqNSp5IOB7ijYQf6AlrVyS
                                        MD5:A0B776EC019C00C5675F6CCCD4EB1A93
                                        SHA1:93DC871B70209D30F5F40E1FD1CA81AAFAF3D1C4
                                        SHA-256:6084DAC498A0D1D4576A3243C891EC5AA424B10522ACDA5560AE5BE9F8A2A36D
                                        SHA-512:2CCDA1670EC0677F51CC3224B99B91E0DE17EED9FF35229B33D8D2B96DCE6F96CA403C0CD3729054D69812DBF33397F0A2C0D5E4250942802C9EA7FC912297B1
                                        Malicious:false
                                        Preview:M.ue.^....G..!.td..].^:.t....`.A%.&.8...E..H..#..~......v......^.....}.........&..0...sE..{2.].8...B.CM.w+fg..k..C......U.....t.{..s...3.J......F.?.DJ.A....S.rr....F..jK.....p.K.t.^d{...r..9.......OE.q..*%.`.!W...P.R.|.....HGrs...%.<.m.L......r........i.2.f...is.T.....A..I.u."..c...E.y...ZF.....h....s...9)@...$.......2.he....D6.H..0.QeI.p..s.....3.o....T.^.r..v=...C.k...^ElC......k.e.:....[....B.E:.....7.{..@..\P.h.p9V.......Cy.hIeLV.G.*ebi6|k?.|.z..tzI&..m..t..~..@u....V.).m\.x..5.i.E..nq.-..zM...,....&V.(.pD...'9M..Q..m .2..(.....F.Ki.r..{-...O.ab..3.<...4*I..4.M6....X.o.....o..lXF{M.+.76.Q......,..M..+..;.....^hSo(f.#y....O.....x.$....C..\7...p.\:{!>..Vr...Z.<..[...|......g..).....#....\".V(tL.....$r.lc.N.y.\....)./..:C....a.b.F...nd..gzh.5$......H..q@....A.../.F..7f....6..2J.&M......i..8..s.).?r=.T._L3...}.../..&6...Fj...D. ...L...."......Km...MB..T.6}.n.<r.1G/.{".N.Q.1...Lc.K........Yf..@d.. ...'9.....A...m.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10040
                                        Entropy (8bit):7.981714430013636
                                        Encrypted:false
                                        SSDEEP:192:MGLoTfajgP3TPj1XfC8aGZiUTjvnMAnvGKXj0ox/p7VEKNCOKFZtpeR49npS:/oL+gP1XfC8bPOKP/p7VEKyFZt8R4/S
                                        MD5:8830E8C1A60D18962BFD7A6ACABD03D1
                                        SHA1:C08793D811F30A2B451EE8D61298553DADE61D13
                                        SHA-256:BCF72387F7D60FE7B121F4C33C47ECC0362423089D46093CF16934DA985E8D07
                                        SHA-512:AF27266B77E292D19B557084DF7C710DF19B93F8EC7D36CB6316C6A0C12D4A88ACC1C0C1682F31DBEB12EF3BC3A3C42B36515F178D8DCB94815A37C39B830521
                                        Malicious:false
                                        Preview:...=/..8s<.~..>.QQV!6.>........;w....i:Q..........U...3.).Q.Z)4.W2U\.I.!;.hc....Q............;6.sGV....-....)`./$P....1......\_J..$..1.B..L.B.:.t@Y.`...Ks!.VU........6.%V...f..H..v.....r....AW.G..>.b.......$.."..R ...|9p.B...j...:qZ..1..9.......|:eN.HW....1....n.....7..T....P.....z..T..fFB.)..6......^..Z.....%y.Za..9......k.;.D{Q.DO.s.+.4.m......Gi...t H;.o\..0.O+.R....j1....j*F]J.S..$.c`..l_NJ...<f|.U.uj.Kv.....~..~:.......u.4=......r....`...7.....e.eU..P..Z...|..f...J..'tnv-.....l......6.=&..sr-S...S.....V.J....Gg...s.....9.r.-x..X............u...J...J.....`l.<.H}.YV.......7.4....@.../..*.T...m..t.a.]".T......'.....l6.&g.G.b..#.^D.....(.......5..@.........).~yIs..Yt<v.......ZAhR.V=.../%.e..E....w..X..g....]E.G.3.!@$u...A.W..`..dsa.A...x..0..{....c$9.L...\..,..,....9....@.....@u3..u4....e..k>...^7...>..?;qs.B.\|..F...O !..&X......x..U(.@._w...U!}..]....O.k.&..h.S...x0Ym.....-...Ea......5.cJ.mO)U.l..........k.)rn0..d.y.#.b.8...2.=N..BC.E..}..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10051
                                        Entropy (8bit):7.9806117155645735
                                        Encrypted:false
                                        SSDEEP:192:E0gvrmG0c5F8xm9duxpyimLa2xS6RRchMHUVV6O5nn5EB4pS:E1mGLF8gQ7mm2xS6RRjHUVcOZn2BkS
                                        MD5:DF85C9E9ACC689D0D6311191652214D3
                                        SHA1:B27A3D8E4492D49F6F506905FCBE75A4EF081E12
                                        SHA-256:D126B569B0E5DA05FAA0B02B61301D607DE1A3BB5A17E8148350401A5A5639FC
                                        SHA-512:CEB4AFBBF6D55F1C2E1ED67E0049C906743F5E49A6B4DA53287075DF18B8D2439CB6581C5B1F0100C762C63B42DC9B34C740FEC11B67DC89DD5EDF833F6E4303
                                        Malicious:false
                                        Preview:YZ..N..a..........}".G..M......_...tc...pP.t..|.c6.......2}....Cl.@....i..V....c...).\..].Q>\u..I.\D\..<.-VD;....,g...D.L..L7...9d..nE.\z......c..J>...3.w...p...L..US...s*y.]\.........^.n58.Z.Y.O.e.BY.e.);.j..65.....Ls...%.O.O..I.RJ..Y........._Vy,.s.....=8.H{......y..$.......*..V.:^oz.-D.B4S..Y.L..^.)p.._........}....^...*.L... ..B.9.ZeU..'el.T..0.2:..gF..Tn...& .. .Gq.w....^ah....2G!...@.j...F!...o.A....-.p..w...}K7.*F)'.9.Q`.df..k..u...Lc.s..M.V.c.I$.p.z..,...[.>Y..F7M..a..m..k.J.......y....c..m..#...G.[.8...9+[.f/...d.......3.{.w].R..k."..,8H:,S...F3R.@..ZwD.D5.xcy.. f.(.l..z...........{.~.m......zA..u.~d.a...Y..D...O.......<...~7Tb/>..W....yI...1.7.z.H,..q.f..oZ/.@..L.<........l..X@.~.T...0.R..4 Ji..G.(.q.Y.fA.I..v..R....4.'..JC..2.>...s.i....u.L5........o$..TL..86.Y_}.g.a....k^q..a..zN5..@.....().a...}.<..Q.k..d..,i?...JZ.A.Q..[.m!s-.H..#.%..-...Q.[..O_.%.=8.....+k....5.q.f..&...0.u..8.z{,....:.j..pbRA.$w..._..r).4#..?.W.e
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9612
                                        Entropy (8bit):7.982212400590249
                                        Encrypted:false
                                        SSDEEP:192:GNVYgorl6rymMcJDtL4QF2mzsPnmCl9Km0ijxbVY5/TGgJeqLVbpS:GNygcl6rymM2+QF2VLl9Km0ixb8Lleqe
                                        MD5:50E15BCFFB35E5EE7FAB1F1A637F0BBF
                                        SHA1:743BCC7962231CF8B0D20033B98BE2A8F04A48DE
                                        SHA-256:A2509DBBEF1E493FB51FBD3A04981E18C20CD26A17100C722806EF4FF1455F5B
                                        SHA-512:7EFE398D29413BC5D1CB417DE6C20020A38543D510EFEBD7A35910AC5EF58D4D018B3A86B7654016427A93A0BEE9D17C0B63A7F44F35F65ACB75FB4BD6023E3C
                                        Malicious:false
                                        Preview:3.^K.. ..-.c.....)..f.W......(L..i.,...D.$H...2\.*.nP@..t..!7..q..@....A{CE...".1...Z.....`_b7.}#4C..].K.,.>[.}..Q....w...).A...7.U.c}..U..2..r<-..(..".q..m.0..W.......v...7.S.y.._...o.....|..i;.k...X......6..2C.A..5..'.N....$...B$-7....F...\.....=.4..mL.$['Rb;FD.Y5.f..M..*"..P.B5........<..5..:....V........@i....I2...0v..c......M...GX..l*....j.Ls..(.y]9,.......L^p.@._m...s.&(...2..c%*T..#.....m.....X..X....9....F..Z.?&V..`....|.......W<fg.-..m...[D.V..q.:}..$.j..?..ts..-...........)8.....O....GA..M.E2...!..4.......T.<...]`...3..".%.7.~r9v..u.&v..9.%...Ka>s.3..J..vV.9...R......E..iUc......3......G..a...'t..(.I.@...#1.c.fIsNh.'...x...Z.....u.Xj`......=...y.J[...tJ.5}+.......d..]......t...0.#..j.]1.o..+.y/H.7Bi.q....mCb.L.j..jZ..|.N...u......G..}.rZT..%J/..S..U.R....bS...L...0.....GuY".z..y.2"i{....Y...#......&..%B....eK&...(B.%.!..s.....F$.S............d7...F{..O>....:.+v..G..$..X...5.l......}.?.................w...A..\-..L.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10043
                                        Entropy (8bit):7.980509080169044
                                        Encrypted:false
                                        SSDEEP:192:4uP1ZEPNBmSerBasnXZ/APj8CD7CGR/SigZEWqDGD7e8VpdpS:5Zda4ZA78CD7CGR1gozQp7S
                                        MD5:1CE5D45C5101E38E5C9495FA093D9309
                                        SHA1:1A059D2B194B8BB3C13DE0A0C5EABB7F3BF08863
                                        SHA-256:050260FBD5EB91C8258ABE1787FF4916DED4BF007DD74E37F54F57724194B891
                                        SHA-512:841A6B02B21F9F0724D8B4A45942BCB9D0C75BC38F4665F8D1F46042A4A6D103310F3D62221AB06C4133E1CAAA329860CB91EBDCB49A33A5132012CFCDBDF389
                                        Malicious:false
                                        Preview:cI...U.q.....iTX.....g.Gw....5[3._.=....*'..e..S.Z.8.{..E..R...m..+0....@......BwYR...fK...,.....K.?g.%...<.p...tx..YR.Y..X.2M...:..}.-).".G.8.....&k.|!.^Qq.:............9.n....F.tt..T...#...u...#.....d.yMW.B(.......Al..*......$G.....(.yv..r#....!..S+.:...%0..2..^..1.}j....h.4(..#...}..r!U.........#.....2L)..g=......i.]..BD...E.........i.\+..K....4.Jbz..1.J~Eh."~d.....^.t.....O'....R...p.(S......L.{r.w......H.n.....+..b.......~2..z.6...8...2...4*Nm>!......Z.i(.=,!.yy0...!.-..f...9.j.FR...7l....)u.C&%.....~X..K..]...V`.99[.V..n8x..hux..D.{......,D..m.H....|...\....6.V.....2.2.?..'.}.... .m9n..].....R.b.....T....q"`..=1T.Qv.&r..9.$.-.(.Y...2......u=?7u....../Q[b](.*.8...Lkd.<}s.!..H..R.jp?b.li.y..E.".H...q...1.|l.~..._.....w.Z......?...........V..)...u.z...b...B....5.);...$:.....E.!.F.9f.C.q\.S.._...rY...=d/.KP..7.!.+?.....bcE.....".q.'.Z..Bk_.D.y....`..@.^..1n....2J.............o...../.._'.F.3.M.3.ZF.:...}.,........a.W.`...3j.+>.BC.BF ,9.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:Dyalog APL version -52.-90
                                        Category:dropped
                                        Size (bytes):9617
                                        Entropy (8bit):7.981632668183062
                                        Encrypted:false
                                        SSDEEP:192:ROk6Ycwg2VRIE58CxcGyVXZZQ7tI1769bDr5/dVwtcCoXvpuiHK+pS:rtVahaGoI1WJ3bVwtcCES
                                        MD5:C765D78B787913B2246AC4D9EB9ED886
                                        SHA1:567A4402C48877CD3795D8E8BA9714B88392D58D
                                        SHA-256:4B09C14EC25BAE37102D29AC0978F7BF700004BC48AE8DFA47852F2EF848604C
                                        SHA-512:3FC7102D48074FDB84AAF0E6B942DDA63F21D8B8F49F5FA5F2657BE5338E9D2167EB840CB9DF19DD7C2C0D57D7FC26B68144B0A5E55BC7DAAA25DA5348D41D51
                                        Malicious:false
                                        Preview:...dc....1.\l....{...'I.v(.7/....|...9.."..M.G.....mJ....fx..+....ZT.O.HEY...rf.R?.Q...O.D.L..2......-$..N.n..T(.F.8!...$n..k.i.W..hh..%l....j_*:Z..O...TM....A...e.\...yV<.......a;.?.3.6Q.yn+...??....zp.....^.....i.v..}A..: .......w.&\....Jw.....X......H'4m.c..H.1A.H!.h.Q.98.].Rlc.4..D.6.l.h.zlu...*+.*...Z}..w.l.|o....V..]T.r. ......CNv.=,.,..&.r..+.t...$.=y.-".....B3.W..K.p...o...v.b...3^..>.2#.x...;.*......:.V/.-Z.._.e7..1......zK+t.0.7..d/.U.#.o..'.._.\..g}..1]r.....H.z..5#....Z.]N..l.B.......u,a.-J.....q...D@m]V.>W.>....1eb.S.=#..\..>L\.{...5B. .I....{.uxf....Mq..$>sLZ.39.8..$P.b.^..l..#(0..[.....4qW.,Z.II2..k.rT.7o.$....]kb....9...h..9..=.cp5..q..I....b.N6..3.>L)..1..... t..cA...-......D..F.P42}..$..yH...R.S.~..7..V..&m}....y.{...%....;....G6a.A......lZF..2.....G8{.DT.cx...X..B.?.3T....}...f.2.6.8.$..HBY.q.>..(.....R.D..p..9ef...(.r.uG.....qL.n.. =/6R 0.O.~.6e..Yc...gv.(.kff..%..ih+J.4.Y*.{.....5#......m.8XD..|..h5.+.Lw..?../j...yHG\....h.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):10386
                                        Entropy (8bit):7.980700039406962
                                        Encrypted:false
                                        SSDEEP:192:x0FiHRLuMWzmsx1+4nIjauybXgJCdEOoWP1ZdcXFzWWFv5tZjRbm4HSFR+pS:xAitfWzvxRIlSXgyj1jcVayHZjJGAS
                                        MD5:A996FBB62A4B9E9D253EE07451EACE01
                                        SHA1:B3EE8D6B304D507E26FD0CB7CF048DC2584F4DE3
                                        SHA-256:C82EA7143423BBAB9CC4DC2BAE40EF5CA508E750FC28E0953A63157E6B25F50A
                                        SHA-512:C82AB7C0D0D911AD7780483F1B1A40D45031A9CDD642238213F577AA8D91B040B669D734FE98A6FA16BAFE57233ACB381FD8791019344AE409885F2109765DA1
                                        Malicious:false
                                        Preview:.d4.......i.@/."3...;.v.w,..#..\.C..,...r.O..........~.5....".[l. .7...uG.9....J.:.".....u'.S.....^..u...t*..Z.....oz.....:.O.....p..|2.......7.G\X.>T.0.4...?F7x.../.0..=..?..Wf..n.....w#..;l....Z.r....|4.....z...ST.qV._)....<i..WZs......8.LX>.3m.......)(.AA8o...3.y.(.5w#.\f.4...6..xU.)$......f.I.......z..Z.{1.......O.l..~.2z?..?.'@...$.F"..)..a..<..du~.nm?h.~.;..)P.. .>..h......hR}.....k...N-?...........U..0.r.W.4.9.rQi..m..w.*....NH.3..'.W.......z......Wp..`D.......h..."...;..N..0R.GN..?Pu/..b.2.`.7..-.@.d.;.An4..u.....;....%.y$..z...:.......+&./.OL.}`..,e.T....vx.r...H.9.b..."..gxCQ.e.r...T.V0I....FYhe...X<i/.e4..Y......<K......7.%......fc:...d$...N.>6.HD...O^z....%.X....I..-.f.n)._..b...O....Y.....c...N..#.v..:h.~..}F..Q.FXN..v.....7.92.LK(.mm...a|..j.....!.G...>.....Wj<}..o........-iR-.....b...?.-.LE.j..zX..^.!m.`~........~v.G.[.0....^8;.Z./<.....e.z.j5^..O.....&$&....%....*.....O.M.J...6.=8...)....)U!..0...u....!B..+
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10959
                                        Entropy (8bit):7.984110751399085
                                        Encrypted:false
                                        SSDEEP:192:qXmfAu91VVLoqrAmH4cRNCuW1dg+KaPTSK5tGAC6v51WS06x4EbBXvFR2ituOQ2l:qv8TLoAAqN9Wg+KaPP1C6v5J0E4EbBNB
                                        MD5:E0257D58BE292841CDD61AD20661F053
                                        SHA1:A55EE7A797190DF5C3989D018D66D935B3269586
                                        SHA-256:CFC766A43FEC418982217FB126CCEAD3DAF0B0D509E8A7325F1809B25BDD629D
                                        SHA-512:EE6CBE1BBD6C9E9A4094B7130D699C681AC279BBF62B31DC84C004269A5C14EBA777417E2E1724185FE4F8E8EEEA7F774216D07919CDFF653E6AE17FCF7738E8
                                        Malicious:false
                                        Preview:jB..K.+h..17Bdx..5.;.Y..$.>......\]M.....w@@?vc.R...].M......}A}..1o......H.....*...?K...8..gj.u.....`\...N...X..^i.Ar..uWk{7...0...Cr.............Q..M.........k.u...;..$.'....... ...@.0.t....zI..}.w4G.P..*%...a...u#.[..Cu..j.....?.Q.Po..)h,.AI...).+.#..GS1:.....g..pX.....R.T=.w.l)!O:..N%.....1..Q.f.T.jF......g.....@='. .>x...M....C...x1.1h.. Zr..........y8p{.<[..$9....b.....s.K.1..U.x......."....j.:....r...n.-...Z.M.(....6...u..Y..D..&MY.......S:Sp..o.6.".(D..e....rLe.2...H.....z*Ve<..*.w.n.Du.;S2*...b..-..6.p..}....v.....^.)...R$0...(S.U.......0S..:...(.............*W......ax.9|.m...t...Yh....V#=..]......-....0..?s.....S........z.c.....t.d.F.....,./+.U......m.e6..Z.w.....=.A...`....Vn..I...$.3.bV.}.A..7,%.1..\.A...p.l.....dh.S.#8-a....&..&....a.t.?.!.o.^...-~..d|.EN....(.xH3..u^...N....?G...a.pz1.....p...d5.eb'=#.!..s....4m.v,.x...k..x.L.8...V...e.8.;.TA.G.t.Pjli.(Wr..+......5.\.....i........,._..gg...........rQ........
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10608
                                        Entropy (8bit):7.982330000332273
                                        Encrypted:false
                                        SSDEEP:192:HOf/nHITU1y0zzGqNAuxgaMFhhSFI09Ogn1E+o73qyuok30mwpS:HIHITU1y6NPIKl1EFad0S
                                        MD5:0693E6A33B04A84BE83DAC1D9F3DA169
                                        SHA1:67F26381E1F1501C2CE214CFD603992921184444
                                        SHA-256:89A836042A254E68D1D52A064A0B2B1D1A8584EAFC3F6EA382E6AA0C818B2F48
                                        SHA-512:E4F0417059D9338DBD5BE9D9C0748090F558A3217BEC1BD1B1DBF4CE5CE5EC0DE50340F651550CC796ADDE483CCD3884C7E2B62D016946CABADE1661DD63E91F
                                        Malicious:false
                                        Preview:....No..En..j?F#....#...OG..#.:.....`..".G$k.9e...."C`R.........x|U.|.K.G...tu.TL9f....b..r>+...<..Kp '.$....j.9....W.......bb+..'...Q~6....w...H..{.X..^..Er...x.,f.~.*.w...P...>.0..\...4....6.....,.U..n!..i/.'..22..GQ.b+.Xr`'&]'...f.` Q..........a'.J.o..Ls.^..>N'...^k>..k..yR!D'...\.4.ul..cL1?BYk..1....3..E/y.../...Z.Ou%c.?:.,...v.**.J.@;..#........v+Q...s..Y....%/.0........k$.s...4..c[.4{'.........7.....q..V.6.I.n...kl.Md...2.jbHcR.II..en..+x.....m...F6.?....\v..3.S..w$.._H....F...g<..2../P...W..m...K....^...r...`..].}.....,|....2j.g......UI,...Q.c......{p.~....z....'...<...Z.mF.C.m-..l.m...X$.1..=..A+.......%..M..,k...].....Oa].b<h.n$....O.......Cb..%.....J........."Z...-......Bs.?......O.P...G..&*.m...%7.<u.'V.5.:'1........J.p..$.M...w... .F..T](.J.k....,.Q...b.c.,.).>.D...E.......W.....4.....a.v.....|....u.w[y.O...Bu.....~....{SO.^,/.60.xi..L...!...XVeu..[.8.{.%.3d....S..3x(N.i..<..`..!..`....`....=......2.O.$E...oQI.q....M.=..~.r.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):15427
                                        Entropy (8bit):7.988291512120388
                                        Encrypted:false
                                        SSDEEP:384:rHbvocca4PYTsR56TFf6D+vT9ydS9Mx8fS5Ucsz3u+nS:TbvH4PYTiQxfM69Cs/z+9
                                        MD5:14CC29EEA4DE507CE229798050C59132
                                        SHA1:1D16340E4A0E90AB56F94B3A8E1E041B193C5043
                                        SHA-256:0020F46EC0012816A67264169529A1B08F8DD1279369D276E9EDDDD91B878BCC
                                        SHA-512:6C6A41972C670CCD279F88766E3492281B93690D9C7C1F7F0BA082F2D09933A2805B208F2FD2E6A57726AA5274A7058C1DE974EB2D3D3BCF439C4084AD579AED
                                        Malicious:false
                                        Preview:-.P-.B.$..Ot .|z.N.NI.BC...K....en.D.....?-(../.r.w.......7..<.N.n...4.80lO.d.{.....!..;.).t..H....yX.bZ..5.......A...F.3@.r.]YZU).....+.<.{j76.EB...i.T|yx.Kp:.W&lq.......+(K.M.kh...(...6..yM.v.B..eb...''..K8%.I.qz.RGF3Y.%.@{.@m..$.l.?..F9..7H8..:.....M]G...T.j4....rl...Q....w{..M.nira...1.O..F.W...jM>\~.p?..!v..A..TTcE.e.o{^..]*...GRQ..F....w.&._.2.$F!.vHu..._v.Gx8.*...c...r...k(U......W ..K.e...i...I2..:Ht...l..,.^.2.6$....7...3.}.\f8....9s.Ea!bt.A.V...^..d.Wu.u..+<...-.5..TY..T<.]..i.p4X..H.s.......H}..L..i....S.*.dK....PA.\7r.........L#...s..S8.M"f.$~.ES$(...g.k....!F.Q.F.;...D...S.0^5..."...Ln.ON..W.....Y.....a88..e.0..f..,...{^.6..V&FX..C.|.0...........*Y..w?.T..ae.h.......k.{..'|W.......b......i..1.&..4J....D.0%......9X.L.%.hO.3.2@V.^U..A..O....p].Z.!...B.z.g..p[.W..A.....N^$...2...Iw._.....O.58_>{.^i.o..!..>.....m.g..<....#].X..:....Yt.~<....,......Q.....f:.....ec......&....Lk...$...r...o...k.S.nfPZ...i...zW.P...........aI4p..y
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16409
                                        Entropy (8bit):7.988808135627651
                                        Encrypted:false
                                        SSDEEP:384:jzmSHLQgtmZhFEdVX052B0f7+ruMOMER9iqS:3XrTchFGxB0f7quMOMER9q
                                        MD5:C6C9626072841B8E40CBFB23B22541E0
                                        SHA1:0E065BDAD1E20ACD08994EAD8149C65C2684447D
                                        SHA-256:781754D21476FF8F4E462245807FBF4FB883BE7D5E0B67CE12D59B75D909C674
                                        SHA-512:1955416AF63D4DDF609C15F29FF5F6EA9916C930C86ED033FDF1729777834F80B64409C6DAAC41317249AB4C0E05F35E08CA08FE5B197AFB42338166A8E7539D
                                        Malicious:false
                                        Preview:..n..d.\..M.Y.dH........S.<.]....y@.f.\.n@....+...1.%...f5..e../+.f|...M..k..R.I.`..'...?&..XS..5.j..rZ.9F..z...F.9oK..;..u..t..^v.p...f......1..\;.y.8, h.QC .I..T...s...[.....+...P....;LP-.@.%.7..pXW....i2....<..8.1..8i.R-.1........n+..S.S.7 .Kl~M-...?.......I..X.)v......W....#O....f.H.a...j..uP.A..Gs=v.Ga...k..p.AGk..+...u.p...#.G.v.........#g.....V.....".'..V..........A7..........l.K[.z.".D.d.!B......=..e..q.:.2.8e.U..B.:Fb}..*...\..ACVvo.,...d.e8.i"1...z........]@0w.#.8..\..l..4Xu.T+.....WP>.....z.3.`...dN..m}3....'@........d....s.....U.w.qdmM7..zEGB..'..ty.=j.9...4|<....|..6q..;M..r...@-.f....AbF.z...4\..c..iG.sM._7.h...O.d.S..,..U...7..d..G..9....)...|..HpY..Pr..{X8=..u...Q.Wi.pn{.s.2d..*F_.f.....Fy!.W.+._.[...Ge{..xcod.."...$o.....9......40*....=....DH..x.W.p.=..P..o...]..6....Z;S..3...QF..G*f.{...`)B...L....l5...*f^.......A..5.......;..].t.......ft..{2~._"..f.6...:.&.;..D..:?............?..A_!.H....f......86..0..Mc}.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10043
                                        Entropy (8bit):7.984059913683855
                                        Encrypted:false
                                        SSDEEP:192:+mRzjTa7OR4jeVKL8JC2KqT0HHsNOnDhbvHxLS844/PcH0eF8csLizSpS:+m4OR41wKg0HHgKbpLS8uHXF852zSS
                                        MD5:7654D1FEA72093AD5674F04A74EA98AD
                                        SHA1:E589595A6772F2A9002DF583F08E25922769F7E2
                                        SHA-256:586A4F4986A304F381384A1DB0AAE40D7878538662212C6AAD184B1EAFDC91E3
                                        SHA-512:89C0F09BF7A129FAF7B340FB7974519524808851C0286667D695A79F83AE0F3D0F0CD1BCD8646724B7CFCED45F5D82A0BD6E7F985380C23A353C749F0912F5A1
                                        Malicious:false
                                        Preview:.W1......b..@....*.C..=...b[v..?...$A..-..w...0..b.M.(}............1..g..p..6.6C:)<z4...}..lv.....`...GR..7H.Q............b.....W@....e...:.....X....6QBy...y..{../..vG._.k............l..n>5u....B..f....`l.U.W.x4.6.jN... .(.G..d....b.p.p.B....=.\J}....[.f...B.).y.o..{.?...p....&...@u.w.....,.....L......`...S].AMj.W...F....[.@..^.......:z8y7v...^.Ne43.Bijz8V......D.#.....kA.2"....+r3..?Dz..gN.:....qL..b.j4..2.o.8(%.V......bTp..X_.Q.m\Zy.....r....X!P.C.......}..@.........Z%E.>...........N....t...U.`..R.............K...X...rvj.zs.c.(.EZS....'.ct7.Q....mt....rE3.'e`...k....`9G<v.N.4.Y!..g.3.}.fK..3.L,|[t=.N.5'..h.c..]:e....q...B.a..r....5.#.....t~6...x...n:&..b.Pv%.5..fR^.m.19f.:.(....Z....f[...x..P....s.>3..19..&.#...vk.e...A.l=y..m...)........".].xP.i.+.!W...p..h.0..fc..:].>!..........}......)'.hu..'...9..y8..*x.Oc..-...O....d....F.x....$...a.....J.c&UO..#..+.$:l.$D..........K...K....X...PO...Cw..V...^9..d ..n.3.6...b...._.-8.....O[_:pA..f_.F
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10048
                                        Entropy (8bit):7.9807474856318965
                                        Encrypted:false
                                        SSDEEP:192:dO6kbiv5oJX6Z44sgYv1raH6kbXr6azG3C10J3wawbyIlYTYvqP1Y6bLHVFyHapS:dO6kbivsZ5gYv1EV76azG3dwawW0EYSk
                                        MD5:53469E1888F14347FC5209FE5628CFF9
                                        SHA1:BD991DE7598AC3A8E312ED3F35883860E4248A8B
                                        SHA-256:850A94D6ADD3191E24E3DAB7D1C229ADD53291327FF3D97D3901F91A63926391
                                        SHA-512:0D5A258838862EA096C6CEA0B456CF83E41CFD37972CF55AC44CC0F723970968530402601E89256DF12E11411D0A95DB052D86602A54AE35544076F5000E8D8B
                                        Malicious:false
                                        Preview:A...j.^.p...P...H....?..8...0D....o.{oY.,:z.2nQ...cC.p.E...+....nl.T).b..S...{V......u!+...W....{.^M.n|Y... .K..].~.aB....T..M.2.....@...%... ..l....(q+.d...S.p.../y~.M.y.. ...C.f.......`v..E`P....\....m...i.....8uq3Uj.f.C.w.BM....E.Jt.Q8.~..2.S3....O(K..!C..TR.y.b.p................+.x.U...0..0...&......S.;.._.%UF.j?j..O.....?.8........1..X7...jF.D.........p.w.)...^..fI.g]....UK...~....(...j..1...4.h...Y.x:...O.d...Z.......R.&4 .oE....oI...K\...NQ...Ny}.73]ep.6..FV..HH4J...X.../.7.yx8..T.#....+.6...4|.."5h]~.....;r..@...x.9....3.?.}....}oE..B...C]<..._'k....P..rZ..]......dY..I../N.DK..T9.,J.-c.<....uLusr..\....X?h..#........?..].5...g...pT0.yy...n.......s...<...s.i...AA...IlP..A....C.T.z.$..:L..o.h..*~e.>Z...w.x..a..[ .6.0...E.k....Y1\.DjAU1..;....^#.`..d..E...s...g+Io....`.c.~Jn...K........,...q.D.....R}.....{.Q.=......`tm.,.{{.......w'..@..0.:.;`.G......].....Iaw..'O....0%...%X...4..}B.Al....Do.....E.!...9...hRx|-x.HMz.f...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12394
                                        Entropy (8bit):7.984909568059527
                                        Encrypted:false
                                        SSDEEP:192:eb8Ln0VIVnfQlTEJ8o4O9IMlsI301Rmfk/1teAzyz9I/Z2BHLMYKRktBbdtM46XT:+8Lkgfdh/flscewfz9PFK+t1M46XWLS
                                        MD5:77F037149C12CEBACC7A9C217A28A478
                                        SHA1:4684A187FC0E2899DC11B04BC8D39CADDDD344A7
                                        SHA-256:407048E575DF771AA17F6770A8AB82444F27855ECFF89FD6B31F518AF948FB5D
                                        SHA-512:261E66A38A6181882DEF013ACD80B5A5E6D9AEC7E2CF03732CBE5F6923973AC677474CCF1CDF54BB62C826B50389EE18B4A24A0C228805ED50D870118BE6A248
                                        Malicious:false
                                        Preview:)...|<igh.lL.."+`...=.i.D..._%...,..>.o..X.......y....+.e...2..........>:..&..O..@9VO[?.|+...H.D...]....S...m.0.:0..Z..7.,P..}.c.+}]..#..b.D+$[|,Q w.7M.u1..X..^.....T...W.......Z....R5I...6|;.$yL..JL.0q.q..~...K8....E..iO.m......r.!.J6..P.)..t(..+....6Y..Z.Gc..C6._6.P....e...y......Nf..*.R.......F-. .H.Nl.kUn.G.Y...:......53..Y...........Y............W.....W..Cg.b<{2.]ZS.5}. .}r..V....'A...i..cB........F....>T....`.32e8.w.....,7+...cL...!.6<.......%O.nw...*.^..>H....7.....e.u..20uOC....5lJ... .UT..../Ol.4|.Ozl.&......W-.m....(...h....$r....%qa.[.2...NwX..#...Z..>.%.az.ZFv.w..L.$mrd.....']b.7Q...rC..`.o.6'1F..7.@.4;N@..m..\./.\..\...p....P..-..<P$.....!zwM...NY..?d.4.u![.4;......$....g.G...#.9....:].vL.$..d..H...U.zY[@.q*.'..M.h....l*?..p...N4SL...#\...v.~(...+z0...@a.. 9....y..*..b...o.Eo`.m.l7..%)w.V.D......G_NX..VPW........$....F...g........R.R..Jn.V..v..L.......%...k=9nJ.D....g1.....|t.P.&.....+r5..w.w..>...{{.....*S......^.2..:S....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):126499
                                        Entropy (8bit):7.998426497064991
                                        Encrypted:true
                                        SSDEEP:3072:6Dyj1LHG+xdLwzc4is/7iKaMdg8TXsJ8tbom+7tGSS6w:pj1CLh7tMj8tTwQew
                                        MD5:F14E4652B5F5915B6A51DA2338EE2AB0
                                        SHA1:460D22BF4270F5711AB30C77C7D7E823554CE1CD
                                        SHA-256:536B30AA15A85967A60B770180207758FF7ADA5CEC8FF5C46A9D9B9A1268DE88
                                        SHA-512:3C619F92E7316E974B0012C9E1496417D7CADB7D73CA86C3AB44F9894DA5FD601734AB0BEBFCBBD28DB038EB6EE4174E23B59A52BBA4C5CF00C9BCC7FB15EF86
                                        Malicious:true
                                        Preview:..)..`v&.4..{......\w...x.....y..T..|r6r....JY...=...7K.m...a.X....g~......K.4p#.<..l....s.d.6..c..l.X..S:.w...o.be.........x.SQzz...Vbu8.@..|..3...d`._\=..i.....]..fx-...~.f9)9%..Vx^.6.V...r.n...?\.....m[.i,.....f...v{..Y...&,:s.o..Z..[..c...c..~=H.v.....1.p.;tWm...T...3.cQ....O,..%.Q...a..Q...x.?L......>.+`.-...g.7y.j...m..>[[.3.....J-.m-W.$...\.....@.x...7.X.7.......M.>%F.C....k.A...p.p....`...>o...q......vB/H...^%.D.'^.4.5....>.f.L..z\O..i..n.^..C...v....2..r..^.R>.)._.>..5..`6.r7_}T....E.c....').....-.."..}o.Swm.....m0.d......e..D..DF.`f.j..... ........*....7.....e.OL.h.*..!.MX.x.%F..-.w. ..S-S..R.....yD..T].?..v.!~+..S..=g-'.W..*...U=f..;74%.*..U[R`...&.3....(=...ETTl...qu..H...V..m}..d......6J.....)_.IV....'...@...O./...z.W2_.;.l...h.....3.4.#..I.}.%...|...Q..$x..W....z).x^f....RX+.t...d.Zz..3E"..\L..d..E.|..Z.Y.`...p.....g.=DX....FE.|8..i...../....V......'..|....K....H..^..#1..N....W'.X....=..L...9.h.:..]+w...tUB...l..H...._...O.Q..r...8...*3
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Secret Key
                                        Category:dropped
                                        Size (bytes):9636
                                        Entropy (8bit):7.981965265498713
                                        Encrypted:false
                                        SSDEEP:192:CIDxDSvbrO25ACq040snIanXtJ60BO14nuJBF5PWMMNyIg21pS:T2P59q0CI89JJB92y7zS
                                        MD5:9AA40B7ABD1D61179FBAF97DC7461E24
                                        SHA1:646A1EAAD40E8724A3782278A4011A58B94F6F86
                                        SHA-256:350AEFFDA7F49E437F1B52B4CC03D1AB2B44CF88F5B1C403033CBA3BBFB5CA8D
                                        SHA-512:732FB6BB043611B6BEE084F5E1F7CF1A8D0F26CF31729A6778ADE4A9F1BE5EAE6D97D900807007517C953136E01C226CBDDD17AD9CDC2D23AC85FEC805F71ADD
                                        Malicious:false
                                        Preview:.Z1..v.'.(..<X.-.i.0.e{M...l!6m_...l.ai..........I....G9.E%.-bo.?D...1.76^.*..+#B!.$...E..#.......F].......x......f.....W.@...x..I.G..U....v.....[.c...V..%Q.p/.....].X.k...R.X.r.x.Z}.".|f..).qBPX.~..T......? ..hV.\..m.:.Yq...k.;..../._1.k.c..*.ol....$....".......?....*...i3k...O..GoN...x.XL+HA......=z.Cc....i..".xH)....:b.c..0....ns.I.!.49e.....n.P.........W...=]....Y.b7.W~v...$.im....U..Ash.Oj7U.r.)...]..../.K[`b...h.q...2..w`.P.....>.I.{.g..?.ZR'mk...2...|...CI..T....i(.H........"@.rx....}...?.(..[e...{.C....m...j.Y....9..E.N+.p.-b..i... .OF$c..`.U.........W.d.p...[..x.2.....J7..:#y...H..HX3.I._....?.Z..?.|.....|J7.P.G.a..P.a.OL...<.)._X.9.#Zz..7]....q..z.I.+.fY|...3'....h.X...1..a...m!..s...6.w..n.ah.<.Z.....W.......XL...+y..H.Y..K .!...*....5..Y....U[>......O.....Q.KP.\.J.:C.G....A~....]/... f.2.z./3..OPwS...p97....\..%....q.nn#...S..H..O..38..z....-....).....Y......f.z.fkd5.f.)f.4|..R.w.U......I.]<.. ..^O.x.:N./......*B......bC......l1j.7
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:COM executable for DOS
                                        Category:dropped
                                        Size (bytes):39045
                                        Entropy (8bit):7.994830561099409
                                        Encrypted:true
                                        SSDEEP:768:IwOJGxdql/ClwRzptDTMLplXL9np3SEYIahVevtY52DqlONzZWdYS1RFesG:dVi6QL0HL9nNrYIQWttDAMlW/o
                                        MD5:DB785A819101469E18E2E9BAEF4FE23C
                                        SHA1:A36615C922C20AA38B0145A598D3BD1CDE25DFD2
                                        SHA-256:59428D9FB8C982B0A98D3A917589DA2875848BFDF46771654FCB823D4B31CB4E
                                        SHA-512:BE6ED01EEDD4D2708E1E92DAD769C43DC5937E9BAE4D2E35936AFC7328F3B532EFEC2B5D52CC83613C1C4130D5A2321E81FD8C00EB83B67FA28CBB16A9DA2F52
                                        Malicious:true
                                        Preview:..o..)...fW...%..XU.D]_...7O!........PQ.h|N...xX....P..Q....#.D.....S@C=..u"k!~..o..;?.}q.mKbV..m,L...6...eDo#...8.5.J..e...*R.........{...Ta.K;*ozE....w....Z....w..I..4sY{...g..g.fc.....d.?Sa.l.....o.+.]j}j....`y....7+.<&.&2..C.Q..y...-.IA..3.s.5L.T!......;..i..G.:).....g..JS.$..;....dK......R.cm...T2..4.~Qb./....w\.......r..V...Q6.t..&]1.1,ou......s,.5^..|)*Y.j/.t9.i..Q.].B...k.6..q.Wt.a..{,yE.....n.;.5.u..`....V..1.....&L.f.H...F..........,..V..D.GpgU...5tM..BL...........i.i..^.i.v1.$.R...Du.U..4Sf.d`2[....S..%...-.<.a......Y.'.j..:....../.m.|.?z.0.....ES_.G...|.vrH.i....:!+...].C.....3.4...?7y..)j...I.CS.Y1..".R0R1..%.........HU...~.C..(m9~]D.[ZSvg..IX8.(.|...<7.*.|.bST......|.{......D.........D....rC..._...Nq..a..l....@Ml....%I;x..@.pj...NM.CE..|..z.......9.j.J.....\....Gd6p~S.!. @].{.G[x.T........NsK.t.>4..dm..wFxJ..7M].{1q..A....Lr.....-.F....2.%dA{o..>.o..4..A..z..V......,.T.... .Tk..rP.Gk]...?.'.a..2.C!...5..],Y...~......*.g.,..rP.'.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9658
                                        Entropy (8bit):7.98144693691559
                                        Encrypted:false
                                        SSDEEP:192:xawldBkqf9Vb5cpP3m0lIt8BpdxOV7hIRJHcGVSK3AcVhhaSUGS28/HbpS:EQBkK55KP5lnb4lYccJA4xy/dS
                                        MD5:5C8E9AC8910C9E9AE754F8C497AAF797
                                        SHA1:56BDCA0EC0D3A2A3F2ED2205A1E0D02D1B530B3A
                                        SHA-256:8FC9D2C33C291A5B3556B696426577D8437F64407B6695D3B1E507C9E52C0AE0
                                        SHA-512:BC88B5627D09246711F44D850933AE42B73D06273A85356356B5E09625D3D376C2D201B2FAFAE75A846896D422F2C1A9C506657C56397E3E400DCC081F4866C9
                                        Malicious:false
                                        Preview:a...2..i$.<o.....*K.......JzM......T:...+.$.4)...n.hn..C..^...{.nS.^T...W.9.Kr.....{..lM._...i4kr|..v.L%,....HI.....r.L.9O.G.,.....5..........wD....2.2....W..FI..:.AN.OrI..O..R._.,x u...Y.).l.I..{-...w.?......!.,.+JE*.@......k..Q.a#.WI.I...6...5%.. ..... .<?....1.j..d\..y...{../..tV.M.=u.\.*..V\AX.<b/.d.8]sPV...45n...UT.M..\..s.......1.s...a......$.........B.....j..J.4...L...FE.....P..y.C.E....=S..J.....Co-..iC.(.].S...t.....Rp....B..|....C..S..6..Y...KQ=C.8.$..h...........k|...4..G.34.....R....W...h."..o..4........o.j...D..Ge.J.....G..Sc..z......7.q..D...{.b.o.Ui.:M..5q...U...,..a..4QMk!..|...sk..7%..7...*..?.4f.o...l.X..|x.,0%.[.0..4L.)hb...\.......Fy.....B..W...! ...q..5]P.v..(.%...aMl....t.a8..0. 6A.[$...,..Cb/..zy.~..kg...3.+jy..4..]...jK!.3m.H4...=0.0....y....P.;..:,.+M....-?. .b...w.+.(.}..z.>.....mK.Co*.....W.f.,......H2S......#..*....J^Uc9....L`..,%a..O.>$......!."|.=n..../.?R....Lg..E~C._..-.:7.-q.&..@W..?,...r......G
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):11546
                                        Entropy (8bit):7.984863290562777
                                        Encrypted:false
                                        SSDEEP:192:I0IbkOI/t2G3vAUxFIDOhbqED9IBhzTDydk9KXxwKsBDZGMUsOq16tpS:Uhmnv/0DwtSBh7JK+eMeq+S
                                        MD5:D06F248AB5BF18D371B3A852614A0D1E
                                        SHA1:5109EAEC0E6C98C862D6B6662BFBEA7A688F62AB
                                        SHA-256:389582C78AAAE1937E21F45C8E39C715554C96F24EC9B0F808644E4BDCA35CE9
                                        SHA-512:E33D7EDCD8F3117D13C848AE4782E025163C0D0A2286D2DF4A5E02845F7625E97AC3CAF6B63D771768421F215129F8CF507ACB3B688C61B55D9068236BCF156B
                                        Malicious:false
                                        Preview:.....t..3...8...%..dV#..&.E..`> .n??...eN.{.....#.......4V..2.........X....Qb_u'..9...<v.)X.I.P..EK.3z{*.{..w-.,...Q....mxJ........V. .7V.@.F....w..........l..|-....=g"...g5....2k....M....4.k....f..%nl...Xk..z./..:..+9.,Q.U............@(<...1........(..Q.*.)...YZ.=..(..W...*.......'bI.%..)..~..........mJ.-.<....6IWL.s........K...W"m.....:.d.\.E..?......j.w.....@.....A..;O..Ss..v....[.)W..Y5......#$.@sj>?..#.........V%.....&.........X..Z....5l.N...z...Io.K@..Isu............k.n..&+..;.a.WPw....j.uS/...Bx..W/p..)..&g..#.......<\.4.%..X...-M.P!....U....4...W.7@H.9D...".P.O?.v.|..-..\.i...z..].@)...7....;A..aF......*..)..b...g.;Ob.G.5..C.t.~aFI.d]..<....y.P#..............OV..h..J........x. .}vc.w"*.&..ns,i....S..".o.|..s..p}.....PMF...|H.P.C]j...?.....8wO.=U..?.....#<....). .....3...l.8l=44@.e...r.O..<1AYI.6....=.t...}.s.l.k....7+}X...HWt&3...1{.....L....`'+.....U.A.p..(o9....t..)..r.=$.......m#.0./..o.\..p...(.u...y....R..h...c..[K
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:SysEx File -
                                        Category:dropped
                                        Size (bytes):8349
                                        Entropy (8bit):7.977446686921624
                                        Encrypted:false
                                        SSDEEP:192:pwLHsWZhg5vQM6i1rMj1ZAHx5658AH2zTf98Z7RMN7mGOiRewhpS:+H5Wt6iS1ZAHL658AW1GR5GPS
                                        MD5:5342F8F92C1CC94B6180B01E05C739C0
                                        SHA1:67EF072C8BAD0F80209A37E690EAD58F513282D9
                                        SHA-256:B016CA2D6791B92AA1D331F8796970AB9CD5BBDDB4DFFF1523F766CF365A8D17
                                        SHA-512:668A3005095EF8C3DCFF70B23BC1E031FEBDAFBDEDFC2C2DD09E92ADE6AEF6EDDC694795E698E1B6A9027502A261055F2DB0223996EF67CE0CB0255208A7A676
                                        Malicious:false
                                        Preview:.n..r..S.....(.3..` .O4....J..!.....:k..U..NP.T.w.;...)..h...C-...b K.....-T^7.7L.....M....R..}.sta..g....=.k..#;H....._..i.x....^m.o3........C^.......3.../V..<.L.Q...N...{..Ot...GxU,...x.....U.C.....{X9....H...*......Y.....Ai?I..[....|U.f+..O..&l.....?BKH.rMH..n...uy..k{'[..`..T...>.....xd....NyD.n...`3..3J....k...v.'L!..V.b.urUY.o.....p.#3......(....J.zP.u..5e........O._.x........v........KBbUy=.........7j..#.e#.X.o4...B.......X$%.W+$*\...DD3m8P......e...&e....w\~i`.&..0...@lC....#V...=.....Nm..oy..K.......g.r....D|P..;..<..}..4u@....:....B.m......h..i.-#?..;[.....<C.H.`....K.<].."..{.$.D.f7>^.E..=-?jj.[.5<.+.......v..0..m.;%..E..u.......Y{.*.D_(.r@.c.......sC.`.`Q....e....~lu.....A..n./...s,/M.D...2..\..A.. 0.E.<.....6+Y..S?..*r..h.1.A....H....p.n.i.2.6....g..<U.....{...`nY...y..H..@.g...F.H...*.S......l.bFp]...p..b..P.:;..#K....Q.2.......#c.A..O..[....-.?.p"..,oo..?..../..}..`u.1]a..aA8..Wv........`."...M.....~,....D%...h$wP...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9633
                                        Entropy (8bit):7.979154843000758
                                        Encrypted:false
                                        SSDEEP:192:1ycNg/rHIihgRzGL/ZXIRDnGH9MWXUAyubx1EfXg2bogqa80jfpS:1buHeu/ZXIZg9MObeHbH5BS
                                        MD5:FA97F64E06596A156ECF29F3112AA6FD
                                        SHA1:EB451EBE4B9D0401161F08D9D7568A3BABE5A6E8
                                        SHA-256:9166EFA42DD7C7E7DE66ED07E8F1B1EBDCCED1F9431B95C9CE3E99199D0FA3A3
                                        SHA-512:CF7C7BD1F75485C6B67907A19A689C71185752B8344983EDE2C7DA5A2E8948C690E0BB1F76EDEE4A06B172F3594B77F7796B49E2A57A0911AF4741EC07E6A2D7
                                        Malicious:false
                                        Preview:.5.?...D.m,.*.#p"~...m.Uv...u.+-.5...<.*..<.....>...i..c...........Av....pL..M....8.v1-..U~..L.g......b...f}Z".@.y.J.Y.M.4R.V*..DZ..9W.-iI....iY=...D..]..._..{.. .u....l...Fz ..Y...`..[*...+...D8=.:4@...U..s`..f.......B?...F.a.....A.a..2HPqdI...G.I..M*IR....,"....{.#...3..0..2...2?.gA..ol'.4.}RK.y...P$...{.....j.....Rhu...Y...`....M...F.\.....L..N.Q...<..dc.........gEb.0.eWF.....%..Y...,k.{.I.g;....g.lq.c.2%..8.,.h.f..V... gm....|!..y.h.z.?..!!..((!z.......[.o.TE&.j..iV...H.F2.3.b....^Q1>..t=....8....Je.....\..=.&fM.....y...p@...+y../.K....T..e....O...moQ...i6.....A.cPF.&..>}X..J4.._...`.(W..L+dR...u.tF.Do.........K..A:..l....C1..........M...v....k<..].....P..>..<.......E..P..=..w....@..9......<..D...|.....r.....j..$w..`..K..7.Q..TIG..6.=M!.=. ..3A7.K...$pV.yN.t...TbFQ.`..w............q.T.....L..N....aW..^C.~......Z.sZ..@a.i.k97.......{.c$[?-S...CV.b.o.* X..|...fL..!...`..... .?b6.....}.w.j....{....W.X.-N.zk.[...:.#...q.(..E.u/M.@H..v.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10048
                                        Entropy (8bit):7.980945780038824
                                        Encrypted:false
                                        SSDEEP:192:Hn2BT6kHvOFLY9IWwF74EjKLqXIyG9fimIwyWevFLh8bFSpS:H2B2wA4p4zs+IyG9fimIwyzFLhPS
                                        MD5:1FE2E36E28ABCB0B2E47A2A9B4E09FEE
                                        SHA1:376ED9F3BC9BE53415694C19934394EE61F4DF1A
                                        SHA-256:060C0D32CABBBDECB87749D764E8C2CCC8667991CB3CCDD2E698D2845FD25E46
                                        SHA-512:D632CE1D8868E830F457F77ACBA100D14805DCBB1018DAD95AC4DBD4A4FA3992874836F57F49E99B03BDFF6E4642997285A84559D455C4F758E66A0630305BA3
                                        Malicious:false
                                        Preview:e..i=HN.^...M.f4..k+..3...9.b.o!..BD..BFz.!......\~..D...[.D>...R......8.4CY..$$.J..].....r.....m.Tc..D....r...V..e}..*Gu....-....@.)....0.D.Z:...IM.D.@&..8~.?.|...U...~..xv\;.%7..:......=..(.4N.......(..M.....~.J.yo;.9..=.5.a...GQ.j...0..0".Ed..Y.t.K.X..+..q..j.c...S.c.m|.......zpAHq...R.....YJ..,8.r..y...<xE[..AY.......@..-..p.jjc`u..\.q.y..,"P....R.).7U@....*...e....mzB.).HH..HyL..:E....vG..O..m...".<.u>..1f...Y...6...i%..S.\I..d.P..E.4....9.}. 7. ...eL... .{....q|.U..P..)Q...8+..8.I.F.b....h.=L.>...]R..<Y/42?.X.....!. .r[.V...g...*......K..!.N..a9k._........Z.~*.I.b.9@Zg.;.%.....d.......e..ngk.l....Dn..P.....K. ........c.......m)w...`.................1..b..SS2..p..jE.....l...CT./.....NX....k.=.N4...W.\~<is.sg$.'f>.....E......l\...F.....67.LJ..H5.nI...Ep]6..U.H9a....9..yIe...........z.[.I.8Gk...l.F..,....2k.n......;.?8....|%..8@..E"8.......x.`uG.g....i.a....Zj.(E.....;n!%..;i....9.1h-.0[..G> .uU. .'.....8..f...........
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):13043
                                        Entropy (8bit):7.984973828539808
                                        Encrypted:false
                                        SSDEEP:384:8PT3T7MVndISIILn5xfb9uqIGBY89OJnS:GTD70yBILPbUqW8c4
                                        MD5:BCB7B7D5928D2A6C6C354B16CFB74756
                                        SHA1:D86C012D400E0DA3FEA10FACD4ED1AEBCF3B2A37
                                        SHA-256:B1261E6FE087B6B703365509989791D207C4D73CE366887B927D1232CC36CB47
                                        SHA-512:670BAB59D8780361B0D13BBBF40FA4B6A27667DB0F1AEB55E79D13B84624B513037F985874AD934FC4FFFF36CC01636DDFF10A1AAE7311B92A4DC555FAAFDF66
                                        Malicious:false
                                        Preview:....d0).QK..F<.H..A.i.S..>...[.!.m^.....0.C.....DQO...&.abn..>>.A...vs.....5.]wI....F.N..M>.gh;.oRbM..."..;8.4X'R.I._gR...W.8Sc....xu..6.l..F....X...I|OLrA.....rOy..*s..ucv.e;_.S<`.{../.j.G^...v.&..T..1....}...Xw3.`ZKn..I.....]..3...........Lkp..o/...hb.jr...j.f.,..%fs..........z.t...~...1.;.O......icx?s....*.!.3Ht.Gr..Q....L....<.O..'....H.y.`h.......2.....S6.4.....UQ5..........2p..t.e..Mk.....V.@l....}x..\....>=...].....j...|..W..7m..&....?...l.R.n.~.RS.../-EI3..\.d.$oZ7]........D V...gZ{iD(.d*}..B...<!&Q..).....T|w...m....D..v.|.lt..b.78V.*.....s.I. ...?9.<E..@.p..xU...`...r.r..:..fL.3...~..tz.91.].m..{........mvh......@.|.............=......D.\d.p..xcI.R,..1..W$.._...2..Ur..+4.D=..S... .......e..j;.f7....{4....|......`.K|.1.p.g%u..-.k.7.:..A).i.k+...t{..f..`.o.E/."...PQ.3.Fk..^..b.-....dB{...4.P......M.;..m..-6.../...,]L.Qk.r......6..M..:..S...&E..kS...>.c.,ex..._.CT.o....rpbf.e.y.....s. UB..S...,......J(..E.....N6.....~...:...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9578
                                        Entropy (8bit):7.979413305364808
                                        Encrypted:false
                                        SSDEEP:192:wI2HJlwDX5qUeYp1BbKul/2vDrJ6G2edQ4zo+4gdGbf2wWD/pS:CpYJTeYp1B1levHJ6G+E34ggH4hS
                                        MD5:212028AD406E4B8071F5791CFEB9E603
                                        SHA1:34A8109E0C8FDB34E581C2E0209A86F323C59956
                                        SHA-256:329C6C262533E2352170D8BC1098D7B69FBC5AE66602E3E7C976C3C4522B62E3
                                        SHA-512:B833737A89C97683D6C870A214115F4CB395CD6FFF653110C5AE5892E5DCD3C5512BA9AA7F4EA7283F80A2420F3CF677508EAF1DCB30DFCD432CC675B316F813
                                        Malicious:false
                                        Preview:..\.....9..x4.f.~.[.....i."..<yS.-.P.p...[.....%....mt...nl...!y..D..0.......D..9...]RT..Zv.5.B.Mebw.....r.N........wi.C..!Y..:gs..`o=Hd;.T.z...}A6..5.{a.......B....2t~.(. ..|.6.qsp..@.$n*..x=.../..d.....]k....tm.(..R..-......r....0W.......]<......3..&_qP?..7.Njg....,}>Ui..."...4..?2..HXQ.o...D..5..EL...`...O,..F..3..0!C.l.O..{..[RV....E...n."Cku.h...A.u=......e.=6.........AN..v.{W.o.J.$0C.RDVJ.(,M..v....ps-*.%......O...F.N....".:.W.$...k..V8....Y..B.%`.!....%.#..Z.w.../.K.{...W...m.rF....`.o.f..9=.>.%])r..A..U.`#..=..<.0@.].5 .._..C......I.;.......f.;..=......vU../%..N..[...u.' .......e%gB.N..z...C..S..LD.5J.V!..t.t..{.7U..........w....."=.......c.3*..D......{.s...G.]D....W....F.D.T..vtU....JD.!.F.;...h[.WZy.|.SZ..*!8.5....m..Sn...Uy....H..m.Bt...p=.x$...0.[P....y..ETpR.S.Z.%...hx.....o..3.2g*!.Z:.......X.f.....H..y..$....!.|..w...=.Cv..q.S8>.l..Z.2..8/...%...<.....s.i.....@....Wd....@.z._Ea\.AH.9....L..B.qs.....>.a.t\X..z].o
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):17208
                                        Entropy (8bit):7.990866015991532
                                        Encrypted:true
                                        SSDEEP:384:j60MBYeYktVzaoC2r1mDO6BYOXlp7sPjxyOe60LunNVspTmAEiS:PrOux2r1mDO6qOXlkgOWCbszEh
                                        MD5:E3522CFBE5C266F5B83F4181ACCA8D2F
                                        SHA1:D397EC32D4FE4DB99BF5E9D97EEE2BDD65B30AE8
                                        SHA-256:EEA03D541EB8F06AB10AE73648F8D928E76724C5953691E0F6A5DA3622FFF9AC
                                        SHA-512:B3586AB34057125E5BB3B25033378EAC46F49EAA128F5177E0F7A3EE28B015A361358B1B428073782709F302EAE66047B568BC2E865DE34627620B14AFCCA89C
                                        Malicious:true
                                        Preview:...<u.s.......{.k..\r.S..}B..;..A..!{..9...:...0..=m.L..'..<.......w...p.....~.O....9...yW..(.J.Ln]>....f...>YN...5."|.`z...A2g8...S.H:..l........|."m.U...L,..s.uv&(......`...6.._x5...W!Vj.Vb.a.2..D....%..M6X=c.....c.$i.<. ...o.i..p......./[..W.9*.6.....h....a.....Z...o.....T.....s...Y.D../P.T.@j0..>.SE.c,..E..5pKQ.)...V..TW....7=.......z....{R.....\........Z....^..qg:...'t.;..g.n;..wV..q1f...S.0.0..Q...A..$..<n..L....L._..E).5E"..\.....x... &aOy.....~."...S.).D@.....!'L..(..[.fQ.'...{1_.....Kw.....].llL...^.e.m{K....>... .k.3e,....m....M..]..2.mbvV./X......Z.z3.<...Y/j....?.....?.$f.S......vsr.."W.n.......,....>.._!.(.j.@.d..&........`...%...jf...o.MM...N.e..4h=.Z#w.edo....T:..K...3~c.......&.K..V...TP.&..x@....7)g./..7.L7...n".....(.=p..9o\..Fh.'k....U..I...2...Mpo9.....u.......b...[?....$.u.4......rQ.P..Y<..#C......M#,,..!.m..Q.L/W6r......U[1K.K..0N.\..To../@.j.C.~2%L...(......T..g...L.!..)Qp........<...u.........:..a'h.......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):12424
                                        Entropy (8bit):7.985555606380052
                                        Encrypted:false
                                        SSDEEP:384:kUU37U1nnfdxkgMvijkbyt6MqJljA3X937ab82S:khLUlfdDbkbdM2evV
                                        MD5:9251047829F81BFBE5B1B6C9CD58ADE1
                                        SHA1:8D1CD772473F3AD48448CFDA93363BF46BB4F649
                                        SHA-256:03B6CF47746D8D6AE40B9B0A2AB351019EDD71C7E20F57299C9A5C35FEB45334
                                        SHA-512:BFE758A1300C5C9DC41837B613795F02CF45641B62EF0C89BA4106CAE369A11E76F23DF7DC4B84C4290EDEE2B8E674094F36E04A96686D3A3BF284F0415C689E
                                        Malicious:false
                                        Preview:..*.b.7hoGR0.R..[y9....H.g...k.RE\]....;.S.>.u....R.C..%.&..g.+....r.(....(<.......'"BMh..fC.y3..&..j..W...../..20..Iy..t?...Rw.\..h{...e...*.....&...=.....Ep.QA.o.c8..**+.H.......].oSz.P...g.=..n...*.......A..."='..v...'."_+.T.}l..(...E..e.W}..1.*.^[..4A...P".._..Aa ...+ ......%..#)(O..b.......KB_....*.PW....X.~.h.C.....q....y..(.tBC<.. .e"...kM.m...D...Q..l......:..R,J9(..r..."...::Syg.i......w.A..P... J..$.o)O.........k..df.......X..O..........J..x.Y(!6p..i!.,..h.W.#...Hc...DT.M.C.`eyfW........FU....#..'...."~I..gAx..N..Mv?.^.3...O..R.1q%...NVBb`.F..'.:..tNZV..+....6Yo....7B-j......)R....1S...g..H.'-Z..l...zt.P....i\0...rC.xvKS.p..L.D.m[.EG.7FHe.l/H.B..jx.^<...(.V....._o.3L.M.mVe.`H{0.&6.X...`y.........a.;...k..r..LM.. ......L0=@.....Y.i..B....{.f.......m.. ...]>..aD......\.....p.Z#~.C.|.Uq^.@_......c...7L......W....o.6.h.D<]X.b...U.C-...W.S"}G.vLW..VE...w.+Z..)....k..S...-... ..;...q...S..Q......+M.._.....).Z..A.f......<qw .yY..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10046
                                        Entropy (8bit):7.980065751058965
                                        Encrypted:false
                                        SSDEEP:192:Ok2yo9eKZucB4LH1Wp3ch24nLRt7GVjj1gqMgvVhzYx3irt1wekwf7pS:oyDyh+1Wp3ch24rG17bzYlip1bvfdS
                                        MD5:5B00A1A44BEEC58219CD7E12A120FF41
                                        SHA1:4CAD012A54AEB3793D5D095F104CD199B0F70EFF
                                        SHA-256:A3A544AC031ADB2A3AD6594D0C8D1F50FAA5751ED0CE2C2BC74F655C5CCD1C4F
                                        SHA-512:62EFE820D5185E1024149A937924B8D2959455702DE3FCFE9DE249C1F2BA2056549DE568FBB80E2960FE806EF19113BE0E49CC527979DAC73759C657F4850F5B
                                        Malicious:false
                                        Preview:...I.lf......."Wm......~.xXJ.N.p..o...J..>.g6..`..^0`...k..;.<.-...t..@pZ..CE.%.l.....6...`2.m..b..*...J..B...~.*.P6D.q.)P.j.c._}TF.....,.II.W,.ztF..<..i.h0....F.....z.u...A%.}.9.t,......92..W'3...?..hq.Z........f..2..).7...Q.Q.:Sl..e........._........{...Y.ru....6....J.CbA..L;N./X.F.l:.'..W.kL...D....N.2m...b)~..^..Q...Y.....,........q...^.DoS.L....D.z...(.].|O... 1....t.d...GHd.i.#...GT.E..odq|...$.........MT.6o+.....*..#....pT.Ba...'.$..Z..H..^D.../}..H.4H>.y.g}.>.N!N.L.......{.@L.d...t.O.x..K/....r...H.}%.x#[.....N>V....T...~...............N...............b.K......6...n.Q].........(|g.......A"._~*.O...iMP..1o..*.0b.Hn'+..O.<>...2qb..q/>.2a=$E<.."..hG.n..{.[H8.}Os.....,.;..O.B..<....Q.@.T3.'....4...0...fw...S...'.rx...<........c]...)..e..r.Y.4.n1...#..3.....3.....?b..z..iT.../.Wq..1u..8...~~.k..9.F;F.e.........7a.......I.;WG..Zk...b)O..7..C..n....M..x.f..N.^..S..x1..n.H...V{v..|....F.".zy`TQ.c.L..Q...RjY..T.....7..&.....SQbq.1.2iU.B-k.AG
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):46910
                                        Entropy (8bit):7.996341447952206
                                        Encrypted:true
                                        SSDEEP:768:gZlsErjX/j0zbqFLPwCUFXjs+tF8rlPc8dgNYXE2yo+TUYrTNd0111iGT3puq3+E:syOkqFLPkQ+XAMYU2y9THrTNd01KGT8m
                                        MD5:BFE07FE0806A784C0E88602E946876A3
                                        SHA1:4F5DF03D27E46E68375D5B7F307D45258BDBF5F8
                                        SHA-256:3F6A2979BFED46783775D70CCD7B3A29D5E1348C39B5CCDB8F9ECD8B255331FE
                                        SHA-512:F4495C44314EA7CF399F0C4E645232E7857CCA0CE82C1C72B5071491770CBA1571C0630E43B042A685EBF53799CAEA2A72DBDA8F581303767DD0DD78F15FF06A
                                        Malicious:true
                                        Preview:...#..'^w..[.6}......N;..2].+.%.[..V$.k.'2.{.;...RZ.4.h..-d.):..h......j.d.."|.tM.4.b_7.&.......".g..`w.nk.C...n>Aw..q.?...4i).L&.....x.Dx6.B.`..^..w*.$.5.g_.K.^$.g..OJv.x3=.fw1....J...2..o............a...y.......4.I.1.1..o....,.$e....['@.S.@..V....I.sR...`.vf..;O+W......E.7......X.3....B.`.*.5...-..f;NK`'AO.'..O........a..%...S.O.."..._....cQ./.kU;."<.g@X......jC7._.b....$.f.~.a...q.>.D.0.t..v........uG.(.?l.<T.O.Mb?.....8YX.V?.ov`.....P.....y....H.....Z......%......hg.0}.v.6 ....o..Rn........B.b...z...2..b....~..........dT....GS...<.'..........L...37.............o%.f.w......../1..`...|..*../k-.B-'.2..'.n.......C...b`...S....-.I.....Ao\fV...fH"...:.S...R/.d....;..j...-........We.K...1.m......Q..!..O./...5!..H......P.M2.c7...5.&.N..5..U0.2X.#.....#~.eESXD...Dr.$.`..=.5I!w$;.wa.U.]=..lV$...u...,..G.1W...vi*S....^..P..7..5..P`5....L|...c.....;..fS.....u..v......n.......iNt.q....M.l..j1F.`...2aV.....{.l.[N~...l}..+.N..m.......C.I
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):22171
                                        Entropy (8bit):7.991919298387319
                                        Encrypted:true
                                        SSDEEP:384:SVeRV2AbV7YZ5zhQVpImmqMbkN67Ctsv5ZHZI+kXH1pTlvtxS:SURUZ5OVimYblV5I91pZvts
                                        MD5:4E6B556A8F712536DF27ED8901CD74E7
                                        SHA1:37ED8F9C4C0DEA1D4B1C280F5F4D64187D7A49A5
                                        SHA-256:98B76FB8E5D0375A91AA4095C5F284027E5888E22F5483210EA5699430ACF733
                                        SHA-512:967837D19C87E03A4A1EC6527D3C6E01A0AD227328C8443C988150607AEBA4FC2ADC779B950FD8499ACFD71C4BD745CD176772F878081EAC5FD5F40844581E3D
                                        Malicious:true
                                        Preview:...r..m.<N....s.W%R....zw;.&..l...Ai.............'~.p@3..4..^:.......].Iq4...H.=..P.(!.0../.d.i..f-y...B.....@......V..Q..?...@....?......-.~...8....zV..[...\#.....)...u.~gP.a..Q..1...&.hy...w..]....H5.x$.I2..h<..,.`......3.:E.i.].....?@.d]F....%.N..d..n~.l....J..jp.HrAyv...VH!#..JJ..i..SXu...,.pED..9nm.s...w..F.......tk'..6...p.W.D..m....$i..5b:,v..%..3Iy. ...Cq...nP3.K..|.jl..e.[k.f..v8c..1z`.7.*.9..Zh..z...V...>M(....#F.S..&...%.}M..|.d..V'.I..kDYjX....u)..'...$i....Y..,....W/...a..|....Um...<.`..yhr6.. .7....i)...,=;..-pMR....6....W..c..qb[...#.OI/...OS...8.s..I.8.)Y....3O._....+..).qa..u..g.~......B%E...k^..W.H..T.4O.\*....qE.....Q..:.....h.KX..j.5..|:!g1 .......k.@._...v...k1.2......8.....V.4r......>.FEe......F...,...[z.(...L.7Td .J.$.+-..rf2{-..._..^..F..,.A.ep...@......u.8.^.5....bN..%8)EX.e......H."B..y......3(....KZ'..M5I....=M..5.....T.;.....t..D@...6..6|.W.1....EJ.N.^"JRcc.....]..dp..0...Y.P.~..n...J^Uj<..[g......5P..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10586
                                        Entropy (8bit):7.98464415317606
                                        Encrypted:false
                                        SSDEEP:192:J85aXa2iIIG60xi4iM2toaCuTQbvGAmVx6BKFwez5UaTeAJM0a5up+NB6arlwGpS:m5aXQYti4iM2eFrGpEBTez5TTeAJM0a2
                                        MD5:420EEB8D4608820AA3AD92DD128BEE3C
                                        SHA1:48ABD9588F76C3AC5461A83461E295C1A54414FC
                                        SHA-256:5C889EA9E9DC7530F8DC47F5C713F68332E240F70601FEE31006F5B932B754C1
                                        SHA-512:18762AC64F35FC6BF54D61289D7442FCCCADEDD43109AF5F49F6A30EF7BC5A503DECE5721CAFE19F1E9958D3FACC6E375F18A7E45414C3CBA6DADF5274C3CC43
                                        Malicious:false
                                        Preview:0..w..M.G..a...[1..+.......j[....,.r.?..B...(..4r{.K......o......Um.:NK'....,.....O.Cx..e..D.~.RC....v....l#+...c..i.h$.Az.%.....7..;7D....8..i.X.U.t....n....l...].E..v..A...hy....k}.^....FLO..pMZ7.....*......)}..6n...}..{.M...h.<X0d..._.n.8[.....V62..h....i$.9..)....P.W{.....JW..?E......:...4=i4...$-,B.G?.....T..5a.Tt/.T.ha....Y....^%.f.P..._....{Y~..U.m..;y.D..~.s~.^~.;[.?._/../U%V.;.R....j)..*...........R.."..t....QZ..sT......K.z..y`....zG......E...$WL5.*X+.../x...%........-.-..;.o...o.&.... .o}/...{...s.we....5.?.....HX..2W:... .AYY.[G.6..t...P.I.l#.7.A?......y..u..<.c......)..z.v.."5..jd.E...n.}9.>yz....{.vV.W3..j.....U.!.....{>h....mW..1.@..,.>gV.../...(Q...G3i.".....3.\.-.t.f.nx....m........uW...[..7.=0V..Y......1;.H...u1V._....#..Jn..}&..y)...S..VQ.Qt..(..<...*sQ.....]....SAOl....o...@....:`........r3$....;hXx"....p.93p./....J(1.5.X.i......X..E"..CX......oH.ga...|v.-*v../....B.P..-.$......L5.x0RN.IG].e...........0.....#6.<C:..1..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9910
                                        Entropy (8bit):7.983384089735195
                                        Encrypted:false
                                        SSDEEP:192:WjPsakz25HcTEk6ARqhikOJX3/NJurjBF2ZpS:WjGz25HcTEk6ARq4kOJX3/7urFFKS
                                        MD5:50AC51C77CD03B35C7BA8BAEC17CB411
                                        SHA1:9AEF38726AC3DAE37F48E117D4BF93FB8FDC9DD4
                                        SHA-256:EA32D30B814F76E5E9956C969A552D32111ED4CD0F2430991918D21008976C39
                                        SHA-512:E86BEEB3C47ECAE2CF1CAC453C0428F21E73A4FB7AA478EECC6876DCFF6B5A61774205BE6FE720619DDA512C10D0152C5E4592B668D0F83B440B85CFB491B2EC
                                        Malicious:false
                                        Preview:e=...4.[..+.....}..ZTW..-..8t..1..."....O+...c.._{i.d.7E..v.C/r.9.Nk.....,......kF.. I..~.....Hm_..).......o...=...D..I.9...@......0....:.....Q...t@L....p.Cl...6.r.d........_.g9..R}.;!.k.....>_..(./.".H.V..K1!a_..q..rfy..>&+.........O.......a.",.........\..C,..."HxK..8.{.wj.I.cL..V..........'...J:(.gB........y.\...Z..c..x...k9..<V.`.m.8i.+5r\..#....i........d..&.})<..i....nS.7{[..>p%&..}V..aV.....1..!6.....i..^......U.,.h.(._4.1_..n.HA...<@...d_.......SP..h.<...../!..`*..z.x...*.3O@s...XFSij .....TF.....n.....p?..!.1ZB#........+.Gs....h._w?YmS!...-a[...mH?.....Ub....1....J.%..3U>.....p.[....a)..2G.X69..u.|.Tu...\..[.:..a.T...@.-?.&......x..'...).KL...N..R....t8.o]..~...h...:5....0...|`[Y."..|.5^D!3r.X.....B...<..v..:.^../}.....%......3X.i..R.l..1i.. ..%......].!T...Az/A.L..+.O@lZ.6X.5.....rI.:....`........{...&.Hl...?...[*......%.S......5.. ....e.M..#...R..a..6...Bc\.........E.CA."..[..?j...|.D~ai..Q...Lh....7.... K........J?).P\..Q&.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10166
                                        Entropy (8bit):7.984023274790144
                                        Encrypted:false
                                        SSDEEP:192:g2yLmJuB5iuDfxE0jNapR9BrtBFQzJjDvdKTT8/ZYB7kZ/t1Q7GTpS:g2yLDYfrSzJfdKTTH4F1QKS
                                        MD5:14DE074F67986C9C58480C65754A8C22
                                        SHA1:58A788A80F95A9D5E4C682C86A493F410CA17BB1
                                        SHA-256:8D932C65CCC6256FF01AEDADCF358D800497443DB27992D4F5D86E9440474C1A
                                        SHA-512:F0DAF91DDFE4BEA2601B12D1A222BFF1F8871F7D2CA7A64B5BE04EF957338B30BD4D068EF6AC29C30F3F0FFF040216D8512E89E307617C47B6EEBA3A4AE3680D
                                        Malicious:false
                                        Preview:.. T...46?J.I.z..y.~....S.l.7.3S...k.w...S_..E.35.'Q.S.,..b.="...S.u.T.P8.......6F>.+O}R..\...F....\...s...[.>o.J..5.f.L..3...Z!.J/c...>...,.H....T.K.W~....1..s.GG...:...2)c.p.V.&..UFA.m.....,T...k.SU{.5......SX!..7=7..*S...^.....h.>...F.m..6<...H.F..`..7....r..@.;e...g.....[;...b.0C.w..U;.7.W8...Nj.........)p..z.F.Y...bf....TE`.....V.5.f`..D..w;...0....*....F..T}.Q...p.#`.~H$.....ra..dE..^.H.=iI.1?...&rO...NX.k\6S...`V..1..'.E..0...|.E.[.Ro.C......$.1..p.H.....#.o,7S..i.<..D.3.Q?G.i.%...L...".&.../=.wm.^.(/.....4.....)K,.`..S...i.oy..MA.l.P9Po.....Ml.f....x...R.N....A.J.x|.....w0%}]....S..!..ZK".o...C.. u.2.qgh.....J....&....9..`....)..Wv.e.H!|J.....C..8.$./.8.i.....~...m...&."6.I..8../v..e..../.)..j..P...._.y.... ..5.ToQ....tw<.uC.h.".y..;....GT.4.=.'..u%..3m3..?8..8......1...u..H....._...0....=D..lJ..g......L3(...o..n...].4o.i-.\|....8X........-..~p.:~..[..Z<.JE..i...\....OsK....=.z.t...JZ...zz.yy,...';...0....._....n.6.......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9463
                                        Entropy (8bit):7.9807527514033625
                                        Encrypted:false
                                        SSDEEP:192:H9tqW3AZN6EUs/UP3DXffLdWlO+nGo18lA0c72ejoCEfMkpS:d0YMN6EUs/i3DXffhF+GAtL20gS
                                        MD5:0D5D54D18B77A3883474CE7054C8DA43
                                        SHA1:8B3A68A44B3FBFB2F43F9324ED59EA07C5AD5AA7
                                        SHA-256:A9E3958C443ED1D34483835410CDFEE8848D9E2A7C9DCDAA7CF6F9884F225B17
                                        SHA-512:113920BA62BFCF271F480B803DF38E9F82CA19F268519BBA6773DB77DB07DBFA3F3203C1E378EBBC8D8459C33F81AA8BBA35A9B2F1F621CA754D242327D0B8AD
                                        Malicious:false
                                        Preview:0..q....Y.M......em..$..z.6UA......7....>......j.....M.1../...hP.1......}}(.>.O.....4....|.....?6E...i...R.....{9A{.v.&...V...A....Z......-.W.g}....Ob#$z....2...V.?H...d..K........d..1..U........6ki.E.\.....T..3D .`D....M....is.HO-*.4...&.*. .p...~^....!.6.w...X.l.b.XHC^#%..%............l...........R.|ly.~.::...0..P.>E7..=C.EM..zKvt .K..Gw.H.&...N3>.......w.r...$.0...Kc..U=..K....c|...Oz.....Jp.J{...1Q3.....m..~......%.....3:7....XX.D.T.....1/..."..|....F.1....a...G.9a.^..v....F'..tBI.7... .j'W.q9_}c..w..v.1Fe.<...h'..M...8.....9........?....Z...r?.C"..).`1#..Yk...P-Sc....}!.....a.5....$.a..31......10.\C`....M.^&x.A%E]......1W%}..JlJ.D.D.O...i.O1;...o..H.......D...\.8...}._.F.gC.W..y......Q.....7..v.o..^..1.....k.......K$ >......P..Jd.JtT....P..........B9...g}....t.&...,..@7..^....R.m#A...."..T...|.z_Z.:.@.!%.%..v`...7..@.*....B..-..K.!.....X....-..$...kjJi@.-.....|o.nd./...!*..P...6@d.!.]..Vt._..I..sTq:.?.G..P.....jv..y..+=}.PD..}"c.ed
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10039
                                        Entropy (8bit):7.98210744284699
                                        Encrypted:false
                                        SSDEEP:192:VqQAb18aFgvU701Ie3aW3KmcLcFLvKA7BscefGE32xwAxQtMspS:rKZT+DaW9qc77BvSb32mrMIS
                                        MD5:6C287F37864B42BECE6A609D3F012817
                                        SHA1:747C0A524C8C24CEDF47200629779410BAB32F1C
                                        SHA-256:3607716109786501CCF27D1D53A4A74C4CDC8644F14B574A7D95039519F139DE
                                        SHA-512:2281737B04B235623ACBFC0FB20BB345D567BC86DBCD0001E6D03875DD31EA39252905260818F978C641935207540873D6322A91E15C782818A7FCB60DD19049
                                        Malicious:false
                                        Preview:.....N....8p.-....@..o.NG..q.....TO.f.:........7;.D.i..{....;{..E...E-x(L+...L.../<.e...1..U...Z.B.`..h.F.w.!.y.Pc.g.}M.o.......1...V....sa..../.`I...... k..q..5.*.;V.g..#\...2.n..=....v.1.i.N.~+G..^Jk.SO.y.3.g..y..H.x.q.S@H.X..2..V...~(...A]g.;u].....%'..b|..;.n..a....*b.........e.....fJ.D.X.N.p:d..X..02.......cf...;./F.+"..q8a/.... .U.Sm.....v........c.......,..yp. 8..=..G..$.q.S.'.d#%RD..3..5.~......$L$t.Z.\9F..+.v......%L...kE..E.....up...q.>..R.DB..TS.;..N.Y..p.?...........G....d.......L.........t.w.x.......]X...Xk:bUSo\,...G<... .o.$d..v.t.u...;.W.,.....}..QFl...........Ow......v...Q.('..Qh.....G..t.m..v[...1C .[............7t...Ow......d..N.o...............K.>U...Bd.8{..2......>.@X....w|..e....(..v...A1.J]....jG(..'.......=O.;...#.,.6</LM.. i..P.......|FcO......SX.m...../.T....>1..+p.w)...HE.Ob0.[5OtDA..Q..:-&.[<..9.....7.....ZtM\..2....B9R..x.S...vZ...{S.[r.j*......7...0....4wkV..W.(... .y.X.........D.L.)...W+]...?HS<...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10053
                                        Entropy (8bit):7.982855503785873
                                        Encrypted:false
                                        SSDEEP:192:ixPX5Y1sFDldQ+cPrR92BHovglZj9ZhUqN3ziBS++IS51kxkPpS:ixv21WZnarR0BHovMF9ZhjBiw4S5QkRS
                                        MD5:39AD8C718ED68D9690651E051B1E8E71
                                        SHA1:ED487A5BBF40277885AFB0A2D00F717E3AECD755
                                        SHA-256:025DB15231AD57CBFAA0949D4C41CAB759D0BD62082FCADFEA41902925A5CE49
                                        SHA-512:1A90E880D107299A82572859B305C3BC0A2EC5E85A5E5916CE17FA53E6BB0F546CAAAA9198B83F74509497D513CF2E1089C21CD8E9F9D4B069C8C252A5810521
                                        Malicious:false
                                        Preview:.......E.......:,..9u.X..oP...-....J..`|JY 37......3.BF*Y...\......>.gS...q62.....8....j....(...]1|[lbx6.*..w.~..,..(.t.....2.g.lb..j...Zin.%.[.....G:.N.`.......Cn....I.U..5..b.s|.O...>.4\..-mw.EP.I.._L^|?.....h.m.....t....Z.....!I.S.W:@-..dZ..(.c.&q;^.e.+Q}.H.E..l...]."..{..S......-....%9...tw..&$`m.w..N....L.x.3F..B.)...+..?....i.u._....aF..A......7...........S..]?.....gNC..O.5...?5.H.iM.?....'..30.fu.h../J..... ....n....d?..^1...D....]?.]...g.]..>.5=.....P..#.....%..X..~.MD....Iog..74tgz.B /..&f.N.x./?.pw&...>....,f..,...wSl..iH*.k..!..d.......$.=..-<.a..q. :A..P.......G.!+.......B..9...^.ht..Us...3,0{.x....w..#N......V,.%...%.._...e..g.4.....l.i....uk......3..3..9>.x.cb...PU...N...pk`....K.........5d..YX.R'.........J.i|.,.5V...(...}m.6Z.Hdw......(.[W...._...{....!....Z.........V.W...QT.o.....$...../..~z....L.q{.../.X....@.\....m.1....e..I.w...,i...10)......~Ac]N....q<..e/ .23.3.`..g.|.h.b...(.N........kK......-...1.o.\:..Yk..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.980987542295196
                                        Encrypted:false
                                        SSDEEP:192:sAP9deYrNxDMYVNuM5iQ3p58YMgO1rzq4GsF4ish+TkouiS67TzTApSMpS:HFdeiDMouM5j3paYMg+rzq4hGiTjtX7T
                                        MD5:9CD52D7469FDF9BB31C6062C3107A552
                                        SHA1:2E8E5ADADF54B5071932E2F0435D0B2375DD2A96
                                        SHA-256:8EADE77BDFDFC3769C9CFA571BA06DABF5DDF31CA76AE7AA1C2D02A0B4152BEE
                                        SHA-512:7D74CCB77BCB351262A55BA0E0BFA10EDE1A8E4D60F41F907E7CF0DB80629B8B691B4A5DCAC7CDCDCA81DC1D47D7CA66ECD28408DA5A8298562583EA36C8B6D4
                                        Malicious:false
                                        Preview:...uz...}.T....W..."......[..| G.p.1..C...).|.H.~..=.....~..Z..X.[.?...5#..M4M...*.....P6....A......Q.,>.4r......2.I.[N...s...4.......^.`.....h.-.1.`..jB.#[TB..9.6..y.....D...p.^!k.......kMd.]^......{<..8`.|/.`P.....s.j....l.;....I........|...N;J...G..%Y..)..n..L......~...N<..v.....\6j..Z..4...e9f$..}......mn.}..u.nP....y..@./..Kl....c...p.Fy-.Za....P...$/.<.h<.O......0.'4-4"8..:c~..-....]..QM..W7....'@..to..z3.v.7.5,.....#..y..<.kc.....9..w.... 0..=......n.....;.....6.Pi...b.....Q.xY.B..#c...;.......95,.&G}^3$F.....N=I.^........0ji.D......mp..... Di..x.<=we........~.{4..:....[.VF.d....`.. ....7.n..!...^.Af.O..2:..82..*..F.!.dH..K......<s....C.o#z.....0V.|k...BO6;/...6...%,.8.N..O.NK.tI..PNA..^..,d*.^U.~...)..dm......R.......8.8...WH@.n..'..B..IAPm+...\..........C....K. .m.....l....\...q3<...1.,......U.]i....kM...|uK.cy.....yS;.......{..Z.m`.,^..\.N..."..J.wb@...Ce......!K.5$.hMG......3a...K.B=.$.280.....WO.~..v.....i.T.a....7...5.l.:.xb).I.46.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):107444
                                        Entropy (8bit):7.998172613295487
                                        Encrypted:true
                                        SSDEEP:3072:W0zlKxCoxhnWMlDPtJDuNyeRr3hj0j/+BDPjL:9zMxxhnWMBH6NyeRrxIj/+BD7L
                                        MD5:E1A878E7124613BF0F5F62FD0F414BE6
                                        SHA1:1291C89E3CF3F4AA4ED4875F08D666B2A10D0ACE
                                        SHA-256:91EA6F0BFA5A1A4E8D1B4C4184D3599C680B5C70A4D85A5D708B336E81093173
                                        SHA-512:BFEF8D401CA7793FF7FA5015702CD9B649F9FF5F497454BEEB022054C8E0A5DAE857B26D916A382C81F291CB6F5990032130651D71B3DDA8F45F93C0F589247D
                                        Malicious:true
                                        Preview:!.K..6....>E..#..a1.;....:Aa.jEJyw.^.&......(............N.P...l..,Is.e.=.E.s...5..|.Qq..........y...#...,...&....9.[/.s.1TP!..zg.~.z.l..#..9!..l....+$~.)-.8..5....=......0..7...l.T...V..B....v..Y._$.f..j.......@x4...hS.*.b...o7.......Az.S........ .N.]Y_.MY..........c=.^.irf.?....K{....<.4.f*..........vU...B..k..|m...q...R]...YR.gc.b.&l.ih....3m(..U.pa.....8....!LB..u......I.'..m.8..I2...Go...4.C..J..$y1"V$.(X..z..j.....4..Ep2(...z....P._....mG..(...M...Y.k..`DK.dS9....jr..~.?<.x.x.).....Qz..2.......Xq.Z.ouJ..._..H..n.....lK.uJ.p5..E .q.aO....x..K.pN..=...[..@}....=..D.l....8.....u+mw'.kR....D1..1#..1G{....\|..,..M.]....k......x.......v..0..$'.&....D.............>R...N...p.,T..U..m.'.UZ....&.K.p..}oV...&..[..,0.....@..e.aV"..N.HQ..31.!.+.jw2O.*..b.....}.....n...M..b...-..MX*.Q......n...|.|*}k}f.X...~.y.].(....9...2cOq...Fc.......*.....e....q-z.m.U....'<.0...j..c................g.........b..E...O@..D...q...%....U;[.Ef4.GI.4......0..E.F.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.976164269070792
                                        Encrypted:false
                                        SSDEEP:192:cIGCpZpcAYaI0gy2DOvjlsK/CmhimovZQmtUMtpS:3Gacj0CoDrhimIQQJrS
                                        MD5:04E57738641CA4A19FBEE91AFEB5FDD9
                                        SHA1:28305FDF86429F089078D3CE160C4A4D20064356
                                        SHA-256:62D17B64F606F5E9BBBE18BA6C0CD8C046B5751359FA005B746A0BC98B68DC23
                                        SHA-512:5B6415EBA81077BA4B1888CE07A3B01C7C90132C7B656AE4062752C7914E09AA803861937551A6AF9AF6022A0C00F56C66848FFBF4D4A91DCBA66481CEBE3892
                                        Malicious:false
                                        Preview:6...P..p:..._.L!.`..*..P.^n9...S.<..=.=..F..+b.LH..rg.<....,h...a.......)....k+.(.j...g.6\b..{n..8..Nx.[...V.....Q.V-.s..#j.p0-.m{......}J.g^..4.u..5.j.BG...C.8..........9...e.=q...l1R.kUx.XP.H...\....H..=.$......._..d.b.6....tv..R..vF..5.+. ....(5Z:.o.^...QB...c...s.....q..K.h........s. ./.....P.C=.}............K..Bp....v.,....GR.9.Ju...|.......^.p..Qu..........b.f.R?s.u;.....M.B.=..o.^/.%.......3..........Wn.......(.~...#i|".=.ABr~.....!.Z.&.I)...J.....^.j...@..l.......<..N..z.......".........W.....Q=Y..7..h.........ce...........T...ZL....f..ag...@q../..-...Z.-.Hn8.?.I.1....*\..f....D.x.a.,........:q8...8.m.........p3n..(.m....8...%.-......ry.y..!..T.U....T....l..$...A..+......c.*...0..n...'Y.FJ.._*.ms.v.5.>.M...u.6...5A.W.q.9f..caB4..[....t.K.a.,.YRfr_..H......N..G.M...U........b.....}<R.K.s...6...2.X.&.{....0...M...4..|+..M.......9.Db....Z.\..E.....]>.kU.......F.Daj..gQ...S.....%....8WA].......H......%r.....j@.w.x...^....K..$..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8427
                                        Entropy (8bit):7.978799882426318
                                        Encrypted:false
                                        SSDEEP:192:5vL0zn3xHpJk/j6VSkJf6fEwArYDWlXYlOTvme+pS:hoLh3Uxa6/AcQXYlS5+S
                                        MD5:1ECCEAED942C5FE97AC1CC5A7FF4389C
                                        SHA1:8978B04C20788CD640A074E860D557A533FF3B9F
                                        SHA-256:0CDEEECA633179C58C8052D6D53FE96A3F52D506678C4E14A5B1877C07D5A6E4
                                        SHA-512:696AAE29123E3D94866F7F56DB8F9370B1F3B7F0814D80A76447815D0DC91BEE8F5BB7C19AD936E53D9C80FC1DCC1DC812BB3E2E786F501657BD094EE10861B6
                                        Malicious:false
                                        Preview:2.....j...c.......68...f..x<.UI$.[.c.Fb=.Z.yQ...:..1.m.<kJ$.c.'...r6.{j.9..(... =-l.q...Z24N.2}.........]............C..R..?........\)..Yr:5n!...c......U.P.......}..Q}v=..U.Y..../#...,.\h.....j.1.4.......m,R..:..j..\.QN........t.....hF.A.Wu7.m.`bh!.VG(..u>.....EO.+N.B..uF...'..?.lH8N.H.}V.B..M...DR...g....*x(k.....L+.Pb......k...f.W:.N..OK...t3..d..YOa2.l.N...X..:a.....f3.U.).`......F..d...7$%..uE.[.y..Ys.b..*X...1?.w...My..fM......@..<.....%w.i..?.LLi.....4.l...?a.|.'.6$...s...Y.C....k..>...'z...`..5.~.y<2....L......A..xK.=....|..u..h.....87....#..k.`.....).A......-f....4...yV.uY....Mz..T......l[...G.UIt..l.*...X.M.^.H\4..;7S......#b..F.P_..a......Y......1i..d/.}~..*..K....n.4....s(.L.4.#........|.d.@,..._....y...&.".....*..F.Y..?..;.m....1.......]Q.1.../.o..&.P#.|%..H...h..f. .....~..<...Jm|.k..w...q.H.7...;|'...p...2...G.y.$..X".#........eB.!.CT...9+.....2ZU.....P%....m...i.%.p%../.O..W...........s..~....r....S..h2%^.......b..K.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8435
                                        Entropy (8bit):7.982009750634514
                                        Encrypted:false
                                        SSDEEP:192:Mv8f20Do1iaTKAnJbJa9KK1Yaigc3kGlKfJlg/0Qkx8meb+pS:Mv8zoIcKsza9KsYawkGk4sQ9mXS
                                        MD5:34C94AB3DF0E6630E7B7231BA4752F76
                                        SHA1:A86E2F574FB77D5B7CF464A70A8C37933123EF8E
                                        SHA-256:DAC2D4730F5C2895B15F4F4D6B9FFA8CC4F1F5DAA960DEC4F7ADBC0C1AA3CFF1
                                        SHA-512:8FD4CC280B1FCD7FCD3FA9F4F263B94934602272F4408688376E0F162754A1670E692F26BE099405908E0A0613DAADE3F27229A07BC26AD7A2185386A3C71785
                                        Malicious:false
                                        Preview:K.../..).{..,R....&......m.M....r..o7....B.(...P9.2...f,.n..G>...hi..8...E.[x(.@v).M.~`.!..o.l.!%..N8.RH.8z....E#...Vd\GdPvl..4..o...S*a.P.z.o.s..e....z..n.....c^.q.........11..t...|.3(I.J.zV.!..r.5.....E.7.....='Y..$._./4......H.r2..p9.....X.c.......$[Y.Mu..4(..&...P..WE,..R.t........$j@qtR.SzY....P..8(..3}...v..`.{.2.5v...V.B2.I.qI...y"~.l.~D.X.Q...K..s...l^......e"......hrO..CQH.|..z.p..gz......!..R...........I5.R....j.+T...A....7..e.....;b.H.........[.[b...Z`..w.(<.. ....u#.vp:YHk`..X-.....J..NI...{..2o.b....Wm.L.7.....P..O.cK(P.......O...i.....&....{.U'...<..4V.fO$...!'..u......iN.......v..i.......l.;%x.}8.n...24.pg.-2... .>6358.P.^.o..6'.k.6..r.i^..`.&4K.Ng........8...`..Y(?...rJ.w.R..%.....4...w ~.E.n..G.>.p.............j..;.]/...OQF...94r........$....;.}P..q.+%...U.~....o...x..9|Z..Ur.....y..s.<....:Re;\.......%..ef..........{!............]_.?.U...).*eT...1.....R2.Dj.......x..f.D.<b....m92.....u...7....-..c.@....BK.y4w}Sfa.....w
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.9774467654841015
                                        Encrypted:false
                                        SSDEEP:192:cVwUhGINea2PSAKatMalbkDECPGaJomiO84zyieaTUAVPOjgzqzpS:0G4e9PStatMaFkRzemnzyifQ9j9S
                                        MD5:6A41AE60563F4189F1D22772B7BDB80A
                                        SHA1:1615317C3052B6F7783AFFFB7F51BB77F519E7D6
                                        SHA-256:7C12BAF6A501B423382F571D4A13828FD6E7A4641E409B0EA2ED45C7A41E80D8
                                        SHA-512:679C7B614680743EFCAA9FA0625060B0F0F2AB0201B161EE41ECC44986FF75EC99A987C1D327A11E994B1FB0C3500AAB5CC0E34616612CCCD07A5DBB1AA52373
                                        Malicious:false
                                        Preview:...E. J..sq..1q<X..5=..wQ+X..(.C2.7...Z.....x3h.fn.5W.....R8[....f.._..n.&..dw.b.x...d.<..i.+3.....k|.l..^.E..W%3Y..t~M......0........O.!.#c..[.BN?.L..rn.dK.9..........3.....Q..N@.E..I...........^H7.9@.....!S(Im.5z..\23.d..|.+...~..k.+.E8....[a;.!....J........m..r.....o#..I.2.g...lV4.*..ZC.L.S.D ...`....Ld......k06.y...>..&...Z*r.....nq!.........O.z....&h...........(...9q.=....g.i...........9.k...........l..8.....8..`.14.p{r....@....(._T.....DSA.(.T9..]0g.....-H...[.jP.....M..-..J;sK3..O._..HR*.........g..w..hbw._..../..+.t.l|.t.}>.w.e`...Y.<tN..&...<....:.`g.,..Q.Ubr..6l.&...D...t.....qM......N...6.KdB..eB..W.mc.O^).D..4k....0.1....l.O......B.5..;F-....K.............f.B....+....OK........T9p.bE.......S'.4...a..<..+,.lF...|... .7b.i.uW...OI..2VcF......).=u....b`...M..T.....&.s.B..`.......^|.-..w....Atr'..."....M..uV0.Cl.[....?v..~.BN..-..0...."..T%......RJ.r..........ku.^.........`..].^..[..'....y.n.E.CH....Vr.(.on.Z.....Vd.0......)
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.978764931284008
                                        Encrypted:false
                                        SSDEEP:192:/9x2iZlMPvKrB1UMNmGcIi4TavWbQTQ+FMotwWYUHivH57sHFSpS:FxQMNmhlQ8Y7+IhUCP57XS
                                        MD5:4401944F69256D2AE5CF1AAFBE21C1DB
                                        SHA1:281053F955C9D36596FDA72483A784065FFC55F1
                                        SHA-256:F543DEC19D637005DF2F70CC62C5C69E3A663B3EB4654EE872F5D80B01F68200
                                        SHA-512:BB3CD3415C92A418E1F1008DC4BF7A8EA84B696CBFB379A77B50FB1C27E9554BFF224A6C473EACAA107A9D1D367E838861AE9D266931081A4B326CBC0C531418
                                        Malicious:false
                                        Preview:.DF.......w.V.....#*....?.?.g{.....\p.Z.;..f 9o.[g.~].........@.i<g...[PY.y..]e.Pu;.S.3...$$..MM.=kI.....Q....1..,.....I].o..H..N..h.l.......,I4g)g..#D..1.+..y...}.i..F....L......8.C..t...i.......]nK...~"p........c.}.>.....1...MKBJ....)..g..[$:]; .{...*.|e@..X3,..|..=[..^8...D....Lubf8y".Swd..$...c....T..].....Aiw.[...#l...1.L..g.|+..r?..$.X.,4.N(...]..h....%t.p]....Z<..<..k.8|!.......5.J../.q"ok..[.0C1.O....C.5...z.....8.myX..=..)...%.....D.}.t.|`.qB}.Y.>.....<."wT..d.U*G..)<.'.-..%wEU.?..Z.3..%`W..g&.D.0......aU....k...{7.+...@o.h+...-..4.u. .C.%...v..".&...i.v..>...p..`..>A$m..@u...w.D3.....&..^.f.W.lH...A..}...p.L.....X...V.|..R+....8^`...X.2.....|...K.H...Q.Id.o#.9Z.Z..Y...=.sH.. .!>N.(.j....Gw\}.q...~.#..v...O.at.b&..b.^..!k..q?.(#.W.z..j.@T...........2-..$^........K...U=z.Jj._e.&....+F..Re.......{.....A.3Z#<..C_..Ue$../&..7 ...(.*.....mC.....U..8..U.e.k...u.L.]..U4:]..m.:..b.yd)..y[..r....^...t.5....,HS.[$.;...t._...}Y\..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.97523228891935
                                        Encrypted:false
                                        SSDEEP:192:8pcypnTWCPXfQNwqht4FortNDxCJp81SQR41jAFo4DqnB5mo+3TXK2pS:8pcypnTRXfMwqhtAohpWy1SQWVOen+bE
                                        MD5:EEB90DAA150FF72282CBC9B19AE2FA2F
                                        SHA1:71B4A4BCE6D1F18440B6B6708DAC6501FE44F050
                                        SHA-256:0893C11E5C2E9203D303C96934E13205D1BB813A89C6E5ED1B1E63E682443741
                                        SHA-512:8653717AC62DC5ABA04BC8C6FCCA28941129C08E825606E6221D8971D048577264C7E414074D6BD65E555CFB5CEBA8C791C104FEBD7F0C4D9DC948EAA655D21E
                                        Malicious:false
                                        Preview:..b....=}B.7.vt.Yf..N.V.VU......UY.*I.\._.m..\$.xo}.......'.hpG.0......Q~B.........kc......V./t......l_.M.iP..X.=g...q..p..k.4......*..,F.i.w.l....:..Vl....e..K..z.......E.q.......e.%f...70..?D..8.W..C.p../........."...5...`>A.u.E....<."...L...u^H....e..... FF?.;DyM...&<...]..j....t.*!6.]k.h..x...M...fMGCp.~...tDbJ..7..b....r\G......67.[..aw..5K..P.=...}h.y.../.$ARq.}~......{.)...6...hcu....C.,....'..z.8..Y..a..G3..O.J<TR..#....Zcy..8e..7.+..2..g......iA..../._.t..W....N....>".?.).....!W..X...D.:.(/...m...tF.6.....=..%...f.(...o..\.P..V..`M.S.hw.....FXID.R'b..b.p?...W.s..}..|m_8..6>.Sz.I".l....8D ...\*k....Jr.@.@....V.9...w.......KJ..~4K.....Wvi..C..c.$....>.[w.k@}.P......U?..F..u..RB.....s.;.wE`.....vp*.-$.7.E....&$^0.r.F"|.FT1..j}....[.....!...Qu,...Dw6p-...G....bA...g.^.z...Zrk.........`.3(........r.W..c..B.PLP...c..".bV..3..~.n..%..y.D!..Y_......u..9....8..?...DFh....@.Kb.......KkN.z......IU...vs.KheV.E.2....O..J.)...YfT.._2.".....Y}.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.981787962783898
                                        Encrypted:false
                                        SSDEEP:192:JOX+8RtxfUReow7FHcVkkVQqqOBKSUGibMGXZUDP6B5UEypS:Ji+8RthhIVQ7OBbCZAPY5xyS
                                        MD5:959DAEE3054C99FE721A8CD5A00AAD86
                                        SHA1:1D5A59976DBFB3CAF590952A4267FA22221E6B3E
                                        SHA-256:E3E2B7280D771E3056A617FFACA11C61630E376292FE80734933306A3CACD3B7
                                        SHA-512:F73A0680A6636EED51ED51C820095478EBE23C67FA83D01F02546D1AF3723F524697885450918D4C6484ED0B99A0869E851D79CE1DE8FA18AEEC706932C36068
                                        Malicious:false
                                        Preview:R^...6...<...pM;..|...z..q^~T....t..W.}....?a.P...h|Ji-1.K2..5.E..,u!..C..ty}..p8.\.I.D...ba...|.....A4...GT.c....>,_.$v9;.v...c.Y...``............]2m6....g......LAW.O.....N.i$......Ga.O......G.q..i... .^lCJ.(.,..j...~...L..<]...R.N.[1.Yl....TQ,...;.....p.^..-......*..s.Bi(../.v.E......)8..G...^k.f..%.].u}..[...8...k.}t.%...L..Yu4..U....._..bN..v..`I.........a.$...*.b.....A..........).........~..@.{^^..f._Q....j...27...Z.+.I....Xm..5kW............ZN...2.W....~....p...6<.....K.4..q...N.^O........,.......k...h...[.v.\.ur....73..y.w...-[.*:P.!#.&{....Z.......%.q..&8.b......s...xitr@]5...^..p)K.f........=...:q...*n+..g...v.....a...!.....*.. O)..j.-%...E.6..."8..!.s..\..>C'.....&.A.......6.8....C.R.?h.....p2.V.j.r|.=G)..7..D)..c.g..2..c......)o........uF.+.......RD.>>.. ..X%.+.c..#..9..b..Y5.....r c.O...".;D0..=6.<q.C;m.m..R.[..[.......{..Rc..9...tq.Ob..8{9...?..4..RC.S2....E.g...+O.....m.g.f..O'M}.1D.g...i..O...clHG.s.[.<U..RI..]....:+..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.980164262218721
                                        Encrypted:false
                                        SSDEEP:192:YYd05/RvTsXEy6GZZX6Ax7ktKIKv8rlP8MU09v45sn94WsapS:YYdkTEEy1PhkcDvqP8IvYE9RsaS
                                        MD5:1A5779A45906705D43AF4FDA41AB9BE6
                                        SHA1:18B5338FEA1D1D47A3F11C51CE8BBAA4100DB1D5
                                        SHA-256:D0717C74615E5A823299FCD799C7B2F8639B2CD4DCCFA514C256D30FEF39F1C6
                                        SHA-512:6CA46912ED8EDB8BEC023FC0F3F22A2B70635A4F68472B868974223FDB550E125E65A257FD5348A6B4D9B6601643B764FD4A50FCFEA71F3AA0A59FA919964C8C
                                        Malicious:false
                                        Preview:\..-.M../..2;..)a+.f.b.x{SCh.o....Lh~.l.....q. $...cRte.N.]]V.....!K..j...p.......`..7ji..+.g.....i.../._.?.Q.b.H...SE...[.0.;...^1.B(M...I#...o.?..?~.I....V......2.....~t!.:..=.7..R5..Zb.p.O..R...s`.8...jzUj.R...H7T.ae._2,..d....}^...?.#O.Q..3..=.n0.\3.`=^..~...c...2x...*...v.R3.ic..7\.!d&".B..{"...2{"...s.!&w...S.4......o......A...I...|...QjN...?.....<...nP......r.0....Z.o....N.th.y....[i.F.A.uT..Y.^+.*...mZ..x.L...... ...i..G..dTUIj..i...{.C.O.....2!.W5.C.*u.m..._.z.T....H...l..A...&E...c.4B..z..F.AB$.?..Y.. .t.........9.......K._:.g1.YUE.y....^..SgN.-.X.r..pL.y..!...)E.K...".....Ph.Z..I........w..Z..rg}.=....O.W/...#.[Y)...^...{.!........<....xh...e2x.)W,.]..{.y....f....5...8........,U....@:..HA.V.%.`0.......6...e.sn.....!..C(.oW.C$..E.....f.......7...W.Tt...-......)...P.(ajl...6?.D..NBf........u[IB..:.F.\.~V.w....#.."5.3..t..(:gT..+.......U..(..?.%...k_.S.6..2;..Nr>...V.p....+.k....eq"Wd..uD.e..b8.........t...n$.L...O5.......j
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.979156760571175
                                        Encrypted:false
                                        SSDEEP:192:rAfCmWHSaHjPzVRH1NFtxfjpdR16M+v1dK7CeVgmEQ6YeG2VspS:8qmYr313T7R0d1o75SmqG3S
                                        MD5:B883C348299EF2CEA081FA71C170F91E
                                        SHA1:298F05EB642F19841538EB448B0F3E2770099E84
                                        SHA-256:783A193EA24706A34AE4B53245BCC8278703E09B4717B5C98D5DAAB97BF6C940
                                        SHA-512:EEFBA6B0BEEC55456CDB379740456433B2007130A9C33C68F3A20BDBA072F181077BBAA5768B8CF05781A4884BB21C1B59C7B0E0C906CD683285D4267E705309
                                        Malicious:false
                                        Preview: .bB/ik... ......q>..G.. ".z...q}.J...TN].....f.S...:{0E,... .tJ,..?^(......#......xAzD-^..X..Mh1s.t{..i....W..E.7....[.[F...x....y.......{B..G...."..p.u<.B...-.f.. N0>...~Y.|..#..K../...0...T....-d...I.`.B.*...(.i.'.....9F.1..+......R..6/..s.yU.ya.f.m.e.l.0oj.+...66...V...eK.}.......aWa....v........1.! .y....i..}...V.F.w..|...z..b..lR..o....*.?.y$.9s.U..r...Y.k.....o./.\.9~R..b$.b..h..J...Zi......dy.tJs.HK%.W ..a.........U.L.Fy...Jg.....!..W...E....e.l1..._..8H....*..Y.@.k.....~$...C...r.?....L:#-.-..0.S....C.B:.....$..c.U.q...w.@.b..pi.q.......=..g..Nc1#.G....)I...y.<...'..%.Kkwv..:\.x0O.5_>.........vb...~..n....g&P.....f..<......@..+..e:.....v...4.....8.).%b.W/..uK+RT.....}E?.`*..........&.......Y...w...KA.......(D...O.Re.X..%Z..td.3tz.Gk..:.)<.....sm....-.].M.*0{.Py.V..*M@..|.b....Z....Qk..[..mKf ng.C.7....gv-9...M.r.S>IR.....8...X._2Mj(........E.....Z6d.|$....J._.m....QR.|p.{8'......c.m.........Z..}<...q..6.S.....O.]F4.......P[....x.c.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.975829176836304
                                        Encrypted:false
                                        SSDEEP:192:uez4jCAvbh4oiitbFcRdpOOQN+cA6Vg1HRM5JbToUu5anOPijdeBpS:ueOVbqP6G3OOvco181tu5andefS
                                        MD5:F33E6452AEACF237502E81078ACA4D85
                                        SHA1:DF69AC245CC45F8260CCA75D41C8588BF4753F98
                                        SHA-256:32AC7FB0D4B9C3BF9F2026A6D519C6AB927647D1A0ADADA3CD32E43FB1090953
                                        SHA-512:914606DD673213DAC98A653863CB66B0CEF6CAF0BAA21991048B7AFCF96125CB62EBBCE7BF8EFDC0628F484D576294D158DB0448FB05ACF0A6A87D39BDF682BD
                                        Malicious:false
                                        Preview:_V....>.{...w.m..K*.....V.*..l..Wc....\......MB0.].u.%Z<..Y1g.SA..<.i.ODng.......4..zBL:.u.4..m.my..aMz.O.....>........Q.....Y...r...x/f.O.zV..M)..V...3..._.vu... ..sSU.hO.^g..dp.l/...R._.c.)....W.Xx.u..tI..4N..q.1..OF.]...Ob...I..+`@8...%...r.&0Gn..r......[.w=..x"....k.-.......4.5.e...eF.....t.&YuK....L.o.y......X.W[<....D@...n..lP..q4..VX..Q..FbW.t.... ..|..........L....t.\E...,m.mG.+1CB.I.h.euJ.X.S.!X.;.b.(^.mf.]..4.J.....C.{.........8z..."0N.`..y..........MK/.0Y...t.$...31\T...C.........eB*...&..x.ML.[\.4..0.......m......q.`..kO..l.e,GL39....:.p. f...}.3..!..,.Y.A.*:.D.8..u=.*X.>F...@(..3...j["............'.B.6y....`./.]*b...3...J.8O.nt.2&..b.rL.|..&..h...|..[.V.]....#.[.8. .eK.0.-.+X.~RE'..Vnok..yO.Q.7_..jF...f...eB....S..........TA..7.q.G..sFk...#../j.9_..eI..0..x....U............L..i....wQ..p.W"....#.5...K......m...j.P,...U..F.g.$..N....o.].N...ax...i..#.df .8.GA~2(5..l...#.E.._..\.l..s.`.'..<.ZY4..i.8......U]h..~~..$.-fJ.R.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.979675972544579
                                        Encrypted:false
                                        SSDEEP:192:amQb67uYz4cx93n6TEQVacvpeZ/fqa8treORFmWIQYpS:a4Lc8936Bxp2fL89SWIS
                                        MD5:46254652969B7778A2B4254985058016
                                        SHA1:70B7B7ED4139E76E77A270F4483F29E6971E33BB
                                        SHA-256:B60270D09624B51D36F4C5A56A457DCCE97EDD59F293D868C8BCDD96B80AEB9F
                                        SHA-512:B27D46726929DB86B2708669DCE98F44FFE702B6072FACB3999597FB09D01D32E4E1844DE2FE478F02972BCB990D85D6F13965CF5DCC22158942A8A548FAA7BF
                                        Malicious:false
                                        Preview:lP...r..s.P..L.V=.S....).Y...&p..j..2...(|M,1R..i...ix.gW..Z;D.........*.=.h5.=...!..io.1..%....n{[..t|l..K....7..Pn..W.k.."..h3.z..(.2.a`...$.......T..K....Ph,)...6.aH.(>..i.J..=s.T.)....nY........4<....UZI...n...6.b^k.#.........aJ.*....^#.V.g..?t.N.I..Ii.....I7.J,....g..o...x..k..K%..$...J..%"...B.9......X.4)C*...T]"...5..(I....$...Q..q..!......`rb.[`}...m...5..&. C...+..8.....#..f=c..S.......y..MNt.@../..*.Y....l.*..>_.d.=M..-.0,L.......?.}doW}4........d6..6...U(.E.@.....5..V+!3.M..3.Dm..K,...Pm..t.. 1.Y...w.y.]...a..,&.`:m.(O..q..%.;.......X\K.4....4_....63.E>..J.._.E.Y6.(."..;...KP.....V..%v....[..g,..o.N..&0..Ub.CQ...E..Fe.g|..>..8.n.Z)...-...s&.c.qK..#Z3P.<.(...xLj5.2...}..u&.=...~...~.6.....i.UW.v..&...].H.HW.....;..z.*.D....?..O.4..qE.'...z.'....oh.d..c..r..\.S.<.J.zv1.J..i(..q.OA.G-....V.!@4.....v.c,y..Q..9t....t}^.|...R..@m:%.6.B$...m...Lf>).I..\.' E-.E...M.@b...3=..a.5..6...d....nE......$.l.L..`xr20..2....u.w[..VU..8K...x;
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.979985185844233
                                        Encrypted:false
                                        SSDEEP:192:QDn3f6a918Cxwa5re1+53GuuHFsV+hdTjBkNsGJ0/okdpS:QuawCKa5ruHFsYR6dqS
                                        MD5:5D9B1B9642171D26EE62F6A67D9CCAF0
                                        SHA1:047B17503CB6DE7DA3B151EFBDAE14BEEC1999DF
                                        SHA-256:F53686AE6B8AAEBCEF67D6460798CF0BBA44BB1662BEDA6517F60186EBD1B484
                                        SHA-512:2B85F6C82D39635F4B0BC8AD0633BE75309C1FBC8293E5FA270C121700F92DB8D11E7B09A21CF3E648614392E218C75527C229106E4B0A138318F8EE4AFE4051
                                        Malicious:false
                                        Preview:t.D.Y.\T.2...v..r8.V.J..j.-F.=...$\'......*8B.IK......?.=c.d'....u.U..K....8.2.XEbs..&..hr..h.3GI.>.....!../.I..${B..../..S..R.$t.......r..P.v...%A8dz&..c..1W.P<O.......r$%\.............+!..o.fqYc..k.d....c.....s.n.X...q..p..&..x.<.']..`[.5....t....Qb.^.......Bl.n.i.*.:Un......*...b...j.f...Rc.(. ...I..%..<.._..... ......Qh.....*z.F.}..v.V....E.X..5u.......n\*..Ul.@....c.....H"6(...N..F....Q.~.P...Ky.B./...m(...K...u..wK....3......7`u.8.M......=.y...*8./o...4@d.&0.Y>cg)..@<....h..Wd^.b..3..E.[.R.`0X,..........4.......*..`.o.K.....D.?X...(...(..Hv...'8C.L..l(.dS.:c2.gGO.rBh...`.s..RW......NtZ...U.......UM.#..<<C7j.). ,.k K........l..5<...:P..,.-..Wr...I.&..c.M....l.}..L.q.+.............`*.C0..6.Je%...A.E%[..S$$..{&W.......k;..CW{.3'.(........i,r-rsUy..U.%..x.J......4....k.b.=EEW..N.=.O..}od..e>.e.m.$.Y-.....s*:..'p..g..wt7-.N.d7z.o-..`r.........(..4..yu...f.Ep.....n(.<>o.'.'~..:b..U6oO..+.[4!......A....g..@..az%50.d.%.)4.c......6.K\...S..J3s....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.980180173585774
                                        Encrypted:false
                                        SSDEEP:192:zvF+9X2u1tB7UGEf9RUk0vqgQm1rfKU+P4AkwSKS/eNuVpS:zvF+t2ET0OvX9DbLJdTS
                                        MD5:0FB70D953AE4BE72A3A2F2D713784923
                                        SHA1:5E02F54FF4E4143A0B91D4CCE01BCEAD62D4F354
                                        SHA-256:E181E2D2FE8F44672EDD1712550614B011A06BFEF4DFACD2415C4E2574AD935C
                                        SHA-512:49854B00F259C7BF6FFA07248C27FBDBB8AC89AE8BBC078A6B1A6E471372F6DEA8D76EFB23A7B3A123ABC5B8E1D79301378C82F1F0DFC89BE794E99C99236ED8
                                        Malicious:false
                                        Preview:wI.o.#..~..mZ.).j.~N]..E.....1...._..f.&}...Ptr[/....NiI.K.....).l.}W,.!.. .;...j.T".=.vO......H..Au....b.....}..Z.d..C..2..N....P....1..q.~f..t....V:3..?..~.l.8..@....y._.Y...k7..m....-.q@.qW...[&"........$....\.i:...r..n3:.<i..l..0.../^`..j`.m.){.....]..G...* D.9D.gz..p.\.5.\.....{....f.N..?,....Z.s...[.^@..D.T._...P.5RL.WmT5~.4._.:...[.k...Q.p..W.7...t..xT..........O.5u..U.F..g.I:...-....G.}hy...K;..2El....).y].....b..y.J%-J<..#.A.uBi..t..6.-...|Y"sW=.H.....Y.E.m"..4...T..<.....<.E.........McS..c.t..&c.tg.x..6uOM..zz{.S...".../...o...e..8.....:.:rs4Z..sV,[...#....y.'...........(.gFkq.;...em..r..1l4.*...P........u..M..j?....v.\...s.X..(.l....C{m$..D._........`K0n...^x,L.Evt.....w3...q....!T.9.Am/..YeP..<P.)I.I..g.yM..=<f.h...g0..:.o..T.-..d..1...O-.+4.U..zNl...5..B..d...I.........I..,...Y......@g./\..[}E......z.mPI.|....;.Wq..M..K..D._.I.R...S...=..~Fh\3........R.~.2..F.c(..l.zw."Ef...ys.U..U`.>...E...UJ...d...oV..B..zB.&.q.GT...oC#.B..I.0.E_.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33023
                                        Entropy (8bit):7.994413591018247
                                        Encrypted:true
                                        SSDEEP:768:g4dgQyIEZ8vOauX+Dipi1hfWREOHsGAGGrm5bkUva5wzc0jmRFSJ+:nTypZ8vgvi7jFGBf9Amw
                                        MD5:7F125943564A3C3CCEBAD3797D53E01C
                                        SHA1:658024C73E6AEB8750DBAC617994AAB81FD31342
                                        SHA-256:19717D4179FAC76F4F302C084E3BD2A41490FD7D71438634548944BC210524A2
                                        SHA-512:C924033E17F93E9F8349919DF98745ACEA3F018A6EC0BCBBF399B6B8FF01E44EB005CC4104C98C647DADEFD957160D20093434AE3EF15803230846E29F8E2F4F
                                        Malicious:true
                                        Preview:u IMF...j.P.].a0..4..v9R#C........x....=........]o.....c..n..s}..O...4...`..d...t.2..4...uMa.....%.p.S...V..n.'..IY..X.[...{P"J....kd60Z./]..t...........Y.f...>..wR..Z...^*..y1l...*....A..?...C....p.ci?.r.v..5.c....6g..~.E.-l....3.8.u..q..a.c.."q....g.~....Nv6d.JT.0oI.Y..n..c..<.#..\T.'...q......8F.$.... ...p..Hjr.<%....@.>.*.W.....z...O..<.+.o9]C.......:...d0.....U..e..K.<....5(`.n`./Y.n....!.L.VC.\Y.=.........Y.k.a.Dy....?&DT..q`.C.P.N.....I.b..v..v..f..{dUsv.g..o...%...'k@....v....B.>c.:.V..vD....p...y........>....L.L{s.-.L.|....i.qb.).,../%:&b.Z.t.5E. .n.....+7....U.....7ziY...@.M.....X..V...>..ou..Z.f..u..........P.........S.&......iY....0{.4..|....s.oy.O.y.-{.c...Y.{....I:...F8...L..O.V.K.b..\.C.Y.......Pw.`aL.&Q.'.(>...Bs.2,i.$Y. ..\.L_[..b...'.*......O_..Ic+...dOV.I..{Z.Y/..r..p.W.M...i........V.)/..@...H]...pS.1....hO.E......t(.A@6.]x...z.Ov.|..d.....5Y7/.C...q.mWU..b....0.x.L..r..Ks....%.\.....<....S.../C.<L+..on.^...-M...x.......1
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1384606
                                        Entropy (8bit):4.2852743527270665
                                        Encrypted:false
                                        SSDEEP:12288:bSUzyzgE9jMqjYyhA6jOd2SEZmtL/xLCex2:fE9jMq8yRjGEZ4LCex2
                                        MD5:94E93E26B9CAC5AE08FF04DD6397A2C6
                                        SHA1:A7EF85C2C768D2DF9DEE1B0D3250A1A877D6A896
                                        SHA-256:850CD4FC9DBCF740D7E91086EB44A19D94C9F54055BCB898EBACD23DDD886094
                                        SHA-512:7570D3AED8E185A70C3AF2722481D830B7CC034501F74EC55328D07FA05627B97EBF1B91B9ADA885E00A2B179A03ACC2532A01E49C16394021B7383E69BAFBBA
                                        Malicious:false
                                        Preview:..My.(..$U...7.i`w9 .P....&.h{..o.tsR"......Eh.{.I...3..?.~.{.&...).}.Q...J.H..h=.a...I$......0...W...X.~....H.."..&%..h..%L...J....H.fa.G>....U.T0(....s...U..-....q...w.....19..8.O..z.$......W\:.ii....?s'W.k.!..J.`^..ZA3tiAg.-]..S.>. .R...q..}...Cs....[.LM]...>.=....#.P....../!Ex....*.z...>.....;....w..d.$eV.V.Y.......|..(.3..4.t.9.P.d.H6....H.b^T.2.Y.?...5.PV....$.[}.'..&_...T7n..u.ub.P...V.>...3..F.q.pgW...r..2.,..).{~.:Q....~V(..j..+.............Z..U.4..n@$...,...+.A....C...h...?.7........+....#.=JCO....|....U.......xUy0.F...W..4.fNP.w. ...g..D,>.:....T...y"F.x@H4.g=I....+ih.c.+r....8.e!K....9v0|.m...NPb.30.<..".;...=i@]})'o......X.....+B..\3C WH2L...IU.M...X.3..S.:q.3....3S....q.C.I.V.%}.7...... ..g..:......Q.G..$..p....y.EY.$<...Gn.....c.?.~...h...B.....@y.(.ig..b..M+......B..p.3t~.e...D..@....R...V...].).0..H...L....N)84......V.D......9U.W..F...@?...$.. ...!i...t"......i..mY#....ml[.u/B..KYP.....?..4.<.N.."3.O.\.~x...._..'.Z.._......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4345
                                        Entropy (8bit):7.95852393732397
                                        Encrypted:false
                                        SSDEEP:96:gK7k3fQu9im/odykSFCgOjAJGX7nzyvOm3bvhJSY9StRAiPrXpJc:gqkvQu9N/od/SF/OjASWvOgb7SUStRAB
                                        MD5:E752DBC06CB322F21A23CD1B8602D652
                                        SHA1:069F01CC88F35974B0217B642843573FED753557
                                        SHA-256:45B37B25B4D5570FA97FECE4A57E114944ACC3FFF87104B088E227035129B888
                                        SHA-512:8A9D5CC39FD9C6F2C513DC50F94CED4EDE990DD284622F902C482348AB611003B58977E10252AF637F738A231B5F3CD42B7A34AC3D47E07D3175736E09D3DF2B
                                        Malicious:false
                                        Preview:x..{...OJs...a}...Y6..uL..b`<..1...k[6|%Z.`...9ch+H........P.Z...Fy.'....04.w.f@:..........(...0...*Qk..o/]...h>L.^............9...m\....r....d.&.MA58@.K....^H.e.t..b"b..{+t.!.U.q.9n..X..C2...e.6......."..Fi.......vW...$..............o..q.<.....\.....)]..{..IG...h.,...T".dVBx.:..O@)B.....v...(..].X.B....4....5n..&d_.q..Y..n.p._...Z.<7?.....).... ....Y<.a.......... B...M...y1p.<.Vg.'|..2.8..{]....O......?4....{...2....Bd4q.?l.p.60.|...'...G..mA..'..>.......~.r....r...\..d.....".h......3h.........*.w.u..u..R%bUBFy.Gl.k.....l|.)....,_.i......\....}...`......|.......B...[.^,.V).$.f..r.<.~"u... .U.3*.."....=....S..#..%.rX|-.. 2..P.\..U{..zC. .T..\.-%..k...0y..s.K..D..A.c@V-...H....i./.Zd....hQ..X.i.h.......8,S...........EX.=,.@.Y[Y.l.(..4....-...^....$......@........e..D.2..*4.C=w...@./.G..{Z..3..6....X.........c..z@:1.^E..mt*..P6.EL.i.).}.....NW.....m.w....?.......c)...|...0...E.0.hI.....xA...."...Q..P...>&...L.g`b...x..c.3* .W...^..TJ
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):65813
                                        Entropy (8bit):7.9971987683587695
                                        Encrypted:true
                                        SSDEEP:1536:UTd5jAVZV/fgocEnQ/AHAPZkIBgBfidV5auGy:UTdsV3F7Q/8AhKB+AuJ
                                        MD5:9D835E1B1FAE6EBBA8E183A0DA9CBD98
                                        SHA1:305BBAE94EB54D528B0E94D96ACDE7D72D3F18A9
                                        SHA-256:72FC74A51C20B3065515F0BC30C130B6D582B21BC55FABCC8BE522A29D12D041
                                        SHA-512:C52BFCB5D112C1B9DF955A478D8161B6439180303DB473C81738CFF03698FB7C4F51316D6E284E672BA7759A6421791F4DF5086512F5559CA554A99940739E82
                                        Malicious:true
                                        Preview:.9.d+..j...X..........'.F}.~....T...vx....&/G0x......&..Tn....N.O....<.s4..+.HG.....Y.E..13q.'...z9.~y....Q_.j...|.BQ..+......\.../.H..e..rQ... .....S ..........Tws9/......V7.a..b.y.....:j.."b.G}vEJ.G[`...mC~........."Q.P`.V./.a.hZ....u..=e[?8n..n.tB.Z,...R...`...tc...sJ...u7B1U......tn.....,...`..<-..r.%zk..W2.5..C.E.N,./....tU=J.qe.r....?.L....1o1..?^.#....F......7_...`/[Wu.....?*....f.m!.Z....*Qp&.J.(..7A.f.v;k...c..,...fr..D.$`~.i...H.......[..".p.."u{.m...a...c...9y....`(,....b.1...Q..S........o.....B<.....1.nIJ..z...d.4~.....7.a\f.\.>..........]....n(....d.%.f.....x.A("4HG........w....\.|1..7..4@g\Z.f..Oj.;V..[:j.)...Y.m^qt....8'z.;|....kG.......`^.z........E.@{...&..|....w.A..i.b.@......w..8........MD..By...qW..........@.g.p.tc..qV#&...J...5R..]o.........9....1......-..........XDV.....;d..;?.....y5.....q#F...k..@q........M.....e..Z.n........SS...1et...]........Z....v.0et...+|.h.....R.2........%.J.....%..`8O7v..}.b..P.U.._a?...U.5....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.976987375114342
                                        Encrypted:false
                                        SSDEEP:192:2pbq7Gh/1UBJMWGOd7aivMM/WOzMp4el0mCaubAoCv6q3pS:WpoJgs7aiZued6lCautuS
                                        MD5:9475F2B03F33B699A782D486B2EF0D88
                                        SHA1:BCBE7D4B92939F3013CA8F06E4BFE1C290552DBF
                                        SHA-256:A3EE8A8EBFEAD2217486BAD477A60E08FC2B992580E5205137BDF7D3340E8504
                                        SHA-512:668FF53DC770662A2E01418A493603BFC07291F8992E5519EB51722C8FA0D11FAF8108B2CDD16DC94791114DA6D4F6D7D664A72C3D807F43D1BE2C49E7A14A13
                                        Malicious:false
                                        Preview:.%MyYJ4h.f.t3.y..q.....s.!.L.......0Q9.v..=qt..}.i...&..2l.@...YQ.es.|2q..V.{c+..g.........c9...+.0......T....!.......3_c...bO.i.F$l...Vc.,..<..D......Y.kH....}.jL...............gk......L.C{."...<.....G'|S>.&z...#.....v.Tb.q.#..I.\.......A.]..#...|...2{zV6..Y..Pr.z..x...b.P...W...x.c.~..G.....+.e.g!..y..3UG.B..g}......,{.%G.......#.+.v...u......Q.!........C....W.t.i.;IG'..#s..{.o.q.Xj^2...w....W1\..#.^..yL.........K..K.<2.d...,D.PAn.*..p(.q..>....\*.-$.k6.5..5&.T.....l.k@.L4..#....'.].#.F.q.~g.z....U....}....UH~0.x...0...C...5.M.?...+....2.F.......]...j..$H.5#1#oM...T.......%./.9.`.xJ....%.*kn.Y........;2.`I...7......0..Q.>.%.J....^...`.g1C...;(.)....Xk$...b.Z. ...@....u...U...w.b...|.#'3...nR..2:_.......A.P.._x.m\f}.[....E...9:....:.H..g..\..,.Rs.Y.....b...|,%d.Z.5.wQ..L....?...^6.B..``.W.c....(.].E..b.!.nY...#(v.j/L.Q.Jw....S....Bp.r.a.?#.^...I....O.q@s..Jjh..b.....#y,.M,.uX..._.3.B.g:..A.2.$h.....[=......#g.%8/............0^.|...E
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.977709079275878
                                        Encrypted:false
                                        SSDEEP:192:AsbBvWl8XRxkTiFLZKd1qVSDQo3Oz6Hk65ZKme7hDSLoVzpS:bbeA3kTiFLeq4DQohH/WphAoTS
                                        MD5:000C641AC27F36202AB6736F3AF0A2C2
                                        SHA1:A3242F2FF82DB7587CCEBFB9D4C4349F17C23EA3
                                        SHA-256:92872E3A21EE0521069C9CDDB4BA8EF7241C55BEA16797347D9687EE701937C9
                                        SHA-512:6E38BB42191AA02B87686555278C397CCA5F3DDE116AD494AC912C17B6409C23AA39E5D95DBC9FCE498B9C59AFB9C4043DE40F40C7D4D97C8599983C868A133D
                                        Malicious:false
                                        Preview:.9.M]..'.#....5.#.W.+.I.xRW..,...p.\......E.....Ku.%Ga<...4..O...0.0..v.aH(...o..Xx.M.....7...../A...z.c.Y.....Q..2|..E".a......q..A..Y......~L`{..V5......5L.$.l(.&r.../.H.p....xz(...@..S.B..0.H..`.oiy.91.... ...P.MB...;.(v...$n.a?.....|.5...T@J.y.7,3........[.$.!p..q.......a....b.".cD7b>..DC..<..k..b...[.A..g..~....<........L.....`.b....h.. ....[@._vA.....e.l7..?.XN...W~.}..\.?.....!#...9zG#..D..).^.8..h.k.....SG.......Q...H......V..I@.%....y.<....q..6..y..H.(.$..O.._.....j....UM?..r...d4u....z.f.sD.....\Va.2..............@)NqLeF..I.w....i.....q...,.E......f.....f.<LC.DLU..eN.].2.......&..(M.4..`.c....kA...N...WE....T..|....rA.+y\..S[>.f.3.w/..d..3...p.f.&7..0.JP.'m./...:'.b..l.&....<I.e.5.......D../.v3.._..]w9.yF......a....9..CLjGu.0.S..,.K.....w.....Z=.e..<..".t..\W..g?..s..Z...c+`Q..r...+.2.Y...M=..~..M...#Lm.z.7K..c$..,.n.!.....^...v...A)./]F..@...W.L...%.xY..,].e^. {B/..s$.6.. {*...._.5:....K.....zC.?q.5C......G.XG......;....u&S.OpA.cx.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1573111
                                        Entropy (8bit):3.600000656834768
                                        Encrypted:false
                                        SSDEEP:12288:AjfJ5P22qOnGJbfjAuDhzerjxwFs5QSP93GHkez9D16r:AjfJbzGJjLD9erukQSF3GkezT6r
                                        MD5:72D27B436601615916F95BA7ACDA8753
                                        SHA1:E5141A06359A9EAE4FBD41D2AB1DF9B9E6ECA333
                                        SHA-256:38E69B309987C7D6069A088B17B07370E69E1FF839B29C9E239F5FF5E90E9275
                                        SHA-512:747028CB7DC6FEB2180DFB209DF7E6C022189CE52E96ED746E6669DCBC0C93DC603D330944D25271ECF0A9EC1B2B9CC59C3C897D3CE016C3116DE60A47475B19
                                        Malicious:false
                                        Preview:....\P...)k.?^u+4.l.._i.k.\an5.tz.S.3.\.2.VW..z...+...i.....m.f;.d..".M/g....K7...-=...d(D...1...5..c?.8w......'.`.....:..~...a.............w...{._.@7V...9..._..L.A.W.@w).e..m.e.J.#.......N...l$...?.S.o5n+...I.3.s.X.d,........A.(G...../..!;x..-g.[Y.<..UEtp.Lk#.\O.6...4tR:._..F*..ui.V.p...r.........[.k....X..............u.$b4V..xXSh.h.Dyp`......nXh.2%.......F]G{.f.NE...(..d.u.8x......x....A+............U.p*..b.-.@.K.....<.`...D../.[.1.'..7_..G.kN.....Ne.........s.$.Z.....r..sVaQ...~+.yG.'.5.9 .....x.;.U1../sTj..L8..xK.>...l..=6ok.i..Q.z6>.K...7....,.....|...@JR.I......Q.r..$.L.n..=.u..-.T..Z.... ............9..:....~...lk6.8.a...*g...w.B...."4jB_...2.6........(...P|.wd.....?.It]..c.i.^.....|4EE.o/G..E.}..........Qw>.m...t.@A.cO...t2&..f.=.O.]1..E..hG.. .Ss.....i6=...3&(....U>..:3.7Nu.lB..._8..._48.T.-.....n&...^......T3D.."hLUxRr5e.*...*?..{..o.?..*GQK."K)......V...J....ZM..S.....@Q...(.'$...h..k...{o.....hsf%<..r.4z.\..?d..;N..XV.Q..=.Y.[B..`.O"AWk...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16632
                                        Entropy (8bit):7.989448653795451
                                        Encrypted:false
                                        SSDEEP:384:5R9rfjtKWL4d5PlGXIXhwvpbonWUqKIB3OUVTbS:5PDjyPnXhSNQWU03FW
                                        MD5:9881662E9439968D38513B086EB6FC13
                                        SHA1:C965AB42157EDEE2668F64FC9AD9676B541508DD
                                        SHA-256:D29A9AE5B4012AE279199727922356DFBDA05894E812EA1940D342F67C681782
                                        SHA-512:0CF29EF16D68EEE9815D555D49D4395DA89DED9F5CAF08C5778E9C6CD6F1D948FDD7A177921B249EFEDB833AE5DB1CE438EA7E36B6E6E1B85074238D644DBA0F
                                        Malicious:false
                                        Preview:SI....2rp`&.#.{.er.#...Va}KNh.V.....I,.O...^.vU.L..g'i.H....D..o.iP.S...l.....p......e.w4..?#...%v?....Y..{?(........a.......x...1.`lb..d~i.rFF...........\...a.p..'...zd$..>...p..c....0!$.=..h=[G..N.~..:...11..Nx...R*.;4c.+.K.uw...VL..t......|.m:sw....5G7...6.R.qB...).o.`$..V..*..Q...Y.~.P..^...&......x(..&f.WM...N...v,..l(pL.Mlm...td.P.. .S.....>..k...2..H.'...8..2H.x..Y.R.1.9q4/.R..}M9....|..5.BQ.>...d.W.'i..._....H....7.o;....2.....d3.;2..k?/<..v....j..r....P>.....5..9...%NE.a.h..;K..+. L....K.....WgWAd.|.W.8.Y......1z..!..Fut.....eam.>}?..]..m...V ...C...<$.S..sSw...C......6i}...6.@.S`{..A).S.5h..sU..).. W......+.D.M}.l.....E..6.]..!E...n.o|:...m7.8......L......&f..d.w..lU.4.A.....#....50....I.f.....!z.v@...&....D+.....:.a....+7.. ..!..8..k.{8'..).a...Z.e...VG*....... ...l...e._...%.N.._f......*.O[.>...@..&..^..k.&#.8v0E.....x..rh.7...g<.2..:.OB..H....d._%70....J....mxG..a7%Y..)@.v..+;..xRo/e...,/8...Qb...-b..b_.C.-Pd.U.......r.p.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2097392
                                        Entropy (8bit):2.8399749524802074
                                        Encrypted:false
                                        SSDEEP:6144:KBkAhAGnXQZwhlauxRKqPPKtOXWXNGoxwpiADPUpX/HNYJQbCNFOolnhO45wD0OI:mlheAVxIukGcopPSY6Cb/XGDSzME
                                        MD5:DE2CA4D26007D421E09ADA27D4BDA7A8
                                        SHA1:5A83D8B77CAB1A50307CE6CF0C7B772D7DC4D2CD
                                        SHA-256:96433975D5D40381802BBA4897F1D68AF5AC01D594A177C480437BDB000B3C36
                                        SHA-512:8AD1DF74EA5EE22288E3E13F49E97A7C13F5210889ACF1DB631F2B71711FA7E217E2349162FECDC2821E5A5A9F47B40A4F773108BA0BD4F7432D2DE72CA90FA4
                                        Malicious:false
                                        Preview:..5..D..OG@.N.L.6.?..B.....RG..w3E.}|e.e...=......G..g_t.#.1)_Rao........k...O..8.c.X..j..(...Bz.>{.t.J,o.......}.*..Fh#QZO....J..fl..ZG.R..G*....vL.....s...Ui..u.5..Bo.K..0q%..H=.k.p..wu.Px..i......f..`....].f.H.*.I.mY<RZ.Bb6..).R....P=.f..}K..OV.4t.<9.aj.m*...E.M....v............yI..![yf.Yj.....Bd.o.7T...+.........&n.bL.z.a.....-.Ac..Z..i..a2.".W9Q...mx........xE"..a^.:..n..E.D....>1.7&)t...u.....^..e.e...e.=e |..{v....&".GN.9..s......?.......J.<.$.r7....|....yU4...Ma..Y_aH../..O-...hKa..:. .....T.. ...]..C.[8$.i..=J=.$...n...KT#.f.....)...\g].}....z....x.I...pd............R^#;..........#T......+..<......1B.......\.+..,|..5..".....g........(O.....l............G.p^..`..ek..zF...t.k..?...n.k#P.F=*C.R...XE....3.........D...~k.}3.Ir.p=;.w.*.......}..(5-G...WW...CZ.;%..z;.s...4..W.i.......c.....Q=9....Q..=......d..f . G..4|...]...?...m....d..m-..t..$..@...\.DA..s...t.+NY....7F....M.c.t\...Z1.o....(>......7..PR..5..q..HK.f'.Z.j.p#>
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16627
                                        Entropy (8bit):7.988520640096568
                                        Encrypted:false
                                        SSDEEP:384:vi8xoTvYfSGiG30JnjFWPvOWepdA2ZZZwfB3NuBg4OkKfS:K8ov2SGl30JjIPWWeE29S3NuNOe
                                        MD5:F066322856DA685D2ACD0DC80ACAAD09
                                        SHA1:CF9E5C56ED397A09DB70B91A181B76C3624424B8
                                        SHA-256:A8AE82009FE8A851D89BA986C3C8C800FAD13F52C99E7B6A8FEAE7BCB523FA00
                                        SHA-512:B9D9E3012D5A12205EACBF25E2508B577D340BD243BBE7994DB4C9243F09F049FB7339D727C5CADFD02FB848C4CC59B33CC48C4B581771216C29FE2A3826F52D
                                        Malicious:false
                                        Preview:.wp..Y[....90..9I......5....RJ.4.A.,u.xn...R......8.....o.)..m...b.....d.G4F.z6....].Hi.[.G..Q.J.,Kr....bm.........u.fkl..Im..}........n.@.Z..v^./...Dq....|&V..J..]..v*O....{.J8h.G.9.I9.W...U.. ./V......).J&.G..~i....4...z.n...J.....2f...$t..Du.q...?X...A..v....n...Z.n......p.....rJ..,...........+. .O.Za..{>....;...:.X.....c.D.....}.%......r....;....I..-.=u..V....,.:&%.$...k......]Gwr.kh........U.^.?Z&'./.(uW....'..d=.[..........w..w.d&4.CnsI......^6SY<Z.......$.?.PG.'*S...%...{..O.3........X...q....Q...g+`..&..}..RY.7....t..?..H.c...0...w_..x..VFf~..vD.,......a.l..k...A....k......eh.*4.l..... 4.}...T...SI.}.....huJ.G..E...W.wx...y'..zgn.,.....N.<:.Z.........!C2.3_.6...%ZPD.#..G.U....$....B.;....z...UT......a'....:.u\,j.>.u1(}.7..>*s.a..n1......0.....n.B...h.j.O..........9~`f....u\..x..2....oZ7.&6......G.t.l.. ...$w.0.O8m......Z........f:j.(.F.6...u\..M...*.s.D>.U....D....W.19.$..wWm.q2Nq.-.>.2..N$.8..D.y]....I.7?.%.q)...0.b.NJ.#............B'"j.b.u
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8425
                                        Entropy (8bit):7.976666646082611
                                        Encrypted:false
                                        SSDEEP:192:rJPXjKhNpBgPclhPtW/zu2tTZO+8TQrLdfLDKpeMJRGqQgFxubpS:rJ7KhZoItqpZVwEJfLDKprJa39S
                                        MD5:A0C48DB0B036456A10A1D214117AE0CB
                                        SHA1:998671311B6D7BCFC210E4463D8C4442519AA3DF
                                        SHA-256:B5DF2E045C5A29335DC827EC9A19CF49256D765E0393953273749B47336F6FAA
                                        SHA-512:612C2A29598DA26A8E5E0782E36D159D52D0F3B502DC5617BD109E398F9099FC08D15318E8EDC9351B9CF7E88C220725DE10CD9C990637E71F76C5A23FD3CB95
                                        Malicious:false
                                        Preview:i].;;...6.`^..W......w....!.(.H;.y..X....s:#0.....3..(..w..%j..9J`i.ui,....[.J...[".D-..cS.jo.^'y."......7$....-;.Pa.gma.A$.....}B..K..5...*.;nJ..l.....C>.2J...B.<_^..|.+u..s.8..'j...].$..P.F^..j..!.9...nD..&....}.....q...3q ..<s=.7=.n.7lW.|.............>.K.k..B Q..t.....q......{r..r..^....(b........]..R.^.K.x....W?..{..p..I.Z..e.C..N(......l8...Gb../.W..X.4u2....|9.2A....B%Op.....D..~........z7`..H.P=H.<..._.r....|4.O#./.w.s..2.oZT.....(y....N...D..@f.vY.,....9.8..g\..."-.7.t....D..b...)...c..?...+7..&...=.. 1...8..o*..H.k@.... i...#.U.A...{.'.....`..Y+-......5...h.n.....N.;..._P...O][N...U...j..:.X.P...hg.....x......:.....v..D......P.9./..6<x`.].n0#...s.Us.y..x....gQ.-ctp....V.$.6.n.<LRV8'f..H.j.E.....|.a........P<.......w.eo;d.[|..wP...y.o<0(Z.!.J..T=......V.-P.;..)..e.z..8.xG.t....;u.ps.x..FIqK.>y.^E.1Ty....b....Z<...!.vc.f...m..(.......F.N...Y..SH.8X.K..+l.p..@%<..-[C.p.R...s.O..|.wRQ1.5*&~....L.iq.c..+c.kz...f2...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):524521
                                        Entropy (8bit):7.9996196670555895
                                        Encrypted:true
                                        SSDEEP:6144:7Lrk0WOiPz0gErQgH8rk8ol10HK78msli8EqyQBH7hLqu9/B2tgk5JmdruWf96gY:fQ02Q3BCK0q780WVmu9J2NJn9B/9Hr
                                        MD5:66108A936E4C2220C19D27C8CD4CEA18
                                        SHA1:291799D145B8B87C550DCF84A832BF32C5E07201
                                        SHA-256:11E0424C15835BC1F1C7FBBE2EB4EA6CFDB359AD2711399BC2281D438310BCB8
                                        SHA-512:A36A68AD8592B6C591128501AC3F4FB217B0B7E4086D87C0D5995AEF722CF594C80E7BF892ABB7FBE1EAE06BF4AC5FE86B083B8FB2C7D01FDD5FD6C389E06581
                                        Malicious:true
                                        Preview:.!..(Lh1#..A2.Y...dU.\...T....\.....F..,:.|}.f......d"........?..}=..)j....DzIF8....u.^..dP..G............M........E\c`a.&h;.-k.x.Y...%P.7..x`.....fV.:9I.Y..e......_G.V.+...kt...x...+.0.z....MeOV...2....Q...d;.".....zZ.....1....s./>...|`....'...|.[.Y.}..^..."..9.../....;|yB@C.Q.....8.s.......G..#m..Wq?qS%b...F..T.m#4POK......#F<..=m&~2X.....T.`k........Z.. ...O'..`G..0....>)B....k..~.c.`.tt...Isd.....J..f...^..-.Q".E..0e.W.+.}$..M?...M...,.'......8m..-JH]...{)Z...o.7..XY..K.(:.,......m.,!F.n.5Zj.?..=../*Ik..x.p...28.XU}Y../.;.a..../0..}.6.'&..y...1...z .[.i;....('E..6.J........3J.f......@..b....7...W>.(.}j .........K.....C...|.@..!UU...q@..U.C.)#.....F..Miu.#.........=E.~.%2.W).,..8"..W.....}x.h.T.@;^C"...?1.9...F...Z-....ec.XC,-G.Q..{{xib..... .....;.({-...a...J...]...Ew.D..\../i.a{.........#....X^/......L..F@.X....at'..yva$.`.....e.J.`....!.V.{1%.J.U.....;.c........YV&.....$3.G.g.R..-..>V.oC....Nr.....lW7.>.....c....Dh...!..&..G...m..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):524529
                                        Entropy (8bit):7.999628805222773
                                        Encrypted:true
                                        SSDEEP:12288:7vo3KK13UDBicUCtM6+u+DZ5GVWpjmEsN3msnsnNNBaFjz7PcMrH:2KjBicpt2JDZUV1EsKnNaFjfPcMrH
                                        MD5:882C3BC2856F40076B7BAA5AEEEBB49C
                                        SHA1:04A1CF4A24724A27E6B469CE78878A0ADF76C918
                                        SHA-256:E6A469834A27D42467684F5DAA52DF74208E0A533847A7BCDBF3A6EAB1AEE4B4
                                        SHA-512:6AB14C6958285CECA259F764A4AE03F6F38B9B59B02B29F709984D134A13FBB82176FB30859AFCB729E38E4C036CFA707244D8D3173622E049ABE4276F154592
                                        Malicious:true
                                        Preview:`.V.4%.D.....8d....7O....jY../0.....r..K.>99,.!.H..J+.?..O..n..,.*...,....hw.:..x.DK........V?.'I\...@...'....N...A7r.....qz.%..g..a~|..(...n......,..h..y.~.3c..8....$..$..w>...bB.a,..A^*.....a......F~.H.'......l....`.J..AFb.f.~.is.........R..V...V..q=.M.z'..4..W./..+B.a..;:o.$..".:...4r.9.O..x...............T...K.}.9#...5.....i.A..|.......-w...}v..f{Xm.S..yv.#...Xn.u.W ......:4....:/...~..\...El..y'..r....:....>......./8.2... ..F...h...j.........~.r..{_.....4Ok...'.2X...G..t..T}..#-..p.b.....G..Cy.b.!.}.p+..=t....,...b-.....r.....zFZ...]...Z.l.......z/l.r.1..`S..(Bp....^=...l.....)i`..ZV.....owVw._..1.5....&....A}4....wj....Uf%#/..1..j-tm+Wi.j..P.W]x.i..7.J]..J..JQ....1(u....e.....8....!OZ2...p.9:..6..A....A&....PU.z...Ga.J.......'*...J....=........)...^..K..........8M..Gpx%.V...9uF..L../.p...t|s3.~.2..{...`........4..+{{..O.........=]..@5...l"V..U.'J.R.&...}.1..$..A...)z.ve.9z.....$t3.b.b....!.7*W..E}.$.^.t<..../c...F..-.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):524529
                                        Entropy (8bit):7.999618776885717
                                        Encrypted:true
                                        SSDEEP:12288:aOWE9MdXY/AXvtoz3BBiiaW1Plttll1yQdhu:/f2dXmAXvqaW1dttZyMhu
                                        MD5:25FC6AA02D3A63B003B862359238EB43
                                        SHA1:BB6923215868FEE92E99B486D9CEC5F6BD73A2C0
                                        SHA-256:B9E82CF3CA6DC57F9AC30BF07047AC36C84C526B2ADC8EB390897594760F7BA9
                                        SHA-512:C7E8DEE82647F0CA38ACDFA64C14268FC4526D51968009F93F315A7F11F3CEB0FE7A00DB3A6B6B8D11138AE95B74722A8E814FB4A4249D5B49DD2F7F4A46CA18
                                        Malicious:true
                                        Preview:..O...?....>.j...{.w._-Q.T....SO.f4T..|.z/8KPX...3..?..;..8.....=.O?..[..+Q..i...Vb[=8.ns...........?.7......W..8.&.. ....O.@..H8C...[3y!..'Llrj.....\.:..s.....8...e..T5.b...........k....I....pQ..ea.KOi...Q..u@.....J1....k..N. ..b.>F...U...H\$P%.....]...zLM..F..{5em..xT8GJ~\..Y......|.E....l<....1..j#....Hpo...=...yn..........m.....&....;@.<.e..\.9.Ol......D\.LVr.....!n;J....(.P..#..sBL ..........%1..(P.v....L#z....P.....Q...a....N.-....c...PE..E.&...1t...,...i......m..........M..........V....!..&..3r...O.~k|......B.......*).....>...U w..4..b......e.:...@.r.rY......)..k.cs...<.f...Lf..U..F@....C..d..c.S..Z......E,O..V..-..f<.'^...9.cB.f#|d=.....A'.V....i:R.j..:2.?.~H[..X.G.".Jdb...E.D....k#Y.......@...C...d#J...=.:.H.]f......\......2z.(.A.s..b.i...EGH.,...//_1y.h:-.M....1....P3=....b...g"...=.m..1.....I*..7.u|P.T-UH^~dv`.J..$..+,....>.g.p.........w..f0.K..9LO.C}~.j....L;.,...*K......l......V9.EL.../.f. .!..}.(....%zX.AR.r4.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):524527
                                        Entropy (8bit):7.9996092097993925
                                        Encrypted:true
                                        SSDEEP:12288:W6x8N4Y4mvUTlS7iTEjO5n7dgJxiFt4QQXV0MdpygmU/IgW1:rqvUhtqO5niJ0f4rnpygYgW1
                                        MD5:C239CD7AB76188F472F2893321A0DA6E
                                        SHA1:F38F8A15C68FD182D260AF913B974CB0663DA2F5
                                        SHA-256:568A6620970F471E1516A3A2C472F552CF8AE1E18388F91297DA7981D413DA06
                                        SHA-512:0B301B28A377DEED66CC5EE5028DFBD9FBDB8AD0599D38A80673D4C64B07705507193F9B740851BA202132CB59DBE24F39F0B2C1EFBE9A1AA4E1BE9CB30870FC
                                        Malicious:true
                                        Preview:ns.......4..Q..cZ......G(.).....g.[.a.{y..5s...V.>.*..:2Q...N..m"...H..#z..("~e....h.....:...........ep..>[MZW.2.....<''....s#<.....*[.-....k.m.(...7`..UP...oh..c..,....Z.ch.......L..b[..p...=......Gyt...J/....A........J.@.$..V9.[......on>.^v~s.....&:.....z,..p..P\....k.......^....N...}.g....7.............v...m.Q..r)i../....g`..e)..5.u#.........5.)..4..L'./w........._g...8..... .._.W.t.....i+.zn.&..l.=%.".!..1.......M.....5NJ...A...,Y.........k}wD"}....X..|w.s...X.-j....w.&.......".N......C.0..C.......3<.u*.p..k.u.il..r..?.*.x..d+E .Vo.2......(....\T.Q...4.ms.....y5.k#I.m<....`..i~/....X..S...\b.B?'.w.....Y...t.-\L.....S..o...}(S........2...y...g.,...*.C.'_xni....Cx.........Z...<...}.N...:. .z^....e......H1.}.q...8T3.."B.L..t.#.U.s....9`.c.L.Q...V...,2.G3...Q.A.......i....d..I.2....N.F/`.(..8.........)(9.#...+.....5.b....YS.......ic&..Yr..1..H...J.O....+k...}.n..X0..o....x.*}q....Q....</.....l........t......H.s.ob(...hD.E.1].
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37258
                                        Entropy (8bit):7.994007247062816
                                        Encrypted:true
                                        SSDEEP:768:sH0HhiGBu6t0I/+/8okgUn5tznH76dSWyOzgbugUTBsLhoW0Q3qxxh:sUHhhHplWyXqgUTmVn0Q3Oh
                                        MD5:756B6798C12604BCCE7EF6C6A3C247D7
                                        SHA1:998EF716FB6030E8D6178456B985F5049BAF4BBC
                                        SHA-256:68473144FCD327A949272B461E356DA1B686477B2D7A2375263F15BD38EAAF19
                                        SHA-512:A34DB7188D58F225537E840024E85B4FF04B8D294EE33F15C299E8622D169FEE284DFF2C919529DA181D77CDAA782D4A433F120FF06352E6A1DF49D4E0094F2A
                                        Malicious:true
                                        Preview:.@P.#./.*.^.o`.V1.l.......'$.U..R|F9....il\....7I.....t..O...>.....e<....,..bw.....>...........&....L.}..8....~.!VC..v..:.....+.S...g..:.....N...n.I.M..M......oV6.}..s..&..&.a .=_./.H.......y[.].. ..E.'....P..M.[..0O.v.S.c7c.Q.,.I.K.._...O.<..O.kkI........N(p.....6..9.....G..Ih.D..-Q:.cQ....(M.+.D.h%....:.n.gC.)....iH..b^.1....-....4^[......<...D......E).C..5$G..P.....Ayx.....Z..<.'/.UW..{...V$....\o!n.|cO..a...+.{..K;P..B.J..4.?......g.\-U.X.h.:...,..[+..O/.1j`L..S...p c......v5..t.J.r....B,H.,..S(%4?G."2.3.,.`.@...^.!....O.U...:.9JODq{.....3.2..'8(....@P.......S.$.W........|AL...X.4.......U~&C`E..]..]4.....*.,.=s......)......L!.^U..4..)..Q.....t.a.....].gKK:[P..!.=g.CinM../...TB...e....C45..&..(U%ekp....E-w.=...........g......&..,m.e.f..r.C.)..H.d.t.@.?.....q.sX.t...Jw.........>.O...K..^.E......@..d6..........S..@.b..h9..7...c.).<..?Bn...E......o.}T..m...<T;.H(.@.m.E.KJk..S"#cX.......*....6....7..O..G.gt;3x.....4.........../3j....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37294
                                        Entropy (8bit):7.9948527651550005
                                        Encrypted:true
                                        SSDEEP:768:0fkK3RdSwnoSO16h8Un9xzWYIh1WQyYc98nL3m9hrnDMjZKdPBrnso:0fF3RdN19xnIrqYk8L2TVHN
                                        MD5:AEA785337B397A10DFD8871D65DB6AC0
                                        SHA1:B65234635DA882445CED265E61E834F4B658D803
                                        SHA-256:482F9EF00B4ABADEF5EEB6C893281A558FE73F14D56AD1F3C12DF3520130A888
                                        SHA-512:2B9DBEC305F0D9CB282608A296EA753BCD9384E803FAB87C2191432A32579CA3419DC0311474EC2CA242B0241C5C3EC838578E28CA4241E27A3D1CEE7F0C9786
                                        Malicious:true
                                        Preview:_eo.&.O...X......g2#.TU.9.5(m\z.....xb..I.W...M.\.${.....~......H..._.....?.9<..Z..o...Qpx.?L....`..q.B..F.......B.j~.i"hG.Mg.{|c.&A......A. ........`..o.;z.,....wR....|....6.@........C+.....KV.d..CV...t..s../r{...+...W..fs.......F.VOT.0@.3.D.x....9;C.\k...-.#.k......{....T.....<2..C*.o......_.M.Z.RFX.....wC.NO.#.~&kCO....5...q.5.<...~.9=`......Q.>vH`..2...O...O..p.+..y.f...K<....]......u.}_.V.:.r..)B...J....5...m]S.....>.4.Ko...'...I.dpM.\.Nd.~p.O.}.S.T..i..K.F)eL;..."..|.r7|^....... .&.;.<...U....j'.q.e.....M&.A........N...).......j...<z....JF.N..r/D7.'..<Q.T_...[...%;A.4.........U..+Ju...g..y..3^Z.....{.d..K..2....^.......zt.....^;[q..aT.p.....i.]HU.....5...7[2f..).?I.*3.9...K.GGS$.L.d.N>r+?e[D..d..t$....4.._].qc[..w..........V....&..kyy..G..kv...jxE*\.....n.'.V._+;7x...... .-...N...Z.......'7........_.G,....D........<..:...L..U..a.~.0.1Y.X..1B.I.%....P..+...Hj.*...h..Q...G.].!O.0.8}e..W$.t.}.Q.&..zJ......+.v...."Z.RE.T91E..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37245
                                        Entropy (8bit):7.99472100209125
                                        Encrypted:true
                                        SSDEEP:768:nufw7mtZZz1Oz1AeLz5EaRIctrrCNu2irZsp3jnmkVf:nr76z1nUEoImuNPitAjnmkl
                                        MD5:FD21818686C09101EF21619545C7653C
                                        SHA1:8FE55567CEB1F7DE31055D44B8487B2CE1A1827B
                                        SHA-256:10956D7FCAE64A7657755896402B1AA530D2E6CFBC63080492207152624E7193
                                        SHA-512:C0B8C40F522C9391544F322818B6AF1DFF2F558399902A5FFA49247F527589C2B8E5E93DC46F66D799BD0D62677755E07CDD275A1A734C4312772C8EFD213924
                                        Malicious:true
                                        Preview:..2G..*...7.7....Bj..O#...,...5..9.9A...5.4.3..B.#.M>...y..s..Y........v..d%......xW...mD.>F~WE..c>......d........6..6.*.5.C{../.5..j.......itN.X2./..D.l-.V$..*...N.(l..."?4.Fl.M..../d.4.m......i....x.)3....m...>.D.....+.....\..1[.{.0w...........C..n..v..F.1yq-..hk.q./b...#A.<D.iV.......jQ..\...s7....+......I .<..X8..?.9.."...[..EK9...<...g..@%...h...........x....- l..F.......Q...FBs.1.}.n.NJ........%..M..Z.W..x..Zi.<a.z.a.k........Y..Y.....Sq39.(.%...S.N.(.........$c@..>....!R..o.FR.5..(^.2cd..T....HY`.<h.U...8...rmc...AQ..Vn.=....w!.....i.EW.......h0A.....M.R...L...y.`L/C...6...."|'U.2]...A...&.......X....'..}...s8c!...,g..W........?L.K..8.....n..uv....s-......`.p._[|...t..3i:..^g.&n0d.KI...IO.,.?0...W,....O...:E.A.2=..8..;J...Q..4...R.J..L.C..g....W.;...y....o.pO...k)U....[.'.G.k.x..!.....w.Z........%....7s.-7...OSCb.LS.....w.B..%.......!..mMr..^.a...".v..g..y....*b]" ....K..U.J.;.WM#..I....k<.dDk.T..../{%.U..*....n.Z.b...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):37245
                                        Entropy (8bit):7.9948720056036
                                        Encrypted:true
                                        SSDEEP:768:fPBvIN6BxJqW0nb9Iceu7gjSCnPsS/SrXV9OHTPjG7ItgfrT7Af67R/YxZsM:hvIoUnb9lrGSf+ouXtgD3jM
                                        MD5:D5682AE8E34BA9947E1A05AC94433C1D
                                        SHA1:BA6004368A98E50384173DB973C753A9500FE51A
                                        SHA-256:C8E5EDD6D52C8BFA482946801371F559A2A06C45AB0F74E065107A1E125A8D7A
                                        SHA-512:9D811206AFD07C515DE7AE0AFB41A2E6D01E2829D52065DCA51600E6E3609FAA99C0F0443C7A0E67558CB823A58D7C2A24F364E6394CECFD6085F5080CACF8F3
                                        Malicious:true
                                        Preview:..z...c.....M.Rd..c.b...[e..L....e.l..`....0..M.t..V.$h.~C ..'....k..^vi..vU|...e..>Y.-......Z.x.H.g;<,..F.v..\.....iEFZ...1."l...5.e.\g..J?js....Ca..ul.O....3..R..+.....,..O....(.[.Y.`dpi1...~z....5...'.V..Q.G-w.O...cV....'..v.rp&>....Y...$E6......sI..@....FW.+a..8j.uz`..S......h.`.eO..+&5.\.Hk.\+.....rC.US..2l.z.........~..w$b8....{n^.."H..v6.........6...03kE.2.....J.u..$.e/...p$......@...7.H......?..........y..{.$. .m...w,T.........#...X.;.pw.3H.d.'.r..B...8.L....m....t...z...CQ+..>@.okh...m.u..}\...+..#d$.h.lT..p...h.....*.........zb......a.c*.......h.bi,.3..Y.p.........t...4...-}..*...w.=*..0.....+.[B`}..K.[......e53.^..Y4hl..ZS...^...UQr..Q....?+7*)os......N`....r<ni..7.V......NB[.)..&.?.......o.d.n..Ef....C......K....jJ............ G.hq...,.@...Y"'.t...h..*...d.../#.i.....%..PA....Ux.M..:.Dn:......).U...........G&...9G/....sE..=...G0....!.x..TJ......b.t24X.!.g2...j.^t.6P..D.&/Z.@|..3........o.. {.'..m..{.U$7.\..`.%.[h....s..B....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8178
                                        Entropy (8bit):7.978105504600008
                                        Encrypted:false
                                        SSDEEP:192:EocO3VaSgRGYbbIFrFN+PASvb5QKFUzT6hCBkcJ6amSg02G+MXYpS:EZRG0Ihn+oSj5v4kFldmLUS
                                        MD5:B78B20942347EE45BBFB4E1A2B57D13F
                                        SHA1:9B7614943C3BD222806B574B1386FFC25661FEA1
                                        SHA-256:ABE33051A3264CEC372E71E6C24F40977988BD61290D04B47CFE986EDE086958
                                        SHA-512:6ADA553AB94C16A338CCC8F66E32D1CCEB6B6DA4EEE74EAB366E16CDE32077C3478E6CB664090D5A4DCB08C92FFA0F1A27D8730169298EDB27E763CFDC517A39
                                        Malicious:false
                                        Preview:_.."j..! FT-..a...,.2...].....F.......K....0.ww.3.g_w.e.e...>^@I..>].;7...0...\....f.a..}...&.@X.H....6. ..)......4!......c4...LH.!b.5.....]b.;.....+.h(...@gyqM.....e.X.Wab.N.\.(....w^...I@.A..=.-.V.R.[..C...fVX\.N).o...z...3.c.."Z...e..nIa..&.K......*.C...;6....;E.......7.k...u...e.1.0.y...*T$......._j.y[B.6...M..7O...YX..Z...P..A..n..|H'W...r..,.........%#l=m (AW....4.....K.at0k'.W....%b.....I..)....&Pg..N.....0kx.2....].v...8.]...j.0.U...8...@.I{.B.9..H.Ek........<.......@0.H|..2\.5...<M .....Na.T..`!;.[..Y..K5...qN....}.#C.!..NPL.A>P....\...C*.WH.no.Du[.....n!>j..e[.].T...W....#...........M..7.m..9.~.c.T.$D%.78.Hh.....-N>........-....t.].Nt...:N.a.\4.r.).c.&...Pi...D.$.^W9 .he.(..4............z.,...:m.......gJ.:@V.K.Ww..#....w..)bW(...D4.S.:C..H7..B.>.[.&67.W.}..f...TVQ...._..n.......<.l.s.T.:@.9....@.Q......:>..Lq..u+.-....y8W........i{FT.'.....[.;..`.F..(..(.G....B.Amm..=w..w........E\..#...>^L.%>....JY..........'.H.\.o. .{.Kl..$t.....c.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37321
                                        Entropy (8bit):7.995441014476008
                                        Encrypted:true
                                        SSDEEP:768:jsgJQ3nyRCTITCE4siGHCXZ6II+Dwb7CZ40KuSQR5h1E:wgJSaCETCbxmuZ2CZsQjh1E
                                        MD5:2CE28BCCC8802DBE364EEE6A173261BE
                                        SHA1:DD2512920FBD7EEC836F71D64B3DA716BD426030
                                        SHA-256:851BE55BBB4DD08C8015ECC703454F3A234ADF45E1FF636F6447457DE66187F5
                                        SHA-512:26ADB191C5E1F70C184986086B0F764FB37ED48B0283D6A5399751E04848FF76ACE81E1D8B8D96AB7C2E6A76108F35FDC433464B43B30535D7E8B9860DD0517C
                                        Malicious:true
                                        Preview:...1l.;...hP..@..0....9.........cQx.......i].h..|;z...:.M.....T.&{...j\.Ib..A....<#.UuE......-"....D)..u...NI.` .k^.T..$.N.]..u.G..Yc.5g...Z..K8.cI..c.G.vm..%GSS.......x...*.*.....>1.<u..7....fn..[-.N"...P...<...t"....<...!..(w....x...0!...E..SVq;.Z..J......{S.X....w.AH,.|.cPx|.....b.o.L_/yT,p(+x-.....M,.Y.....Q..."X.IH...7..a<.=..l.}.....~i..L.9..O>.....R>..Huo...X...4.W..X.[5.,. ^..E...........?A.i.D....^..).cU.a5.N.S....=.....s=)`j.....*_%".[..6.........Op.'.;$...+.xKn..c.I.`~.W.k|......}...^...g..D.0...*...1S.8...z)K,..Cn.\..&?O^.0......g=.n."......^...`.2:&..=...A.#.J!.HC.][V.......Rt.x...K.)..H..^..A....!...|....LQ..%49..EQ/<.o.3....Z.>.0...li.O`h...m.&...NR./._ej`.z....Y........:'..C9......#....#..v...As..J1.....C.4.......V(...mU.1T.c....L.....w.Z.....Je...s.*...K.....7.v3`..AF....#u?..2u..........B~...$u.B...C.1.....yU..?.[sfz6}..v_v....S.!.D.'i...t .X...z.?}.bE|.W.A_1j..W.xg.E?o"......FY..........v.w...5..}*..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37325
                                        Entropy (8bit):7.994788645233873
                                        Encrypted:true
                                        SSDEEP:768:it2UE+WsaFie355f0jgUXFXBbpk4xWzkOrIlgWOd45xRA+Z/XA:mE+WsO1v05Fz3IzkOggWcMygXA
                                        MD5:A6FFC292D487724D87B24037647E5FAB
                                        SHA1:BFEA71EF648EB47511BB4F53E6A972241150AE43
                                        SHA-256:D40725C0CB0855AEA356BE1876E5CBB719786A1D3C5654B1CC64178A4394F369
                                        SHA-512:A44E7808C9C0F1C6DD1340DB6734EDE218D4FA61FCAB42353D7712197EA11BF70BA8581BFA742A49088B4630F23A6BEF276039E91C7D33247E39F309809CA09F
                                        Malicious:true
                                        Preview:..5"..;..I4..Y.gn...N.LH...G.{a.7.P..... ...n.....v.Q....x.z.^.2...Nz.o...^L?x.........n..>b...{.....Nt%..FD..#....F.,..!K.T..SA.|....:Y.L.._....>\...=...-...2...<.`n....-..v.....,..l..RN/.:Qj.K./{.3>......@kx.mm`.o.........w.4..M...@e<.3%......FV..N..n.Jq......*.V.H)<CT.)..GgEB....S.Z|....6J..ax'.TT$.I...-D.):+...3..V.wX.L5fv.&Bj...:f....g\......=v...V...i.d3.J.'v..;Y..(..t.p.N.4.+j=@..jf.R.y...h.B.......Rv......tK.....`._.&.-.L..fq.V[}.........ue...2....Q_.^S.1.Q@.(v.Z...8z.I&..J.gh"vD.X.I;`Ii..).....CX....&q...$$..b..v^.R.........v(.x....L...O...}.z...Bt...-.V.d/.yN.x.A|v..o[h[*Yh-.T$_....X.q.W. .{..B.y....x....7........>....(...0C..G.FD.. Axg,.E......uW....TZ..{...8...Q..7y....TX..[..3..(....lLy.........C.-.=.nKbg..t.!.......=.....UK.4..7.E.Zr..i.,....i2..@Q}....1.2....g_...db6...q.q.X.!O...../*...8e..MOK.A..(sz..I..j....(^G."...@..d.Z`N.k...Qb.A......x..t...].y.....6G.ii...D.L8.O...EA.}.K...jq5K8v_...6.....:mP.^.5 ).V4..(.".c.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37325
                                        Entropy (8bit):7.995551261300556
                                        Encrypted:true
                                        SSDEEP:768:yk0bmbcYG1cZcFzqOHp+MC8ljKr0uIUp8T8Q/KzZWW/H+Q9:S7l1cVOJ+MLIrWuir/Kd5/+Q9
                                        MD5:5A9CB075A629ED0701B9CC494B0B6D87
                                        SHA1:73EE4C5DAC823CEB34711BD29167B81080AEA51B
                                        SHA-256:467FDA7661CCCCA95D1F38386D3863DA5E2333CC9282A2B8BFC23610538A4829
                                        SHA-512:88FE89C7498AA5D2031B1CFF84B95AECEFE1C798C1907D4C36EC9B68C185BBC2F7DBD35F874EDD0BB4E4C3C2B63FD1A11B7AE0DBB116B354B3660BAB3A980B68
                                        Malicious:true
                                        Preview:...fPY.0d..........!.....kO.vge....N.(.E=>......E..+...)m.../qT2..G.o4.n......6B.........|k!...?.n..}..-.X..g..GsaVwk-.Y.w.Y^Q..3Hg..rlC.8B6..V:..U.J...EF.IO...#..|M.E,<....7..z..2..tc@Ef...i..YQ..h..C....3P....<....G..-)....A.]-!..=....@.l.|h..~7....!..,.m..W.!pu...k$......c[sf....."}.f..2......}..|dK#.}._.......6..t?al/B.. .'4.c..BazT9U.....`Y.Zk...+........Q.....-.md.......uz.U...e8..0.........1\.WM;).=.5...-.....m-.jYW:..W.P..{......f...Et.\..$.....a.d...T....Y.?..7.M... @7...EZQ./....<.9.....&DoQ.n.qN..P.&...5.U...|r....#...i..s....)3..)....U...r.0]..>h(..m...$...........40j..T..P.*...6.]J.-QB..`...t._.Q.^.....^Oz.0..6...,.=.L.....K.s....}..c..k-..=..[r..G.s.c...H...tk..{k.a@T..2"=.....T...0../".... ...,..#..dY..sG.<..!f....-)\4.m..*L..@;...}T...#?.W....u1....D.KE.....4v. g.Y~.(/\cG...<.....Y.;O...v.[..<.......C?5..g..fL.......p.9.V........T...P..W..By+..._.~..c...dM.B.8......u.w.ya...#z.\0).)...........c...p..4GE
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37324
                                        Entropy (8bit):7.9950349030088255
                                        Encrypted:true
                                        SSDEEP:768:17xEQUartdRwZ5Yuoi/eJ/elfa/18STfTYkEpTuQ1954uNnNCUhSUW:JiEtdUo9Jua/18ITYkEhtPvNpfW
                                        MD5:A94D7E09E1111E8E4A87FCED9639FEBC
                                        SHA1:00DA5A94C50A4295BDFF4F3DF45389F8B091DC2B
                                        SHA-256:09216DEC0C09A4A79C5EE778A6939E9B73C1F9F68646AA24F1CD00BEE4478243
                                        SHA-512:6DACEB56C24BC19AE893E58E55357C9607E77A8FEB051E89D2FA55F94C3C851E764B99E75CDA280A9A9ED154FF1B1D0C4A7F242136AA075891CFE0D1734C6841
                                        Malicious:true
                                        Preview:.%l.V_|(.[=..LD...n..e....%i.k..sx.h.V....<l......2.......Gr.Y{x.K.RE..t.o4>.%.8.3..(.....2..|<LH,MT...w...n^..v...Hk.JdLkV.....E....4i..aa....jv..H..3j.4Z...;.$.s..=.l..~H..#T......Lv.....D..4...s...X.) MH/.Y........-V...;..g..I$..........l....h..C...V..h3q..%..5.ukJC..o..,>.@l.*........1#.....FZRW...J.~....s..Jp.......h..\*L..8..{'K.......~..`.J...1.W;.,.&T...V...g...N...e.......6c..A7.3........xx..Va..boq.........j..{.;.2.:@..u..Gl.;.N=..<.zmh.=..\...+.D..h]..U...i{.Z.|.......|h..o...!...2OEG*.:...b)..Z..1.N......3w.+.V..=9......K...".....Ss.+E..B...+s}..h.j...(}}....:..:...v..Wq....(k.(..*......t..,?C#l....:m.}8.......^...j[9>..`.....4..q@Hr.H>..;Fa..B.UD.%.C.a.lw.E.6...CV|.:`3.;..."]....6...b..Q....%..5.H.../...l..A..pz.......g.U..1g...)..o.c......"........=.;C..._\.[WX.6+-....=.0.p.z.!..3...'....K..f..5*."&.9D..7.-.a.)L..bq...vfjdL6k.}Af.w.Y.+.....R.. ......8....1!..UF...e6..F*T..]..u.2.z........@v22..#.M..`..7O...P.!Z.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):37326
                                        Entropy (8bit):7.994422354095122
                                        Encrypted:true
                                        SSDEEP:768:PPpu+Xnzk9c8jUkDcbw0B/S5+kx/C0N0EigpQSceaiOFRa+BmLhOQ:5u+3zkK8j/c00RIRxh0IQSc1attt
                                        MD5:4DFAFCC7E1734B9E56D72B8D2B4D1D78
                                        SHA1:F82D30B108E864B843EBC9BBC57F3D12B02DBEB8
                                        SHA-256:E1771FBC4DA15CB55B36B1CF74E3E7393B4E5720F738B4CA06C0F4DC7A97839F
                                        SHA-512:8D38CD7DE275D52A13B5EF7067B443E20BC517125657B1CB21257A9FFF0AC3FFC482125FBA8B752E8FEE7E351A7A35F3DD3E98A469096C994D407EBF22230876
                                        Malicious:true
                                        Preview:.a.....v.=....S]_.\....0.......J\.3:.h8..L*!w.5.......9i.Z|..A...!/..-.....8<..1...3..a.)..o}D..xw...z.K..^....,.."8..D.O..'.c..M....pk.o..0.|_K......5.&.ru..-................u....+.-...w.....eiM...I99.xS#w............L40......6.r...~....,d..1...H.(..ckpy~w7....S....p..x....Y...V.6]...i....v.)*..J.:8...4e...|n*Z...&.F.._..4._..).S..o.?.#...?c..;........|..L..A....,7C.Xo..<.o.pf[.]..(7.h......2GEG.T....A.f|.A..-Q....G.+.y..v.D.cv{..v.I.C.#> z.)..yuG...D..U.o..%.L.1..-.'........Z.Z....L.$i..\!}l..U.......j.V.9Z1.n..*.l9...N..l+K..\..z..Y..]...jC...P...T.....~.en2.s."V..>....G.qI...........&...5...2W......8..qp.C....`.....t..>..%.....Er...n.$......T...d....f.iK.q.!.'J....%..M.....Q.a..{9&c],.E.Q....(...hD...n..? F8.k^a....}..?.(.....e[..v.0\..J.........d..@......?..Y...D...9.*+E...I]PQ.<..Y.ELR...}...:,P...8....O..%..`..L..x...&l.^..K.=n0_.]$H.l.x'.6H...{.c.@.r.i.,...N..z....t..0......h^.O.".9B._.......C._z 8[...X.-.8_d.....@.....mE...0.b.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37320
                                        Entropy (8bit):7.995206961486391
                                        Encrypted:true
                                        SSDEEP:768:EQXyLE3MptTJ9lJA5CQTZJKLgdZfOVF2/I51nVz2ghbBh8EKek4:EBY8dJfYKMd4VI41Vz20e1F4
                                        MD5:A2626E4800C1ADFD04D69F2EF6E56B33
                                        SHA1:654C408FEB3FF1A24852F7ACAA26F09E0BEE47CE
                                        SHA-256:2EF06F1D12D9825B790E084F2EEB29FF6F7AFBD528B2D09193326558535CE947
                                        SHA-512:5463C9A5B6889523B1A4F2A2961F420FB4B0573C520A826713B950DF202D65A2A66BE7E954003925BFADDB9A5409B9F980422E74F066757CC2384C4E9DBF3ED4
                                        Malicious:true
                                        Preview:Z."*Ri..............XQ.5.79.1M...%..Z.-^}._...!......{K..(O.]..xXs.Ti..F...&IG.^.].2..S....E/3...57....G.H9.!.IdvH..%y.....^.R...}..\d...../...Th!.3j......#...pBV.{........`.G.!J...;Zj.......1f.b..z@.i....JFZ..-..!.?..O..yEw%e.6.8..'....mY../.'.k...;.3...U%0.t.../..0.F...zT.yT..+C$z./=;....rfu/..7.;..L.wu....iF..V.o...].......7T..Y..G/{.$dd.m|i.].]..n..+Hit....&&...w..noh...[..W....2...y...j..j.I...:0?..g`..?b.1s..?..p...<.K.TL.}.F.:3..B.e......*.....t...+.........#......2EW....U./.${....p......F=....%JUA:..Sr.......,.[. .[.k....}.....E.*.6.s.....S-..#.ZL..&.o.,..wZ.2.\?..P..V...C~ZsY..v.p#K4.s..&.....WU..].l........3$..]E...........5.42..+.CQ.:...p.*..+.b:g....`.C..4@........6/T...4.6...<....xJP....v@..7...b....r ..e.c.9....lM..zp#._..}.....>S.mV...?.....p+i.....$d..tV.,O[.t......(......D..}...py}....d....r0.S...$.......P.0n._Jbx..:2..&.(..#...)....}.X.U$n........i.)X..........?k.1".{o.G".Z...J..c..K.+.#.^.k2x..-..KA...d...g.........
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37326
                                        Entropy (8bit):7.9955512388404575
                                        Encrypted:true
                                        SSDEEP:768:syUg7CgTbZmD6ZZlBObZGMrr+9xM7xRClEmYHu6vnOzywyKy3:KENBm2vObnrrAMAkOK
                                        MD5:9ED87C92451FD7187AAE16DDA25B5AC6
                                        SHA1:337BD4B3D2407200B478336696A3D93D6F02A547
                                        SHA-256:644E670619AFB52C8B9EECDB7AD6EA81BCA9426BE24C070A6F7D5BDE48AA3296
                                        SHA-512:5A46FBB80D1393F8618E6B811B8130813A08732A9B60A2248E499282255DD8BE35F1AFD03994E8EAF358853036D145D26C4C16A0378A38CDD65B61141A99AA8F
                                        Malicious:true
                                        Preview:..~....eQ.i4.......m..9j".....vv'...W.@\g.L......u..&........@1....s&8vR./<).F<...d.....@.h...b|..Fz!r...bh{&....X....K....T..me.T..(.E.........}.3.4......u..j..g/(y..F..y..........<f\..fb#H#..)..2...'.vK.w.m..?.&.g..|.P.B........u....QC....y.(.iX..;.......S..3s.JK"........P.).d.YOeL..E.V.C+,.uy..j.m&. ........v!..polPmOZwp....u.w...*...O^...x-.v..l..k.I.5.......J.{+AC..P.b....6l1P.OQ.."T'f.-"......p..kS.....,Np.......ZE^....l.kN.w.......AQ...x..G..NX.d\...F/s....>..?.Qtx....Y . ..a.K....mIL.......q.i.X....p.....u.n..r;..+[..[..4.....6...fC.....bY'.....C.A..8~.8B^k.e..Q.x.|.O".....L.A....3"s..9..d.P.YF..RL.3...R......F;..9V,..RT...!.c3%.Kd..M..j..R.aK.XSx...Z.SD.LlB..C....4.I..@...j...#n.|g..m.f...9-....w...<:o.x=!..I&.....|..Y...a..|}>8D.'....J..]e.T.2.......Q.`.f".#.v..;qB!......&"..>.[..u....g7.:...(.P8.N.2*.......5....6.3...X..>....ty@....Y...~.....R..,K..tA....1bD.....{.I!....K..~.nuG.g... sN(.N.y.u. ..f...5._=qh.<@N...@
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37320
                                        Entropy (8bit):7.99391612444621
                                        Encrypted:true
                                        SSDEEP:768:BPg/HBa7/dCzQk0jR1T1Hx3y/x/R72h4gmJtd6fdjgGhqmE:S/HoiQkiNUH2ZMkfpVqmE
                                        MD5:025413674D9BDEE5F5C7B74C09A85C4D
                                        SHA1:0EBADD183F740CFB5F2BB2BF605F165FA28E54C7
                                        SHA-256:3F55B8F4176EC7F750A6C5D258FAC4CEF784F7EF8F9952FDAD78052D534151F9
                                        SHA-512:F67F3F9DFDA109E17EECDB9A7653F69FFA3630E5DEF3FD27D2A7AA04C3BDA2F3AE9D636521C534E4FF643ACD4804158681AB091246E833E337C3F361062FFF65
                                        Malicious:true
                                        Preview:..{A4..N.|..xU...%.%A...:I.O^.#-&.`oX.7.h..|_...9.....X..1..}......,.._....3.....\.(i.6T..@..o.....j..9..../.7..#...F..U>Lv..D...&..V...W...e.{.3...{..`[.....Gwt*.).r...F..U.{.v.G.s.W..H.V.e.n....f>..SW.c.M. ..N_6....u...".^.g..~1..@@.S.9\`0Xv.JO..Y..+.V.".z.R.Z%...+P.*..#[)%...(..c=.<.i........(4.#...+.....`$...o^B...yt...K..>...A........T5..Q....|s....q.....@....*..F}4w.. .w....a.X>N.Y....Lro..........S.!.f........<_W...)V.~|....._G.2.ZX(..*A.KD%...@......zi.(.Z...]..u.....]...w.}i.7.@0..Hd...e.Ll.d...P.......!Y........T.RE... ^.;........L..&................9<...-T......p&G.n..>........o6K...."....-X.z:.B..(.P...+^.a...f......m.....QH...hlJ.U.7hR|Pk.DH..M .Nkd.JhN.`...... .}....%..../X...iN......`..w..XNB.l...A.......Qr...#..x'8..M5.....7EQyo.; .2mc.....8.........8AN..1@dL"8..H...%......P......x.h........+..<w...R.f..e....D`.2.).W.Y..P....SA4..{.D..R.l...A.mEW.%...e;....u^.....(......$C'2.P...~.....O...B...S..1y....;YD-6.ua.._
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37322
                                        Entropy (8bit):7.994218389528033
                                        Encrypted:true
                                        SSDEEP:384:AQ+g7OSvp8cXI/ffWwRXhCaesC5nnnjSHF3LLnWxlmTjwo/2hMIfx+fQjGHwHVOn:AqtR8VzReNnjSl7DglY9SaPbhq53+hR7
                                        MD5:2475795BE549DC6CC1B89400C3CB0C1C
                                        SHA1:B7029BBE1467F1FC7E2E444452DB9BAA4FC9DAEB
                                        SHA-256:EE075EA27061BB84D89343DB350D89C6277457AC75E391D9B1C08D2764452D5A
                                        SHA-512:78F31FD5C820BD468041E57AE1DA8041908F49AF097852BBA9937A4060D23D7C87E14EB0F44737E707758C1476BACC8447873EC91ABC19BEE72A5F0A95BC51EB
                                        Malicious:true
                                        Preview:6!&'t....B!.g.L..p$B..m....%B.r...(|.+7(....#.....5.c....d.z..L...vi?h*...\N.E.......5c..#-.a3T.@.Y.K..-.....e....V.P.f.QF(.R..6....k+...+.j..WKT.......\...S.D....o.+..p.a.H.}.s.7Y..NN...fQk....!.........!Q..}6....-..~..i.,P.........a.!_...Y..=.c.H.*e.)....CU/"m.)......<K......3..M...9...cP...:..B.'..u:g[.Y.c0..=m......5.I..7^f....P..1...x..+(].P:...$..rr.M.Q/.|Q.lS..1Lk..d.f.A..........Fw..,U.}....B.:.y3--5.......`..C..........Q].Z...yT.=D3n.l)..u.._.Ux^h.V...<-....y/y...+..m.....C....s..)l|....F.h..v5...{.~......q+.n.........M..2....O^~.u...Z..(].Y`l$2.....&...J...*....J.......j.a.p.R.:.vx...{..H.A.H...6TY#...I~.u..5..>. E...o.-...N.:..'1r.F.......4.=......5.n|.....v..R!......nL(....uHL....6)......P.......G.4(..N26.7k....I...m.9.=6O.Mz.I.N..>K!....c...+..w...B=#$...X\...:.z.r..!.\......o.k08..&..1.<...T..m'.K.`.zY....Q.....D;.j;.].QaZ....K.Z...UG....x..L./.1...#....8.J.h.J....u.j.7.z...W....eh.X...o`...'L..z.Bq.P.<V.hB...;.^.e..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37325
                                        Entropy (8bit):7.995231941216344
                                        Encrypted:true
                                        SSDEEP:768:/phAztKGSB8vEo3vzqNKu17fK/Yc4/nmVpvDOxLAA9i9W:RytKGS6NqYY7f5m/vDgLAOi9W
                                        MD5:1059FC7034BC18655D7CCEBED96026C9
                                        SHA1:330542FAB047BF7C4FCBE5900A9CDE2538E137D3
                                        SHA-256:9EE3B6A7FE7A2D04648757CE3AAE0619F59AFFFB1E55067CB0748F39FCF5B558
                                        SHA-512:F4F52D07D10505603ABB27CB2D1D7CE84B31A25D31BEC7DA965FBE9D7C1E106FF765862625F99E0CB81DB5F480BB02F388E462D7A001DA2B2337EE6AF7CFC4E4
                                        Malicious:true
                                        Preview:...k.^....?dQ*..J%..l.C.Gf...2....T.......WS...jGM.{......y..f`....6.|.&.......d.;%.78^... ....v./H9.f.G...E..K...;.c .Y.8>.x.eL(c.....G. ..4.E%....,..{.2..].c...&M.L.BJ.x..M..f.....8s.-.of.$....C.aTO.cvFX....E.k^7-..,'vvs...L.&.....g..........l..T.dR.|........b..:.R..Q.\....<x...T]b.Z..L.. ...........G'.0...u.`M.Oq1.K..~CD..M.8$.A$...B..........u.0..M....X..k.?Iu..(.B.,7.Q...Z.N_..L,c.5..4.u..8....a.YW...[.E.T..w].._.|........M&. c.G?../....a...X.=.Q.-..X@9Y. .9...r...c6".mG.K.Pp.E[...n.xU<...?. ........5.$...N.`p/..^mv..... x..3.@EuI9...x....x...h..q..QB.!.#$....../.).kd-B...c....q4.R=...}..9?..|`.....+.hY.....-...J$&|.S..#.pH..~GJ.2J.........^{..rm)L..b....+S........t9.cC1kL.Q?..R1|.......eo .Z96.>.w...(?`.&..s.....6s.l...0"KscL..<..Lq.S...i.i.......(l.O.).b.....N....)..l..jN......oo..";nA.QnAhz...G...:.-.W.[..g.r.H...c.y...Ba..8z..7..K2^v..5...s..aF.....O..ys...:{.........A.u_.......N.*..x....S..A.....0.$'g....d ..........tdw.lo.^
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37322
                                        Entropy (8bit):7.995433966291774
                                        Encrypted:true
                                        SSDEEP:768:uyB2gzx2AYYCO0ZuHN15Rnz75TIbfKf6tlnL0cn1Cvlw3K9:vB2gzg6CO0ZajvZM46DnLl1CKK9
                                        MD5:11070E5C4DC212BA818C95E54318D6ED
                                        SHA1:04F73B25B3A39ACBDCC148F7FB7EB0D0A887C347
                                        SHA-256:3AF5F5DA479B1B63910CD9CF1325588611B47A3447CF509F0BC92DCDBEED51BB
                                        SHA-512:35FC87FD9862AA2078A5D5429F4684B25E8AC76590554BAF7B8641BA8142FC06CE40F09D1CD35943B720D9E1F0B87D4E7B8297DADC379DCBD39D5B92A4850A36
                                        Malicious:true
                                        Preview:.emKi4..R..!~......b,..}.>U....k<..'..^.&...p.$Y.[.&..5..*...J..vB.+..#..A......w.L.I....f..Oa.6RF$O..-.....>....w....r.M.5cNqQyI.......T..u.z*m>.S....V'...@.....;.0.U.... q.:)..BR.gq......p.L.l).F.N..:.........Eq.2..k.5.nY...9.3.Z...=..&...#&...!.):....*..F.....%. ..@1... ...[...#za..B.<.D.u..z..).<.r.%\._..Fflt..O..(...v..h.W...|.*Ya..A~f.Z..k.Y,.pX.f....-..8!j.u.xp.l>..zL....v+.NEn.......;..6......."..R.(rc*;.*.v..Q..O71D....D.e.........W.g..Z4G{2.E.b..|....?...9~/8.T-~..j...P..L...F.vA.Y....H..ck.uA..|.L..T.tKS..x&...G.sf..Z..W...0@.K..^=....5.h...Pr...g.?..2.^7'.+.7Y......>..f*S..2......._....Z.W.l.'...M.Q....d.7)f...abb...+......%._.....:......A.y+sX-ol..........-.....v..I..UDr9.>..E.B"P.1....7....p..5. ..4w..@..d..a..L....F..G.?..l.....<. ....k.{_yR..F...g7'io.).R.9.......Fw.e..].j.T.?....$.."..&k.n.KE....0...b1..s.l].+.D;.SV.i....N....Xf..[.....9..l&(......d.s%sz..OA.7&y.4....?>.I:.....L`5wf.M..T._....~.... ..........W..4..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37324
                                        Entropy (8bit):7.995430352301751
                                        Encrypted:true
                                        SSDEEP:768:cQwFNVWugdhjipf/PHF6wCpZCkYuF069lgHEH8UsaqnZlZQ52Xi:cQyTfb/t6wCpZTSEc64lIQi
                                        MD5:2DBEB4CDE0C8FD4408FF54404835C161
                                        SHA1:C34AA9CF32C781F2D9AB665CEC172A58AA256976
                                        SHA-256:F9BD01EEF145E96EA4EF04A724F37307EF62ED120831EBD0A4BD67A61FFBE419
                                        SHA-512:6776DA0E740499A8962D5B1D08A704F1F5006DDECF46F3CDF2DEA3BD37447C097C5DB801F6C6DBDA424BA38C9E4522717734BE6E993CEC6EE43ACB15C99A5E08
                                        Malicious:true
                                        Preview:..o{f.:.+.....f..lZ.SV>[zP+.?.\.....]...\.f.!Y.X...~.....0.^..2@.&..+1\..#..x&k..[...,.8E...q.y..9-5...c.|C...R+..\$.}8Qd.Z....&Z`l4....+...A...xq..S..R..*.........'.....b8.....r@..........;..ON>.'42.G.(a.O.s.....w?..x.D....!..Y.....W........"..<...e^.!O..5..."..L.c..91.........@a..1...X.r...I3. q&.._P.7+T...Go....W..HC..]...9..ct/%..@Z.d.,%.....J....z1*F...}G'\..5........i.2.%...Q..Y....br...]LU.y..K"?`...m4T..H`...../.l.I....f.k..1j...zFo...9RWR.#D........bE,....Q.*..Ho"...=.L2.."i|..U)@K..Bh8;`.~..j..=s.Dr.&......%}......0q..i...T....0.J.......5W8q_....Vd....5.d..0B.d.....z.'..9.s.VM.+...o.W...........A.......q...Q.....h,...k.G..k^Z.-...$U.....~..r.;Ep.mz..n.....Im....0t|I*...:..mrPV...vr....6K.").=....5./6...5..(.0P.4..J"&..*.F..K....?..`....Jx.p....'.eF....D.x-.s.....QCP....!8..4..p..bw.L..2b.3"..W..~....b.{..k3!.Y../...q.a.C.9....h$-.y.....a*.6....T...z..........3.A.s.V......:..K~p.s.{....Xyi.....D6....;b.......;.......RcC7.B..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37322
                                        Entropy (8bit):7.99543011954112
                                        Encrypted:true
                                        SSDEEP:768:GHsmkf23iLP8VRJP4LdmWHEmuaXYXjDUYfOiPwuoBZbnbR:GHsmkf2SL0hghm+LOzDU57Z
                                        MD5:F2DEAE683D682279EFCFBE44CB1EAEED
                                        SHA1:C8623D396CAA278793A7BE9652AE8079C6EBCCF0
                                        SHA-256:A842B5460434B6CE96F1702D18A3DBFFE14A2422655A20D49EF59FC944E4AEE4
                                        SHA-512:AAC802F34E8E92C72FD9A4AFDCEC30427B87001EBABD2F2E09169F5C733CCE9734F96858801E294E6FA58EADA7A4E1858F76D350A83A31C24FAB5B68335BD0C2
                                        Malicious:true
                                        Preview:T.......{.j.?B.oT$....C.....G...s..."....o....D.......DA@.d.)...y....aml9.F..?..S8.D.g.@e.B^.0o......d....` .N..l....;\....dt`.....7.*...)2......T..q+..y.....A.v...0..@....lW......7.H......e.J.4.<c..V..o.SZ.y.d.Eh.....?.L.....-.R...O....A}H...X..L]..J..Z.....g..L+..^a@.4...#3......P..]..F..U._...O..:C....;/.../.[4...YD]...2....[...9...r..n.$.VZ..T.&...Z.G.ec...."..g...r.....2A.1f....8cS....d..0.4.. .}....v.....U.....!..+.@~>y{....A.y..>c..,D.d.....{+.R..8..y...0m....*..PBU.D....D/.@.....g-..s......+P.RZ7Mu...-<.q..4.kQX...w.$.S..K.......>z...hz...`.%I!..k.?........d....2..,...t{...[.U...\~@j....a.[L(..%...].3..7.t.s.7h.#q......x...q.m.y:.fP..|.......'.:%..4-....3....8....^..`..|j.J....b.E.Y.b{.B.>(......7.0....>...'T..B...{.~...6..xD'..+...l....?.%2.g.'.<...W...T....j.(....S.n.....b.....o..2H]...@.M.....I.{....2C..x..b]6-......Am.<..s..".5.K.Z._..m.J........|.!....5..GY;iF.._.^.1D..V..Tq.{F...._3.$.aL#0...h....6R..!jkC7..?"..kq-
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8175
                                        Entropy (8bit):7.977162450428511
                                        Encrypted:false
                                        SSDEEP:192:bnYoj525nwY7avBm0svVg76qA/v0oK9IsTrHAGdg+5enpS:bM5nwtYJKdr5rHE+kpS
                                        MD5:7067AA5F9859FD2FE7A21662D69C6C23
                                        SHA1:9A0FC4C35688070F8A533E79A3247D0BAD6CC7F8
                                        SHA-256:5DB94C998692E790069374BCE9C8B78BF68DD9F376E149B6E215CACA15CF399F
                                        SHA-512:13826DA2D784E0289E2D5C985B92CCBCCBD0B79F0B87C26B045B8ECC8168A6C01556EDDE2B6FE3A2F1C7F3453D74680CF7C6BEA62A83ABB61D9146D70D687851
                                        Malicious:false
                                        Preview:.......c...;'.../l.;.'!.w.&.....O....s.|J...Pe........6....WYmb.........+r.V<~nb.nL}...h.B.n.\B^.k.b`...&YY...K....+...g.i.q......[.|#.....ctcS.O..........u.J...9d...Jx.t.AB.!..B....).K.<0L.... aJa......h....Y...GxQ..E.XK}.....6.W.............&......1....lMmy..\.e...........f._!..9:*a$.{..j$*..uB...a..g...]}I.....(.= C.H.....V@..wcd2g.P...$..W....k.w=.S.....8}...L..t~.j.8.O.X-...,..l...$C_p........{.%k.+.1...>.....;|X.i.[kQ...Z....'...;..2o......(!.....Y.9Yetgj.5].5W.o.0A.#.7#.._...,...Z..M.;.j.mw,....{m.b_p...mg.M.F..."u7o.....R..d...j.A..&ohI.@....s&..d.H.i...=.;.b..p.{.%.*......]....7.y....Q....Zn....`.....m..#.Kj<.....S.z.W|....'p.'X...H2./<.}.2....\.....k.KEJ._..c#.@/7..:.s.i..a(..Rs..UmSt...h....~..=.G.0YF#..&.....L/S%O.0..v>.....F...V..3,....$..K...a....o.v.1...V`....1.=....(.5[K.X..s......7.']n.q.M.g.q..b...QM..LH.D.... -..[dzE.v...Kf...f...X.Y.F..N...'...eSrX=.U..(..W...]..m9..7:...$.....5$..!....}....zc_..\.7..s.B.N..".lr
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8168
                                        Entropy (8bit):7.978183742241897
                                        Encrypted:false
                                        SSDEEP:192:bD5tW1O0SHJ9FrExMTUwVi2NF6wOGmTfZkjM1rwoUsupS:hr9WSTbI2mS72ruLS
                                        MD5:C71E38330D9729F6F4467FE3CBD0291A
                                        SHA1:042C5C0429C82672996B6C37A6F91FA838989CF1
                                        SHA-256:1CD58B1A4C3D3483ED8A7DF31129480018C9EFCEC4B96E1CD2C4C6C95AC382FD
                                        SHA-512:F1311191E15AD5982B417E79451579AD75F3181B7DBF34BA2452C915F6D3F42583E3A78ED669F2900163467DF1C4E0A616106438A0CADB264BF725A370435224
                                        Malicious:false
                                        Preview:D...i.....&r.F..iwb../.Q..8..$.;J.Q.I;...,...a.P.......f.utk..3.zn...- .:...K..k.E..2bnv%S..........Vl(.$.O...N.yc.N.XZ)..vz....A.h...d..3^.._{Z...>...Q..q...LJ'....R. \......oS........G.....Et......y..*..K.)..1f.:...mO...}.l.[E\. 9..$oq..Q...3.....b.N..{.K..c...$`..:&.na...q.W...G<..;.1....M....<.8T...X.m7....o.8.)d..5....7...L...x%`.5.<.8...Y.!.B.y.a....y...........To.:O.:..< .3........J.A..nT8......ui....<._.uR.{.n.....O.27.#...x.OHD...G....#.........J/...m.....ze...-,...1_.......'....G-.p%.F.^.*D..5V...s'.@d9X....Q....UE......x.^(.<l.`.\..1;6ob..'..../'.&)iv..x).{...h.xF.G.d.(o........h.EKB.L..Y.g...}..8..1...qi_>..l.;e5...I.+.,.K..8.V.VpK.r'M.~p4.....p ..G.........z.x...$=........{7.Q...Vw....}.[..A...aV...Vl.lf......x..%Kz..+$...Os.W...G..a..5........P....;..woA.".r..........w.EY.vi..\...h|R.|.4$.B..3 ..f.^....m~.T]...#..^...B^`.&.. .........#.....2..v._..[.W.....*u..,7..x.u.T2B,..s.B.."=..........$28..t..-..r..Iv....w.58.'..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8170
                                        Entropy (8bit):7.97959888336268
                                        Encrypted:false
                                        SSDEEP:192:vjLW7hYhCpEjjWcFARbVnGnPclV4G8qxUv2dExrcamp3pS:vWtYhCpi3ehVGnPEVv8npgS
                                        MD5:EBBF0460E113A834528D0BA4D1BE8E58
                                        SHA1:BEEB85A8ACC5BD3BA8D91943D098267E70B30A00
                                        SHA-256:2D334578B4CAE6FB45CDCD349A3C40E468230189D5AD96FEA2EC6C77BD30C298
                                        SHA-512:AE1709F60B3570DB8DA8F1F63E4B3A5B67FF91DB3F2FC38506951D5F9CE255E1995586E905689AED12563E6922B55D0C27DA30C2E7ECD5527FB06E6A97500946
                                        Malicious:false
                                        Preview:..~....>.a.4e.S=L.*..6=..n.?...j...(0.Q:..M/THC.V.....V....O"<A...+T..t...C.v3B..ig....[.....Z...^^......mds.8....)..`...;.B.W.........J.'..1? ..u.f..&../.2.........VI.O..0..Mg..\.y....P.v.B3].......j[..?m<~p.k...-.s[Pd....o.%.lh..8.W..E......b.>..C.^....a...,...sG....l....Q..F.s[.7/..{kW.....gWf.......L}...Ll..9w.J?s... ..x.T....P.Yx.p..!...$.XX.D].|.....t...*....v..4"..S...5a.P._U-. .A.S....b.r.w.....T...).uG..y.w..o.,zF.IG/W..N../....cq<.t..!.....U..##.s...L.~..U....4'........'..3..3....#...IF.$..'.Z.pU.v.[I.k].-M....S.%q..\(...-..]./.y...:...AVd.-.!.`....0.*L.p..v.n.....o....m...W..[/u...'..uk.T.r...q..K.H.8g...y.U....I2.V..C.'..n|W..N..].6.ry.{....L9..!&.Q|Z...>.>...m..q...8q]D.{_.wHa.....l..&.^..4U.,...&3...n.S..H5...$j...E..N*.:.S.Y..(.b5q.!3.tn....`U..+.r...8Y..'..,..y..i&._.....G...8.4..<).$.0.C....s.2..>...g6>1f..7F.F.j..L-9C&s.A.........a.........j.)...T.s.....I..$.iaz.l.G../.V.um..J*..j.[..`.g(.m....aSrtn~..bg.P.......C
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:COM executable for DOS
                                        Category:dropped
                                        Size (bytes):37285
                                        Entropy (8bit):7.9949756007461685
                                        Encrypted:true
                                        SSDEEP:768:T2k6awU+aeSl3mF7NkbOTgJ3Ht7shprRxS/bXZX6T/Ftj4ecUI:TEo+adO7NkLJd7ipr6jZKrFtjJcZ
                                        MD5:4B65A476A156182A6D279D6B359BC768
                                        SHA1:10AC8736D922009E275BE7748E849C43F5903D21
                                        SHA-256:8A8DCBFE2E46825A010C0F4DFE92D2B6C20A5A9016E2F6069AEB76900B3A34CE
                                        SHA-512:E88899C8D326EF574D325AB7C9019F4CDE782E4A8B77159105E60BF5A9CEEEC7674C21F7DF5D2643B86F382B37CB4601E95F6A04CF6F45D9DF6FFAAC487F2A4F
                                        Malicious:true
                                        Preview:1....SK.!.....h_}'....*..#g.d...O...M....]N..U)K6.}6.j...}."..g...q.d.0...w..}s((..;t&..UC{2..t.4.......=y.f15.^c.......#O.u.Al..c.~nu.bUZ.yB:.......$........D...!...Aa&...;.p<..K.k=#..5l.`.R`k_....v.K.$.3|. 1".Z.[.%&.%.....z........_/.Y..W.z.~.B...\..i..f...".~..+l.%h....)7&.....y/.....7.....K5(.f.b#...|....9..g..l~........BS...\.....C{.[.\.R"|]...;...i..:w. ;..AH.......;(.auX...CT..........u.!F.+.#.......Q.hlP....a.2I..b.j...3..j|...,..k.9.(.......U(-.=a.G.Z4...h.S@..<.[...F.h.._.D.......[G..=..|Z...<..Jf.4..c.x:!$..>.....ys..m.I~....H....Go8M:]+.OT.........p..X....s.../$.....t.J.@....".#..F..}..w.pYN..#.[qRV.X.....)....\.c..C..?..N.2.........N.......]P...}L..j.k.Ak...ir..X.4.......eU~<`.L...u2......^...A..1..k...T..$..>.W...z.>.t.PSC.C...J-..-...*..B0..m.v..T..<'.../..8.sAA.Q.R.AN....#2Z7.r..6.!.|4.....9..NA_E.OS..............nsg..../|ot...|.....PI......v.jX..|]....".r.N!..R.^e.r.......Y%..h.....f.:n...0..+..Nh|..).J.....RG.c..=4G...4..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8167
                                        Entropy (8bit):7.977300112139107
                                        Encrypted:false
                                        SSDEEP:192:1OrTXgUvFP1/G+6XyayDwFMEfRVoRRC3m9C1wub3GJkpS:UzbP1//6iIMEfreCSC1sgS
                                        MD5:5EA2F3D5E30D3B2B8006B87BA9B8B2E6
                                        SHA1:B49EB5912B43B86895DFB5B1E8F82479863B755E
                                        SHA-256:93111D71BBFA31F59429B3AA2DC49199CA649DF14FBE13126EB4B3C4EC745552
                                        SHA-512:5BA58495F70A11D56999C6CF840DEC66151823B37B53758F380A6C115BBACA8204013D2CC191654B3A99D1714E645C2883389DCC31FC23B199379A1BAB6C6BDB
                                        Malicious:false
                                        Preview:..y.....4.R.J..Q..R*&.....N..5X.,.X.O*.....p.2.>.7.....gY......$.m.9..m.^..`.)..AF.`F4..x.Wd6.L.....<..B...m..92.....<.j.....#-7k.._.....-...j.U.@3)Y.m...V...1J!.oe...q....[..X..Nd|...=..}.\.a..[..-.z-......i.K..].I.,5r.q*?7...v...._.p.p..w..+M.g..6.v.F+....h..FV..$..Yn&....^....(6.h..!.*j.(..:5....B....[o[..E.....&.CmCQ(.O._..=..I.]...c\........Ia..C.;p 2..H4{.....`n[..'.%...?....]....Rj8...~.B4S...).8m.l-...%.`T.3.-......$.Y.C.)H.'Y,...#...X....C.0W....Z...9.,.C).z.I....0K.....e...:DcN bw...,l..._?...D....8.-..(.3lV...I...D.J..*A....z.I</..}...4)7H...;h..B.nA....`h0L..Gm...8 w.....1.1xN".ih$...(.2....|.V....%..'h.La...?...^gns]s..u@.c..4.DD. .......W..Q.....z...GDO.g-V..e...R..Q...e.@.y.v..w.....9.b..]..=...=Q.*.Pg.Z..*......6...,\cQ3.....93/1).I....9]m.9...7G../.&@rJ.$...z.OR.;...S.~}.?0.#.......<..q".............G......;.5.L$.....}.....fig.>....O.1.*{..d..........]h......o.y..q6..I. g...n.&E._....4\.....o.......>2.b......X.....).
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8168
                                        Entropy (8bit):7.975569660168694
                                        Encrypted:false
                                        SSDEEP:192:yRGINNsoyDMFZ5PUkRzel59rsxmJGfLjqj8FGxi6I0jFi3+fVjpS:4GINNsoyYL5P9RibhsffqgOy0JwAS
                                        MD5:1716B273C716BCF10B3CCF81074E6D9E
                                        SHA1:912FDD35B4700A2654AA09529CFDC826099359EA
                                        SHA-256:EC85715D9DD0F6449C905A778E5A50CC0191B721D2F384207E324943EAC70A4D
                                        SHA-512:F7DEA6A33A84B220A6699BC85439C36F8EFF53E178871BB56DD22A606E41E5AA56721B6562DAA7F8625752E121E737EB09C0D138F30A816B45A6FDAA38F95078
                                        Malicious:false
                                        Preview:...c.CF..hX.@.{s|.u..X3..|.......F.<=XM;...0..E}....=.O.fB.5?.l.<......^..@QD.f.[.;@......_H....b...W.!...#....[.....q...ho#..k\..rbI...z!.,.+*0S!..~.V.{.,^LhC.qd..=.`7A...|....w.^w...{.g...gl. ....D... .,..<......L...j...[.Y}..s\t.NN...i|6.LS....r\\c...6..K.|J....HK...O.<.V..^......*.=..m.e.:.x.?...q..-.....>.,.6ezH..,.@....=|.L..L...\...l...V...(...S..:.......<toSn..f.a!c..\Ru.9.A)..nV..a....x....}cq.{..q3..........R.F6.#.k.x.V.S........p.....si..4C....L..].A..$.v1.D,.x.d..h..y.....&,G.%.........q...6..........{.#.......j..)r.L...{..q.M9...i....Z.J.JZ...%[..S...\b.r..D6U|g.8$.X....V....,....0...%..(..'......@.m88Y..l.6...,{o.<..bh.)}.....e....A...2..x......}`.s:..;..+..!+......_.....,.....4.....Y}9S...D..!<.r..X...n..#5...)S.....X..o&<e.*.....P..,.'.k..j..1./....g]...^\...pfI.z.S.i.<^.e....@.B.6+.6..........D!..[.8Z.Lc`.u.....?......J........N.........v.,B.T.aql.%..(e`t3.;"s$2..`..*>x....b..h.d........4zK...8J.I..gW.j.G3...w.$.>.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8169
                                        Entropy (8bit):7.976012831220604
                                        Encrypted:false
                                        SSDEEP:192:+PMiCdAQZOJ/PK3XS6l6CUvc/VuTasqgr4RblzxpS:JeIOJ/oEvEhhg8RblzS
                                        MD5:F46EDDDEEE0B5C3F8D4B02015274D8CA
                                        SHA1:3EB2D93CCD9F7E54DBA103596C92697F2373D02B
                                        SHA-256:333E4F9D5BC1F20950E8E7C0CA7EB2644FBBE7C3FDB46A89C6B0A58A0CD712E8
                                        SHA-512:685894E5475A3D140CBAFFA2CF9F30BA8D8456D8DA2D05D6BFD9D8D200621803AFCF0D5A1C8689561BF6170E637553E76F1358B900F1D4F82B006028B6857AD2
                                        Malicious:false
                                        Preview:..:...T`...W.`U.eG.'NP.jb.LB.&.h...j..mCp.u....1.P.Q.s....=VpQE..IMO.cOV.z....8X.M......m..C[.4h~j;.Q.8....#.n .H)......R.~..A..f.^.a]?Q.&......7.fku.h..\...Z..........W...q..c....g.2.Kk.\.V/C$.~X...t......&`...1....S...T..N.~..f.B..C..p..............9..[...k....w...U....D.2..SE......n....aK..0...U.p.Z..Ub.DW8JU.G7..#!.......BU..M.....k.U.D..Fr..)Cp>........:_..Y..1.\i2.<I........n5..b..df./E.......'..0.....W.',[.y|c.V...-9qf.V...k..>..*T..?..0.YP..65Nr;k..{g.O....#<.CZ[....N.-L...AL. ...4b../..U.u....oUp.....l.d\FS.{W....Y....'...U....R..y.D.....8..|.\'....g..F.#Ee.....Y+...g.kn.@..v...5..I..lc^~.v..........4*\..5...g...oN.S...\ ^..Tg*k...U....=..)R@.w... 'X|}Xj....."/......c|..e,N;.WuRB.G....&.wtV.'?..6<.}.X.L@.j.9........p...YBM.....y4.229.uh....CP9....."u...s...G"8P....*.%Q.=.Y..h.=....OxrH.V+9..`..8.DY.j...V(...m6....L.+..AJ..0.|.-...q...?..17..{BY...S9.I5w.V._?..uzLK..p...UYd...(C>bM...8..&.z#?R.`.7^`...1u...t.D/.z..)/h.*
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):8184
                                        Entropy (8bit):7.9746442423230945
                                        Encrypted:false
                                        SSDEEP:192:5GIYs1mHa83IXkHFxieSIOodar2jHpMQnemLiFN9RHKEGpS:F1m6YqleCrghn12N9BKjS
                                        MD5:3CA2F14983198281193E097E1DBF24D5
                                        SHA1:43C83746DCA30E2E1F9FA90B4F1DFB1E65273D00
                                        SHA-256:B6639B8CBF0E9DBB3B225E88A6C29EA7BBFFE936B045F6AC750CA0108B9E572A
                                        SHA-512:76A58BCA49612F42BE63BE361AEE2AD05174F984D1D74B8A69CCCDEFB677D9B4C060A022C4E0E3C49A948DE0AE7A8B5FE6548CD75D6907A6F75459C8511D1329
                                        Malicious:false
                                        Preview:....d\h....."%~.P.T-G.%.*..3.:....=..)...~.....:X8%..8....|.*ll.q....../..._....g..*.. ..O..f..cv..+..U.U%.^.:3.N..........|+.vk...<.......P..k....E.{.>..io2 U..ae.[.../R..]H..f.bh.|..Q........}n...&.)...y.... ..6........5U5.4.A7D$....A..9H......n........-..+...i7...|E..o.G./......-Ej.7....X..)p.}...y2]...^...l.mM\o....vM.`.......!.#......6.|..9...5.{|..D5.4F....w.^U...TX\...2...>F.C.Gtq...a..q.Lu.Q.W.g....K(..g..{.,7.*.C../...U...KE..\....kD.\N}.f...*..0@.......t_.'.../..R..9wJ.74..~B........w..$...%..Gs.EE.[=N+..M+.7..Chp....>..k....g..=..(...['J....g..kfk..^.W....J(-....g|..3........c....&9.../.>..o...._...95.G.Jh..a"..I{....0.k.H.P..n..;.k..{e.R...b)lB..u>2,...f......7[.,.._".k.Gj/..j*....q!.3R.}....iM.W.EO.{.......=h|.m`.}.?.H.^.Q..#..J.~..WQP.<%.WyO.l#..E.p.3..A..I?.W...'}.?..\..7..E.3....r%..]....%.../.M. x..U.Jn...c."..E^.62......Xb4...).*..].;....,.A..[..oph.XwW..(~d..h..k....@...:.z...2d!.i[...3........$`..}Yl.....e....;.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8172
                                        Entropy (8bit):7.977781291542636
                                        Encrypted:false
                                        SSDEEP:192:btNmy2s7pskjFkMmoaDZusjf0RB1SV5JYr/uwYpS:btNmy2sv/VaDZ/sRB1SV5GwS
                                        MD5:C59621C020F63F60BEF4CB0FFEB88CF5
                                        SHA1:C52C985F8499000477CB568FC8952DC8C7519D6C
                                        SHA-256:F42C5BC2A327ACE5AC1DCD60460D801BB2339EC79D88234A423F54EC418CC941
                                        SHA-512:0BDB7FCDB6674E0A6627B854A80A8E6A66FC707DDEC436DE29B703E6FD537797DF12252E32542500C0EB7619FE356B48E02227FC4B36646B1D5FCBBA7D4598B7
                                        Malicious:false
                                        Preview:.T...v.....S.....&&.....dl.g.G5.V...<...]..hp!/#..g.[.v2.w.(.....].j.p.;..1..zfb...g......R.!.".>.<.....(#.._.:.Sz.......[.(.....F...bb....B....+y.\...>.&.....:.?a....R..).J.5.....J-..R........>0'.-.B..l.8..g.;KfilI\}..$P".d.4....E.F.....V....>........\.ZA..WW.......FqvXLy...h..P.K.s...]E.N......?....Q..d..#.8....di*\Mp..[.LI..u.g.cl1.3.{M=.D.8.P.....QTp......kO......../...c.....Q[...t.z.L|.)^.R..O.Q.I0p*D._&.B"..~._.r.....W...`.Ec....k.......cShmZ.AF~.....'%..4....0\{..(?...'J.<2...D...... -........5....k N.\.Yh......%P..EH..........h..c.Q.7e....T..u...B..z..'..[..%...B..n.w.l.wH.4....w.i.....Q).(..v..ZL*....#.h4...'TAGM.X.Z..33'....R..n.C....K.<..........\.;..".}.....:....<0\2e.Vu...iG0..$......do...g...e8..N....HZ.2.2%..g_..v|$a.2.N..km~.h[.....@.UH4...V...5..W.H.....6..-.jy....~..q.o;.B.....J.av0.bi.]..7j..)9C.R.n..#.F..B...ol..6../..Zk`s..-R........k.H.D...7..I.#.@..X.i.$..p@....U...g..g.4Q..X.}....'#.`..",....}....n..=...<.U..hm.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8181
                                        Entropy (8bit):7.9795731216361965
                                        Encrypted:false
                                        SSDEEP:192:hu58oNdKvVEb6c8oZ9ooX3YHEhJVXYu3v/r/r0aQ0vp0/qaAYUJHkpS:hs84KvVEb6FgzX3z35Y0T0aQ/cBHgS
                                        MD5:DB72D3DD7D13AC5409F6383EA82322FE
                                        SHA1:89EBDBFBA1BB7958C1D3BB2CC5E526B9F75FDEE4
                                        SHA-256:34FE0665B512871480827C3A1C6009FCFBDD1CFFC4EAA0B97E02F3AF07D917A6
                                        SHA-512:25A11AA574632BC82F011BC2014FA8B4BD24E4B2555128889C5F5DDA90294A7E0FFB874DBBCD6B5E8618CA1E5DB3D54A89E531021597D234E195153569D2457D
                                        Malicious:false
                                        Preview:..f.<...TGJF../.%.e..........V&.;0.-../.'..]UJ.....JV.."gu.^Gn.d...MZ.T....0E....65h`f...^.....Hc....f.=..:...j.....S.ek?...Fr...N......t.V..v..K.[2v.q>..DSG!KT.zK#.C........}Nz.n....1..C.L..Jk..8.:p.bLN4...A~C.b.Y....`..s..L..~.#.e.!..A"!..NJ."..h.8....N.....)E..f.E..p.....U...-.k=.......tp.......YW7Il6.....;)r....=NTThP........3.......^R..k..w..IB=d\..n+7.......$.*.....o..9....|d...5..~....G=.>.XR.v...r.&~m=..S...>.+..X.u.....@..m.....Gk!...R.....W..d...^.(N|..Q.....P.M/.............y.\%.a...18..;.t4..Y^ ..*..l....h.r`..DQwy...Y+.f...........2..~.'.K3..AX.uT.s.9.......T.......vh%.7.o..1$._.....S.]>.a/..3g....7.E.=..M....n.6.sH......w#...U....6....Z.zsB.G.q...B....L.]....`..Y............_./h.,<2.....8.......G.....b.@.............k..{.F...+<gM..&.]U.q.h.]......#\0.S]W..?... ..3.......R.ZO.I.wWq.....$j....*.r.`..v....]j...V*}B.].!&JK...{...`x......'<..".SO.X].y.sP.=9[]D.V...z5G.......S.......<O....N.Cb..i.6k..U...W.d......(Ed.)Y.Q)8..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37289
                                        Entropy (8bit):7.995683172148246
                                        Encrypted:true
                                        SSDEEP:768:p2A6ptnUbXFmEZY4uP/ZwNiVCcxbarkqi228Y8AK:F+UbJY4wsiVPxbjP2283
                                        MD5:44D7E49BD2C5B7575DA9D1F90744333A
                                        SHA1:3C4DF1375B0313EFE652CB847CC5BAFE7933D905
                                        SHA-256:AAE9EEA13E387E9B1FB92A488649B28A4AA5C59BDBD1AD72ECD4083DA5217CE0
                                        SHA-512:0C8011E1FD3AA694E26075076FE6B0A47C0ACDBC2A430AFB255FD2C6060370A6B94612C326C9165A6B8B218FEFB47B69A8E3A40D8D3D314BE64C29B7A1D55476
                                        Malicious:true
                                        Preview::.HE.....C.....-.ek...`=..5.I......f......2...1..9...&...o,O.@tXUh....../...^.S..:d...3...8 .0..].1.,,.:~#.. ....@\..pR]ZA....1B.R}..*~2..P..6d.i..<...Wg..".'...T....6F...M..-.~...~y...s.........6.>Jo.].....ha...2.u.t...{Q....n:.4'4...f.C~6l.....=.&..-..d....Y......og........`..BG........_\....|.;_..K.6B.4.......N....X...m....Q....8.a.8.........s....z.S/...ZM.p...*&....x.....7..H\IW...O4Jj....y8...a...1........u....Z.z..aJ....}....a.q..mu^.../..k.'+....Y.d....t.>..9...N.1...k....~d.v.*q.!.j).|O....G.x..<k.....T.K.8..7.{...n.r...m...b.|x.-s1..[.|c..R.......}.c..WSw..V*........]...?&..)....M.U..9q^.....pNmr...>uN..'..(|.V8K.<.)...x........^...7.'.....g`h.[....bnT;j5}......9XV..."\y~..........3v....v.v[...+K0.#[o.PA.i...(.Vm._...A^.L......vx.sT....$....$..!=@.?..C.ekN........}...Z..gLJ=Qd....q...%.....O.....#...B...[m.`.?......r..Ik-{=......$.yq...L..:..........Pu....=.B,.>....j.hE;..68?0.v.....Q...C...^G..S..A.H.....3....O.$..j.E>.R..4....Q..xq
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37275
                                        Entropy (8bit):7.995026181850991
                                        Encrypted:true
                                        SSDEEP:768:4iA/m/jGxjV4+mMORrjlqE12ruvtTzczvirSVc:HirjV4+mvTtTzcerac
                                        MD5:AD0252FFD876BA663795A081F96A3C98
                                        SHA1:79C0387167BAC0EB4503147BFDD58C885BFE346E
                                        SHA-256:D0A60DBE185E0C80BA8B63E499A30E420023312A67163EDA89E4E79E5B4656E9
                                        SHA-512:A9526EA32F4948AFDAB004C27120CABE5FB1BBAD929A039A20D4A79BD4915838EDA960F35546DC27BB17B1F5CE73614AFD229E62E4422535142AF7BC35DC26D2
                                        Malicious:true
                                        Preview:2.S.n.c.\..e.......63QN..Z..._.Hxu&.6..w~3.&.4...Y..S..P.....S.-...e..6$4....x#H..p.n_...xd...R..F...6.....o.../Qf.,.Qp/_.f]....2....Z.?...~....K..r.zCt(jH.....4..t...lc%.d..e.....Y......^.s.~.3.....d.Nl=.k..{rD..?..z:.A.-3C.R.o.oV|..-~..>.R`.5s.E.5[|P.Fi..c..M.9Y+.G.5\...B.......!........f.x..HL.=....C[....-...T9....k..A..W_.P...%t~..f..P.BN.+.....T......e(...~,......pv...R.E...C5l..d.#...1-.....`d.?.thS...O.*i..,.j.... .".Mj"..z...Z...cv.g.v.o...hS........t.r..:`..Z.6...op&.&B".....f'.|..OB.....E..........F..-.).>....\6..@2..@.9..|Y;....U.8..w.A.. ..........;.k..s.xB$..}m.nN.$.X.h,j6.~Aq..:.......U.#.i.{..b.x....W..@Ps....,.z^J...b...;..Qou.}..S..e.3.CX..QJ7g9...$L.]{.r."...p.5~X.1~.".n.A:z..1..r;/?..s]g\.Y...f..%.....bD\.....)...U.PZ...}.[|[..".EF',...$..._.V^0.......t.dg..)...".R.......=5.nl....E.*..."..H.i....".Z.....p.|~....Qmsx.l>......E:.I9.:....Ax7<...G.Q.].. I..*c..nr.&^E.G...[.......$.e.. .G8...ID....Qg.F&..5o.....c.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37281
                                        Entropy (8bit):7.994922771442923
                                        Encrypted:true
                                        SSDEEP:768:XhvyCTW98uKp4883b4h5O1LjyiCdFpoZhK3XETo0YsoTcDw3Z7L4i8:pbTKc4l3b4EyH3oYUT0slDw3ai8
                                        MD5:04F9407C803D9D2BABB4F0CBCB74488B
                                        SHA1:6EBA73F9CEE362521A29AFE3B289520D6993A2BC
                                        SHA-256:19851E81157B6DA17EEB932A078990D3CC92CAEF9EB01D52E748068C36D09DDC
                                        SHA-512:888548A8F659AC33ECC2367611DDB438AD9A719C64318AE05C2D4DF421CE4309A875D376A334620721DD276F2232C8B6440913FBDECA3F49AC2F113B2A004D85
                                        Malicious:true
                                        Preview:..$.....J...?.H.>..1...f3....WzQ.W....-..p...W.P..U..v....k.HA.6.Yn.i..&.-.3..0...'.Q|......j!G..V.;d..s`.>.i.B..CC.fr.3q..GTU.b...B.........-9..V.Wq..^..Q;..2....H..\..K=.;&...28..t....O......E..C....O........E.]7..]....a.....T...$[.5.B.G....<..O..PW.2U...9.....9AO.7]....G.N..#.X..V@*.)_P:........N".......].. ;41d..l.^9..2...ZI-...e..)....w.(.T?.aZ.q.X].0.,..E......B. i.(.",..'`D..s2J-9.z.../...D.x).T=.A.e.$+2.So..9K.MR*..@..I..k.#.cd,q...Mq.}...E.Xl........V..!...s..D..!.b.........4...^..c..jf/.k....g`E.......3qE....U...!|`..;.L.../.ve.....*.....04.).d...",C6.../..Bv..@..o..+.......iJx.r..j.....|....L..y..W......*V.....y.#.9.$D}..1...C...*.c...w.~.o...Sj....1. c.......P[.......OJ..&.k/..m"...x..On._~9..@#...{..%U....]..T....R.CqJ.v.ZT...6......-.i.J|G..\(..........X..q[5a......-.}.x..7$.|....$...8xzO...^'w....F7VKNI%C...V.p.......3.......fvA..\.c*V...NQnN....*tn.O.f...T0.Z..h.....w..s.6]...A+.nl.O.p.*..a...~..>z..H.....B%..Y...S.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37279
                                        Entropy (8bit):7.9955381224513244
                                        Encrypted:true
                                        SSDEEP:768:71JQFoyqrUE6upCVmbon8O+CVP6N15+yvMtDEuXnD4vB3IsNnl:DzUElpCVV8OZm5+yvMtIUMJIAnl
                                        MD5:78E54976AEBBB17F3863D2AE7EA7B42E
                                        SHA1:7264A5BEBED3A77591D24C67D713A944279D838D
                                        SHA-256:E3DE09507DFA605E8C76055BC7BD63D17EFD4368D3E1C4690172A75A1F8C1EAD
                                        SHA-512:73FEDE540D57DF7822D5F28FBBB2696810B59FD9D7953B91ED5722FD4A71CBF72A9FC305D8B6127D14F95F3E714688A2DDFA597F2BA3E9116C210F9B1836B18B
                                        Malicious:true
                                        Preview:....|.H.xg..a..N.jl..p..F.+9..+.....S[F/..s._.0..o.*..?.t..n.,[..s...4.D..MkZF.c..'p.#...E...aD:...nJbS.8.yik.'.4.%.TE&..x.N.MJ..c....=..-.M^.I.%..U.....2...}?......W>...0k....<..8.v.co...o.X.`.r...v...N....8F...X.w...Jx..(...k=.......B./...\....Q..8.....\=.V?.YA1..Y.PF..4.....S..|.e.nf..........p...[.J...W....2.. ..P..{...o.G......\.'.....p....A..|9........-E....C....e..\`:)..R....jy..#..V.6.ZdP.,8.|X.z.o..!...?.<..mJ2..W..6...].....I.u.2.r..<,....{....;V.X|.:.....@t5r\.X.=...Hpo........`...n...Fd.g..l.ji1...W.{..].Z.*T.*.io.p_|...D........zAQ.!...$..1~[..zN.r:...]F..30.I...A.le....Lyt.i....A.0....M.....4......L.`.tm.Iv]E...=w..khP.^'.G.4....u.5E`...[.\.Y.^s........!./6...0....F3.!$4lv.X...;.es/%.[..A.A&.H[..8....$....=....x..a$..]....0|.....M.x.>..#._../.|.oP)P....x.?NE,....H.p.i..*.];..g.{........M5..r.MAB.K}.......l%8.h..0*1.....s.Ohn.)h..n..MX&g.A/.fjg....~x.......=#d).R..X..J.......ls[F...i.s...../.o..]&..Y..6..B(. ..ei).~....S..s"...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37277
                                        Entropy (8bit):7.994913111435199
                                        Encrypted:true
                                        SSDEEP:768:nQPMfJoZVM72A+xmtZiqkFZseE1E7XIC4J2J5Uh9uV:nQPMsVY2fmt4qdeE1gk1h9G
                                        MD5:18835CAFC5BD4AE6D3E1D449B6BB8FBC
                                        SHA1:88B0476313DD7607025DFCF95FF0154B1017CAED
                                        SHA-256:E80ADC43B90A2682FB7C8ED8EAC1881519EC2296C5B069E07B0CA4D9D82C7727
                                        SHA-512:85D608D196497B433EA557829FC1119ED45E64F5FA5392A2A843F1717A3E12D64D948BD8A9EBBCDB7F1070AF6DBCB539D876EA7FDD31B2ECE99E83F47410137C
                                        Malicious:true
                                        Preview:.P!..e/2.I.%....|g.<O.5....~..}.....k...<...M.t.a......|..O..........".}.+....^......0......Hy...(..r.....N....._En..><\....k{^.z..5Nln..5.a.wQ.,.M>)...S..1.A....*g..V!....r.b.1'w.u.T%......X.P.0./...^...j.n:.z.o.@..F.Z.uf...B...J.-..t.v...Y....3....Hcz.E..8m0..C..[.-..t.._.....t*..c.{aO.%.J....6dI.k!ymS.i.....!...P..S'.R!z1..&c....V. ..5.!.."i}..N.|..wex..9.Z...N...b>.a...;.{...]......:C._".g'.k`A.J.........&..d^oz....;S.Z..D..c.....[N..e(...N...v...... .....I.Fp..{W..7...../..)0...h....'.....>.&!v.9.+hD...&..1.`...M........C..i.F...5..[..Vl....b.~h.5.z..uP...+...R..2.l.y@R.$.y.VJ...d...6..V"..-y...`:.........z.....m^.}cf.O..x.q....X...tL...V..eS$.f.........k.%..}`...`.8.lh.b.kKhG..!.RW..*.@.b..{.%....Q.'...q..$.."Z.].S.-.p..C....<kQ...K%..7.......o.....h.?6a..{...Y7}vIMw..x.r..uW..35.T*....n...@.n....ai... .....jB......h..S1.p.....H.q.3E,7c..P4.a.|..7.0..f.g.,>..!W...k.b.....U.?.......:.9....S.F..."....p.$..fs.xH...~.J....d%....22..{@..Y..l
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37280
                                        Entropy (8bit):7.995986455328824
                                        Encrypted:true
                                        SSDEEP:768:k/evEJwKsKLswTOdTCsifFswNV4DotH94o8gwH90oGJ+hAxXGTgx1azCNxKG:9YwrK/si9swQ0tZ8GEhSGTINl
                                        MD5:90C134A95F67F50EAE177C819666B083
                                        SHA1:48F3569FF8D9EE042F423F8064F3B82B241342DA
                                        SHA-256:B665ED93AA47143114D2BAB4BAB1F32BF8BECE0757E6030AD16D7309ED92CAC6
                                        SHA-512:13F7840E04D4387F73EED8761F77865B5229E530407A72F4AD609B68AB3F91FE0FB5E24339E39A7302B2C7CFAC31BBE07CE379FCE371B3D32B3BA9636FD9167C
                                        Malicious:true
                                        Preview:..,..o.=.2R... .N.T`....Vj..w.5pL!w.."...G.9...e...(o./.I.*.bMAz.0R..{[.x+.?Y&s.{.|....F.R...>....a.NP}..?.....L ..g.@Kr!@./.Q..|^.\$........tY.K..pK..2.w.,0P(?..:........_...Y.2..4.e.H.v.Y...B...X..8..C.@+g.I..*.H.+.....t5.... .2.s./.."..BU.&..m.G.....0q....G>aN$.m.@.jn.R.........i...w......5.9......j...(....<<..%V...B...^Nm..$z.W9..s..d.+..U4..S..i...r&..^{T#.f[...g.R..p..b2...n..$.A/.!..E...3.q.E.~.]........V..o...1.....Q.[.....U2.7..(UO..&..Y.....4.Ub.,...L...N.; t_...~...K...Dpl.M.G.....S....]AD.3,...0..vz.......F.}......&Z..-_..\a.....y...=.OK7.\.Kw6..&...R.....8....._..x8Hf....v......l..%W..Q..t......E....g..J........TB..+.]..6zf...6_......T...(S........1W.3.M....^F.k}. ....T..@..>.."e.J.O.W..3.......W.L.J..|.5..t....c/.f....Ag...E0..U..!M.v.%...amxy].....Sus{.&pG>.TR..!.N..+`~eoo.%,n.|.99..^vk.T..\m.i..>.y....s..~U5.i}VUmk..%D.sb.a.."92...<F.....1...T~....w.....u..'.l.L...L...... ...R..cP....3..TnG..e...0.f..... ..o.$...........T....aD"UF-K
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37280
                                        Entropy (8bit):7.995109959421692
                                        Encrypted:true
                                        SSDEEP:768:dVZg3yX0cwcaUM8UXPW3WNBWcie/6hK2e2GRKWXzDguZinihFjC4ttqnhpd:dVZg3yX0csUM8UXPW3WNQciyGK2URKrt
                                        MD5:DC20643C03BD9CB0740D7911BB4F4283
                                        SHA1:0B74969E4F8092A8ABBCF5C091ED1FF91C6777CA
                                        SHA-256:5D910A541304A884F0003A65E466142B7731440D142AEF64D1C577DFC199C6A4
                                        SHA-512:FF89920ADCB93E6A6125E9A7E9E1608B3710262BC34127DF38915033222B485B28EEE66399DF1A4ACFDA496CF8B3ADF21ACD4CACF34CCA6CE66F459A1046882A
                                        Malicious:true
                                        Preview:g' ..E..;DwW.M.".#w..inG..k...N3.e..<.w.... ..hO...B.!\>:=...[.gH.......y.....C....@.....N....]...J{.a.n..k.^....g.p.:......z...j....K....%s.g.. .w.+Y.d.....z.m..7tfu...,-.......&.......rx=....Cn._...~j.... r.8aU.q2....s.....E.z..\.....o.z.0......|t.N87.N.[..!;`.Ccmt.*.H.bt]ZaA.....?.......V....w&{g..-.W.....A.,{...=.E...U..T...@.....vs..} X....%d...U.B.....m..c..3H6..3.Q.bDeL..k4.H..C.i.P/v..k L.8..{?....B84c`..02].) @...A.x.m,w.=.z3..&.u...bg...#..c{.9.......&.?o>J.D..=`.r..U.....L.u.t~..v....1.o....o=...B.p.m..^S.....$..E.....M..K....LX=..O......EM....@%..\..xs..c.?`U.}"..$.....xj.u...L.......W.G.&.`......J....*(...[..cm.s..`.7. ..3.60bb..f.>..<_.JU.._Z.{..><@H6Z.E>..$3......yV..|...........a...Lq(;...oHhq.k.R........_5.su.-.....j8...Z..1...o....,v.!x..TN...^.L.~/........M..1..$.~.J.I....l9*T.X..;...|.....|~.D.....|.IR..]..]4o..Xm.....3..0...2.1=.Sr........#..+)..~L....$..0..p.?...A'{5......a..G..\._./...f.1.s.i..Y......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8178
                                        Entropy (8bit):7.979234559138106
                                        Encrypted:false
                                        SSDEEP:192:XM9H9KLTTWVmaQyUJf7svdAD8Vs4YGxhYhZIq6YB6i2/LApS:XMB9SiVfQy0wSoVFxhY8vYB6i2/gS
                                        MD5:810643E45C682EE2096AF1FA90D41A4B
                                        SHA1:97D4C9E254F348B86A7AAAA67209CA05607F245D
                                        SHA-256:D165500DE6D41ED3BEF9BC2DA9AAD774281F770B914E699444197263B8DB83B0
                                        SHA-512:8F11DCD3F4AE2AB16D81A3B15D2AEF04438BC9E4979A8AEDBB6AA5022DB16E037BD1B7F0A296162FE9E78C9144F197A29B560EFDA9ADF1F85A35D9D3A7DBF383
                                        Malicious:false
                                        Preview:\.E.(.1..W....]...=....VU....1...|..+."3g...6....J.N..a.....u.......<...........Y...X....A.....b.Z.z.'i2..B.|&......LT..sC.[m$..mY.....-o..V~2Z...C........wo<.n:...`.r.k.../...:.O.m..C.Q.Cm..y.H...E.....'nh.Rn.T..hr..........~..Y..r5.(.....,]..;...iw^......+..........H!4.\.....ue..........)..z.S...(..T....-V.........|.ee`D.6.".;..MeP.>3D...~'..t...a..2...Y.'...).jx.%{z.J...dO.../.3.e.....XA.0...K.`b...ah.z.e.yI@......./5.*l......v.t..W..?.=.G.!.l}.1"..6.6..^.a.4..."..2.PN...j...FWO.....!OsV..(D.....f...!Q`YD.:X}.8{Ba..C..3a....n.>..y..C.#.x..A$.*..!k|.,g.G..'..Y..7b....c..?Hg...O&...G8S..."n.;....T=.i....S.e3N.r.rF...3.7@&o.0...f..1|n..r..v........o..w$)N+.&......|.YXm`..Bv...X..'...8..3.J.....?....2_R..(.h.....W].:....Q..Q..z..X.P..&..U..bi..~..b..7..j.E..Iq.j."2...c.x0.I..Q..3o.>..tE}T..Xb..^s8..ve.a#..U...2.9.&...^9..E..0p.>PQ._.\....Up...v#.J.......@-....2.1G.1r(.M........S....Y.*.Z..f....J.k..8m..2mI.1?........f/.DUL......b..N...X5.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37282
                                        Entropy (8bit):7.994646031602082
                                        Encrypted:true
                                        SSDEEP:768:upps7CKVTyF5NPs81WZRQ0YD09Zagc5sHf7UAGfMPmu+Ib:uPsm8TyF5Nk82RQ0YD0NphUQ
                                        MD5:C336CEA2A32FAE5DAD5CDBD499E7D133
                                        SHA1:4D9D9989C54C25FBD82F77A8F044885C8D53A0CB
                                        SHA-256:C38527ED4582884C49F9C2A9D43B577426F1AE69FB86D5ACA1EDF3BAA2EC0635
                                        SHA-512:8331AAA084CD73D7C6F3ADAF602D01D1352BF92B8744A4F2085ED7779334DA5874CB8D82548DA6495ADA3353731B488315992CBCBED970B8EFAE5786DCD2EC91
                                        Malicious:true
                                        Preview:.QBv{8.....X.;.%l.......aE.S.X.+..z5..C.wB..mP3f.._.5.....kn.wS^.y..98.\}.VV.K..~@.I.6..A.....h.L.l.k.O...!J.k..S]N.....sk...<..._t..a.0...V..\..W.={.1.8...n..[..1x.Z.89..%N...uQKMZ(Bt=.h....U...|......V6..tB?........4,.v.Z..U......o_V..t.....I.._!.rgt'.T...3.......v.D...O>G...j.~.i.....de.zJ.9.T...F.]I..].4v....}.VK\RZ...(.F*.:....l..A.............}..(...u./...KX.=|....)..M+.........L.*..I..\....../.*.XE5.[..i..*.|.JV.d.L.$.....;.q.9A...N....>...G...^..[O...."V c_z..J/./f.oG0.$.N..c{2@]........L...I..S.S......+.v....^...............e.B..L.9_'.C......VQ...Y..C,..r.s....n.H.<.C..\UU.2]b....;l.W.....?...*....].F.O..J..Lf....%^.TU.H..+..yk.... l.%............Jc...I[s.4.'......Ep..E.!..C.}.h.. .......c..]#.rR...[."[X.u...P..._...v...y..y..Q...R'......s..Z..e..JvO|.~.i.6B.6....f]..a/{...Q.../.........{.-*T<L:..H.0..-{..T&.nX...a0y..@...Ca..."..Y.6^.."ir...U`.m.lvO1<T..._.P..xH...2..8....}.(v.C...b))..6...a.^$.Q..4...iQ...].~.X.b...h....j?..j...j
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37283
                                        Entropy (8bit):7.995553063674505
                                        Encrypted:true
                                        SSDEEP:768:BFrV9usXSSzr3w8FSwsSZIOFyY/ahHU5rxbR8zm+U1XOkq:rV9usi0AQI9cam5F98q+aekq
                                        MD5:26C790C4181B23F8E23B00F99238112A
                                        SHA1:E3FB4B0D69B9965EAC0402B9975BAFA9573CFE78
                                        SHA-256:F2FE7D89D26CACEE867C91A16DC526B0240A052829B9C347C9D37B5EA4202B0B
                                        SHA-512:5C6E086A7C2851AF923D90FE0943A5CCAB0A66990FE93818BB918EBB688581E471144D43E8ED2DDC1CA2D9C66B645B2D21ACD236250B0131C7EBC43CA411E5E8
                                        Malicious:true
                                        Preview:.Q.E..co._[...S..:..?..s..GC.J.%.L..n.K.RU..X.X.F....<.w.....f.J.."....(%W..".._.9.v.l...~c....3.V..8.7,../..{.9...F..........3.3..*.......a...H.y.d.,....&.]A....n1....m....>MH..9DTc.C.n..F.m.......k;..d...N..^.W..>eke0..#..:^..).l6...P....o...D|w......n..0EC.Ls.#.Kb....e.i.F...)...3,.......}.rS....'<..Z.....5tn$..;.u..NGlX".Dx..,iR./.X.K.,..Y&5.i...,....4d...x..p..d.4G1.ao..z.;@.x..-)...t....|V..I.....S./.6.V...N..."z.:I.0Y.{xoQq......L...a.y.oo. .jbhe....=T...\.S.........?.....C..]....F......6.)....{y..T....W*.k....Y.s= .?.u/...~O"...J.3.K....j.....)3.8a./N.,<.L..G.E.v.><=..a.t.U(...G.|..Y `......Xo...=J...o-(.5..:.9.B.6B.E..wQ...........D..b.bL\q....+@7..R.Xc)....O.U.i.A;...oR....m9....g..X.._*=......;t......Q.v..\..c....2 X.....'..q.37P...V.W...h.j.L.C..K.H.q..A.0...G...8....L.#fWz..........A...!..ax...%..tnNY.P.....Uw..|t...).R..me.o......&.l..iD........\/....2.,|.qB.|.<m.6W.U..y.\3......8..E.T.>..qtn.a.m0.....=..8.k...ZO.:.B.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37295
                                        Entropy (8bit):7.995490896959826
                                        Encrypted:true
                                        SSDEEP:768:Cdp4Nr6ck4Yg6dN/6KNw0leSIvF+Y8HTNiUhWVK0EHG5ev0aRy/Ygr6:Opsr6wYg6dt1lPItn7sWVK0EHEVru
                                        MD5:B8B4AA105B99DF140E78D102185C2A75
                                        SHA1:61DA7E718D5A8BBD13CAFF1F51D57CC5305E5B65
                                        SHA-256:1E94951A259430D8CAF45A20C8109C3B5BF47557B63D7851B584EE33A476D683
                                        SHA-512:6E5C28B20CD314804D21FF6F26860CFE8BADC51765A6166D4293D487E58F8475DC94455D8A92E1D9C1DC0F611F5D7B1F4584DBC9549967178C1118D7411626D3
                                        Malicious:true
                                        Preview:...;...ZJ...?Kl...`...xE.....;..O.U..u..{8...-RoI.c@[.)...q.^...45.*&|..o.~d.........:LW_.(.?.T.X.z..K...9..[.._K...1.(..P...R.NN..A.y6.=......#,...0...r<}h/cx...3_V...&......*2...+hG.p.a.Y.........ur.b.E.E...o.Y.l.m..M9&...vv..JX...U...*I.Z.%]c.m...G.+)_Nf.[d.........8.......ZjH@....f..R.d..'...A.Bj...6...R...Bl.........%.00\8.1.s....j..N./_B...j..n...+.c...,Nj@.~j;.[..&"........S......@......C..:..il....*..<...].....\.}.%5'...V..*.d..U....S.`..X.&..._.I.....*..I....8 T.nH..D....M.......J..h....v..tR.O...34..w.X.7w......@C..icyd.._V.....R..*...... .Z.}.*..k$"N+..+DOC.4..r.%.D.ja.j:[..6....RF~.:......H|G....U......o.E...........R...>...s.....S2.......N.....Q.....s.N....4.......O.....&m)....G.F]..1...r........B._.!2!..=..(EA.8Q.o...w.N8.Y..W...1{..r?....u4jz..b8...r..4........W\.8....;..q_..c.#..?.0.E~...A.S..,Lx/......D.~O...~..yL.D....>...z..m..m.8Wd...*.Yl....g.h. :..-o...`2..w.H.sQ........}..!....|C.:l.....r.].#.A.+..IR.)...Bq
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37281
                                        Entropy (8bit):7.9947305156495885
                                        Encrypted:true
                                        SSDEEP:768:l0ZJ9VFzLfz+iSL0+I371pAZUAWbAIthLdM/Wt+ZDH78hAm:laXfzIpo1pqrWbAIeRYV
                                        MD5:605C7EA94D316F4B29AE6DE47BEC55F6
                                        SHA1:12E1724B2CAF140C21A93A3FDFFAD4717B6F4356
                                        SHA-256:89035E4E33730827AE98826D633BD4F7FF8A457CDDF273C40CDDEF3D7C6B6031
                                        SHA-512:1D0E7AAA0469C19EBCE38F6A87424275A77024E9BBD0BAF13AE09113C647FFA906610A539130B2856BBE44B21522D3297D958EDD5E4AF36DC8C9C815BB72EAB9
                                        Malicious:true
                                        Preview:..Y.-Kc#.W.y........qW./s....:..G+D....4*..[$.Nn.Dl..1.=.2....._...%Cc-.>T42..K...?..'^`..v..`=......CrBS.B...Z.......F..'.?.....d.....;....u.~OEB..E.9/.[.Ue0....+.^8...v.&....,..c......8.....v7.....1.s.^...z.......fB.+e.Q2R...|...l...a?.q....3w+.W....#.sNRr2.c+......#./....=.....g.9Y...[YO\.)e..7.Hi_P.(...y.........I..L;Y_.&.n....*....\.H].."...je.I..* }.Yg..p.$y.j.........[...or.u..(.{.{=.2....L..J.|......Y`....p.........d.!O|L......7.^n.Aa........=g.....A$2...I...Cy..+..|..v5..m..5c..T.n.........o.p.....@..~.8.u.RR.wqv..a.r...t.......EL.-.[Q;8.^...YS[4..3*...^...r...*..d...h..;......-9!.H.s.....[q..k........}P Y+.8f. EeW.Z.zZ%..[.:JA,..".q(5...G.O..w%.[.!s....-..`.1.6f...r.8p...(G|...*$'..#.......P.Q.....z.Lk.....!...5i.N...:4!.5a.dyX.A.W..U......5..T.y.s......}.._...:+..E$...#]o..4".6..f....aYH.o$..%;.p.........|Y+....+cp9$.......$[,..pn..k.._.....h..9...O.\.7..x.....-......a,Fo.u....%lZ..*.!hw.OA....f,Pt.or.....6|.!z.Cu7.....%R..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37275
                                        Entropy (8bit):7.9945066187403855
                                        Encrypted:true
                                        SSDEEP:768:sOr60ZxriC/WXYjKiYtHhwHPT18N9iGG/Ot7g+o1oY8UxMuX:sCZPXjKi+h+T18N9LYI7g+o1ThX
                                        MD5:33C84F7C1B247DAB8DCD16E7404D4F21
                                        SHA1:CD3702EBEC300C67C3AA3E387CBE89AD11FCDF7B
                                        SHA-256:BA80882D4C776C7C59A09A850E7B1537586E3C5EE4C67698F230229105CD5C5E
                                        SHA-512:2E3C553477EDACCB3F28CA8F5E76AE5A76D2EF5246008773634F03EFC3C624A8FE8BCCCAC106AA88DF280320FAA043860FF1ABE7597017C06A2323A439C9975E
                                        Malicious:true
                                        Preview:P.......b.ze6......:!...nI+9..iq{._^.KGO*X..r._?o...|...6...{....$...2.i..*.*..x...r..C.....>_.rX.a..x..UZ..Z..i7.~[.U*_...^Q9.b.<;....Ed...~U.y.)Q.....v.{7...}.!.....|di..d|.......F.8.?.O.Cj.....w.5R.$$6..4.n.../...B.tbjE........|uFe.T...#.R.N.\..7z.H.!.tQVC..L.:...f..1..N.......t P.=(e...,3..j.E../..S.....D.[...rC.....=..9../,....p/.F.x......T..0.."zqzEM...uv..k..@.C...)gQ.Vm.VS.Q...............)..mUp.%.@..f!......w....8..0#.>..g".-0owK7_.v/.......{U...."D. .....w.5..aroV'...c3P..3..y.9./,.].-!.~..&...P......=7.9...l^w..0..V|.Uf..... #..q...m.E.t.Q....U.7..t EKq2.0=.........M.........#........7{^.T.O...-S...z.....4A....".V.`w+~......Y...q&...6.....G..fe....[2..........).q...DW..........#.....[H..-........#..A.ziM..!...6.....G..I<..ue....9..<4...7...g.....=.d@1.!..K..Ll(kkP.<.D..`ea!.;0nu.....iL.mD..aQcz-.u.yI.....2I.*4...7...Av..P. @n....W..'..i.S..6.%@..8.a..v.."..LQ1.R..../...9.].@..:.V....w/.?....Ya.(^~M..2.../f.d....z.w-....p...H7.DP..T9..OF
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37274
                                        Entropy (8bit):7.995256576394745
                                        Encrypted:true
                                        SSDEEP:768:1NA2pDKnw5I3ILUVIOubN2uthJYCsp1GQtg0/rcTsVunG6NAADTVffBlPrIYET75:1tKnqUVDubcQhJYCsiGgLJVyADTVfDr2
                                        MD5:6EE3F84AB47136DB47032CF01A59FADA
                                        SHA1:5EF23412480B2F706875E40BA5D941F368D26B9C
                                        SHA-256:D66497293621A428E37C2C296F01D66485918275D7BCCE7507D0B0275646EEF8
                                        SHA-512:DFDDB4683689D841A46A4CCAC5E89C239DCA799F54DCB3F4B5906B1B50F759A3E27166084ECFD6D67B126F5DEBAFD83256613A037A27F2DFB3897D0861946B0B
                                        Malicious:true
                                        Preview:x.b.U...1.;...4a..4...a..X...L.d_.7....!!m...V!...Y... ........q...]..l..o.._.....T7<..<..J3#..U...`...J..H.I.......:.Y'..D_.Cr......]......s...*f...N'.J..eM)..nL...z..8.B*...X..Q.......H..w.;.g0K"k.7...d)T....V54.%|..:.|..HC..(.@a.|rS.._z['...xv.....y...d....S.0..{.....r.E..............K.(.l...._..J.(|c....:ft...........dp.J..J.<.c...G.C)..wJ..^..O....G..+{.o.jd$+..#.9]....n...G...j....&nTJ.K....p.........x.N.ar8..&..F.....N..Y;.M.;.8wM5.|u..........:Q}Z..t...i[.vrkA.v`..&...'.[...s.[#.*...'..P7.U?3.wER...4...]f-.."U.<c....R."._4"s..%,......_.....B.....@.e..]US...9......H..C.....LR.eu-<..DR.9.LO.........U.;.+.ft.....X...)[o...E.Wo...../.4........~'.D..v:..R.[\..6....bS.@.T..Q..g{.b...`..t..\...........O.......|...D.k[{ETu.:......l.._...F.2u.1.4.....'.eWEUE......3..|....@o.J'...S....3.QF=...SRc./=.I^[.p.b..(Wc..q...]..d.<......27...sI0...ZO....PV.......o.zn.....d...k.v3Me..}..Q?.3u.d.0t.]......z....O3.AU.!..ia..Y..W/.x.V..C...^g
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8210
                                        Entropy (8bit):7.978583748442119
                                        Encrypted:false
                                        SSDEEP:192:EPxwl9bnP080J6citFjLqG/v0N3dJ/mpS:EPs9bGJlAtumsdJOS
                                        MD5:343F2E9EB2BED19CB4416808B7488BB8
                                        SHA1:0F080FE0AFEBFD6343837ECB0C2F0447A228DFE3
                                        SHA-256:B8EE57B7796C2BFD3ECEAA17C794062CBBCBD76AE6E6092E84AC2C84A693B10E
                                        SHA-512:0B7BC4E59F38EAC504C2A55D9BA736574DE1A5852495E4499D96DB5390F44D45AEFDD46BEAB98F79237D827BBFF443AB67E265671FB8A2305B0F298DB7E489E2
                                        Malicious:false
                                        Preview:.....X...R..g....Be...4..G......N.%..x..f.9.8../\=uK5..8I.$.p..c.....4....#.a.(.....w.u.....p........7..Z7dd..v..s]...V...;S...q.....$.EN...I...)..(.p.*a.f..Q..038..>...F...D.~a.E.[..HQ....v.u..R....Y..kU..[.)X.+....jkO.(...<............6....,..R^...iR.h.t!..R.-..yB.#.k. y...u.....!+..!...1.LD.>.....r..].Y=[,i...;v..u.6..,.Z.....Z....`.....G......H..2W.q.yM.jE4..ui+....%JD..u;j^sV...c..g....hU...mU..y...sO......\_"v4..3.].....q.A...~..jK.k.K9......)......|..].dJ..yV..P.4../.....~.....+A........./Z>.}..:m...".c.4.......=@Yt_u......b..YZ/.....D...z...^.CV.H.Qk..[M.[.^hP.we]L.....V..I.N.....F.Y.xv..S}...Eu../.u"3 ..7..Tag../.Ld.(.....%.M..m..#...D\./..~.6.....c.....O..\^......p..#...Y.rj...p.[....8...Kn.xI{$....]k.rf...*u...\.....r0. W..2ja...&.,r.kZm.. ..0zA.1*lh.G...Fy.z.p..sG..r=D...eK......1x.S.. 2(lD...j.!.F3.......!.x..@..^Oy..W..`9..,...+km./MPC..MBM.$..a.m.6..).L ."Grt.P.XE^.Y...0+."..]......3.........;.=~.....h-yx..|...>.]..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8172
                                        Entropy (8bit):7.979233955437197
                                        Encrypted:false
                                        SSDEEP:192:FW8IfXrL1ErRsuXL5kee6ewNtfT1fXHN407jHF550EkcA4P79ITBpS:c8IfXX+rR9XLGY9pT1fXHvf5lTNQfS
                                        MD5:0DF70DC86A0B8573CC94DCD41029D065
                                        SHA1:13B88C51E4ED196A5C758E2757CDE3DFD5F93FFD
                                        SHA-256:B248189F4AB4E74ABF606E6A593CA9C2428646241C2999E35A29027564FE1923
                                        SHA-512:FA1FDE301D3D8FC6F3A77A12A5AEC40897203883651115B0F4DD3114060415FB08D0A0D0644C9EE88D414CCAC5A5F3CCAA2CD11012ABDDC26004055DD05E0143
                                        Malicious:false
                                        Preview:>O....`...r_....=....4.Es,...............I.^l..n.u..#.$.;a.U$.i0...m....Ia.`R5.[..A..#.r.[.e1B>....E4lB. D....B....../.s.T=%QB.5...F..m)JQ...w.!....=.F..i3.0.d...%VO]....+r.u%b..).%....?...`.#.4.`....$...>.....,...6...z.Q.....P..\...0.Q....0..O.b..0....).$Fj...c..}.z.I.7....V.!.HU.e.@.z.......B..'.=y..._.d..Y[{`.G......I\.r.w9.....Gj"{...$....s<y.8..0..d....N......3Jz....*.6.eR..s.#......Y...x.....']...&...5.r.h..&>.^.Y......8#\..~....F. .....eO$`.>'n.jY...}mnr.R..$f.P.?.4...r.~.b...u...6....cn..E2;..J...o6..2.....>.... ..v)_.)u.L..q.a..[=.C..@@u...(o..b;.......U.a.....&..(.J@..%0..:.z`"p_.&...a.Q......{g.3S{..f....z<...O......R}4d.hw..(....J...K...e...0..|U.....V..u%x..0>Vc..d%.......?r..P..0..C<.H>.sg".cE....#....;.}..#...|4|A..'B....!.....+...'..D..G.".....b.s.;tMud".{W......-.A.-..ba.^;.._& dYt?.....<..([.w.........|.....uG<...5.I...Cq_s.......n...W~cvj.W-.............g..-..eX,.V.X..A..[....:.t&.....2"...L.....@.|,f..)./...j
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37275
                                        Entropy (8bit):7.994795790255652
                                        Encrypted:true
                                        SSDEEP:768:MHZdp7fKA3GTsp7cuXX0zerD5dQr05WCJFaULnymAe7DQWh/9H:IfC4GTgcunfrF8pQsULn1/XQW99H
                                        MD5:3CB8290CB54E02D684B1A634B03CCC1E
                                        SHA1:1E42B313AEE2E71C19FAF94E0E8FD1EC648099C9
                                        SHA-256:5E87FDD61FD4ECA88292BCD136366C9E5E6A8FF38073646D67D73AC301D09775
                                        SHA-512:85F41D45C2791396ACF76AC041AC4151285D98E7145E1354A9FCACDF9727F488E88671A1EB8C8869268F78159CD07226454DE93B000540397BC49027CEEFB8D0
                                        Malicious:true
                                        Preview:5....w^..[(+....._.@.<.......0..ASb+....".9tWY.J.)O.C...6..X..N.=U.....c..Z.R2>s...UB........1Zb......\.. ;.j...ZW..13...-;\MN...R...D..E.v5?...W}._~G.(....v..gu3...X8..}....9z1...x..I.d.b.S.R.B...&.UV4:....`D.....rb.@..'...87.......;.RH+-.=.<....bc.....;..w.E.|K~ts!.B3.5.4....x.......}588.S...Cy.2..M.R.N.y../HEy............&6....b6.....k...W.......D2..."<*'*.&.n...X....\.......%....v...d...V.z.......k.r..l.!..+....m...3...vj....z..T1"..h%....r..~..!....t.ntI..um..ip.D..."....(.WXs..k.~.MM.x.O?.5[s&..._..m.x....l.li?.z......|`j...hq.G.pvn8X.4e.D3C.B.#.A5.wq.?y....%96f.iL..7...E9...0...n.G.p.h..bx.t.[..M/n8."....v...\.-......p..QMI..Q.....9.<.l.3..%@s.N.Q.....,.....D..A.2.0.......+....5...yV...........L3.o..<......4.. ...a/.d....(X.6.x!..PZ9......z{.......o...}3..4..IG.............r......4.l.](>....9..=+........oMHO..Tfg.J..u...........B8E.....0.......Y.w...>h..E..\.;..$t.v............D...'..&ep||.C.o..V..Hz,..m:......eo.R.5.A
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8168
                                        Entropy (8bit):7.977532376102766
                                        Encrypted:false
                                        SSDEEP:192:puz3NKzrqNPq2n6mgIxcYFyv5UuGhprobT1hDMy0OtQDpS:pc3NKzuRq2n6TlYch9GhpADWOUS
                                        MD5:75CF356CB0C8EFFD97D39A5EB02BF559
                                        SHA1:CE58B5062E15ED9C1346156243284647F00F9817
                                        SHA-256:5F90068D43DF21CCB07CFD261EC2ACEE701DDC11B918A69CA7518079539D53D2
                                        SHA-512:6F3A4108CE22A6A4775C1A9D715C4EA35840AB2BE03942792392A09F3FC3FB643E86E1A969A0F51D0F9BBCCBEFEB9223914DF583378A9510743AE6E614150F49
                                        Malicious:false
                                        Preview:..ec..P.c.d..;...;..h..5..n+...\..%..~..P..TN.pU...MX.....K....Q........v.....E..uh.....I~~'A.v....52.>..tw/O;.:n.I...D...|..I..).n.z}......]t|.s.'....v.q}lc>....kIG..ER..t....z.*...&.ZHJ.J..;.j.N.e..x.j.e....R.R8;.G.7)`.4.-.a."..-~.Hc..O.p..%..S...h.IY....b.............Ca.q..0$.5v88.j..S/..'.T`r...?5q.Xm.w...}.w...l{'.......1..IQ..7.P...5.R.V.}.m.O.....3.7....I.t.Pn....-M(@.Dt....|.d.......t..[..\.I.eS.4.D...|.H...?aa.OH.....7{.l.#.do......*..=....2..O3...s.....g7.....9P4>o~.fV.j....M9.M.......x...,.M...{......c...i.eME`.K'..)..0.7.=.^..Gxy.........y.|....A.b4.f.^;.e........E.....).s.nQ.d.WBp....3..\Uc....'...g.|.#.~jxn.`..J..-...@...|h..m.<Q....3.*.6..o.s....V.U....E|u....-...p..c..D.h.=?.-C..Jg.].H..<Y.<....s.9E..7pVU...s......-.. .!T.va.....V...>...So .GED6.......rB9....|..'.c&eu.(....!...^+k.+.........0..8.y.m9.$1...`..p7.....7......nJ.....4b....#.,._...8..K.5....1w.-.Q..c".A./...T.....s..QGW.a.`.?..^......!..*.C.......e
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37293
                                        Entropy (8bit):7.995351201948348
                                        Encrypted:true
                                        SSDEEP:768:hCagT7sK2/50p8DGmKSnEmonjvsq8dCUO2Oa5eeTBC0iDqmn9+KiW:MagTQzR0p8CmzojvsqAnEa20iHB
                                        MD5:82FCD30F0666A87974D698EAFED12114
                                        SHA1:7E18E76DC7F704B9A7608CBA1CDF67838A58E3D5
                                        SHA-256:D49FFEBF39E20E44334463174CBE4DC46A53F638E499BD66671B9FCE575C2DC2
                                        SHA-512:80D9CEF3A93AB13B1847D09C5224FD488582FDB7A8433DB4B8856F2E854DDE26C92C0D45EA06279C18228FBE80B24AFDE3742F6AC94CD92382BC1B73E5938A8D
                                        Malicious:true
                                        Preview:...&.b_@..MOJ..[|P...;.4..4..........o...F..8&R:w.../.....yhF..Y?J.......5x ...V.n-H#."]."!H.bOG.h.$...X<H)k.*.x.2"..Oc..z...y....'...`..BIcV..n........o.G(..I..Y.!.|T.'..6o.s.M-......9.@..@M..E....(b.A0......V..i.8m]n..s.^.<......^....1.th5..Q....q.#..;...VQ.O..<%..^I..z8.4.{..rS1.*L......nM..K.lg.....q`.,x,.........E....}:a..?.AC.0..H...1V4....a2...p....N...$..`.+.....;.o.7d.K....M.W<.....n..E...a.........9...F.K. _G...A}..:wY..t...VOy.O.Re.jAK.w.'j?.Kl.......9.<o.aSg.V.YH.dK c.z.. .*..p.y....^..~Y..y..I...bc@!.S.O.A....e......I..+...G&,W.U..E.>.s`..D..7...U.N...F#)...A.+.<.....JM.<....OXh...nT......C...Q.^E 1..p.b.N.7..I..XL....q.{DMK..n*dJ........<\.}.....X)..td.4S[y....{9H.OO.B..K.f...j.P.NBZ.{l...1....~.4...".h-.....<...Q!.W.]...e.ty.O.,a..)=..fx{En..?).....y....E.p0BL.k.[x..o>."q!iv...hX.^..B297{.$\...[...h'....AQR..`zO.ge..w.rw//..V.z...#.W...AS...CWG.....X...pg..UR..M.#..a.. .....by{..-..X.W...l...0..8..}<............o
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37300
                                        Entropy (8bit):7.99482949927783
                                        Encrypted:true
                                        SSDEEP:768:W8lQHjRTsE6NxQWTdl9u1IIaB3KzqP44WN2Kw48ezbNDHHCE:l6HtTsE6I2I43AqP4462K04hD7
                                        MD5:3DA17C2B0947CE35065BE75745913864
                                        SHA1:1C458C8EFC2CA7D109B68F2AC3E824FEB6771474
                                        SHA-256:D9253A72C7378A7BFD88B5D56612A0C5B4F91835EFD8EDCA0A7CAFB1E4FE3EFB
                                        SHA-512:D9A2EFCD133F83E8500DFF93284F9255E67259E235BFC514AFDB7E582C1FB96FEFFE081B795009F7F876D56288B0F9A01222A3D235468EA4713E3349767A5D63
                                        Malicious:true
                                        Preview:.-.&.B.H...f...J.F S...F..!:x...-%H...}..>.`..S.?..p.o._.....\.0.>:|...oN.J...P..YV......|L.@.v!.+.k.....=. .....E.(m.......u..8..=.AZ.........S.!........v.....J8x5.c...Z.......9@^...q"\.^Mi.xW[.a..~i."..../MEz'_9.\..l....5......)o...uQ...3B.S.#.x.Ws_.nx../...4.4x..CV.5PB...u.&.J...`..X6...'Tg.4.Q5.....=...s"..Y.ZW...`.ON7.{..KU..Eu..N.l.Z.?..P.a..a*.'..E..?Q.....J........J.c.R..)y..B.?.K...t..1L .ow.\...:.". ....:..=.1.dsz._..-....F.Lc...1.{.!......p...?Q"RJ_t.4.0...o..1f@r.._.>.;v6.^...du}C..Zg(...4d{>,lF..6.d.......!.n.J..ok.....`.cP?^...U9.....Oh.qHp....#a.N.j....,.W.0x....A..T.h2....uC1..|..F...K..?.@.fH../|"v1.z.........-......l.9]..Me.z./N.s.j..Wd...%O....O.r6 C).-...x.....7!...."-.....l....W.*.+!I..c.}.;a.=.%'......A...j.@*...B*..y.[......V....i:G.TU...FV...M.f..n..tjZ...$U.....^..VS|.K.<z#........B.QErv..ug....-...N.N...v.7...<....'..6....../.Z..y..`..|.(..%.....Y.b..Y.Cr.`.n`.\...r.0...n.;$(dh........\./]PR.K.^..O*....g....y..H1./
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8175
                                        Entropy (8bit):7.976636580220352
                                        Encrypted:false
                                        SSDEEP:192:j7YwEi9bfNvG1CbJdT1da6kTudwY0FVClXWm2CIwJWpS:jfEkbfkAfJdabuVAVClXWDCIlS
                                        MD5:24716207ACFEE734025BF7A935B40FF4
                                        SHA1:88086E37A9B1FA8433264A881A75AE36BE5459E5
                                        SHA-256:6AC9B1CFF83A4A09BBC796AA46FB1ED8DCC7E866E3FDA1329F9E753E9739BBC7
                                        SHA-512:454C2DCB1EB91402BFF41ACE5FEE4874CAE85263A25A1A6A32CBCCEA46E4D5779F89EB9AC8D6FD382EFB954ACD7106F42B9397C0F33C6F422EDAA7046D4001F0
                                        Malicious:false
                                        Preview:MP#a.1..0.`n&v..z...f.j....2.CR...............R~...Z.....9h.....:3.._.m..G).s{..O..<.....N5.e.p...6.b(h.Y'xaO....l....e_...N)..u(.!.X^2.. ...2;../...+.......q.y2.qg.6....7.Nq.l.@.,..|Y.....6.H.J..^.&p#t|...H-.OhA.,......y-..<K....Y....6..$.4....f...9R.~.....|.,..Y.......G4...L.1B..Y.d..UeT^X.4')uhrm.t?..1^r<.H.*....!.NVk.U....."...Y*d`.s.W..l...A....9LOY..$..51..rYt,.!...1.>.c...m..bp..,.W.}...".[..S.....&2.C..4.]..P...w...o5........a..h..........EK D.;.t.r..>.WGi}.D....*.,..........$..R...g..`..*.K3..K5R....m..E/...\..d.`..x.q.P.*.V....l.....t.d..V.A......f..&..m...rs.u5ut..i.7..T..=.4...'u.8.....f..z..#Xu..nT...y...^.taq.b.vBq...._..EW.Q'.....P..#<....O.....b.n..>./Y2..#.X......z.<.%..A.|..j....._?...}NF..%.=X.x.`U.`.]..o.F..7.h.....;.X._.IeV6..a.....c,.Z0*}x.{u[PK..D.....P:].ywg...<...y{.[..T.!.f.u.-!.i.,)p$....(~..GNq..r.S.`...N.8cR.sPd.._..m...T.[VpM...EeWd.....`.q.X..4.......d8...g.jf\..=[u..h..X...)..$.5c....F/..g...w.'..A......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8180
                                        Entropy (8bit):7.977480194311934
                                        Encrypted:false
                                        SSDEEP:192:dhcy5kHO1S7Ip7w9rTtWcJHDWEs8AkCvTE26EwN1pS:dhcC+LIpaZWcJjF8x6EMS
                                        MD5:FB1F0C7CD5D5A5102E844B4298E9A1C4
                                        SHA1:1EB9D81A6E3D3010AB6A446B373169EAF9EF3CD9
                                        SHA-256:BCC2D108683B11DC0D7F14D19662D4962A77A1276066224AE04A58B3280718AB
                                        SHA-512:4EA0ADFB693C7C54B40C1C283AC32331D90CCB00BE98E09B385383EDBC49D503E10FD37994904079F30FE051305ADEC33B02F0D02BFD383DE07D98716CBFDB74
                                        Malicious:false
                                        Preview:......T....z:f.....|.i..i...w.c..dv............8B..>9....v9p...9..-...K.....?D.m$...5v...O.....z.u..H.....&?,....7)++.o....z.'....O.O%\}.t..=..r....a.@C2....v>t.H.c..*4E.pk.Z0!..g.R(.!.y...hZ....S.g}...}.I(.,...]^.E........f.....m..[#....n....l............/ca@..X;......].(..5..e.........:.......|....pp .x..g+.W...Qw......nK{(.._.~.9......U.|.....<G.s.}r...8_.l..-......D.....5....a(.....oG.R...Ww.~|...H.H;h.....W...".."[.]..-.aH.|. 6K..G.8....'...p..&*.....#;.{..ZC..`...?|D...X...P....X.(g)....|.E.{{....w.b9c..8t'.k.;....%..A.F....o......#m...8#+..].*........+...C.j....J..4..&....X..THtV...g.......>..m9...:e..c.E.C..0.sy7h....1....7.Tu....-.w.../..xa..UZ...$f.-^.B..:;..c1.(...[k..*z...........Cg.f.....9..flz..i.K..<..D.!;.w.a.Xh`.\...V..C;...?...i...R....M<.5Q...M...u8.<;..w..z._DA..D`...W....q.:....... .U...C......M.b..Y...}.9.9..c..cQ..-a..z.A.J\'ff.`q&......M.wE/+.q'^;mv.N...g.M..w.Q.n=P.$Adp}..."..!....8m5........x|.5./.7(.<.e
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8172
                                        Entropy (8bit):7.976196961231963
                                        Encrypted:false
                                        SSDEEP:192:Cc8reePXtaNIhs/jQeHd85d9hh6YoeedNlKDNdMJ2r64pS:VkCDbY5dbYRVGNdMJK/S
                                        MD5:461FCA4B8A594E9079319D1CE6120F4A
                                        SHA1:FB74CA80A5E6BCADE40CB3AEB452D867FEF9E43C
                                        SHA-256:0C01656D41F0BED673EBAB6184BCE822CFDC8B52FF26674202771F295EB7CD11
                                        SHA-512:352AE651BAB0A65AF194ECAB871AAD6ED8B8D5A7B41D130DD181ADCA37E50BB2FBBC0F687BD1C3CF6DE1AD3DD1ECE3AC02FF9ACCCB54CF808062A101C251327D
                                        Malicious:false
                                        Preview:.Sr...~.qOZ..!..q$H..l(.>%.8U..../.1..5...Gl7?S.F.U. ...\...S#...........T.o.WmXx.l.....L'"..~.mN_..`...4..:.....~..U..A..^..@Y+.|Yf..m4........B..m..y......8|q..WM...........O@.!4[x....g[.../0GD.........u....._............5.....R....\.y.."..g.....f^..(f.4.k....t..x.0P{q=9.....0....U..q."......24..5.8^.-[..z..t.|..h/.`..!....S........d..-...o....../......].t,.^..N.@..y{$I....{... `.k...d......D~n..X....u...mB......~.r...C..yV...s....xGv..U...br..ho....A\X*.q.........)....;...Hu.x]J.....+[Fu........C/.\.....@...G.4...K.e~.......v...7:...l......F...I...>...X.r.x.....W.P..pr..=........;a.$...)....M..xU........0...<iP....7...e?....J.._....l...?..b.!..u.....L._....[?+.W...V..W....],.y.#Vu%*B.`.....y1v.8.#..5. .W.......]m:.T....X...>.o* 7.q.<>......F.%D..?u..,h#..{6.Q......x.w.*?...=.R..:....#F...zwb......;Y..o}.d..C..#..N+...z.... ..W....(I.\."h.X.=x.1*gh.E.{...,...=.J.g...]s.I..../..."..Rm...{3..;..x.A....8@..........r]..3hv.Sf...d.M.......W...../.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37301
                                        Entropy (8bit):7.995257638845127
                                        Encrypted:true
                                        SSDEEP:768:Fe0rVKgB3nSsBFT5DOtUwnolrtrrwKE6T6evXGud:FBrVlBnSo5DOWVrwb6LvJ
                                        MD5:AA120873192DA3F82BE06D492EA7AC74
                                        SHA1:583C0C0B20EC968345769C41FDCE87F552196EE3
                                        SHA-256:568247058E5A1A2C647FCD6DFFFEA5FAEEE8FD195D487F8C6BA3E35A36222D06
                                        SHA-512:6435C08B02FE2496A2BBCE5C16DD34E1093EDBEF9FCE3C576A230954C2D5345844262A7CFE348228C9E7784CF358A4C53E83550DB6DDA250FCB65F9E6DFD412A
                                        Malicious:true
                                        Preview:d...X...sv..eu?..$_Jl..y__.....Q..:.]......qq...._s..).z....QL.n53...x.B..._.q...>.%....v9f..X..7|L]...e...(...uo)V/...f.4.....B.}...T.@,JYp.]k"[29F......d......./..J.r....i..>.)s1....C&.=..Or.h..@31....Q.%...&..r(...+..<.NB.......7?_........7...yH.sp..xa...u..%~......f..............>....H ..l.w..{..w.m_;-}....|....s.........of.E....m...9.&..}.i.M2..Q..O.^".6..\B[x..*u.....L....$!.J.....N.;x.{/..N..B.(OQ.w..5j.[.aV.... ....XJ)%.m..........|....l0..At...C.\.b.....F,....l.v...(.o...+..L...aI..F..#.X..$l..V....%*6.$/.y.IW..h.B..*.5[......f2..k....n:K.\.mi.0.[.ZT..X.......!(..^......u.Z.\6..D..ld.)od....d.f...\X.[..8..L....0Mb.{^...R.7d7.v..%<f.)....KZ*.....:}h.`..b.*.1-.....~j}.9$....H4...NX......6.)-........:.B[a>..T%O......7.~......@b.;90..Q.>....;S...........r..{.k........).Z...t.j..u......N...6.@...ysF.v.}].o....,...|.u{:../.#.F:E(u....t.....#...b;..z.-...(O\.m.Q...cm..e.X`....p...9.$T5@.d.~y..M ......Wh.....l.w..-..]^p.a......<.l..8>
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8172
                                        Entropy (8bit):7.978090855782094
                                        Encrypted:false
                                        SSDEEP:192:/F7a6L4sytT9CIK53e1xAn3uWb10eEV7raQHGHqWjKpS:d7a6cP5KJeoHIaIWWS
                                        MD5:70CD46D74F633FDB2E66E80BFBCF7133
                                        SHA1:C7CD6684D1AA39FC42E7CD19D5E714E4AA9A0804
                                        SHA-256:1DA3354D587D349A1A0EFA37DD1D7F50002DEA04360E68C7AB53347855C3E26D
                                        SHA-512:419D080192E9D9C1C10B150CAFAFB61D894A85BF5BE30B08B0B13D74258F2CB0C2ED2B0204BC1A5A0BF92F4ADC0B2AB915F1A22FBA7ADAC28E6A0DD98E2D6A38
                                        Malicious:false
                                        Preview:k...YH@.._...YF.i..SE..N..^,.x..@._...V...T=.G..\..|}.+...............f....r...(.e0..........s...3....>.%.6i.$z.*#..A...J...0..7.<..dA.\..9....$.....].99..e...8.S...X...}y.....z..W..j....`...i{....K...f.....C....=C.<..n,!..TkU...E.P..z_.0E.:..~..,[ .g..^.?....cr.s].6k..........)9o..~KV.....ow............>.2!.W..l..a.K.....m.....+<tx..q*1~.......W.C,9j. :'...Oz..[.F.yi.......I.... .4.b.....:.. .~..:.L..h..c7.>k...9.h...O....=/.[0...9...e../]..X+.s.........[r..........P......O..[.M..!....:.4..}8Ew.L&.....A(.....~`.N..e.sc.N.`.....e.-Z[...........o.'+.....D.....v....O;..e..I....F.p.....5R\[..k..l.a(E8mN.......b...@.5!....MWH[.^......B<..'.!.ME..w.c2I.:.T.......L...... ...)w{.M...FR.3...y.f~......6N...q.tt..N....d..&.?..F.`...Ol.x.^.IJz.y:..Z...../....].>.?m#Yp>.(...F.C.B$.....R.....E....5OS...e.f..)}...Uhg...l..xK.Ec.2.o.@1...dIj..I.oh...2^...,..d.HQ.4.p#.A..wq.E+..H}lH..;c{.Q/n.....9n..8.VW....`)drV...7.l....y..eq2G.r.:.M.e.~...-...?.q..)
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37286
                                        Entropy (8bit):7.995090363002574
                                        Encrypted:true
                                        SSDEEP:768:GfOpPv1cmfROtZ9aLzRvRZ9rLn8Jjl5C/xnx2NC1k+3:GWpP6PaXRpP8PU5YNC1k+3
                                        MD5:1433C41B85474DFE58EA8EC176DD9B09
                                        SHA1:BBACE99D967AF3617185E5CB2BE7CF00571F594B
                                        SHA-256:576DCB796D72EC06CA512B9E2479CC4E058A58DA9A34A1863D509B839892B8AF
                                        SHA-512:C75003DE6FD0D9BF5FC73E5EEB8BC5DFF672B5DC2D5C17062D0E4AC851DA8444D2EADD2AAD530D7B7C26A226FC8FFBB1D78BA0FB27808F878F956B89D7C1EDA6
                                        Malicious:true
                                        Preview:.!|..$.U.....z....$...F....o.../.=.Q......j..X......'>T.4....?....G...&....Z.&...0..%C|I.. ..'I. ...47.s...~..o=P....L..P..zB...-...........8d...F..H.#......q....Ah.DZhBd..........0..OL(.R*.[..h.0J..p.+:.=X...=.lY..sA.7Y...["u0.0.h"..}a@r....&.).J.H:..y...L<..B..U.m..\u....;9..4...P6.C..Oa#.L<KO.....$rZ..M............PUU.\..0?>......<...... p..]..[.$..T..P...1.UM|...?..7...l.%.;...>.....#.!...#...:...4.E.c..r.X;...H3...................\.xz.....^..p...m.;.Hd....2...#B...#.....R...QF.9o..9G...t.8.<"......].bX..q..p.9..YC<0....`..R..!.Y.....Y.UD..\.F..g..}.S....&.Y.W....F_;k...p...[.i'z....6...7..~h....+...^...&...M.. .`)%;...e5.s.......i...@|.....f+....P.a..g..J.o..G...@l.H.+>...P...#._I.{.B2.C.f.......E;O.Z...U....j%8....c..S.7;>~..h......g.~J!.]...Y.U...n...O[?.5..]......x.$^f......m..I..S.i....S...Q../..d...4.(fyD.s.8(..@...kn.$q<.B$D.?....A...6.i....*..k.eI..W...].&..[.{......t.Q..[iS5W.>l.....fc..1..+.U.W,..;m.cQ....5.A...R..X..O..".^]G.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37273
                                        Entropy (8bit):7.99518365657853
                                        Encrypted:true
                                        SSDEEP:768:6cpONMfAzSgl+d+a5XR2mtfD5N32yriKpT:HpJitA6mlDTUK1
                                        MD5:0C35B24D58FA97AA7E2C7C69C269590B
                                        SHA1:AE098B7B7835D1A1479BBED0D3EC64DC91C1F630
                                        SHA-256:C55F6CD664CA3973C665C1EDAB88F1680522F6B017D93C144A45662EA3D60AFF
                                        SHA-512:77530B278A046AC941133F9A443FF6D7523F46F1BAF748F3A07F58BEAD75DA08791072E7493C0B727B5DED449192C43EA802A62C025F017BBF1B42ACC0F4A195
                                        Malicious:true
                                        Preview:R<.2.^V..Xaq.\<..... nRX>I$].....@..eY.........)...!F7.V.0|S...}..g+hNE.|..dG....g...(...4y.#..(.9...o.;....8\g EB.RK....u`S%}....N{."...=...>`..X...Tza8e...W,.QN.(^..G..H;s...k..V;..0....d ,........a.<......;.a..>b.u.,..].l...d_..:....I.up..:../..{....~..\...n.C:=...\.1.]..T.je.=X.i{........ ...r:...N.......)...m.I..j.......4.>C........w.R.`.d..~.z.@.'..V.,.......7m.9....z\....;bX.xd.".B .].F.}....x..5Oq.,H.37.x.i.;.....[5jM{d......'.I5.z......>z..7..@M.)...j.W8.....~.b.6h'.].3...Cq[4M....z..9f.sHQ..f.?.3G..........m..B.\.....v3L;.r....M....B.vy.......f...Uj6.y.p...+0.C.(6..?....Y.{(.b...bh.@...Y...Q..t....6...B......0....z/w..l.!....KQU...a._|,h%}o8....=.%.@.#........L..C-.....]...._...yN...4W.....uJ....bSMa.=.e.... ...;.. .7...f%ggZ....-...U...lOw.h.6W.M.;!./;0.hux.s#..1~J7\ck=....l.vD.".V.no.w?.K.a..is......F.....@?.U.^H.8.a*}.P.../.{\K9..;..n.yT...._,c.+.U....d#.<...&..nx.........kb.c?.7.z..<W...!,.......ii....cj.l..8ns..g...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37277
                                        Entropy (8bit):7.994334286124844
                                        Encrypted:true
                                        SSDEEP:768:vAhqr8UbgFpNs7t9u0rJxZlRKsDpwz8KoosXYMiO8:vAGgFfst9uMTzKEpwz85XYMz8
                                        MD5:1DC56EB8EFDDC6BA778B196F5015E3A8
                                        SHA1:6AB38E5DD7891ED3D9AA22E9AE1B67B5491FC782
                                        SHA-256:A915B3FBC7D3EB2035D6A4D811338A71B6BD9EFB9069AA6D13A042899764320C
                                        SHA-512:CB3CB968EFCEF7E6D9A991CFF858271CA9AA80A4C316576F0EDC82C49BFFF944D60883C9661F543B71A7A0D321DE10DEAA50FD1B6B061DB370BCBF35ADB63B8C
                                        Malicious:true
                                        Preview:p..2..Kb.q.\.[>8...&Vt.A.'.:...iN.)..Vc.U.|...>....M~.....N...y...a.LKd....P..h>u(..7....!..|.K..=@1..U.........T+2...z.w......bn.\I.<....C9...8}........L.......{....=...1..........m=Q.w....1+D.....yV.).....~M.Y.....i...j.4.\`...Vb.|F5 %...).Q..Q...T^D.\....}.......7fF~&...3.1..5{....%FRV.zH:..'.>.d..........U....6.h...c........ .U.]. .....u.M9...n.n,&..M1I..L.}h...Zxton.v....'.."'..!.Q..3.rKg..4....3.M<._v....%.V..B.......s........T.rL.t/.)?.F......[.=1U?Mcu.....`..?n\..&d....B.?.Iz....'.&...c...F..?5..V.. ..R..j.a.u.M8>-...3XwZ....F7.QQ....o.BJ..?E....w.zv.I.J.x...;.%.. 6.~...7...h....;....w.q.ZG._..p...@..F...~.@:K.|.8.........r..A.o..y.../kcV.4v...W.a2...1h.....J...uFn..h.........I.z..I0..V5...f8"....V.T_E.d.5...V#.?..X.q.;...tF....Tv.H..^...8i\C...#s.t...K}vJ%.. P;q......).5...5A.........[#i.m.+.......i($..)..|...../..$U.lQR$...HV..C...Qd.........`.|.i...iy....SU.9.g3.4..V.{.[......Y!.a.n\.T.....w...c..&.D..Cl..(.NG.Y....uI.l..1{....8
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37274
                                        Entropy (8bit):7.995679669859459
                                        Encrypted:true
                                        SSDEEP:768:HpB3J/tL5SsDA1O2ZaqCIZXqqAaR7EMtQdYY2PA:H5XfD92QAAaaGY
                                        MD5:6198E3CE32963D0EAB8F5176998A8A9E
                                        SHA1:2292C8911EA5746859DB1D2F58BA5ECE4F6CE93C
                                        SHA-256:660113301002A8C291535498F0CBE6DE1C7D0CA8509F58A08C448E9F9D32B454
                                        SHA-512:F0713E5DA4DFECC807F107A87965354998646AC116036C72FE30BA58A2EB837945C81308E3D605C2D89EB86B64925309CDA455980BBADF92C4B752C383AB16CF
                                        Malicious:true
                                        Preview:1.U.>....fJ......x..Z......eN....Kos.;97.&g....d.A.).cKV.>.K..%.y%W.|.CG.\,...~...'u q.0|.]0.b.*..&.2...2`.{..'.F._.'..dA...,....C..A1........MU.5....%.$#.;..`!..`.G......#.w`..l.ZJ.A...=...GZ......;...vDbM*.Nq..t...I..Q...h.....J...Y.....V..D...w..`...>......C.\.KQ.`\..m...=..o..'.<..c.Qe...@....t...W..?...JZ..(..[!.5..;...9.......Y..p1.E..-......F)L..X3?kU-u....".#q..le.<.).[...r.....1......1......<..y.\![..m.^y.?..)V....4/....w..,,J^..G..K.mNU...wE.K..C.B...<.....GM..Y>.<iE^.L........1za.FoW.U^.Hk@....Z.P...9.#b~.9P...l:....Q.a._5q...H#...(....pE.'LvP.RIT....;.@.\S.v....z3...l.:.01....A..`...I$..;...6j..+T.>;..F..!.....LP......=.'....L..v....Sa..q0}......9...Q@.m..U......`..[..~8...d.....6.#.4..O%.r...A8B:.F.b..Z-...ho...L.s9c.;...3.'..8O.}.1.#.t.6..Z..#.s.."pS..Gn....-.!...s..3...S....v.R..g..H.u....N..)...7..B.u.GH!c..E?.E..ye.q....}L.....{...Z.vG=..i...D#f#G.i..........J.V.$.D.O.....;.|9Q#s..q.m!S....M.v({/..f.xS...98N.a
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:COM executable for DOS
                                        Category:dropped
                                        Size (bytes):37281
                                        Entropy (8bit):7.9951353626623245
                                        Encrypted:true
                                        SSDEEP:768:hxAf8RuAzwG7vNc9Kc6prW0Y71U/I51pHlaIyfYfQNYn0akih6nQHFoEoR1IUTT1:hxAf8Ru1GyurW0Y5Ue1jaIyfYfln0ak/
                                        MD5:DEB667C5279C032E6200554823C6FEB6
                                        SHA1:3831A8ABAAA239DB0068E3BE5A52209A0F64F3C4
                                        SHA-256:9E1DC47141FE8949EF0E7B5156815729BFF6FFD2BD72AC7CFFC8E1476D1B2DFA
                                        SHA-512:437D3A26EB11F1FCBAF195D0506F817C640393DD04CA7386599AC57C4E58FFC2BFBF41339950561D177A8DA517FDFB960D9427B501ECCFD205014E752AED6DE3
                                        Malicious:true
                                        Preview:....~.#s..*.7.%.q<..z...Q....Z...-J.0_4.o.N.=..:&MuY.c..!eSB...j.8.Gk...z..O.6i...l1..Fz.a.....(V.O..q..Zd..xZ_;.1.N......$....f.'.C.mB...u3/I..g..|J._o.Md..Y....[.......j$..q.Z.2m..x.Xd.M..WI.=z]...{#nL..u...$.1j.I'|J.......nB5.......J....I~.R.........&+.7...m...c....0.:z,v.{..D..........?O..6.3.].I.nHp..O....c.......ii~................{.zD.>.<,Z%..Gu......d..-.^.w......R<1X...._.A...p.v...]W( }.T........@..Pi.....H&9..b.G....|.Y<.R.MUhg..3.....S.A....UFl|.^-.....4...q..i>.e..<^.8..8.....H..3.y......LQ.T.\..K.OCq7..=.n..e...^.....'J..n,.y.B.....h.?..-~+...B.=....6W..I........?...5..iE...9O.fuj.h./<#o.d_.g3... {..p......#......z.L......a..<#l)QD.o. Q...:}...n.....+.\.....W....4.N.Q..`X.Q*..;..3t.$.V.F..56*.1d,gE..1.<|..k....^#_y..p.....K~w...u5d....j...CqxGA-sK..U.....H.b<G...w....//0U7\..M.....K.+..*v..y.....b\.s.nF.I...h7*.\xi0.=....2W.'1.Z4d..mr...`j....%z)).C...A.5!..7..+n.x7....L...3..za...../.J..l..n...-..&..{...4.E;I.+&.(.\.:.?..J4'.!.G..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):31407
                                        Entropy (8bit):7.994245897792467
                                        Encrypted:true
                                        SSDEEP:768:KSwSLI6UWxcE+1nUkpZ7k63lrDlTBUT7+JPZ47d1zldx:KSe6UN1UkpZ7k6BRBUv+JWFdx
                                        MD5:F9C1D885BD9ED576AC726E48279B22F8
                                        SHA1:B71FDB6D4DCFB29650264D92F8C5F400948206B5
                                        SHA-256:5F01C611692FBD26077907F0B4AB13369817A6F8900497CF3119010A5B3F19C1
                                        SHA-512:E11F92D28D4A0754F7E8BDAD4776C565DA6707487E4DF6C85D002B013CF2CE6E9DF38F853F9BE6B6AFB83F4ADE09E50059CF4A008CF831CF3E0508E7F85E1158
                                        Malicious:true
                                        Preview:.m`....j$.......3..<.G...A....BB._....N..W.t~H.J-........O&.-...gg.F*(.n...=.a...3...h.o!..;.....`....#..sUK1T%.._l...t.W..8.......*x!...+...6........i...5.....NW......X.bx.J1..?..u....q.;..w..8F.G{..Rm.......Y|.L;.W.....PX....*.b.p.Y...2. r..Jm%.F..w'2.........z.U...@E..yK.,....y..G.i.fm.....q.^.....Bk.0.D....TM..[L......:3....O...N....4.FG...v7`.g..".....Y.>.(..>..@..3.3..h......dl...'.wUfi..D..%.u..>./........?.......R..~..p..|.a...........A......O.pM......c........#.e.%.e.L...#...Y..[...D.n.hTra....%....F..e.._......z...(l".R}5.C...fF......K..<m.9-..Y.2..Y.W.y>..,..qP#.]....#......p{.u.ytC..dG...ym*C68Nou.?.V......._b.tS..q.......W..m...C.M.(.S..CP..k.....P..ZX......8.|.kR\'GlXc.._.]/.P.m,.?...#.V.2WY[.G.7xB.^.E._.E...Z........Sk.Nws..E....>R.M.....t...B..q.......^..p..3j.T.!aS.s..i.X.=Y.\.G.sr6h].\..d..>.6.3r+..Z.L.<......+gN&'N.......UX...A.#....[?.B...u..f.Wq=d.E.......d......"...#...=.s.3......e...z.J...W.vQ4..f..}#..H$.=)F...g.1cf..]R
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37281
                                        Entropy (8bit):7.9949298654954015
                                        Encrypted:true
                                        SSDEEP:768:Zzym+4HZe5wdL1g1BP6DAIP7dm5YvSF9EnDqeSyOOeR8uX:xymVA5wbg1By1BmJADG
                                        MD5:6F2A4A07A4BBC22FAE767D0DF30E63FE
                                        SHA1:EE5E62516416CE5798C8B0072EB3C5B38F9AEA26
                                        SHA-256:2DCCD5998B03739370F467D51FF8F521B7531F54FEEEB320DF21A26D5D1B850C
                                        SHA-512:B30EDAD46FA81CF42073D5281D27CBC382119B648FFC6B7A5C389D27781D5FD66D0234E105F2DA0E2F989CA5B316BB46704ADBDC17536B22A02E48879F2B83EB
                                        Malicious:true
                                        Preview:.!.?.D.~...*.d..#9uy...........Lu...<.l.T~&s.<....N.:...l?..|.1......*.byni....TC...i.>H....0...gb..}..U..=}..~Y.776.m.s..,...u..&..7D....<..FY.<..BT.w..........?...2..v.^.4.k...?...<......_....2...{..O!..6...t...ij;......L....Wt.B..9.|.........`..k..._.ca9be..(....*x..H..C...V....5.....G..C(lhsj....F..F.A7l~.Z...)i..1/.E..]!l.MN..I.)....CqYr.....v.*R...eC...\.{.0Ys&........n~..g..6!........S7.`..)...!....QFW.?..M0g...Z.. Y@l..].\.Fv.........j.4].1..... ..;..].j.+I..K...I...Hi..$;..z.....r....c..\....9Ea.C.....*.viF....]..I^s.]...f.......u..x.`..x|...V.G.Sry.!p.#...;..`A...2J%..C..Q..g.{.X$.....@.@.@@.......~.t.;.....l.R{..h.c..I..=.....?.....3..._.`5A;J..,.$.... 3.kPw...../.4t...c......1..+A..........-......6.9...c&....\l.....6c.m.n..._...........gM0B...M{...e2......P.2#>.|..K+.w..g...2C>\.H.{...%.g.6...Y".0.Q..#t..z....\^`m.J..nr8.Y...........)3.A..k.>T..,.....d..J.>.M..'...I.A{j].nq.p]...<.......`q.UV..&...H&.. .....iJ....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8180
                                        Entropy (8bit):7.977390388352676
                                        Encrypted:false
                                        SSDEEP:192:WYkyMLb3yCtOGuSCyHI+vSadlE1IdXH1ZTY+TRIQhLpS:WfyMniCpx7hlE1IbZT3RhNS
                                        MD5:4EA02DFBD75D56DB44A8F04B9C70D451
                                        SHA1:436CF3118C2AC78D34DB61C34EE2CA196D6172E5
                                        SHA-256:CB732BDDD3E3150B4D5C158E41D18057309779BBFE4B882093939791999F630B
                                        SHA-512:E1AF641C9818DB609BF25D01F5DE2F49CBD2C138265509F8A67D0FA472FEB63ACA60B832010E56FD323555387E1AF6AF25E1F5392969EF20B5B58CAD0B6E3D55
                                        Malicious:false
                                        Preview:....3....4N..U9D,....a..i...n.#.....hC.....(.F$.M...M.r..../.m.w..C._7...W.....r.`...0+.Ny:..kg.@...h.".Q.IC...........mr....F..J..M.rX..\y4o..kK.Mr.K.....v.x.x..l8..6.r.E...C....KZtN.'..m.zL..&.x,c.Y..mbBP.*.N..Y..Qp`.$.:.........Pop..~.....*.j..qJ.......Y.R..O`.UHM`!:+..}....X......cn....I..`.+#}....R...3.z~.R.J...?Fq...F5k.H.oka...:........c.8...q(...n?.zN.}.^..L...1.%.Y..Z.......c.....@D.a..e.V..#.d....u...d..J.$.NO.Sp..$z..60.Z|.A.1g`K.=6....~.A5w.b....._.=I...FW.u$!.1...C.-....G....fA.......~..[.vG87..FS..C.$A..=,{.~.8].a<...O^[?K....S.!.=_Q...Z#....+A.o#....t..:N..@....j9....2.@.Z..!..G B...cR.28Q.....o.!..[....]%....#n....8.[....>$a:...m...{.X.2_.su.[..k*.\.....v.r.....9....Y.'.V..^..... `.< BM'.HI...O<.D....3$....W...n...^[....=...+..j.w+ns..e.+.X...i..#.......tE)1[....J..n.#."'.1... ..X[.J5...............).{.K....w.Z..o.lw{.,xnkO.1.....?.....J...f.o..r7m"F....U..W:.+.._&..-.^..Y.s......;`..M.v.Y].Lr.Qt..A..q@$j.......e.JL..f.A
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37285
                                        Entropy (8bit):7.9953373993698955
                                        Encrypted:true
                                        SSDEEP:768:jGYy9T8oMBMGOSAl+y56nS3u1zKAbMPx9gMV1AYfsMP:SV9ixOSAD8ti9FVbfNP
                                        MD5:C5F383FE840CC6A7E1CB01EE60786D72
                                        SHA1:881A1D0E1E9DA8D53289F2702AA7CB3F0ADD85AA
                                        SHA-256:2502195DA11A128D2A12A0EF35990DD884B06142001B31EDBB63E5A926C3029C
                                        SHA-512:7619FBE250BE9568002A66AE0EDB691005967C44CF0AE6F714E950B3E11A5B52EE539437BC30EE95312BEDC08711861EE342EB03213435A44A81CA9B9BDB831E
                                        Malicious:true
                                        Preview:|#.Y.n./...9..U...~:m..Lr1.n.z.].0...<..e.JR...T....}...FQ<..a.DXW..T....j.....K.Dc...9..P....]..Go........[{.^. p..''~....IM..)%"..-.Mf.......}.n...P.g.C...........k.6%..1,Q.,....nA3.n{.io...r..".s)f...T).q.Cx.N..qX.)..@..Vx.`uW...I...nV.D......[...}..;..p..0...z..{..S.....B...!F..o.......|...].eW.}.>:.g..u.......Y...r^...')....N.....Y....(........c.V.-.*....K..,.%:.i..f.-.5.E..H..9..K...2M.....Q.2V.Lf.o.... ..[...'.W{[.R..".7kh.0.G...........3...R..T.d.d....pW9=.a"..S...l.,...C.b&c..f [..oR.'...I;k....H .........cM@....py.....W..U....}. >M.0.'Qu...@.+H...6......;.J.Ra....P.k{.....h....v._.z..Y.8..b."p ,.m...~.ET.ylJ...X..+\d(.-EW...Y...A*!...C.....B..o........?..3+..[.......X.t...q3..VH....=.?.w2..p.....[.%W:.8x..x.4G..<~.geh...Q..Z....9.`..z%......kW.`.P.b. =.#6 ....n-*..I*...*...>.Wu).o.6.<{. ...i....BB.2...2,wJ*ty;..p..4Z.\.(WD...w8.@.kr.X....=..ocC........@.5.A8).......R.vI=B.+...f p.X.]5V....:@.9.j...+...+.G.C..5).V.<h.T. .4o.X..2
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8168
                                        Entropy (8bit):7.975452061491957
                                        Encrypted:false
                                        SSDEEP:192:KIraG+LbHB8azXZRgGXlfmEHizoONo/NnDm4GZzYAP/WzyJSofM4ukpS:EPDXHgGhY4GZzJP/XJTS
                                        MD5:186A298655C14DBE58BB416498B73692
                                        SHA1:D85D0B36CFE2EB32AF8B392F9E627E710934AB50
                                        SHA-256:3EC9BB2E805A121F3D6CACC91D655456AF1C4833EB8EEC41A8807F940D8E0571
                                        SHA-512:8D52FE2D7E09FA4676764CE9C6237CB9110F73B392B05AA0C76267DE4153C8742A913E451691D092CD78C2E670741BC0ABDB1950B868C2F119794030426C0B4C
                                        Malicious:false
                                        Preview:...F.Bx.dC|.p(X>..$1..<.........{a...k.v..D.y..d..W...8.=e..{.3....W.k.....{.......5.$./.&q..5...j....vj.../.\....,.......1.......<..X.uc...6.'.Y..e.=.@\.=.o..}.2.=..(4.Ao...t/..h..Y..m.jCt..\G?}.KP....XG..h...IW.lY....r.1......"........7.F}...s,.k_ 4ex....\u.=.N>.Z...).....k!..P...<#T..n.0.cK.9.7m=8...[.F..T..E.[4..^...7..FD....C...es..S.DJ.....{.PQ8....5.i..!..p8..s.....P...F..s.s.P.!.....9.9..]._....J9uhT3..87I.a0.y.%....#.G...%<..<N@......o-......ow.\9:.c|...Z.'...fLk"..{NZy^..XXI...{.'.....}byb.h...!T..^.-..@.O.....NQ.Wlm.?...N.B.|z..V.'.l_f.?....G.<.m7V....8a.Q...Q..{@.f;.x....h..e#i?...SH..6.....d....v.0.#..u.%..:%...A.....k.]t}.i.u.9.v..j...........i..Cft..s...8k....R.|...xdN..1+v[hcM..d...9.W.s.'..C.......9f.r..\Z...zt.^...<c.(..?..*..7dY..T".U$..z-.......$.Xv.T.....1r..~.&..^......y..T#......Tk..+.;.h.Q5....{X../`cr...;T..F.....'r...?...143.%f....,.Gu.e.S}.c.j..n!Z(.Su&M...4.f.oS..m%.......].k..tw<.v....U]...H.2...k_ Vwpo5%s&..4x.7
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8183
                                        Entropy (8bit):7.980173043871742
                                        Encrypted:false
                                        SSDEEP:192:GWYaepN1gd+CHpTaePX4MrmH5P/BruEFUZQMi7+WKRpS:TY9zgUWpWkLr8nBr4ni7+7PS
                                        MD5:421FD082CA60F7673FFFEE0351E124DF
                                        SHA1:9385B2AB4514AFC1BF246EB213B5CBFAF1FD649E
                                        SHA-256:EF6FC76BB0A28208C16B4C3358C67A1A13BFC7B5F3F2A3F18D087A89AC6F7A5E
                                        SHA-512:BF409E505F829282C1667D0CAC1E040EFF213B53FA2CDEF76ADC41470F593893139C5AB4BAAFEBFC0691030DDCB3399B66A238D06958B8CAB8C5F0FCE18CD15B
                                        Malicious:false
                                        Preview:..{.(:...b....Ry...by..;.n.%..+Bq.FW...9UU...T...,E.l..HK...g.`7..L..4W!m... .P.T..>....P...-d3..&;.-..Y?<.%.~..7..rh..U......W. .b-k..<~.yz.....nZ..j.)f..ib..S....k.b.mG..9{...W,q.i..}j....J.8...o.../......E..CBD..1..Q..8L.l.}z.f....1.9..:'VW...,u.H...D.1u."..n9,.%.?.Y*.Y.3.P49c....U.....B]..z....p...(-CPb..B]_(........PV..d+..AT;.'.5.z......".......:h.8".........fyMF..Wt&.bV.T...w.L..`..`.....F...f.~..`,......&&..,..M.%x...ZM7rL.h.gsWK9.(..'.!..Pr..,.....g_..B..."s.8R........9.K2.G...X'......<.8#.....;....&_....j....."d)P..{.w.YC...M.... L.of...K...'.d.<?....79..r....Y!....(v..Iu(.g...s>G.)ls.8.......v....d.[.Qo..t.+%#..R.4.N=...I.sr...h.w.L.T..Y.f.`G\C.........f..7.....:.;.+{u./....Q...vR.GV1....t.>7..F.B..;..j.S......A.a I..P.=K...D..z.p....9..AA...a7..!JO9...sd.S........s.^.f|AM....|..[.O.uo@....2/^..$...#.pb...B.H".F[..8...w++]iM.*b..3...K...C....f^S.b..od1!..D...S.;.......<..G..-I........i..e...#O.Z_.w..N..;+...]h....U..h...o........+.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8170
                                        Entropy (8bit):7.974820091106641
                                        Encrypted:false
                                        SSDEEP:192:OenXxdk5uVYpXDjOJeenxlNG+Gff43xSkj0EIsBZlfLvhuJ58lyrhpS:O0fk5uVYpXDalNlMQxSpoB34/7S
                                        MD5:3EEDBB3161669017727B93D194BC7BE7
                                        SHA1:72606F9459D62C6660A75711B3ACCD3CE1AB5E5E
                                        SHA-256:DCC8554DFC994D9D40CEA19187774C8B7634302BF668AD11DA2FF08D7A8357EB
                                        SHA-512:066C0C9B372EAE35BB92B7BBE853104C7B60B6B7E78B458BEBA85A2DF3A1ECD24D74C74E52EFF0BD5A5FF0F4C1CC2E32902AD58084D703B808641C840B2B339A
                                        Malicious:false
                                        Preview:...N...2.P.<.+kq5..6(S.D.c.....z.M...n.' zw...YC....t..r.:B...$Ew......|....q.y-.Gj|.....Ke'...er."..D..q...). ...a.....l`h..V8...#.E.!..\.,M6.#[.....ww..0.........W.v.qr....M2...2..[!..K.<....u.o..kNx.4.....A...R.O2,.s...PF..."?*\.w.....J..pt......B.,......sA./..E...`.D....37#...=[Z.u.;..e.s......S3y.<.....+....G.....({..F.h.g..=.............R]YS........ <.o..+.#OB...n......_.h;.[..K.+D .......i..XK...L..s.IC..V..Ak.q>K....|.z..8lViD.l...*k;.....,H_...n..0.xt.F.....p....2N..>|.^D....~.G.K.....*..ja...dO.U.!....+Z..E4..aT..(../TC..,....../dP[..xi..u...b.........r...T.I|......e..7..^-..e.4...oZ..wR.P.t.w6.m.sE=.$.rG...q.....0i...}3...:..g{..F.\....B...=7E....uh..d#n8..~._.O.j.(.+...F.q...Q.|..-W...[,.#.Yk.|.D.X[X.[..u.Z..6..c!l.). hb.....i...4u.......j..~.f}.m.^........]..........'...sY....&..W.ULZ.V)./[.G.Se.H.5A".....W......>.!>=5..xe..,d.(J.$.|.K..1/.....d...9...M.C.f.Oe)...........F.f=..u..o...&.....B.]..n...J..L..^....vJ#..G..`...F
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8170
                                        Entropy (8bit):7.979282855322405
                                        Encrypted:false
                                        SSDEEP:192:e9G6D/expUoCh9+elMrENeMiWOniv0oAdjLbikhIH7wntRPDbkS1BQpS:eNEu9+3EN7iW5sRneItRfKS
                                        MD5:2A00C84FAEFCA73B2D9B1A2CB824320A
                                        SHA1:B822C23E7B3DD74FE711A4A5253CA983DCBB0138
                                        SHA-256:709C99FA4FCA9B0D73B79EBE6782B0C8A01875F88B9ECCD43880F28B938D13E9
                                        SHA-512:23415FF96BB93443EAA6E408567995FB45DAEEDBB535C48559BF58B9EADEB8695CE5EEDA6B39EBEA36AADE399BC0B71ADA36CB27CD2DE05926F2174D694677C7
                                        Malicious:false
                                        Preview:...NX.....A3...r..>..pW.....p..q?f..<...i..yazb;.]>O.....A._.H=.c....&w......bE..IId.M}Y3.]............+5k.;&p.j.q.N...%.....^..?......Q..A...O.8...W....U...n6S.....2!.L,6........,..)..y. @58.'....#}.?x*..h...'m...1.@..^.d.'..PK.l._....}.mpR.q]..l.U./..5........x..g.....TT..If_..gK....4.....5...O...e>d.Gor..P.\..U.....ep..@.. <4}..T..:.]......pqBzT..h..>.F.Fn.\|..`..H.-.....Q...A.bt..L.;T..).P........_.ji#...,..}bq.k.x,#(Bw.j..........{..}T.L......g8.......a..'|....yR....B.h.A..A;...E........F..2....9..h..c.A..vX.4.[..Ug$5...>.}....X...?v.h.....Y..<"..T.Am:.G.#..'.K{.)'.b....o......o..!...v.6*.{3...s<:...8....7.&./.y...4..XAG.....o......@SE....~..+a......k......_.....@(.j. .....C...'.0R.Oz~nb......*)7.......P".7...<.]....H%..~.x..(#....d..@+).tx..F}...w...Q.R....m.J8.H(w..E.........~>...4K.r@..f!.4...\...[...,.\.A.#...QV/.v..]i.....b^.<.!......^.vEy.S`F..+.V((..am.....C..t.-.g6.....A..[x...,..q..w....3t......1......e..0.].......O}..K..)...V
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8170
                                        Entropy (8bit):7.976140769764474
                                        Encrypted:false
                                        SSDEEP:192:QdztQ7lim/GNKKyLNZ7vgiT2svXVq0o3nw3Kb0b5951TpS:QRtQEKRZ7oIVq0R3KbcHVS
                                        MD5:69DF68D1C7653A9246A1E9EF2F894132
                                        SHA1:7362D3B734E8A97046C278AA7777E8AABE14C8F6
                                        SHA-256:DF37D7CBEC396EDAFF6A764BA1C043544F4702139A070D0C78D4453D57C89F51
                                        SHA-512:E9C4EF160027925045B5D92D6CF7C06E13B0B81BADD3964EFC0FCD43FBD6F069A6CB56C84A274F05F8B79C58DBEE94E05631FAED75BAEDD04694EF6E36AAC20D
                                        Malicious:false
                                        Preview:.FL.....r&.R.z..n.".....L.....m.:z!....i.............x.zK./e`....S.d.%.kn..v8..n..j.Q...i.[..k).{.4..R..e(.8F.+.U..... x.....a.-.W...+..Q$.An9...A.....C..0A.....I.AW.....h..:........j.{/_.n...u(...7...J.!l"......G.n...fz.....%.O.`.*..R.3....#...%|s.;....@..'Z.!..5.}+..:.w.n=*{^.,._5..v.X..].6..sM.1"...I%.....V..n.....'"...@.@.q.D...\...u.A'&....{V../.......d. ...Y.J...tUNl...1....be.<[..,.Op.....9sQ..........W$[..8..>C....D?......d..|^9rg..4t.J...P,.e4.T"..q;.n..9....c..y%.....Z[.eH.{........W.t=..ss6....-....eU......@.oV.9Eq.."....2..T.k..KX..W..X....I-..6.e..I=UG......n.}.Wu.m...<.'..1.Oo..._....hZP...B...o1B..p ..~.S........)...l..ti..f.....z<.io.R_.r....T....{..%...........g.d/3IU.Y.g..i.':.tBa....o#.#}0...y.w.G....|..]...x...a..D4......$pE..p1.n...}...{.G.4.Y....|8...,.....<I.G5....t..`...Q.'.....U.....iTj..a4.6;.W.P.DB..s.(....e.]....X..cr.V.....4...[U...gi...r....S.L}......rL.Cq...#wc...f.`.l...oP.......Q..!p...A.....}.....Q...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37258
                                        Entropy (8bit):7.994991082037366
                                        Encrypted:true
                                        SSDEEP:768:sB5WWEKOJ1PY+jE1qQWQ2e0SP2l7DW4XCihGI4aCRyrXgfCc/T4ZKq:H3KgP7KKez2l7yW3IIcyHA4N
                                        MD5:4A4D0F8DE8A5F794ADF5248F5717800A
                                        SHA1:1E7A6FA47DB5896FD1F00ACD03094643555D798A
                                        SHA-256:E5664A1F824742FBAE1012DE2E38D00AE41CEE648FBCCEFC2950D9EBC2DC682B
                                        SHA-512:431CCA86F7AC000B4916AE3510F674E2514AEF7B9E339742913CD6B2557E98C69F9DFE31379A94559906359C4393F6350163CB82F2E044FC0163031FBDE470E4
                                        Malicious:true
                                        Preview:...v...}d.7....<S.3...7...E.N...C..M..*=..O1q.w.+....jH=$.e....J..N..LzfM,QO........l.9).3a..Y..^.....jk2.A..!..}....WH[sb......6\Si..\...=.V.LO$...vRs...4=....b...vlNL...:;..XC7..e.B....e#........U.~J.;..o..@/).{r.M.Y?5cW.nn..5..W-$.v........."...4./..14O2..[.?.,..C}.,.nT...g..=......D...G.ak....w..T.. 1...'W....Ej.b1..5..YA..............C.......$<..DB.(..%..E......[..'.r..@r$."L+;..A{..4.^.@..g..5.:r..A.f@....27.c.P@........p.\..Y.2..yS.=kJg.....?X....m..5..|F...o.3.........u...k5.]eh7....<.*4....I&.vwT0...c.0..FW.kD/..D.>1Lm'.C..5]K.,.h...7d...;P.D.A&C...1M.C.q.K.....-....A...y.|O.J.....f$...<...p.......7[h.LOU..O0.....@...z*...z.Y..jvb.......H.O{h%.j.Q.,..wCr,G..W...../FBu....\|!...(...E.....%+.S..k..P*.p..._Z@...M.........I...V...G..SD^N}./F..s....P.E...:...........j...6Em=E.>..nb.d....Y~W.."3,....Z...V(......D....^<..e1.l`-v.z...XS".r.!.p.....@....!.X%.I...G......ph.y.M^.|..gLO...N.S.Y/..Gx.l..D..].f..y.o<H.Aw....8...3)K..)...A
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37263
                                        Entropy (8bit):7.995390627092596
                                        Encrypted:true
                                        SSDEEP:768:hIg/2q7n58YXJ/UnNntt3o80JIEfPcfGQg7/Tycd:Cg/H55+nNnX3o3IVuQgXyA
                                        MD5:217EA5589012EBCD462200C79C100976
                                        SHA1:6B527C31776A4FC6952CCF87E7E45BC6468C09BC
                                        SHA-256:37D8B1CFFF47EBB7D78A84BA1006372783BDDA95D39F3FB77214C8C63C5C5816
                                        SHA-512:EE972D2DE6EC58F468CFF8B8710588C133FB71C88D1225E036689F1EC8D20E4B4D64DA82C330B743954916D19712DDA1B2CD525FDC9DC7CC6326AEB34CD4E8AE
                                        Malicious:true
                                        Preview:....d.R..7*)..8......m.5q..1...+qz?o.9...7...hb.sa.1.@xV[.W...Yj}....w...hVO.F.......z.%.r{.U\.>..n.....1..X._..&+#yj.jF..\C....t.;.$...u.x.E..'N.....Q..%.nyK.f...J...j=./k...D...2.........n..c..:pu..-...."4....._P.~B.iHC.3h...3.|....w..fsX.......Xk.o.;...........N.......jjY.&d...".`x....?...B ...'O....x../D..k..R....Qp%.t........n...\.q....{.....M...)ZT....Q...].s..f-.>N.....V.....1n......\.p...}.d..x.c.....LT......ZS...o.E..d.d<.s..lDn."..*........Q..c..........Y..M.,.T..R..X+.5.\..c....\...p".....P....r...?#...yM...I.g,y.e.We.....$}&P.ir~.. IoT.....qV..I%h...T>.G...wM.].t3...Y}.70.&O...&.0M..1r..BI..........."...."l.y..1..).W.n.A..!.[..\.%z.U..>.9.r.&.S.=}K0.'_2.b..=..Kb.LY....*.3.].w.7.....nZ..C@.{.E....7...).....g.,..(%.....H2.w..!}i.......u.#C.+.........).KA ...Pq..I.\e...m%x.."...._...*.|^.u......d.G..v..j.Z[...+XH.X.^d....o,.%D..`.Z....\...oP......M.aD.06...@@..Dq...i..EP..6u....?.D.6..TGEa.P......Ma..ZTI..c...{.C.;Q..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8200
                                        Entropy (8bit):7.978199219385126
                                        Encrypted:false
                                        SSDEEP:192:pjUV7v24zc0SLgu6IInqxRMHLJAOx8scote7/JrlBpS:N6v24zcX1OqcNAOGsRo/55S
                                        MD5:081033FEF4AF139898D7BCE77389176F
                                        SHA1:8A4CA140BCB03FECAC43BBD47ACE5026B92A2CAE
                                        SHA-256:17007E5560845B8EF40A48904310185994B670B9664FDFD2CD59A8248B42B87E
                                        SHA-512:9860B3B8655FF51FC16288EAE4E08C04629750B1A2BE659F8B9F3649F123E0159C61A8CE5326CA1B111533B334EC439C6783EFFE2B4F653C104069F5F63D7076
                                        Malicious:false
                                        Preview:.._...M.5...6B.R..Mn@.q.4.{..(d-UJ......... .Q..%....!..o0L.R........%.'..G.6..G..F/K....[&.`......#..p8...t{.....ph@.!.-.!U.-n<.R...m..fG(..s.?.....J..2^O...4=.D......I.sC...'L..s...g3.p'.s.....8b..(.......cPG7.c..CBR.(.....=$d...wb%,.(.. .......T.....?.T...xi..S..;...4....w...fUm............Y.)..!...........D+n{...S.....||5...+....."N,.-..G.H...w3..&xP.........d.].G.%.?..8..C.......0{....P.}.,.x.........`.*uB.tPN.KJ.&...8i4.k$.......A?.:5.....DH8..m..LZ.r....Np..}....KS..(.{N.....1.$../...k;`m..]5e.0Z...N^...7....O#.. &bN{._..q..m...f..Z.......S....q(.oL.^.....5.s......k3^kk..^6SX\..e...G..^.........W..c......]....2.p>S^.i..]Q...p7...Clc....+;...v./....Z.!...$.$.^ E.v....p4.1.~..\.<..(.~.d....=O..d.I..dPp..{4G.M..|XL...v..e\m\......Vn.[s.6.@..y..].r{.e..-........=a..%\~.:....}.....<..Zz...x......XK..8.,.#M!H5.pb.!..7....|#..2........sD.r....* k2.........m.>....fH..m.Q.4&..)...t..v..B..l.JhB...x..8.jV.W.R...~.....H.........B'.....KN.DK....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8196
                                        Entropy (8bit):7.975900104557459
                                        Encrypted:false
                                        SSDEEP:192:+0xn+T+z2hh6t4lI4AkRf4w4Bd2AbGNcGmz/yAtopS:xhmI2hrIvvcsGuGqHuS
                                        MD5:F336EC1AD53D86574F21C913F60E04F8
                                        SHA1:728108C2D61331C4D6ADC5395BD21D4EC7E93FAF
                                        SHA-256:73FDC7FC9E9296A413C6472FDA3BD57B2BB7CFD4DE68B6A4B851BAAFE17916C2
                                        SHA-512:4BF56652822E6C43C8318F3CA49024489231CFEEB04B9A8375436F477B7A3B71B600A4EAD13B6B1A87D3B6FA9A5DEC607BD98C5B2309753E286C523ADC61226B
                                        Malicious:false
                                        Preview:.........iv.4.&....{......Q:%....9...=...$....g.%.#h..4c2..b{.s.U......KU.......?...].^.7KxZ.k.(q+...&!....|.2>.` E...........K2/...@...\..V94s...]K.......A..m'....Y..o...`.1/._]..z..2...*j.cZ....vV.K.}.o/C)...D...@.Q.......k...N.2...oD....8.]..%R........?..`.~..,=$......y...d._j.u...W..=..O..L...VW....Hv.......!.if....5m...~..f5..{.p..F.?.h.]....1m-...zt.+.t...._C.V....p".;.Gs....9..;.........z^g@3......B.M<.Bd...._..,..../.".W.O.W..[.s.TW.8H.5..z....A.F.............$...6.>~0...Nv.4...%..".`....D+..7...{I............!......Dy4B0.).w.w+.7.].np.4.?E..HQ...o.r.]..s...~.)x..&..V....SA...p.....>.IN....8.....0...3......kK..pak5.>.=Qf.^....OF.../.....DA.].....M..f..Z..?.=`.-.........W.b8..&............F....[..3........[yy/a....T.Jl..-~..W..O. .WZ.l"1..U......O..N.y.2..s...U:5)._..s.\b..{ft..R...1..Z.....A..App..Y......q....'..'..s.=|Z.S#Q.....8...nFfU.n...B,[.,.b....4...8j..#..._....&.3..).QFmr.".$J....2.P.....XMoHt..N..t.(..#....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8192
                                        Entropy (8bit):7.977233548031829
                                        Encrypted:false
                                        SSDEEP:192:1TIXWKw5HgWUxiXU+QB1ttwMaUlZFJ4S4hgXZGxttZ4xj9w2qhpS:1sWJHQ1B6uFAYZmttKxBwDS
                                        MD5:D41579668A2057AC41E573193E171CF0
                                        SHA1:E096E5820FEBEEC2C6EEA2EF57F4CA0466457788
                                        SHA-256:A5A086D4AF2A90CC3C318A270B84E24EAD54D4B26790215A48EF8DE050D61AF2
                                        SHA-512:B1D9D1B5B21F463728534141C442A20AD1844F0A20A36672EB6D23E6F8A3B0EE62F926184175C3AC96DB2120C63B21FF7B24A1113883DB4817579DBCBF18DE9B
                                        Malicious:false
                                        Preview:..mc=..i...Q....2.N....R.xa...........9.......l.;.Yx..-7.3..'#......D..N..%m...:....d...79.i.....6....3......z..f....WLw...:0H..).......5Jw.....f.;f._._!v...ftw.n..2#.,.....h-.>[F..i&..1...8.<b...N.>.......q.~N#..@.Y..~..vEVJ....7.].x........'.. ..p..IW.......%9....6....t.fl:...e..0...m.=....x....&.\V%5C.=.!..v.8..-...G..iT.<Y][D.......c.....dP.J..M..H........f.rS.}4..M..1~..AQ.,.kj`.6^.R.}.i7..-..j...q.(.w.W..j.p s.i.......~..rkQ`H.*.X#m.w.H........|.?..$.. P..d..9...+1.%.s?..B..G......s1..O..[.F...i....x..?[.........*.O.J...s......P.U.^....O......-.o.B...'...L..Q.*H.T.&.z.t.D...&./d,vm..H\.3.....x=,..I......M.2].}.\...<.....ee@{........a..~.)..m..6.s.fp...).^.....NN....7...N.n...n.......(?.....r..........n..@J..Q...v..u.#d......<#)....p]..+d.<.Y).a.zO*<+.*...i./..!... g}.[...@..Cf.;.p.5NJ..;6....,0..Z....q...b..{....>.).E:R?.+.H.q..s....3T.+........a5......F{5(M....Y...{=,.a"......e..[.....J.{...)c%...m.p..WE.."e...`t9i...V,w./....,....c..:y
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37300
                                        Entropy (8bit):7.995918489373836
                                        Encrypted:true
                                        SSDEEP:768:NZQOxjhZ26ZZ6XuGsoWf2JZX0TYY/UjG3BgGgko+WXEW5AKA:NmKjSuZPGsh+0D/U2B+++AD
                                        MD5:6B66E231041E0E15A2D504BC3F393FD8
                                        SHA1:E0FA955AEBA55100CFDF2D09E75C14D6D98CAC85
                                        SHA-256:FE61F33C730BB2D2E6FF32F9F1D001B8638A3CAE9A0AB4818A9BEBD374F46B22
                                        SHA-512:4D7C875DC86D08CA1348610E850C794ECCF480FF610A74B52943D7DFA8E8B45FF8A75DFD456E7E82BA4E91479E351BAD79031D0885684D9C84A0FAA11B4F47E2
                                        Malicious:true
                                        Preview:...>V..L..|.$5o.g.8P....*.5).MzK..u...h.7.l...dHJ\...cx.IE9&....O;.).I:]...,..u+..h...p..^..>X 9o..m....._9.sO.:8u..p.uqq...w._*.4.\...5.J..*...4...w.B.9C<[.,p..b.a5N.X6K=V..lP.@.3.W....?....0.......M..|..P.0~l..IT..2..KJAX]...I~...,..F.Y.`.)..{.IN.....=...l.k....n]O..AH#..5.3..j..S...Q..%.n.~H.8........(...C7..WE.v...}y.`.\....Z.r...7.).G.......qr^S.X.B.tvj*)|...f4.....x......O.V..X......p.Q..X.........lv.q..P!i....}..3.F.S'.....g..SY........'..H.....O.......g......Q.9.@..S..........m.....$.?d.....K;....R...N.......~..r.j.....O..I/......h.....!.l_.K.h..a+.WU.....um...k.}.$i.8....s.n.R.]7..(wI..j.....J.g....?A.V!..2.u^....-70^...gZ.......H..\+.._.J`..W.zp......}M.h..!.,<..Q,f.?q.Jn..nDB...D.k..![.....l..%..-..EYCH.3.1.....`.|...<:.|.0...Em....k....I...Q.7..eb.....i..&.....fa.y......g6.BZ.b..yr..u..~*Dw'a.E....I%:faEs.Jl.J..F..]$.{.i...K.m.w.3j.-..)Y~.b.d3....m.....y........".x...7...?...r..^...S.'a]._z0.C..+H4..F.y.......(.Ve..3:..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37306
                                        Entropy (8bit):7.995106107843006
                                        Encrypted:true
                                        SSDEEP:768:gXbd3kjX3DYPTBOYFPakrRVzHESGhNS2Bn/ggm/D3U:8kb3DYLBOYRaklVzOkSQ/D3U
                                        MD5:6364FECA4857E0FFB6AACCC392293FBB
                                        SHA1:591C7F1A731C6E5F2C7627E886E7EB9E2553FD77
                                        SHA-256:B617530DD4E0D49C1F101969F078C51873E7E8991E8837393D513A4600B97B95
                                        SHA-512:49D583FA1DCED3A53782F047DFAF176AA3D3AE05ECA3671477394EBCA1941A3D173609D27D39CA28AA7DC67664169A9BAFD9A1A0B576373EF94E41C65C003B75
                                        Malicious:true
                                        Preview:...<...y-^nW9.3yF.5.<....]N......0..N...x...R]|W3.!....%.h.Z........=..sII.][.U68._.....78...JM....z..H#..W.8..X..J....$.8.K..p(k........G........ioS..0D....[.....J}:..... ..0?..A..j<JR'n?\;@...>k....h.....6aRd..H.W.h.?QH.}%|..XS...x&.=.....Rd..y.}o.T.s.B....I..P2.4...}..?.&...[.|...Lqm...|.Lo.B*.d.s......"..q...e."E.{..zU.+.I?.I3G.*. ..Kn.|+5.....q.q...QA/g...^....1`6.A~e..|.n.CR....,.s.U.........?I^..........4.7....#l....V...(..?..t...R....*.\'....TqT......=....~.P.....5.....l..+...Y..W.;S...IK..C.....~..P.._\.sR.l...t.y.F..6.[...dD..O..Ub.*se_.k.........'.)<.X..HH.j....t7k..x...D.lE.8}n.....]..2j>#.!>.r..KQ.....:W...-#.37...L..xI*-.......e....hX..'s.......:.s..uD.W.N.....;,.....$;VXD.]..p...:.?...2..E..k..u...%.7......._u...B]._....... ../.DW.M*...L@..l.......f..Ce....|..&I6.._..._...`....F+t..[(H*....K.....2.Y.J.K./>F.8....L..*7FH....o..V......Gaq.x.$>)..6.Bw.i..d../......;/2........cK..D...j.....Xn9.....3....).H....&..TZ
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37307
                                        Entropy (8bit):7.995062700973785
                                        Encrypted:true
                                        SSDEEP:768:M/qJMj9hyoX5/MZ8RzOHQDpxe/EMhM84Tg:8goXOZ8NRje/LhM84U
                                        MD5:1CCE2488A856F6767A71477749ECC33A
                                        SHA1:3D383C87E2F3861C1CF38002C752B149033D3EFB
                                        SHA-256:C10F11646E0A3ADE093389481DC82A9BD70C3895F71FD3C68E807344252C2DB3
                                        SHA-512:9A2BE0D1866A57650F753D5AC5CC96C5CEE1F4D7A1BAF5E7534BA671AC996856C00EC26BE36F6355B505BA7E5BC3E0CD976A5E44E6905D27E3691A534A0C5064
                                        Malicious:true
                                        Preview:....I...c<.QS38m .....!d.R.}....(......4D....`.....YM...gg.{f......A....$E()V.k.b3G....b...{Zd.#..-....4......9...c.e.+.c|....B.Q.M......&...J....].I..Z6O<.y`..@h!Z......4H.}..?..q..M..'..j.MYd...G.o.._.,m.u(.ts.iV..E&,N.6....h...e..m.w..i.e1...&.1R...G.)Dvg.....}.vk2.)~...._)..$r.JJ.....!.PD.$...%.K.;.;.....U...?...."...1..?......^6.&...:..D..n..0...Gd..TZR....$<.4.5.+.d.m.jw...l.Q....SN./\Fx...x.Z.oHF..lO%.!+xm.........e..^..B...Z.Jr....r...R...E......Ql...8O./..bz...I'.o0r*..h..'\...pK....-...G.SU..... .C.k..5AP..j.O{.........:=n...A.8...=.$...(..t.T.1~.S.E..W.e.p...g....r...m.t0..).....4.............o..3~.......|s.z..kC4(.t^..`.[C...2....@....I..H=".....?.Y...#.h......Do.~..XPKu.........AA...e3.....Q...Y]a...>.!NX.h?..]....LV.3.i.G.3.!..p..-..:...^.U..)...1..B.....cpb1...{.6........J....h..........8.Ta{x....x$f@e...S.\..5...y`Cf...J.\..B.8...x.....DyBx.....@..M..;P.9.|../Q...4......Qp.L....I.u.HS...v..O..I...rJVFt\.....8.f..".2>
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37294
                                        Entropy (8bit):7.99403416580495
                                        Encrypted:true
                                        SSDEEP:768:lGoIYVKjwHBuxXDWMYnl10pHY5pyK331cwhez+mQA/YsRbpkt8ExGf:l4oHYzWZlGWym31/Ijbp9+4
                                        MD5:9510B0A468C10EDF83AA7DE78DDCBD89
                                        SHA1:81134A90E5971B9DEB9612EAF80E08C9B4B77131
                                        SHA-256:DC230D431C4BB0641C29A2045C5BAF4816FCBF614CCDB701F50251C28FBDFA83
                                        SHA-512:9578888D11EFB09F1F6FE67B70988F43AEC0D3C426A57798777CC56E2C9035287EAF68A57DCD90AA5E0D41C40A67E0200DABFD15659FA7C69E5E918BAAE9D715
                                        Malicious:true
                                        Preview:A....p..i.\..e..p0.v<.~..`..../}o..|..e.....h....5....J..K._;J>.4.t.........w......Vw.^..<*.8.?..#.>..};.....{...p.>v.Q.....e..../;......F'P@...+?_..0 .....Rf........Y7xl...?.i.......C^.)..c...[Ul.F!.1.C.i..2.yTf.C.....G.2([7........V`.A.......jHB.Z.A.....%.Yd..q..=..1..q%..EIC.Q.L3.g..h....t..qd..1!}...iK...D...h-......r}.N\.-[....t"Z..........V.#2.xn....O..h|:D..+.X. ...|..+&.rD.<.Db...P...T.N"-k}.K....3@.!........>oY...p.12....7.!.v'a.1`....]...z..RbC9.^..oD...t...m..be...n_g.P...5.:.L...F.....G......#.\2. .......M.:.Z. .vo.`C.v..r.....d}.{$...%l....zU&.=\..6..kC.^8.C.....rj...Zw....eB....3.....$..&L...a7...4.>.....,..D......R.'SQ....6v....LGb}. n.._..>H....<g.....%4.py.++#~..Z.qM....A..1../.j%.)m...E.]?F[.O.......Mc.4.^l?'B....dv0R........W...r9.:.Ec$.7D)kb.O..b..I;.V..N.0.....8..[)T..8.PS.V.r....%..D.K1?;C.%...UkU..~...k4...g.H[}.......\.C..?V.A..2s.A..Q*.Tx..^..A./2-.+...3.*...G.E..l..j....R[..N.a...2bv.I.J[.|.9>mlE.;F....n..W..$.?..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37293
                                        Entropy (8bit):7.99483833444938
                                        Encrypted:true
                                        SSDEEP:768:MEPzGmTEY8UJkeeURaaDF25dPYUeSGVSoFUVY61iEA/D8Pmtb:76oEY8UNuxXPYFyoFUVYzEA78+tb
                                        MD5:89932E6DD21BEA656BAF8AD65FA23904
                                        SHA1:A2543B9644682C19192544E80AB1B1F9E6E97EAC
                                        SHA-256:891C7C84687E9CA9DBA1BBBBFE81FCDD49C670DAC421E0AC853ADEABD3458E1D
                                        SHA-512:C287341D759D1CFF307AEE002BDA06A644658B86EED46B3885EEAC37154381E899A73618DAE9FF91210B192CB549F583BAAD330A7B5DAF85AB97B20127C5A201
                                        Malicious:true
                                        Preview:....).._..p.#.."X.|..:A.y|<X..eq...AA.........S..._..D.X>../.I~.-.....d0B3.....u.i...^J..{.;.$.X...L...AqE|d;s.oo.....mz..6y.fT.t<...@3.;.P<\...{'@...aEc*%..i...S..N$;N-.j..\.x.L.^[... .n.....}..s+...6.].].l........u..;.=w....I.<..#O|..}m."Z.&Y....,.-..u........}..[.w.)P...ds........g.;.}`.c.C<..G.j}."....|It.-.J....[*.."..\....V.ra7.d.f.0....W.K..N;..x.....9.s./...9c..^f!.J.o./>U...i.....F..E...d......0.........P....L.N*...*.V.d..6.n.aX..C\^.$.._..5.;.H..&Y.....@.{.o....x/.x..C.S'....zy$....m=?..t(o...a.p#..C....-oE...-<+fZC.X.C....?...ng.UE..>(.H.WH...,j...g;....fQ........t#..o...q.Q.zL..'9s|u.b...v.....O .p:.M.z.Cc........|.,..*.+R..4D...._.Q..\......L...=.$"..O...'.L.no.Y..b".[.^.?..V....?u.*j...yX.y.J........b.F4.`.C.x. ..y.....R..X.-.|..r-[D.._$&...7q;......\P.{.n.D.*.+cu..D`.....44.#..Y..7........./mP.r+$..sJ.......R....D.....(..].X'D...j..T{.&r-....Y...0..x.i.B7.y.y.Q... E...&,.}...SMh.#g......Q.I....o5:..5.}g.H9.d.j.j.Le)......k
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37328
                                        Entropy (8bit):7.994467171329161
                                        Encrypted:true
                                        SSDEEP:768:A/FYxy5ANM8BhcdoNf6FlaJYVblQzGd2QhQYCc+7g0C7mVF:adAX4doNQldVblQMCc+7Uu
                                        MD5:490A1B15AF84F16B9066288A85FE27B8
                                        SHA1:F4416E20E29D4C8536AD9FE6BD1338D1D6893379
                                        SHA-256:5EEB6D374C199D1AAD891CFFC1A18F73840629E8D1FF727174D1266AE39998FA
                                        SHA-512:24E833B902F2D6E6F9E14AFDD00E61DCFED221CBB8080B904AC4E9B98463FDBFE9D9BCF7983B1707D3392C2037B95F14613C9CE3908191CD6A0730173439581A
                                        Malicious:true
                                        Preview:..y.....`..d.......~....G.|..o$6._=n.....D...kp).]5.....a.....Y.......T9......p..F'3d../0@.).<...y.:.J...E.!V...8.w.g.ml.........d.i.3....%...+.3.X.I>2I.Q.:.w.....o...T..!...\.a.F4b.nT..."......?7...R..r.o9.#..%.....K..Yf0..<.4.8N.&]9.7._..T.=W._.WP......;.U.^....|c.k...f~X..t.a.L>S....,;...6.u.}.U.Y..B.....F..UQC4.@6"...F."..xE...kU....$.y..."..>.]..Eyz.:...0Y...-...;.../dc`..>......b....oW.../b...o.v.{a.b..Q.C.J@.C...'iS.|3...b\..C....b.lW..B.J.H...L...... ....D..K....%I....Ow{.M..X.KG6.c|...ie.Q.}.j,v9>>..}...wa./.../._V.K.9.3..&v..........o.m|...<....^..<5..d.i-..s:."....f.]&A.|..b...K.....\_..{1<v7.5..ky....b..Y.3....7h/P[.u...6a....bC.a1...p.D.........U.......:...^nO}.wV...8.b..9..^fm.....={...*..U.....z....wS..$@..l.2...$*..{_...X.\...{....ZV....5.D......I.X.E...#.?......V.n4...;O9...../!;_....M..n|.Aw...\..C.;.G.....T......u..Y.4.<.`...NTs.PoP&O...[g..i...j..6..m...<....._..{....YP........#v.W.Uc..M......|...r......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37327
                                        Entropy (8bit):7.994746691968116
                                        Encrypted:true
                                        SSDEEP:768:ORZsfM464RyV09iZD/I7sppjGwG4XKwvH6ZQF3cqIoxN1Tf4lMyCw09sk:Ozsu4RyVzD/lpjzW8cqlxN1TJtX9sk
                                        MD5:D15F864F5776389A52BC3344D3B37E55
                                        SHA1:C5CDC427A35DC533719C0711B29E571D9805FEA9
                                        SHA-256:E2E2E7BC98EB81A8A4B45230E87017A9B3AB1D821F0D7EC80D8B59520262493E
                                        SHA-512:019DE5BC8CB33A5033EC36B8F24706DA1C7DC5BB31DFB8FAB5432E239593B7603D290CD807825CF3C194CE2F74A01AC0093B5F6B628B844877FDEA0E65B00C07
                                        Malicious:true
                                        Preview:.{...F...R.X.H.....#.....@qA..nUi.......bUTb.aIZ....?.F=j.5.q...r...9.1\E]%.,/..a..v.{...T.......+...v.\..l..d..z.............i..q...!I)......K.w.d..2... .....;s.....+13z.P......M..t..I...k.oe.D.=..w..!....X...z.Q"....=..([.3fX..%...}.e{.....b.0y..<oq[yVLo..I.......'c..D.......1snv1.tR...7@.a..#lQ..)..>.4.[....N...Q.V...8.O.0..."..B.g....U(*=G./j/z)....Z...p...;.K.;..!R".:zT6.r..S.......n.....%U.Ei.kx..r........m#. F...V8Z....D...VG\.....Z...../..7MOs....t.^K...U8..`..I........r.......<E.~..J..Do`...#)...(...O/iw.i.z.?...;.....vL.Zz.<..=Q...[I@.\.)...^.I.x.2.-q.."._..k.~?D.b+......LP7..3@.....j.d...d...HV}.........ySo....^&.np........y0.\t7..{.........+d@`b.C.d.I5........g:J^......O\..H.p....[w..k.N.~..1..!s.....v....&M..Qf.o......P..._.M.^r.5,. .^....p..?...@$...K`pK.7..."&6...=.1..).g.s...b.<........ctaLu...D>C....|.yd...12~*.R6"jB..S.3B..UA....]......3.H.tt..:@k.Y..6..,4....G0.=..Z.(..K....eUC...1 .*/....|..J...-v.U4....o?....N.V. G
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37300
                                        Entropy (8bit):7.9951476277572295
                                        Encrypted:true
                                        SSDEEP:768:lsjGBQyfTV88SJKN8Kz1AzHsqt5KB7SmVObZvTckFSJoVGJfagtAHPkgN:KpyfTV88S86KezR5KQmwSJOGRJtgPvN
                                        MD5:82F4B3E43910DAC8940570ADC893ACA2
                                        SHA1:AFDDB6564B80A046CA9CDED3D7C933359E34D74D
                                        SHA-256:993964EC265F5121222AD886B94E07B668ADFAF03C4438A96D75D691EC35D0EC
                                        SHA-512:5605024D21C4B5D9427DFBCE7E9E5175845517B1E93665BE0B9DA56B70CEDCA09015700E4201FB5C44775DBCDC137E88E91F5C940E102697B629E53B1860A9DE
                                        Malicious:true
                                        Preview:.......E...F...-Lg.\3.Q.....Zq.........`..z*!..~..........]../...V.I.:..9Y.!..n.. ../,.V...j...A.x.>..^......^..G..3pxM....N...C|.1.3!..<.l...X.v[.4...0....%.EV.....@...@..^X.~.....j.........B...v.[.].Z.......57m=..:b.+..-4..S,.pi.Q.{...7..@...YMs.n.9....IYu-.M......!r{.Q.1..)l....+V}?...\.o.......m..6.......OK.*.;.Y... .p..xG.-..fd......[..!v.u..4.G../ -/..OP.vdf_6h...j.....E.j7.......~.....) ...!.{..[..A....F..7.../8&x...,.G..778.5QA)n..L-.;K..]f...').w..E.E2.h"......M;....s>piOU(.+z...@..(...6K.b.....W..+..fiTo!i.7....Ez./&.h..:...t-mi}..l..).a.?.y...!....1...f).....S.....?O....A....4)....*..M8K...9,gw..W..>..N.v..xkx.uA$..0...&.....`k+..."(..H......g..`..4N..T.....2*..r[.~.]..........k3.".;..d.......f\[.%..[C.D.f.m..'....E.=o.>.;...(.{.U..Y.....e....3..\.N.....o.@.S.:.....rWG..0u.Q/....)x}Y...q..;.KgN7.......B........b...z..qM.3.UMJ...h.......=.r<.@...3..).........<..Mn.&..FSk..]IWF...G.c...#.C....p......a.(..;U.....C..jh.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37303
                                        Entropy (8bit):7.995117056068999
                                        Encrypted:true
                                        SSDEEP:768:+7VV0JMfj60zJyGCegcSL5lk41laWij5V3AbikJQRrlzViHx5KYnIAQI44:+c+z9yjbjkqlaLVQbikJQRJz8R5K74
                                        MD5:825D9DBFFC508EC9335304679EFC86C1
                                        SHA1:B2F81527B7EA230C64E3B393990E134D56457C48
                                        SHA-256:028CC79591C0DC051A1B701C04F6FDBD33E35307853DC131010EFBAC2FF79BA5
                                        SHA-512:1295DC4EAE37DBBD11D36E84D515173672345FCAAB814B8042127F7CB83192ECE9EE7518E002DC9267D5AB5AF819185550EA58B93EDE0F7AEDE5EF590BF892E9
                                        Malicious:true
                                        Preview:.D......y.....,N.....S.>....y..E...Tb..M.l_.R.....Yv...|(.a.g...p....q.......\.F..c.E*.m)X-.1d.1...-.6.v..c.....9......*.....a...k.[.~R...F.....6..#..oM...`.Yv...0RS..z.]..........><'......{...y@...."Re5,x...... ).j.:...m&........j.y...=6[.......U...MNM.....M..oY..Wae...},.....ot..AxA;..R.;.......y)..Z.T..}..>..T..U.$p+..!.@....~.s.......|.nQ...9c3h...A#..M.kwQ....].a.._...M.(M../....|..........Cg...;.".5..I .{.dP`...l.O.P..(M?.}.<L..._..L.._...5!@{7..X{:.....:...;K.....r.t....G......@.&D[...g..F..;...9.........V....U..!c..q...J.<l.)K{.r...IzTp ..Sdn`....M.z~..X.~=5P..i@G..O.....H....rW}..J5.4E..z:...!Fw.[K..K...N.!..L.o|J?.....O.@6..E...].......t.s.TT,}K.M....{.8..+.....>...^6..3..t....9..+....[......z....r..E[.ZV...).*eu...U..;......I...Aa|.~...\.4.E...c.S..xp.^..u....4...L...P\...N......RZX...n.4,..T.^.2|g.s.W..;....JJ.....lg......e..yDs...Qw....K.;'.tc...K.SP.`...?R..\.n.m....o].j... ..}....Y......9.8C.{.8.. 7.G.4.*...vo..V.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37294
                                        Entropy (8bit):7.994462327951572
                                        Encrypted:true
                                        SSDEEP:768:2pYZw9mw820239AP825xHzatyDPDnWc1rP/fdIU:2Lgwz08KU25xzaODWKrXaU
                                        MD5:04B7262EBCDEDD8A7C56775D9DAEB889
                                        SHA1:7F78217378450EBA88B6A8742BC7CF8A0A916E84
                                        SHA-256:163D05CD1CF77317E22EF163E6BD13234F9230571AEE5E026DCBC9DA76DC1306
                                        SHA-512:CD7FE3BFD8F170D988211D1148C0E3ABB6E70B6BD06B1BAB4F7DB94C98081B9F8A2C900D1A70246957B926D6C693035C5DD7A04D5CE323DFCE7C66F86D0898FF
                                        Malicious:true
                                        Preview:_"..[..G...6k.k........i..+Q(9.+1..44..........:.Y...A.t.#4o.D.v<fn(.+a).D.<.7[H..AJ.....\?%.=x...iB....N.l.p..w........]H..%Pt.#.b....86.U3....#..nw..m..Q.).A`...z...I/2.>.-...W...Gt......r..H.t..0....]q.X@...-.,>...?@...&[G..!...._(.2}c.$/...P..Z..pG.kwrg.`o..gl.5..VR.`.........$..&...jV...E.u..).R.>x^..H...c...n....7..K...W....Q..]..{..S....uAL.w.1..A...kN....@..k.'..b..3...&..14OAG.hIc_7..T.Z....[.(..GWlg.4...1...6..^..H../....W]l..wAbQ.hI.rd._x.mFh.;.7Y0p.q.(..D.+.y<.)ZkJFj..A9...S^I<..;.#K..2.S.G.r...%Fd...c.......;..T.%.......p...+...;.X[.L....x7(...3.j..|......}.t..f:...?6..A3N..+,.I...f......0..1.d+.-..OD...q.....g.C%$HA....03.J.5 ..!..*..,a..0..n-.%o....d?.=.J::n....ME;5..\.C..0...d..aa..!..m. ^2{...XE..$.....&j.aL..*.4V.7.mUQ..'.r..><w..j.+..q.K.V+.......Oh.|....$......|.x.^.f...?.D.;..Z.w>..)..5P....x..A.G.$<%.w9E.b..d..lR.....l....C....e.p.(.G5B.....g4.......i.}..S.<.E.......3.....~k.i.:w..i.W....8..a.\.;.WT..j......0!..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37299
                                        Entropy (8bit):7.994936201868459
                                        Encrypted:true
                                        SSDEEP:768:abQ+9dbvhq/CPbl7zR7tm2NtQZ8Kb/KoQcz31fnv:abQ+9d84pzRpm2NtQWKb7z31n
                                        MD5:A4A8F8BDA2B0CB4326388CDD8F6FB044
                                        SHA1:CBC78A67C8F25CED125945F3770AFB86BF0CC543
                                        SHA-256:46D8743B7D3498A893B4438D9186B8207FEB8C521FF8E49992AB9B9D74D30CBC
                                        SHA-512:0372C8FB8949FDC0246895AE61CAAEA442516B41C179F15DC8C356FA1A42DC0F190CA472F5B60F8CD4CF04E9804604FACC9685008D8700FECE3DAF9BBEDA1344
                                        Malicious:true
                                        Preview:d...|...^{* 1f+..>:...;..DyFp...]..0.....=..6.....I....b.....P....O]*.ez7..i......b.L{.:.@\.P\..y..)XC..6..u{.3.F.5o@.J..R...H...x....4......tg....."..).Q..?..v..`.........A.p..b......j~Eo....zg.. Y.V...DI..}..0_].:..Z.p....of.ud..m?l..d.Ra....-ZL.z2<.......-.F,.'b...}.0u....O.n{......;.ke..K.y.....D-.I...ty."x.J..'Fw....."_.I.|.Z\..A.N..!.ey.@#..\...*..v.m0.R...t.[.....|.d.....U.P.;7.0J.....[.-#C{......N.......6..x.o...T0...a@...8.N_...ex*..g<~.-..|..L.."C..........l.v..:q.(...Y..g..c..G;.......g....K...p..d9.<.....A0.......$.]..q...3.S...B.pq.ur....`..q......y.nV.o..".6...u...D..[...F.-&p.s..........x..e..8..r.U....IW.cd./..7.z....Os/[W..7-.../..........k.1..).H...F...........T...d..J.T......w........XQxvzc.v.[..w`..k.]..U......7Y.!.<<`.k.]..l..N.......~W."f..=...$.-.y..F,b.n.d.Ax.....ED|..fih.x.l....:.7../`.q..k...s(.C.l.j.T..g..&]..oC....a..VP..I.......!@.|..4g:..M.[\[..G...O..6'.T.......7.\...O.b).R.7.....$.q..%..4s5.a%.DV..9..~.'.C.&.R .~...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37300
                                        Entropy (8bit):7.9953402468134325
                                        Encrypted:true
                                        SSDEEP:768:nxOd40fErtnTe6p06V55tneT1P3Eyn2E8z4z2nP3:ncctnLv5tnKhn04z2v
                                        MD5:F92FB8FA47F119D9B5B9F392D3E5C0BD
                                        SHA1:BACDF048FF1EED63E0AA3DBC9F587AA27084636E
                                        SHA-256:3197E9A0D4A294BA5BD3BD7B300E644D6946235087CEA7999C79AC846CF59E46
                                        SHA-512:0BFF3B7DC54A0B9D12690DD139C72B974BCA01F4BC95AADA466ECC6C96126F2D96A98C13BC6B243DB149821427B7167884E7ED29546C499D12FAC2CE4DD47CE9
                                        Malicious:true
                                        Preview:1.L...6...1B.....jLI..o.&...J$P.Y...u.Q3f.....F,.z.Z.._...%....xy.....wd..L'.I7|6..././...|..Es.M.4?....!.i./..!...|...q"Sh. ..{f.i.=nc..%.V<.wT.ef._.+...&.U.5.......#.~.0.<N..-......B.. s...\E..Lx.,`,/....L)DC...r..mC...6..%x8.....Ao...<..3K.,.....{%.....@..d<.P... ...b......`.dL...YS4.T.7.=.R.l0d..]r.e~....'. ..(.....i'.#..=;.]{7.S3b{...^...F..5..6.&.(..q.._.2..;.m.......R8..,p.....%@.m.'n...T...zV.).~C..C...d..,....}..2/......e9.k...[....h..0Z.t`....:...d@....K6.av.}.sBV...\s\4....+L.3.B...$....}.c...8...)-|.X.....:.....|......G...q#!.....6G..]......P.|.'..d...$....q..12.|w..i.o...x...{.-..o.u...QF..:Db..%.#......H.*&.]... .....B...z..]..w..g..p)...=S...tk..`OP2.^.O.L....a.YDD.........n8..V..g/...n..I.7...AJ.$B...$.bc.......2...>d8.."....&bP..........g.Cu.)if[;.j..Fng...B......U..R.G...}...1#...<.....0...:~....C.....<......f+......%t3....B..............8..m..x..i]2+..Ow!uQ..Z....W%6...>9........gs%.]L.`..B 9........w.8...D.r].`......a.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37301
                                        Entropy (8bit):7.995015528412174
                                        Encrypted:true
                                        SSDEEP:768:1VYmSaSrj66oWbM/jP7aoB3mYsketZPuIDdhxkv0yW1QURRfH9dz:L6aSX6ZWbA/aoZrhetXk071QqpH/
                                        MD5:FD5CF06C20804F4BDD85D08C25CCAA27
                                        SHA1:39E9A37332D8B9C008FA35566FAAA818EE3FA30A
                                        SHA-256:CA30B8E286EA0F348F7CAB338AFCA19E80F489FF1BF6EF2F8A5FF5730B288C8C
                                        SHA-512:F5F815118CD9EA4FE86344DDF3D5F4EB612CF2937D08F7C5E81A6CDB2EF4ED9EE007A25CFE5D10ABE137A6B5D2B041F52027450F78D93890C6E4380A38D6CEE6
                                        Malicious:true
                                        Preview:.a.:.M.......T`.p.@.]..OY70.`...s"..Zp.BV.1.Cvo..H*.NE........g......C.....W".*no\`...\^.Pf...$o..|..s+o.."..*..|...<^='.2"...9]..........g..'..(.-.Zt...J.......T.0..e.V......K2..#.......?1..i...yVqT4....]...1w..8........?..."7:..(p....7.3.%.d..E.5......x...^C..'6:.f...C.r0..4.."..?..."...z.T........ .rS........4..(..6..#...,s...-.~..x..Q*.._.p.%?..J*-?..$i...l.j.J.P....a.P./...@. .iW....#.R$...)..i.n.U.^{.k....r...3...?..w}9..*..H.u..(..QqC:l;."S...~.*.!.fRF.J!B.BiN..g?j...+...o%.....KZ..R.A..s3.!G%....x.....g....DJ........N.u...........g......?.N...Q"...E......*.Oj....KJ.V....Q.V..B..LU]l.9.J..4.s....[...@...y.i..-g...:....6....1.6..N.i.....R....*D<..(...y..$...........8..o..L&.^]M"..M.9,.:.D3[lP..2z..6p.Vn..=w........,.........vV...6Gh......7..(b:..?.@l....~t.k86M.mD..r%.....er?R..].c..#.8a...@5.%.......n..&.......]..m....2.TE..v..b..i.@..D........@.....H!1....ne..H..4...n.3......<..Q..Lz..?K.].S.P.T....s......I=...a...x..r...w
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37302
                                        Entropy (8bit):7.995014943598917
                                        Encrypted:true
                                        SSDEEP:768:sfWHNJ0b/CxNShTqAPbSbTDebt/ryKN1V2aFWlJ8X5bgfRzxlS4:sfW70ENAuCmDc5yKNb2aQ8XS3w4
                                        MD5:21226643978799BEC98909AB3348CC50
                                        SHA1:A7B1F7A827B5F44FFC3DBB2231CF38AEFD89E72C
                                        SHA-256:573C4C28C659CF235111FE70E0246FE52F603139311033212A0BDC71DA83A467
                                        SHA-512:23C8CF96CD076AA761C267653935F3CCFF9240ED79C5A3D6170B0F62468B6E5DA29AE0D40F4FE8A4A3C16B2258D157D03B41C2FF006B7CD79E61BB13CDDAEAC6
                                        Malicious:true
                                        Preview:).\......&......<..WJ........Z.(.yE...;.ly6...)..3.t..K......wZ....#....F=....#}j<.=....6.W.V.3)9..K)-...t..t...f..(_*...4..t....b.).=.C.U.$.@B.p/"..Z9.%Ql.=>.-H.d....G.'......&..w....-lo.R.G..(..2).i..+H..Q.{#.."q..S...pBp&}....X.oCl.}D....!...AC..~...f.7..2|....J.'|..%....I.p.8..M...;..zz..-.[.2....`l(T.Dp...;3.n..K.9 S.V..*...!....B..f.X...............w..g...3L..../.M.S...@...L.|...m........1;.v..7.G..)..0v:.4...6G9F.yG.-..t...uP.}..]f...... ..O.Q..gF....c..*.....=.c.v...z......^..2...z.o.sm.'8*./..(ab...7.....:..D...>1..l...7U.j.KK....^y\.r......*..o ...?l.92.......+|G0...hx...>#.^.>0z.m.1..o.E.#U...?f...V..*;7.?f...{......RIy%.......J.....5...c...^......fX6D5=6.}...........{b....?.T.P...q.Z...1.#.C./.\...n..p..aaC..t*..!.!>.&.wM.yD<......e.S..F.......>....Q........*c.tF.t........C.y._p.G.Obg.h.Gbz..H.K-_.z..X.hl.....0H....g.G...]*.NA...eeMV..T.H.....HU....k.o.5..)..]..i`.Qz..v..i.b@.C-..l..{...XcP...bv..%S.........q^.^k..Xh.@l.....6.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37304
                                        Entropy (8bit):7.9949914303827505
                                        Encrypted:true
                                        SSDEEP:768:d/PGjScZVq5SI47H4KAHK3Bf2H3BU7V11UWm1IWRpd1pA:4oSHHpAq3hBmWm1IWW
                                        MD5:8F5982E978F4DEC9E7713D887C238F15
                                        SHA1:AFA11A3B2D0903798D8FDB1F77AC00E9B6FF2B46
                                        SHA-256:9CC5FE8BBA3636AAA7BEA68323981D3A088EC186F2A70CC2C8C6D412BEEDAA44
                                        SHA-512:C523165317F9A47E52CCEDDADAD56616C56DA31F76C2177ED613A08048989AAED45C76BE6150164D8DB9CCB6D3113B8CECE64A4673EEB47E8A82CBBDD9CC7AC3
                                        Malicious:true
                                        Preview:......1.,..G&1..7h......e..X....m$.G.FX......&M#.[(..g..3...{E..!.S........d-..).=:...x6SQX.u;..lS.,{.n...K.z?..).....#<a..dpW._g1...,.+.a;.0...`.....Y.D].*..>.X.......C.|....i.U...!5.....u.N.......^..5f.H....|'....S....'?r..*......mM.t^|"r.......N.3.J.o.:Ozkp....G.k.(oF.|.g&......;.G.(..e.W...ZJ.8.../.h..Q....]..........I.....)...$.G9... ,t..[...e.|...x,[..7.~.K.UP..z..]U0..Y.."L.-.....gd...2.t7}...U(.v.....W>:..lU.<O.c..g@j.0\w.qs?...!m..7.u.f.%.......m...7....Ou~.T...O..d....7~...8..J(..u..dtB.... ).R#.......I...9e.0.%. .......*...[...3.rG......hm[mk.k.S.S..Sr....u6...X1.t<...l ..K.?:..U..hlZ..'..........Ld.Rt...dF.(..O:.....*$.6.0.Pi..I?.).c........G......Y,...^....s..\...0.w..@9#T...I\.`....@e.g.u?..R...&..ik^.T..J,.%./....E...fb.w4r...j..z/[...#{.T4t....41Y^2...r..\D.<%!q.W'R....1>.k._k.{...mg.7x.<Z.=...'.....R.5..7.\..g........>...W...{.. ..w.......3,/`..Ro.+.>.....o...G.e...g....(%. .ce.._ha.#..7j..V..z.2.,$......9........X.|M...y..... Z.k..M
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37303
                                        Entropy (8bit):7.995190160390007
                                        Encrypted:true
                                        SSDEEP:768:UIflpILpFdQivZROO8IrSCOJNNqwmVsujc0LkIj30f7sljWY5h:ftETiiRRQIOCIqDzLlYfoljWsh
                                        MD5:BEC8B3E75CA1A8F4AC966880155E12BA
                                        SHA1:15DD727197A93B3FD750D60946E0D952ECD4D7DC
                                        SHA-256:2FE30F1A1330D66759A963334A16CDC4552AE2BC97511B58172E80DAF16FD7A3
                                        SHA-512:59D3B4EA62FC0D659BFED16D07F2A0AE3CA82853F2A54801677DB4BC3C0F376340F8D1F3CAB76E4B97BC778D88E6A136896917E9391E884156F3F81427198AA5
                                        Malicious:true
                                        Preview:.VO.w6.@.a....b8c/l....L`.!C..`(..j..4.{........w6..NrfH]%....6N.XKbJ4......5U.'...}....Vd...U.q..w1..B1.O...b.J;f..^2.......Slki.&..........N.D..Y...]3........m#.TfCI2.D..G.#.@ru.f./l0~.P.)_.q.. ...?..aAB...*...e...t.6Vd....g.....m.&..MY....d..@Y..EQ%.3+\{..5.~..n{...BV.&...9..C....KI.i2.i..M...~.\.....k...-"B..2...^}...F...x.W+..\.^...'.\.0....Ww....@...6/%..V...D..V..76|{.n4.b0N..U).g..v...K.es^......V.8.t..m.,s.3&.m..F].....$.f...g.W...f..6..e..L.ZV..BW..W.R.O.<8a.,.e..!..)..A.rz.!..ri.....r..ML...f....xK.GnM..5....R*..C.{....p....Qp....8.."...;.O.EE4.S....k>W(Ul..o..]..D..8 q\6....@.u9.c[.....`.c.g......*.f.....V;.3Q...r...:.g jE\..4....D..g..3Z&..j..k.j8...I.$..\....<.;z.Iy..I.E.8.@....wD..H.d..2`...F...Z........#..z......cu...Ipni&.c.8...F..Vj.~..:$p.^/..z..'s.....o......x/-:.T..../.:}Fm..k.P.ul.....Zf0..J..........m.3]D........y..3ZW.l4T..T.c....x0_Z........6L4H.|..*../.......h1.*.T..1.!`?.>-v..B-.w.+.,.:D.x..p...],..#.|j..yM.N...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37302
                                        Entropy (8bit):7.994980732368739
                                        Encrypted:true
                                        SSDEEP:768:Set+1uTeTcyEqyHGktqbraklsFA+eAtMTYxzYqsZtVsGJbtUbubM:bEZVEFHGktqbeDheAtMTYxzCZtVRXUGM
                                        MD5:E00B6A20470B61E0754056DEC9EA82DF
                                        SHA1:C22A15F19D774BDBDC70866711C90E2DD9CF8A97
                                        SHA-256:04746F5B3E840C0883466C216B05DD4889E1026F0D4B16D770796ED9774D00B7
                                        SHA-512:CB61E9945FDE4B80294EE869481AA9DD2C4D90B40455E9EE2F8C44E1283F62D109D1B2B2351FBC1CC1FC8017E92DC3DDE4098F4AB28404FB3C1F25CCD0708921
                                        Malicious:true
                                        Preview:.i.A.U..$...u.AT4....R...%.;..{(..[-HFLp.E..I..`.&%....76../!.H..$`..)S....z.9.E....Q:.D..w.e....j..~k.^]@8L^.x.....Sh..3...Av.....=...E.....!+9.f.5.....|.E4.`Yf3....t....)M..K=....k..`.lO8.;%=.V..#.EP4..Oi1........u..w>?..Y...!Q;[.B[....jXQ..n.j......z.......U.C......N.N.P./.%f&.`z!..b....q|q..<d.BF.&...n..=.?:..!..;6[.....l..........?...xg.._u....6...Wz.v. F..+...<..S^...-@.......I i.'..`UP.Go)..k.SN..[.d...G........o.=3....m..).A...j...`....y.i...5....5\Ri.....cu..W,.!./".s.%3.V....s\.d[..../.@.B.W.ct'.[A...{d..r...W...V...s...hA.3w......D-...o...ES..i....f./o./-.....Kg..x.UQ.....u~..R.R.w...H..]..`...[^..8ss.gDK....../v:....6..km......&Q[.b.....R...~q.O....~.m.wV...g.|[..Wb..U...#..}..Q+...n....7.?Z...R.^.Yq..r......_.t..>H/....8..W..K..R...ZS..f...>..:...Do/p...N...8...?s..O.1..A)gW...z....<BL?.p_#s=...y..L.".U.+.n..%....k.>|:B..0.6^C....'..(..^.O.u...D.m}.h.......GG.(!.....N.h....v.v...A.J....B..N...6?ZI. AL..<.Yu.....#....'..u
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37301
                                        Entropy (8bit):7.995118018720194
                                        Encrypted:true
                                        SSDEEP:768:Aonr8uauK2b+tPV0IwMTFAcFHtSGrlStOrzAZVij1iGWHV:p4uPK4+L/F1VtH8tfVij1XG
                                        MD5:3CAA3CAFE1A7FC35A0F3925A73A5B00F
                                        SHA1:2B335D16EF8B487A6CB5701C6D85F15CDC0BD3FD
                                        SHA-256:4F3D31D65BAA63C22CF1B9C8CDCCA81900AD8E9521F34E5C34242097E4A9AF87
                                        SHA-512:BBDB6B17B217C561C076F3BD7AF54731AA013A40DF382FE3533C9106BFF5FE61CBFEA09B409778509EED509EA5DA9B17B577E4FB573882B4F65131588717E803
                                        Malicious:true
                                        Preview:wT..L....].7?....].g..y.../[.4@!.......4...U.P....}..%..kK.D.8.!....s..h. D.}.H.....K....k@.z{....[v.jVP.....'|.....[_xK.H(f.L.~.01....r&.O.Y..7.n$.L..;.j.F'th[....s.a.m....F..v........-];.......3..t..'$]..M..B..H..G>Y)...ED.*..1{../ "K.tK}..i,...b<..I..v....'..pj=m.^[(.Ql25......=.z.nx...~|0...e'3a.......3.q.!F........D..#.....j...Z...I..4...;....z.Ar.T@._.y.D.WVy..{.F.6.bd.Zp}sr1'.H].O.........t/.wn..Ad....~M...B.j.=d.+.5.Q.....T./a...........6.]t.Z....d..H.......A..v"...Z.T...+....f.....J.5..<7..ob.:.4.gm=C.c..v..P...V...^k...g..uz~.....#O"g..D6.....dx.~x..*...2....%4D..;............6..r.W.....R.:.ja`...b....tIW+.Uw.l.....W....Y....w82.RL3*.U=.O..4..k.|.....w.-.iN.Z!...1.z=..7.pr~.+......Vz.G8......%..'C}.YD.e.Q..h.dh......'...D.".G./(.\...DE..!..d...!.rc!..... [..t.s.T....18.?....a(9...YD..V.@WV....V..,d^...!9g...l'..@.T..:.h....N....q..m_..!.F.dH|..>8.wCM..w$ae.....)#l.yy.....2n;..{gB........,K..F.*:.....J...MZ.Q>=..sm.V...L..Q...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37301
                                        Entropy (8bit):7.995426191121276
                                        Encrypted:true
                                        SSDEEP:768:ihtuO0TgBuy6o+VnYER+1uN9MFgVdHoDDvcAd+mg212:iNUyn+JZEoNVmDDvcfW12
                                        MD5:7B5DDB51F16411AF7A9A6D28A691DB32
                                        SHA1:FFCFB41168EB42B3DDDA23954FC4F13A5CF3424C
                                        SHA-256:449F4C6DACC88079A4C35C7D70BC5A3D9AE39B841E9795F761BE064646F92C4B
                                        SHA-512:082C09FE9C07C1187D970DEE08BD8DA79B5E8D50052B72EB3285A6026E6348EB0B025DA6C660AF82A9AFAD732A8411B2935043F34E0EBE284EE07CEB28728AA2
                                        Malicious:true
                                        Preview:I..W..v..X.T...N.@Q...P..."K....S....."N.j.|8........).<..!..I_.9I.(.........6.V.. k.H.g........./..o...t.3.8.6....X..z......%....z.%K.._o#..<...A....{..[.....+.e..s.&..!.9d.U'..6.}../b.M.@-.R.B3l.....w..=.1Y...'....f.j<V...4......_...Z..H7..HA.@=..;k..v....Z.4h..C.f.O~...Y.UXa0Q.4G5...Bn.{.....p.,..:.nU.*..}..F...u...U...Y..Y.:.kF..F......}.._o.......5.<p.`....e....P..P,uk.6p..q.[^........X...G\W..^M.$...B.s._.7..Fl..}..;g,...'_&....uC.{Ct.:.%K....2....0:o.\&.z'...D......h7..\..>n../.,e.[.......iA*./2..!54,q..-Ph..]D.>...c F.......O...JZ....E..0:.n.Z....7.i_.h..\./.eu.v3.J-P.!..i.?..{/..........W]3$.az?}A..R5Ikb...k......;{.'....i...-..3.q.d..=.a./.o.=.....Lf....pZ....J..P:.).tx./J&..K<..\....S.6.;7_<..d/.S..S...e.L..{...`......dg..+....h..+M.{l.q.E.i...... n(..z.0^.^..i.+..G..s.!....6........GZ.. ..........2.H..U...-.Q.[g....P.D......UUw.......Y:...M6h.2.uB.`......Yi..}..Q.g0.p...bF....U.._...-:.V..3.HG.....$.pi.D....v.G.U[Bu..$
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37302
                                        Entropy (8bit):7.994578229764332
                                        Encrypted:true
                                        SSDEEP:768:RxZnrtJb2RcM6Qisx4JJ3HvThbSooklLdepg2bdb/uz6KsxUyvn0kDR:RxZnbMoJVhwIdeXphjxUyPHF
                                        MD5:F8153A90786C26D8A0B46E036B1F0629
                                        SHA1:29B7E3D2C379089C2D7EF37439EFD3E3B48C1255
                                        SHA-256:482C7A31C268FE2DCCEB7535299DA1631C6F6A8407A469FF70C4B9A64331DD0D
                                        SHA-512:69847B9E63AD850917ABEB7EC6519262145C928D2B672FA64DE84BECDDE4C18CA8015C56F638B179E4576FF55DD528BA1F71AA1B18AC16E1D823390684BFA1DA
                                        Malicious:true
                                        Preview:7.3~#..dH.......H.V...&.#.........<..t... [?......n\.r....S~..vE..."V...i...!.^.Q.f9......P...$.[...Trol6....2.d...A.(.(>.hl.:K.Ly..p...p`.f@.l>.)V..F.W..R..T.....Sz.#...........C.~_.oB`.'3^BJ..'....Y.z......BU...7.{G... '......q8*.n..w..2...,..N. O........7)..Qy...v.....f..S.y...?^....H^...X`.{r.....n....gy...R.6..{....$e.=!.u..[.y....8..U&..*.]...fD....%!w........]...p$......O...x.....2.$...X...(.e......0......i .4...z]..!JS.a.[.S.`{.M#..8....ct..E.t.....i....QC..pA...9......]...c]...@........@6f.W>H......./. ..m..l.Qw.=..cq.p...Q-#.Zy.i.5...%....>.Iz.....ER....%q*N(..`.p.Q`.MW..P.[,[..C\.-......*T.7......A.T.../&.3%....[.......wR....j..2V...<...B0!.\....F..{-6P.;....'.MD..#T..~..O.wct}...W.W9e>.....T..m..H.1......)U..t.o..6i@....:..U.(.jr.F..X6W.z8..... .....VG.v...IW.t...U.~a.1..}..P... [......E.$.G.!...2.. ..~Eo.Vz[$...7...J..$..i.+..Z.............}w..6@.c..)..n.*......v.>....FPo.!..FS.q..q.<... .s.qg.._.....q.y....9BR.._@.M.J..w^.b.,..H...Y
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37294
                                        Entropy (8bit):7.994376318842437
                                        Encrypted:true
                                        SSDEEP:768:4t6MSWgrUbdBAiTj0mskAZ+yheNHsG+hcNTnxi:4EJrUbdaiTj/TUmHsthcNTxi
                                        MD5:3772FA531BBCA259A5B7E26E84F467C3
                                        SHA1:03E7BAF2DE6F92E195C3B51D227FF57C8693CF71
                                        SHA-256:A00708D2A10165C13F454C2708EA28D7C3D6100B9791173DDC25093A7613286F
                                        SHA-512:745651DE5B49B107AA19236F408C60AD4EBB1E0075124D3DFBCAC194F33595E4A7A3E85FC0AFBCED2EFCEA4EF5823C76F8CB3E3A26038A446C0EC243944E65C8
                                        Malicious:true
                                        Preview:z..2....fd.u..x!..YN..Y..,...Q......[..;...[?..0..[./A...n.:o*|.../y.U..-..aB.....m.......J.o6.k!....._.......#8...o...Zz....kc......J.....Wt..{./._...5...4})=.@w....-../.....u.Rf..+s....f..<f..{'...b$.......0C.....U.'u."H!c...}.. .@]..X.-...u...=c$..9ww.[...i...c-....l..1.....2<j....).3.?.i3Y.....F8+UV.....~.Z.&~.......u5E.e......Je.h.8vK..-}....'.....i=0s....\I.U.........[9.WYM...>....._.....;.:l4.D71.....(=.b......T]"P."S..H5A...Da3X..j.9..g?...:..&.....ll......$......HT-./....4...v..r.....u|...'.}..^.s.9S....1...)...$..#h...{...e.!..#2{bD.&u...N.T.Z......:.B..>R.<..h..........b....B.I..M..1..-.&.s.t...q.... ...s....6a!DkQ....Z.W..>.:.-.U....t..e...J).@..3z;.l..QO..&..k"r.K".w/.K+..F..|(>...g.#.sR.5...`{.tQ.v....9...2.2+X4..m..^..a.0..].. ..i.....6{...A..]..R..U...RR?.BG.~#8..dB.N].O.y#K..hXC*uj@.i...H....,V.....&..=%.s...cz...gm..b{....:.li......*.#>......GC3.......'.H.....:....~U.{..Rb.eD...P.'.u...y=..~...y.......fz.....:t..9.L...as.l..*.X
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37312
                                        Entropy (8bit):7.99466824149491
                                        Encrypted:true
                                        SSDEEP:768:NsZcaI9xDmzZ9yp75e7YtxzU3UooLFdMsblVxN6CvcffkTyD:NGxI9xD6Z9yA0EkooLFGsnuCSME
                                        MD5:0E83D58D8164DA93FB3EC6A71F65D1C9
                                        SHA1:D20558ECF76CB50FE0CC4AB8A6C009041772F618
                                        SHA-256:5B1D073A357AFD13DCFA227454F5818C6312C4C90DE4F8BE95305C76F8ADA328
                                        SHA-512:FCC201652630CCF4829B572C11E9A9FF3B6A2CFCFEFAA2CBE2B3DCED7B7EF6C9EDDA5A7876E5CBE8BEC6C7386C3B8529B15279ED1F5890D938A05A5E55FCCEDF
                                        Malicious:true
                                        Preview:....'.*d-..8.}.}L...i/<.?:..S.....@1X.E.....2..b3g..49R.&.o.7....apg.....a.a....o+.............T...x.).D9..a.[.........;f..|3.=<...+.=#j...y..L.LYuZXC...J...1..5...h.dbg...bm..-..`....&.X..@.Z.....j..\.U..iV.A...........MA.tkvW..\.&.....n.tr..?..^./...Q#.|gy]Pnj....i.nR.....Mxc..E....l..#.t.h.,L.....xB....?yi..i...!..@.A.V*.^...M..'$...F!.Yoy.N..[kXV..&..==....*..ta..G.;..`d.L..I.-.m....;.S,.}.D^0.....D,r.4...p..i.K4........ ..;H..).H.NIs......&u.c.t.....#.~.Z...SIG.t....:.........Q.o...!0.6M......n..gR.D..kM?g.p..T..V....U..,Z......\J.....,B....A.gU.1J'..a.B/.Fg..Cs......e.b..U.L ...[.8Yt...>.].5.....I..n.MN...C.S..a.)..:.i?...FB....E.*...s..f.Wi$.E..D....vD .Y..lVB...IgY.dc...F=y.F....Q...}4..e.Sblki.?.*z....x...L.>/..p._...|...q.ejk.z.....!1...!.././a.NP[7,.`.s.?P.sx.... ....+..n...`...S..Y......M...P.!.!.......YC.}..9?j].,..?q..B...H. .@Q..v.K.FM....?y...8.l._C..l.....AY..x.............2..c.3BRC..........my...... .<.....W.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37294
                                        Entropy (8bit):7.995157094840323
                                        Encrypted:true
                                        SSDEEP:768:3Ct6sWHjgHA8MkddYhgrqaBlPG3UdV8grPSQvOVLopL:3CtOqAMdBqIY4PPSeOVg
                                        MD5:BB80937EEC48F523DA04D44D192B4D4E
                                        SHA1:C947EA43A021F2C7F825832DCB37AC13CCF681AE
                                        SHA-256:1A083277760CE1F4C3F27EF38DEDC18D614A38F2B7F995D77D06C7396CB7C178
                                        SHA-512:6B179D4D7062707DB699E761A2560FCB4ABDB229F39CBAF2E41DF5A39DAE9D4905F807F2A81D5039BFD75D2E0C37EC0E9E400FF351AAE36EE6B642E97F3597EC
                                        Malicious:true
                                        Preview:.M/....y..VQ.\..%(}...Z.lB......5b&...Zz..!.U.GlU3...3....j..,^.~....i.....s.R.....n-.PU..0..z....._w.!_G+.L..I...c..M..k.0...s...b....I.l;..G.i...$......0[L.:.zf|`.!....M.i....p.rqN._)....Okfi.[.p71..Mc..........Q2....g....f.....=.[U....W`Q..V2.....e.C.C^..m.q..........DH.()h.H..H..#u.A..d=!..~...7lCL.gz#...)..{.c...:.,...A..k.....(....a|.[.`.&Q.t...p;...+.h.|t.b.........J..B|*...abB....\...~...L5'.J60.7+..\....^.d.X1S.^C...|.y......'y...+..C.m`.8.t.bT:T;.#..z.<.'..'......+..C.1.1....G.eTE......1...E..L....|e..g..+..tNqKuYN*9..O.d..tau;..-z.Y\g.....+.PH...`3.H...w~...29......9e.....8.e....&.uL..FX.e..O'NB..++.%QK...l..P.....rJ`.......3 ..3....b....u...!Cos..9.....`...q......2ve.`.b.eNOl....H....._..S".L..,.h..C.f$...M/sJ.E...W.....->..l..UEVl....@.~Fx....r......C..js.mr7.u...d..:T.B.....V..-......s.r.k....._[.j.A.*.....5`)....Sv.w....V9...V.|........J}...W..nsL.4..<.~..kY./5.m*X.X^-.*.#..X.O..)5eT..=.a4...X...U.C=ey....y.y.(_.0.......G
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37307
                                        Entropy (8bit):7.995657673912775
                                        Encrypted:true
                                        SSDEEP:768:x4q3CWWZEGPDhOqQa7B2vHgsZQfUI2lOPQT6py7mV72NJ87Qm9fM5tSHL:imCWyFPDhOs2vgsZQ92lOIOpyakNJqAA
                                        MD5:CDADEBF8B46FBA9DC4E7C569BF552445
                                        SHA1:F3C2ECBC27E9A740137B0A1FA2BE66FA3B6AAFA2
                                        SHA-256:6E7EBB61E315067A5DFB94D34403EED4BB2B3C24A06561D72007248DE8CBE4E8
                                        SHA-512:F33A2C6BAAF4D53A2A0898D43334C80B6B186BDF16240C6634374060D94BDA58DCCDBC03606ACB18DB92E5B76D176368F8F3D14E37C4EDEDFF6E6571D88F99C9
                                        Malicious:true
                                        Preview:#...c.d.pu..p[o.D<.q..".^.$|.o*}.(...oX.q.7.r......~.G"D..6...H..|..Ek.GGgH...9.M[(..B.....~.7. ....8.*..?.v.?..'p.uH...@7.:).X.=}.G..C7pm.{.....N..).{....3.... ....Gs$..m.....}...67...2....*K.5#:a....X;.Y....?..Y.kt....E.y>B}......hI.|O..^....p......U...h}ZY.v.(.+....o.&kaN...`#U^.X....p.h...2.5{z...Z.9.......G...z.U.z....K..e...d.C(.................v...6.<.+..NV.9......0..Ul...V.".a.F...OX)B.e.6.cT.......1.R.4.....]$/.z(..:...?T..I)..E.q.O.|....:.....a....u.....'} ...F69.F..W..>b..'.....;.}.?g.b..X......O..x....\;.`.D......K..~..............I^O..5;...(.X_+F.8..yU...#.."]..o..^.r.A..'OMH1.|&E.D~vQ...2..U."..6.D.....!...l...]....o...XnHwA]...M.g.ik...=..r&......3*v.o....t`LM.J.. ..............q.{.%..d...|C@.|j.`j....Rk.:%.%....3\...ah......].K...s7....L......qx...!.^.....>...h}.*D.X...*..VT&/.&=.z.#$F...b.a>`..]..p.FD.T...r..b..vi.A...Y..,.......S.K.,....'.v.....]E....6^..Yj..&;...C.GA.&......"G...Gv._.N7r.\q...Z..i.v4@....W..*...A.X...Pz.-.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37301
                                        Entropy (8bit):7.994948409121168
                                        Encrypted:true
                                        SSDEEP:768:HZi25UiyqoQ/95ZyptsdQuSb934Ik2jIKzB+w1maKP7Y0Y7Yu:HNUiCo2sdJS2N+RzUDY7Yu
                                        MD5:4199F26E88EB42D1F11F34F00475F418
                                        SHA1:842A7F34A0C4E94F062281FB1650E7509D81B86C
                                        SHA-256:9E81C764E9D689865EF97CE400063F183DBCF79B51E209C3B10D6CEED25143C0
                                        SHA-512:E247B0067169F083930A8470298B13B215A6EB4ABABAC8DB18E2B301C382BDC241877C5DC45982F0F06745A9C23F95DA89D83D91B3B1B644D7084502F4FAFE2D
                                        Malicious:true
                                        Preview:)......H.Y.OH.:.-['.S.....D....Qk.L..9....-NT...+...k.9.nh.#85s.......y...7.....g.6.qw.$.0@.....KJ..19...M..(..5..'.ph.k..\...>.SYS..<...s..&A{j......T&.4.uY.DU-#..........yJ6Y....e....l.j....+...v........V.X.EN5...M.3.b.f4..b.:`.Iv.t..?&..Z~....O..-x..I...W..e..2..}.I.".y}:....`..h..Z.....D....+.`....d..6.....2.C.mzR!......Ac..oxe4?.{......:w.!..|.K....P7...AVb.).o)g.8............5B..UF'.....e.s..N2......|......Nn.b........Q.)Z..w...V...QZne^.FU....t.zd........K....."....`.MTX..~N...Wcx.......T P....\..4.J.. ..o{.w...:...iP....#..Jj...^..9".A.....u........5i,H..6..U..r.nOV....k#...?.P...`..f)*.S."a.n.o{If.t.K%{%.U.....Ob]...K[.m.na...k~.>\..!..+.. @...3F,,....z/..........PZ...C/ok..E.L.W@.=.....|.0[Wz.....U...........#.."..]...7....../*..uYN/.n.....d...%......d.T*...2.....E..0.r.,..%.....n.*......g=.Fl.(..G.f@.QL...k....4..~..:\.c..a..VF7.W...M.V...o../..#q./...3..{z.... ...?.]G.K)W...S.%g.:w...5G.b....I.o...G.......}....P.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37300
                                        Entropy (8bit):7.994450875940638
                                        Encrypted:true
                                        SSDEEP:768:dSghMT0d1rSG7TIa4MOERBSbZt4noWy0n/tj+yV7ttT1/u50I8W:dST0WG7tRYZtcyGRu+PW
                                        MD5:8B20290ECD5D6F078C4CBE0D7F568EC9
                                        SHA1:A747B46C6CC808BC755B494BE5948457031FC52C
                                        SHA-256:5CBEFD99CFB6795FC13B87D9637108D9AC137077AA64E58B607EF3EFE4DA94D2
                                        SHA-512:F84CEBC5D9BD0DEDFF7C43F1BEA053BB1A6F623AED8F33650CEE53B37FAA86067651DF0C483E8E835B16AC0D82E0191376D4003C26E88EB875330CAFAB843500
                                        Malicious:true
                                        Preview:C..g..|...A....W...=Z.......G.$.NGH....v{u.n..l..*..[.zZ9...../.$^V.b....Z.GC..RR2....._.o.V/..B.......OM...yzZC... .....)[:..-:.;n.C.s.`A..uw_...J.BU^...^.....|.6...s..x3.:..a.. .....v.....FI...`Z ......F.`...A~....l.H5...}_-.?..q.......|A.mO.]..u..A1.....1....+.m....6.g..X..`Z.r..R...Tv:..........W.r.m.K..M..o.%2...d.N. '.p...Z<y...S<..1%.>..F*....U;..4.K...y.....!*......A.i....7.....f..6S....(.T.I[8....|V..7q-........Y.....2..':y...*.F..j..B.*......8.2..,..#;.B...e..B.$..#...F...I)...J...]UX.j.....f[....'i(.F"....OI..._D.Z....!nG.ar....&..5y.%.CY.0..Z@.edB....W.2.._h.v.....yB.qf?`.f...v..PP.........4&@+.....Q.......*.0.w.....cU$..(.*.9r.*Gj{..i..@.?.Wi.k......8G.+.Q.}...Q.......S.......m.>fN...~..K].S.....!..)Z.m.l.[.U.:8lH......|.....C...j.4O...R..GX..$...G.~.@...c>.>.V0.*S5..8.W9..H" _g...7..?.l...}..../+.v.. MD..H..Ra.dd.o..@...a...o....._..._....k.7b...:..Q..9.K@{x>...w..Mn.cJ...t....>'.D.... ...5.XUQ..,..c.C......{wk..$.,;..J.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37301
                                        Entropy (8bit):7.994878768478605
                                        Encrypted:true
                                        SSDEEP:768:xeW39hrMKmPNssQX3ofnPAsdoGpuE1PIVHiaTUh1cnn9:wW39phA253gFdodESkyUh1U9
                                        MD5:EC4380BF651794AB16C766712897BA2A
                                        SHA1:0C25EEA66867B67B44E214057C1C9684B2962BA2
                                        SHA-256:E51D84A7BC44F9D55287D9402BA1F0643D84FB27CDAE342E09638DBD0B453BF0
                                        SHA-512:906C0D8D0CDDEF573648C036F16C80D84F48705C3E4BA39F126AAAFAC035B47DFBAD1C0D143C81CD4A65802A233615AAE6F26EF3D89539BD5DC05E9B4E176CB9
                                        Malicious:true
                                        Preview:l.O.E..hlz.'....am.y..+k.. 2nH.]...%.k`.._2..M.(.4R.+...z)...b7...;e)f..\d.8...x.RJ4Z.T....h.3.l.....I#..m#,....<t....v.....B..%Y.E..a.Q.X.= C(..P....P..:...i...P..S.#<.....T..~gE.S.K..... ..U...vk<Kk.....$.e....u8..../._.|,....F.....v...s.*.a..Cr.......[..d...-..y.._..#.v.I.^.&......B.9.?.Y....6..Y^NMI3.4.7.l.G.YQ=.F'W..3...........h...t.....?..A.(Ed..i.....k*...7.1..o..5..a).).Sb...L.R.-......1......+r..}..I...\.8V5...+Jf.....c.@.......@.ru9._....I...6.|...S..h..tI....Rd{.7G.,.....)e..|d6......p.P*...W...V.&.?.0.T.l.N{ok.. U]A..J..uh^..@...n.-.%.|..=.5..L...0.v..j..1o...._]r}\x<.@...@k..q*O..w.../-&...XHTzX...{5e....Ck.ui.9....R@0.R..f5.#._].,...F:0.q..e.h\...a~.D.F.\.V..*.S.....tW..K.v.qQ...v./....SB.P...u..o...W.~.m......:q.......7. .3..^H....Y8.....(... H..............Z.A..(O.\......"..H3=....q;..?..'bI.O.....d.)..E..,.%Us..|.=..<./.[.c.I n.:......A..>..W..F~r.XVE3|..H...."..;.<.]5p.L.=+...$2....].Kbh.P..?."F-...f.y>..<......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37314
                                        Entropy (8bit):7.995102175288233
                                        Encrypted:true
                                        SSDEEP:768:S/KyKbh93KjBWUFZQqxaJsiW1BARHrGxFX9HJEsW0gMomA80bZeAOG7/wk:S/S1w1WUFZQqTjuLGxx9C0g3PbRek
                                        MD5:67D29046812D674C88211D5BFBC67369
                                        SHA1:5D18134A95E08847430D65A22DBB482588AC3360
                                        SHA-256:B3316025A171AE77157793CDB3B00204715C00BEEF9AC4F011016128492757E3
                                        SHA-512:53E31C091C1D1CF3A4C3F815C3FF6121627E6388266DF432C94A22847146A5A86663825F2EDEFEEE33ABDFAEA0D3DB14330DA29688EE056F89E39F569D2E08F3
                                        Malicious:true
                                        Preview:i...nw.....O.O.Q#$.,;....D..I.E.7.w0.F.A.r._.....>.YK.......S...5........t}#4a..".42.[;/.(....q%.....Y..2....ipw...!-.......|C.umK......'.#..5...Tl...P....e.Z2.{...."....Y]...!..x......wp.....xZ..T.<~r....P.?. ../.......O.@T..0..A.jTp.<b.2..!...q..a&j{.4..e.~}f.Q.@.Dl.(....AN...]...a...|.V.9^...YG.#....H.....;g..e..l..`..i"..F...I.x..Z..,.!x.X...FG.i@h.z.$y..........0......22....@U`.......6.dDb-..1..H.xq/ya...x?:.k...{...<4?.;.J."..s.`.N.........|.@...b....C.Jm...T-t.I/1...w.9..%.....C...G.........}..}.J..?E.7.....<.....UT.].m........3.6...0.w^......R..I...r*.8.d.s.j..5...].% D....h.i.9....~.....+.V..2..xs7...Z>..<.u_./......C......TV.Y .=&t.bT.v$I...=7..w..u.=.By.K...k.M%g..N..H.H.{4.@E..jn(m...5...[]..*.$...k..%.Z9..\[.i.,.N.."...;.w.t.u...@.pi9...v{(....c.L7a!_n..5...Vn.WbRY}..XPZ...T..=.A;...l.....p$.V.`.K..M..0.&...!.......+..G...........b..y...}....g......W..KHD_.E..d.K ..p......_q.o....D.......m.vF.<.:.....<.6...E)..R..-&..S.j
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37342
                                        Entropy (8bit):7.995456695008733
                                        Encrypted:true
                                        SSDEEP:768:9V0EuJocYK1zMs+kLgUW0/DkwmwIsUuD1Tx8wsGR3:kEuJBYK1P/BmKUuD1B5
                                        MD5:5C479E24B5FCFE446FBE5BC46E3ADAA3
                                        SHA1:5E7A09F1C88F172353296CFF320852BB09548B19
                                        SHA-256:FE30324EAD0B187BE7B71A785D950A1576E929F00472B3D9B58CC3E73EAD33E9
                                        SHA-512:7DFFECE22F3F4FEF279D9B3F85600D7360889D2CB9B8DE7B839EE05BF67A2ABD05D220D721FCA29C3EE491B9C5F9DD42D50A06C4B9D636AA7B0AD4728333044A
                                        Malicious:true
                                        Preview:..(.l(..).Q.]..y.'.h..7..{c..~^Lz.....x.J`E..M.l&..-.OU..YP....}H..-~C6.o. ..M......5.6.\2...x....,V>..-,O..%9.O...B]K^...$..n.Z%.Qf\..e..".e.w..zj.p..IW.i....&A..._..9L....-....Z..M.l.%k@."..........Q.Mw..K....QD....fD..:...X=.....yOh.'Uh.++V.n..H.VV?.He....h..J..rr..jTs.]....K...l...\.+.{..b3..h.!....dX.wK.8..1...Q.g....*o..:K.%K.8Q......z.j.x.....9.gB.F..j...t&.....i....t. ...v5#O...~.F..]@.....m...PJ(.R._z.....=.F@.nmp...D1.?EC.Z...x...].>Ds.w4.pN.iMo/.X.M.)P...|.}.W.m,.Nb}.].v...\..A7.NRp.R.....ls.y.l.*`@O3..+.~.L.V@.5Cs5.......Fv.]...?.P?d.ea..Q...g.....J..g..}u...Z%.b<,...#..8.A2..y./..P..6.Wo+.j.....AtW.s...!S.g...+..I..E..s.1.e.|HZ.(..\...:...}/...R..."..R....U...[.....`d.Ot!.....do.Z...l.+<....`..v....]..n....{X...]-Xu.=X....[.d.d&.....KG....H..>o..1.im.._xd.d=s....%......'.kX..A`i.O..M....y...J....{...:..;.(.n-G@".9...M.#....<...abd'*../.1..!hk...Dz.q..b.......^..U._.M}B...94...SX....>..Y?..p.._..h...D..`^.K14n..r......8-.K...Yg
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37332
                                        Entropy (8bit):7.9950837889670785
                                        Encrypted:true
                                        SSDEEP:768:49CNDThVjP0NCwkF5X9c+Q05DqHmzWDtaYkzy2mwbIfO:4IthVjcNCwY7HRqGzJYkzy/fO
                                        MD5:393E2902864EA0EF27BEA8723A5D5840
                                        SHA1:DD3D1BF2280E16B2BA182AC3C013E4BCD1DB27E4
                                        SHA-256:670A4E7D498E302BC6E05BCE629C0DCACFB8B56F45D3C95F1885016F4B49E48B
                                        SHA-512:8C32CA08042C25384A44D8AA1DA5D7AC457F8379B4AFA1E742AB542663D9B110CC31575371D912BB8F901C10563CB4CE80F68303A8FA7675B22B80B7570298A1
                                        Malicious:true
                                        Preview:.JL.t.?{...U?.pu.t..+.....QN..Y..X..X..}..`3.zh..*...m..%XDS....z~..r.t....I.6f..0..,..e=.2...#...T.f.Z.........@.Q..I...[..m+R...h..........s-.t(..3.|8....{.7...)^.Y.SB.*[..LC...../.....\.w..U.#. .......#.+.0X.M.".Z.6.]..^3W.....T.A..V?........V...}{...I+...>..7..2.,{9...{m..=.B......D]..w....[..+......!...G.......u..8....'..Bf.......x...Y.cS..S.&....M.Z.z+..H..K.'...%.#iVB..IU.?........!..&......)...B...Y.F_..:......o.............t....C.h..."8..MaLF..zk"."...,......U.W?...].%+..d{!.Q...**3.|...".......Y.>A......*.....Q..w..d.....n.9P..%..}.....c`.b..{..iiiE.B..{a.zM..|P..f].M.....jw.$_N......`..k.L......e....R..!.Vd...D.CT\.aZ ...q.t.......sC.V.y.(.#..ns.[J.........4.:;\8t.l.O.....o........9.r<.6...S.....(.+..R.....S....B... .8.0...... ....1H.....1.......OV..+..m.$#.rK>.+./.L..P.W..g}P..?...hZ....@..%..>/+4W...1.../..%{.8...gT.V5...l.z...."l9.y..3.N.......Su.)f-......z.^.{.X.k..<....Cb.X..9...1..}A.KW#..9...PBKo....f..K".}...b....T.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37312
                                        Entropy (8bit):7.994976249402636
                                        Encrypted:true
                                        SSDEEP:768:wldSU1H+ZwrnizMVV5zEe9TH0uLD8NRY6l4zLZj9eaDzQz2FmPv:wljwZwrnwMX5zEeRHdLDtj59eOQzRPv
                                        MD5:3AC0EE2D51FC991EA42F78542CD03EB9
                                        SHA1:57EC06CB10EB1FE531EBCA14710410E13B7F2556
                                        SHA-256:C218438A7BEC3F9B872FD305C6D6FEAA5957F627313668CFF3AB3801D0B67136
                                        SHA-512:C4167295413BB2B4E510A450E74968A827F201C4325F7E33D0A4763A54797616EBE5843181AF5C8491B93A313E19C0C3F55F33675E0932FB2FD8B103CAF69652
                                        Malicious:true
                                        Preview:..2p.1kbA.......-..$.0...H.[...9.....l..JT4>..........8..|.G....#.z.[b..D.y.O.."..o..}Y]f..X..)C....|..&...S7.C.,.....!b~.....C"[.`.B.N'E..O................."....<.P..m...,.Q...}{.v...XN^...(.n.....(~.E..0e^$...3a...>..7.."..Q.(!Z.\.t7.Wz.........y...q}.Hk.D.]k...z.../F...... H.#......n.7..B@z..Xtj...0..Z`][z.~.nH.l~...'.kL.....~...!.p>..6.z....|s3.2.H.9#...s.]>........G%."..F.z..P).:eA...&.......Z).c.B(\........_*......%.9d....j..v..+D8ZK'...9.S>...}..;.z)...eBx.'...m..).0#.....Y.>...'.......N.._.W.0N.$.K`7.9.e..Y.!3.qD.m...R......<.v....^.x.5.^.Z...5).#W..5.P...ZO.....tH....]..{......4%t.2.s....O..:.....qW.B..... h.*.ee.hWDW...=.mS..=.8.~.$K...b...U.S4sw_....U.B....U.*.|..f....r.v.G&..x..@~....aW.1z.< %o.r.Y..[.+_...Q.Rd:..,...6..<a...$.S.\....&.R...@..=.u.].,.@......E.X8e]....*.......5..."...I....4.VT.....H..H..../...,[...H..0b'..n<..^l...+H.==r.n.2..4..&W....6.J.)N..N.a.Q...'Z}.G...=*RB<..l..>.........*.S
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37318
                                        Entropy (8bit):7.995220011098813
                                        Encrypted:true
                                        SSDEEP:768:T9pfpHyG5NGfko00GQgJ/HD29RIevvdDDMIU6mdgzhrVEdw:hNpH5nGfz0iEIUaOdw
                                        MD5:F1B64CF72B9CEC5F436E2C88C3B01D9E
                                        SHA1:676FEB53BAE6E8F0A548DE90434BABEEA11E9ED9
                                        SHA-256:67DC0CD20FAA765E26E12DFC485C7F772885DFAAAB4BC98FB1F32EFD110C2DBD
                                        SHA-512:F7444C0D590D94C8CEBDFD2C478D8102AF59D2D4B2EF8D1B8ADC2999BDFA910D1407B62409D0245C5515F387FC49D3D398383AD2E2FB0F93A3E3C40635C270A1
                                        Malicious:true
                                        Preview:`..C....Z.b$..i...a.Hb..2...l......Q...a...$..f..U.Vo...|...s....P...'P.."..+....N.&..=..#TD.k)..........U.=..sM.Gl.-.,.5.k..C.9.I8+..)l.J\.......$....p.0+VX.....7.Ftz.U..Ja$.0?4Q@!..P7......u./..L....^......Xf...0H.3.S..R...!..d(....j.%...b.C..(..P.....`..L......T...9........6....0.U.R.Z.......4..:...w..r..,A},.k...xV._...NR'..1<..O.....}A...E..A....y.WTX.....Wp.o.,.-f...o.....p.$Oh.[.2....&......!.88.k...T.^FV.....c.=m.....W.k.4.<..p...\7f(....U..l..u].*(......w.HH......6.....i..D).....zn..Z...y...7.C..A+L..W=..2%..U9.P..p[4.i......+.r/. `B6.M......-.#.m.n.J..._...t."es6.Rv.=..Op.=.eW..!.H.%...f..w.."./<.%.`.<I..|....`+..Lh.7.l..v*...Adp..D..k..I....D.<#..2.1FQ...0"....R....\\QcieV..Q..y8t.9......8.s.M.u......W....x......D$..W.b.l....c.>?z2.f.RTbB.y..9...2;[{.......M..s.S.xD.ek...PR..<..i...U.g...4%..v.lv.Ec..7.......W..S..E...6S....Y.p\.{.W..o.....y...S..."R..5..`;..ZBQx1..e[f...p{.(lp....-..I.y...|..-....i|......7.\..Q.w.Ql..~L......2C.zxcc..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37311
                                        Entropy (8bit):7.994983481861245
                                        Encrypted:true
                                        SSDEEP:768:s43BjTWMFkvwjNDGij+mCA4Y4o4rIHAISVlJoRd0GSxLMbP3rHKpFk:9BqoNiiSPY4rIXeJosoHKp+
                                        MD5:456DFF44C05025F23DAEE1BA86932FCE
                                        SHA1:3CCADA59472333A6C27F1386E0FFF6E0F921C56E
                                        SHA-256:C0888DDDDB8006371030E02A642DB95B7833F1646D945E27AE41DC55691EA6EC
                                        SHA-512:598E32260621981BFD54002048BF5213328F59A656BED271DFC49EA65E89444AB4E4740819A1F5903CCF80A27D2887BDC2AE981EF24531A6AB64A912F49A8960
                                        Malicious:true
                                        Preview:Rz..t...r....x....H((=m....!..H...N....H...W.D.Ep...W.c`..w7`.2!.[234.B......g....u...<..Q4.....F.T.:.'..K.....`.....R...5jImH.....K..4B\n.J.%..Y....Q1..'........=A.j..V...egE...r.o.yz"......J.....^B...hK.(...3.(.$..}z..J..4..O..O...p.iZ..c......5....N.L....QN.%.8$r(8....~.qq2....\..#'..'.K....xzp.G..^Z.;.G.6.U..!........mC..\z'.._G..........S....^.X..YA...T...q...#b.T..b..}C1...c.).'...6@.).\...r...ImvR..H...(F..-M%..7d.!..g.;.F.^]u.M..x....`..(...w.`..<..e.F....<.1U..)...E....p.....^l....KH....S.L...Tqo..'...-..o$./.N.........1K .Q"..2.U1J..bZS%.[...5.....L..7.f..+....4..p...I...#...q../..u.J.........Nj...RE&.WU...]..DV.v)...?.Cyn.T%.Yr!.w+.|..4....!.+J........37A..?g.8...w?J7..+..39..c..E3..@.".D7.M.....9.+......u.o3.7.d D_..y.P._..........v..Q.....8...D...6].[.>X.!.JQX..c...;..n...bE.......}..u7y..,a.9.R..........FJ.~S_,H .....t.4.M...r.<...._.ts...G._Ma..u..N...1.f../..9e...lY....>Dsp..S.d3.l#..q...."...B.4...C.NvC..Q.\..Z..(.._L.l^.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37316
                                        Entropy (8bit):7.994757018339243
                                        Encrypted:true
                                        SSDEEP:768:4AJyKnM0dtuNOkyc3dzCvAbQZye+keCxjfIOwa:bjJ7uNOXc3dzMAbeJ+keCxjAq
                                        MD5:D4C507795D65F11F530193EA4C4EC482
                                        SHA1:F21A1C4F6021A2F19EF58F6D38555D91E4152044
                                        SHA-256:4ED6DF17ABABEECC6CD26B01F1E1998CDDF6B58DEC03A52054BD92A2CD608808
                                        SHA-512:9BF89DF8F23A4481D4BE7E5246D2ACECF36BC3E73F15F544929C01A8A7CDC3075BFC580C5C767C4FDC443C517F76FE18A9AE70B46B146A932FAA816AB27CF7FA
                                        Malicious:true
                                        Preview:r...Q+K..-..<....Y.,.R.....k.2t.`.._.v.....G..M..b.,..k....f.=Rv?W:Rn.,.7R.....%.;..N|..M..G...HS)]...2wVP..mu I.mn...CH.(...C......bv.$+..v....!~..f\Z.2/.2Y..u.$t..E.=.(.K.z..o......#J.F........7.Y.V.&h.."I:1.).....A.6.M...kt.+..+z..#.v.......'..._...6..\.D.e..),.......Z.ECA.O."S....o,Q..,....>y....v8..c..[...n..-.?.#w..%.J..{.{.>.+....P.}.....b.=;....L...4e..W..4[... .{...>`C;....l..._...q.....t,B.../..a4x1...d.g...Z...&l.g..a..xD.3,.1.....j..v.A.5.". ..F9........{...6j.0.1#......3N.L;...]s..............^s.......1%..Wq.Q,^..m`..D..)D...DG....|....u+...'0.'...._.EY...+A.p4.C....c.W.I..`..(c.][M._.1...Db...}...t.b"(gKF....CH6M.w.z<f..Y.\..j*....SR3.....S..3..EvJ.U8...I.A.9.~........F....h..Xh.6l.@..u....Z..Ao....1.L...I...U.:4....Gb.j.C,9J......].~,.Uv).s[..P..ji...f....Vd.X..D.....#X...@U...T.(k1....$.g..(S...t.=.n...~..M.k%;..M...I.,K4j..NL.X.D./..5c...k.fi...].%..)....../..j...G..~.x.#0...=.J.E.........,)Q...{y..-E.O.(\..<....x.J %.2..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37324
                                        Entropy (8bit):7.994215509143248
                                        Encrypted:true
                                        SSDEEP:768:Nuls9PWBz4G17oc9ircR1bixKlPHHHwN/07Z4iAjSjVKXD4J4KjHpfMM:MiXIi812YlPHHHafjN0J4KjJkM
                                        MD5:961B53FCEA9D9B2D0F5D2051694BE45F
                                        SHA1:E016115D0D06D09180344375B4181F2143798E6D
                                        SHA-256:872CE0B414A6B8FBA3766E69CA4248EEC139B0BE0380DD81F480C0F295AED9DB
                                        SHA-512:64D7324A3977964E8CE5C7FD93FDE0E30E584E2713D4475290807D16409FCE651EC99FF867CF6F7302E60C9E8ED0E413EA8A1028DE2F377BA5ACD5EACE783BB2
                                        Malicious:true
                                        Preview:.....f.1..4Tq....N....H...Q.Zk......G..s7.-........l..<F .U#Fa._.......;^5WWC.......|3,..aJ..DPYgIbF.IF1.t.eI..o..o...(E4.+e...r..j.......)..X..t-.K...T2..|...B.}(.|l.ig..........t...{z...8JF.t.....M...8..[%.A.t..8.Q..7... ......@. Z.8g.....Q....A-n.....*.\....X.....-FQ..Q.zyYY;.."T.]..o^.tX,../.....h..#.Ql|.......9.d.i.^..'.UY&hQo......`+..b.R -r...Ja.".hX.K..p.`....`....1x.b..R....we.8v...5....p.N..e..l/.U..<",|.O...$ .|.]..W8/B.l{W...[^E.D..ND....'x.`Ib5>.....w..'../>..v....|...c....2.0.=.."..'.L.....oD..<{H:.9.i......o.`.{..t,S.q........".. `D!....$.q.._$T....+....yg..7....7Lv.m.....L..=@C..i.%...fg.e"Q.^.z..lj....{..q......W..4.. ......./.(...I...$1.z}cg..\..sC[....x.....oj..m.Yv.s.sdU...^.Y..E....~k..kH._Z>.....^.|f.7.%.l. ...dh.*.V.:~..T.ec...]~....OV.d.L..R0.=:..s.C..d.~... s...Z.....V.LI....P.......9^~...R..O....^...o.)..J.q...[....YL..J. .......|.......^wY._........."..f.t.4...j.a.$...m.0.U.'sXb?........c.A".b...J.r....h
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37305
                                        Entropy (8bit):7.9953756726626874
                                        Encrypted:true
                                        SSDEEP:768:y7YlCcYL/JPYjHXMnpEOx6zGIdnfsrRyBDO1gjc:yGsJm57zGIdnkrRyBS13
                                        MD5:85FE42AAE3FDDF7DF586A82B7ED32150
                                        SHA1:D163970813CFDD95FCB6437BDFDAB44E78915A39
                                        SHA-256:20BA8C7952F6174AB2163C80B6253F73C2CA01D8053BC79B2E9B9CB3A6760B9E
                                        SHA-512:30AE74C15688FAD75B1987371E2F015368A94CB6DE2FA8B8437964ED751E363B37A3EB546A24097700F5C6963B132AD5B97C69CFDB87A896A7E8BE46B4F4C2B9
                                        Malicious:true
                                        Preview:..q..W*x0.......v......2.?...y.| UU.m~...G6..........i.Z..-....M...x..-.tF..!......M`..........TV(.T..._X..4...,1.w../.P:.2...2.g#L....zw.*../y<...R.3....=8..^q..v..&...(..Q...kh..../.....w;.....'..8.....5r-Z..-......v...J..\....I.`..........:..h.{.E.f.E..].K&.6..SU(..'...q..d.j.E...>.'R@........u... ....Ui|$........lL.V.E....aW.:. .cr8!.\.pz..O.w;'....P..I9..IS..*.4y............SD3.W....T%Q...cCd......pu.....=P..cB@..>... 1...ohr".........:..F.kZ......%.O..v.E0.A3.4.3.......e7.."......^.....a...&[.N.m.7...c.9..4\CQ/.m2.%....H..%..8...vp.u..h.b.{.r.B..;.,._P^..2......]P.8+X.q....B.3A.9...pS.`2.1k.XPSe$..[......:..XL....L....].....`p..08....O6I....(.7..3...i.}.B..l}..*.......ob......./.-.....A.^....m.R..Z.p&.t..._..uy3.*.%~.*....=g3c.x.m.Z.i..0]..Cf..u.../Ds.q......t....3....O...C......e.. ..$.....9...^K.e./O.g2X.|0..Z..-.VP......#.v......~(...Z.F..?.3...b.E.~/.:.{...w...../^W..5....A.>.........H...7.....o...Viv...y{.g..Q......s0.&
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37310
                                        Entropy (8bit):7.995361685361679
                                        Encrypted:true
                                        SSDEEP:768:YLqnpQyKhHOYGXVXQQpDBZKqgzrYxpjoTD+YioJtyRfT+FqDnjSnQBiSd:YLGGZcYGlXRisxAD+27yRb6a2eX
                                        MD5:4D84F0C42EBC3F63C53A6FC2EC96FA4D
                                        SHA1:5AE68326504C823ADD0E4CF863557A5474548D6D
                                        SHA-256:532335FA21A5401C909CFCB574819BF0820CA571B90CE77008743FF2BB162DDB
                                        SHA-512:FE2125E460A6A0C9F71127F7E92E7F267E3D6637300C3D6C8B1691FFE6B236CE9231DF71F3558E0B988032B35F683679DA82A77AC376F19BA20A72F17CC2E3C8
                                        Malicious:true
                                        Preview:r..u...t.`.c._..zu}u.HJ.2.p.>..)...L4j5X....j..O..-....P6..Z.......&E.o.#.......:.......'<..f..dH.......$.G..2$.i....4.{.t....Y%..c.u6..[.:..R.zXi...d..p.h.....X...x.(.?h[....K..5.N..;..~..r8.R..........7.....h..H5..\K...^..,k..K.-...<..0d. .M.4@|q...5.....C..6O.........^..u=2c.....%.$................`.`.L..c..}$-.>;f..%.........S.p...G.../.e..rSv.....)_s^'X.L..B)['...._R->....... .ih2.R....3..Q_...........P........"0^..~.x..i.Noj.s......T......./%`].]K...(&6Mb.9.r=.y...3T9=......G.......5.j.....v.f.?nx.1......z{#..:...^......e...v$G.P....T..9.....p.&T...m....X.q..Tf....k7...u...^...7.!.g..P..HQ...K...Yn@....S'..,...#...7.C.K..E.!..>.G....'....{L.]3...n..+..&}...A..,....f...y..S4?<.m.1..2.4........S...B.I....Zt..P..i...Smhw.{".Ir.\..B.'O..c.s..N1K...sv.yv..X^...K..\.d.xF.e.......$m}(1..e.9.'_..H.....?.......h... ).n.'k...h....C...>*/O.&.\e..!.S..a..$*.o .j.i{.G.uu.j.!......-7..<.`S...aA.=.3.l}.\$..3....-....8...o........?
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37309
                                        Entropy (8bit):7.995801555711727
                                        Encrypted:true
                                        SSDEEP:768:mPJmmKkMa3iWnBu/68jY0swD47UP/fBbB/BcaU6Mg6nybKBe:AmDPWI6gsLwBX3U66nGz
                                        MD5:D2785C5165882310C6F6B5F508FE330A
                                        SHA1:24132376B92AAB9CB2A8EE604E2600C91C70172B
                                        SHA-256:E8A970F2409759B8C7CD6DE99BEFDEC00C405C93A869ABF1D6FCABDF87AD7AC5
                                        SHA-512:55FA1F6ACD26946DE9CE9AEF298E7435C52DA7C8FF109DA74FBFEAEDDDFB91F27056F11619D2CF2ADA605C096C2B0A21DF8125E0F3F178B4685EB73DF6CE632D
                                        Malicious:true
                                        Preview:....iK.4_^...}........1.S@..'..K...[.l.V..p.).)..$.-....=.........I..#.\2w1.|.......|J%..`..J.W".. %..B(3.....\. H...O|9l.,...6K..m..V.......e".....].$..y......3.:>.y.I5.`.?MX....$:T.....,.....]...h...\.d..j.<..E...3y..S.a.....+..l(z.+$....T>.....~ZE\A....y....8Q..Z.5;.7...ky6H..!....0.%.|.!........I..3`..[Og.2.G...i..\..V......+Y.s.P.*.....|..j.}.\.L.Z.p.:...C0..aI~..dQ.K.i.dp^..'...o.B.g.l1".2....'R/.......r.t...M...........9.pR.1.,.X..CVk.../\.K.KOy.g.).s.....1y:|...>v..;.i.......v.n....J..s....{d...GR%g.d.Hw..;.+....d..N.G,.7...F5v..mLq..4..4dC.u....p.+..F9k.......g?{B4tDa...:.[..%\...A../..or.c...3..&e.L<....dP..\.....z.............Ak..2,...).=...$%...q...;L..JL\>6S]....._.........S..OT...o2..d....7&.jD.m..F...5.3;{f..df........R.[..R9...{m..B; ...'.#.s.~.9/(Zg..Fh..R{.._.G...P.T...I.!Bk.LGT.t...y....X......H..r.....A.h.X.<...Y}......p...h.f.{...%......r1...n+.Yvp.....8.G..9..s....s....P..NJw*...8..|.[.a.K....HZ..L...k.7...`.hRp.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37307
                                        Entropy (8bit):7.995422132979371
                                        Encrypted:true
                                        SSDEEP:768:yZXXlcdbQ3q5DgxxIB8uqrejPe+Xfj4Xrhmx7ZQrsQGGRfrHL:cXXlcpj5+IB8yjPnXftxynzRTHL
                                        MD5:40643A9DCAB3F6E90CAFBA1297F36D76
                                        SHA1:595763248103EEC140D7821CAB327A8483F1087D
                                        SHA-256:451A36BFCEC1EE16246411330240F20DA536528D04B1C5AE02431264DAA2E15B
                                        SHA-512:38A3820B5EA769C62AE960CBBB3F467A87C40F473933E23791D9EE50AC852D35F7FB807940238FA4E97CE82D0A9BE5B576327FF8278E18BDA4536AFE3BB4C481
                                        Malicious:true
                                        Preview:S..?4..~[...,f=..;.G.$.)}.....QZ.G..]...J......D^...z...s.EL_U.3..(b......@E....%.eX@...N.).d.C......;.B.x..SAa.s.......G.Ug.Bgb.B#..._....\..m..."..p..}.q..'.e..9-a......l......k..#Y..=.....N..H.>H_..s...i,...6...j#.c?..0{p..^[e..Y.J..-...!..(`.....zt.;Oq!.X.4....Fv{.<..22.....8D..l..ro..|.......EP.j.j@.l..K.h..?.8..Q.+.g..;.c>?....bo...g......VI....A........d.K..Q.h.....].#.>....o.....D~..=.....3..-./..!....OE...n.65.a..wM</~$*.....Dy.;....[..+V.....5.Y.j........NO.|....t2J..Q1C......z.g*.M.M.$....v..4z7../m..qn.......&J<......OKLA..f.^.B.<..R.....Ok..a.Er..|z.|8.*E..C.!J,.3.....i.E.0....S..I.....;".,.kO....4?.;..i)U...rB..j.e. _...K.l...5.i.B...g..@..F@.......0......\.+=....6.m.~=...0e..y.ls..+s...B......z"..._.O.W.D.......8..Z~ ...h.(t....(j..UN..Ac)o...'..Jb...Nk=q..c..y.w......|s|IP,..y]...c+.!...E|.T....*B.z3.RgP<S|...............v........Af..yh<9&X....'/.n.U....C..C...Z.PU.IF..H.RX..4..`.....-?.....\{.B.0.h..j.......70|#..ta3>..|
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37315
                                        Entropy (8bit):7.99514915322729
                                        Encrypted:true
                                        SSDEEP:768:9Am5pcPmRouAwhxJz613h682hxbb1Bg2HoFy7W7HpjU/55qoswIX+4Z7GVW:/iuOuAsxm3h682hdk2HoFyydA/54Hw05
                                        MD5:B4FC2583C694A61E229636C2F8426BF1
                                        SHA1:7D923CDCBE927E93BECC1E7492C3E8CA9C1C52C0
                                        SHA-256:A8EB92881C17078CA02A4F99D4FB286A98BF82D4C91B70CDBA268C26B3757144
                                        SHA-512:E4B36768066D7273E8F1F5A02503EA988599D7D113A4C1E5EEEE4F76C0CEADF185D52C7CCDAD0B279E184551307FD96D873AD28D4C06177FA950C333C6F284A8
                                        Malicious:true
                                        Preview:|R\.......s.M...=.k...~y>........7tC.Z~.i..r.|...RE..:...d..?<.Ui.8.s[..h1...?0B.}....#,/L<...%A..J..h1m.....W2..v.;..:.aW.".....a.@.a..k.3jDC[..8..I....%R.Zh.c..\.....bg.D:..k.........9.......i...,...E(.3..u,........}H....s...c*.B..j....,|?R)5.)....1...G.\.[.[0k+......*>.K..{....*..W...C.\.-.{M.2uqH..Ir9.bh..:.Rv.r.G...$.d...-h....6<.SxW .4.t....v....0;..Yc.].u....j....K....&G......2.-....[...+...z=......|....dh^...0...e.w#~....j.S..s....)!.....~fGGA.3.]5`./...j.Fz.4J.0..&I uS9..2.>x.].RW=X...t...1g).C..v..A=.5Xk....m...\.o.....R....p55w.4=g......C.u.....a.F ...Lk....0'.+.....=G.\^.......e.......\..^w5...:"_.4F.m....5....E..M...*.....H{..}..=........).g..`(...[8......8..0.+.....u......|%VX.*...j..&......Fx.E..&......t....oqRm.U......u5.?..C.m..Nf....7u..>.Bo.......cA......|>....ov,.i-.S....,..f...W.S.m ~O..$.6..| ...dd..u...Q..v..;f..m7+{:..{.Xx....4.c..`.k..!Q..g.Q...C.]V$..4VY..r.B\.RVGc.h.cq.ecjGu`\.C.w.....N...w.... .M..x+2....Y.a.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37309
                                        Entropy (8bit):7.995204488516846
                                        Encrypted:true
                                        SSDEEP:768:hVftt2cc2I9NknlUDYx1bKHnO5DYO8AF2A1eZ65SIbrpDfen215qwDO:ftxRpcYbwOhYO8AV1R5SW7u4fDO
                                        MD5:733347DC00DC81674ABD673F81758591
                                        SHA1:6CD560C5BC53E060C8C1E3DDB0AE0FBAC3BF3AEF
                                        SHA-256:7F4208A4FC48865F6AE14A18F191D6E2FB94C8FA99D38B6CB430C6CB965B751A
                                        SHA-512:8A78A2C7CC46EA4F18FAAB27531BC94C5823DF770CE8C1862DF363116519F494BA92BBDE699B194FDEB5CC85BC8DA0AC9F1607CC8C6A07E99F88D25C629DFFE4
                                        Malicious:true
                                        Preview:...\.A..*....fbm.-..^......QI&}MN...muX..5..X...p.7z....V.=T..GwMn..LW...j.-...-....W.+..c....`J......\...w..).~.=_.x.f..j=....".H........T.Q.............=q..W..p!..x....Q..k/..a;.A..w...j.>..qO..i,..O......i..V..a...a.#....u.....I.....7IP....\5.).=.d...7.{P'.Qb..Z.{!...r.|..wt$.....4Y.o.B.....m....O5|To..j;R..1...@..N.r.....P5W$xU.=.^....P..).3..U.....=....S...*...R....d...rJ...oT>...y^...:n..VZ..3....#.z..../.HS...`........B.%......F`.M(mW.8-.".6.~[Q(7>.Z......L$.8......d+.xq{0....5.....lu.;.............*..0N\..J r.."-....L.'..m.oL..z.^..g.:.JT.......G.w..&..f@.N..../...z.*Y.n...^a..R.W7......s.D+.mQ$H.o&B.....9...*3.f..oB.........d".].;.K..w.s....q%....&S......].0.^*D....Q.oC...O.b.:L...U.....7+o..W3G3..q....+"..?...x.>..KE.q...9{..;...%...D..^..S.c..";.....>.=c..J..Oe..D..F..U.u.5'..._V=.....wb..e?.G.a]z.. .W....#.z.3.r...Y..J..;...0..:I[...[..".:.(..5$.9..nOS{.........+.D.\V.....)......!WY.u......%uv)f>rV..w!q....h.d
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37314
                                        Entropy (8bit):7.99535567428991
                                        Encrypted:true
                                        SSDEEP:768:ktwF2gsjWnlrHCEHjmyQyYkd5LCmI+PM/02mPw+b1QvkzhXzEo:ktwF3s/EHyyQgmmIps2Qw+b1Qvkj
                                        MD5:1B0C333568FEFEA50B967ADD1FF9DF74
                                        SHA1:50DCE8D15E83DF41611689F4BCD3BB61BAAC09EF
                                        SHA-256:B32AE1F571A4D8A819A786199605E49627AE576A058A62F0D5D5797955D3DA61
                                        SHA-512:A057483AFB6E3C18FF84B06650C8A3984174D25DCF3CA613737560318B7762E1A672221842483894101B485CFED30FB593FE935FA531E658FA0E29FDE38F2AE6
                                        Malicious:true
                                        Preview:4..\.sh#.I..Yi.p...N%..'q.64\,.2.d...I....N?......\......N..!x.........r.....}Y..}k.......T..H...M.t.C9$.....O..kh.D'..0tk...+..B.e.....-.D.do[.o.3.k...0.VC..M.._.........j...p.,T;.M...p..+....n.Vb.(2.R\.|/..g.....F.h..*.........6z...N..J.5.[C.9......2!d....9s......3..dn..hC...#..Eqz....z......$.....R..&..MNr...qd....J...c....GW.w......-/.1...?6.5u.nPl.3m.S.%..y.T..U.y..5.j..H.mm..s.x.........."l..5..@&..-.@.%c..u..B..bT.(g/.Y...:s.=...rg..p.lR.YN..z.....o....f..q..V..*+6.1e..\.E....Q3'..w....X2.H....px...u?.o(.."Q..e[.n.n)~..oK..pf...J.....P>L.4.ve..cc.74H.~.+K..).+a..`...h....\..."..=v.;.......hJ...j.Z.....X..s..2...KB..gou.B..(r$0h.a..H....H.....}F...........U]&..*....4.;.....cy#r0......&,.. .}..q..Nx?x&|..............o.q.{.>.....i.Q..4.!..B:.....'..^.R.rb+..'..#...M..&mt@^.... .1......}.OA..[.oF2ul.W.X.O...n...!.a.g..c.&.....[6.a....l.......F^..._.YQ.....,.{........5J....%..;..f.....T...`V#.3g..wm.gG.J.45Um.J...6N...zm.V.pP$.bb.f.<NY
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37326
                                        Entropy (8bit):7.995156041226817
                                        Encrypted:true
                                        SSDEEP:768:Le9nmpNRjAB8lIPFt7pL6JABYy8uP1s1taGd642QOZ8KREAi50G:LeVvBLPxWQ3P1Otj6jF8KRQuG
                                        MD5:834A353DBF37B7AA16BAB77D409ED07F
                                        SHA1:7653A3E5CFA57B303257F47D2C735871CEEB33F6
                                        SHA-256:8DC479024F8BEF2DBF8D999F313CC3C9265937DE54006A8CFAF603638952F06E
                                        SHA-512:A9EBACC9F0F5417CDE2601624EF3BDA1E1F5160E610A28D6EE45E1B278C21D70B058F84B657A16EAD8D7949B6B2399AFEC1F6B11A6B5662C73261E5EDF4CC5AE
                                        Malicious:true
                                        Preview:.k.....t....y.R .6.....*..6......;.......3*d...UH))O.Y.w..4..2].......5...n..R.vJ...d......L-..9.......-...L..Lu$t8.....H.=...B.&.........k....c..2Ze6.[...fj9g4.O...A.$.<R....=H......{:.....@.t:...)....T..A..2.c..aL.....S.$j.]V.._.r...!f=...j.g^......J0.....h...9*.ngH....v.n.6I ..-.P.....b.YAi.L..3..1..k>...gf1.b.kCz.=.k.....J....K8`?..H.BD l?..PY.>.q....J:..r.........Lp...h........>...N....:i..p.L.....Y.."O..........l.N+s|..l.m..[....)<.......l...seoP.^..ROA*}..i.Ju.NGi..c.......M.".X.gd...K..0.o......s\~.E;^E...mm.m8.p..$..A.....D...I..[.D....r(.v...4....4..y.=.h.k.E...T..t.....!..|. )2..%'.....J.W..dOL.........p..1qMQ{.eH.....J..m...b$...[F..o..s...^bJk....[......V..<.....+3h..d....;a.n.e.H..SyDP3.....I....]]..r.W..=......b.S&V.).x|.n...F..g.....m.....X.v.......X....5...nVA..s......6.....u..(.W......aw..Y.`p5.,.......^4.....DEn.L...|...y..6.._*....M.....&*.V>!.IE84.....H..(...W3^.....eT....W...0...!...*mQ....A............uU..`.#h+...8.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37336
                                        Entropy (8bit):7.994798792842685
                                        Encrypted:true
                                        SSDEEP:768:woQ6W6monQX/gWK4w2v14ii9ta4WtUDvubLNEY:ZHW65QX/PKtM4ib4Warul
                                        MD5:905B55BC50868BA39D9CDE9E9C228702
                                        SHA1:B000DC9B158EA95BD14983D596FAA48418316F72
                                        SHA-256:A2635C06FCFEA213956710931627D9E87500D24F6B06873C21E0A73614B1224D
                                        SHA-512:29B3DBE1E58E0DAF4EFB42FE325EDCE1428B4F1CB1ABD72729D2687CEBE70EF233F8A8D7DC29FFE5515F81C51E8CE4A47812E7E250D4EBA22394F9F447BC8512
                                        Malicious:true
                                        Preview:..V..+..i..N.'....n..~..M.....[.....G..jn%4...q_L...B...ER9...+.7...v...~.0.7..p/v.N.."SzJ#..=.....".S.q...=....{..U8.m"|a..5X...d.....t..{pI.S..j..y%,.r..k#3......v.......^z......&......bZ.;.I.b..mK.k .(....;...x....b0... |...W<.'N-.4[.t........A4...lasbKL...#....@...1..;..N.KqL.x...W......k./0.=X.......GJ...y..7..c..F.T4..'.....i.d....;.....,N.a..........,....n......Y.1.Q.`...Ed.iD........-$B.h......:.*..[ww.o...dI.....F...a`..).!....4.c...(.F.[.w,.Im:.rel.&.{..'....PJ.i.}vg.Et......G\....-..aW.&.f...e...b(..wX...go.*..{O....t'.4....i.*.._.6^fD..w...f.f...}.Z$)6$O-K...Z.'d2...s~.}B..aqk.8..?..I...6OUw..)..cw...q6.k9kF.......]...o...?..........h.&...t...Z......".>~....@.g..I..4.C..6?..*/...0....n2..>:.!Z,..L9i....2....[).N.X...#..`.zvZ...k.>3...~{A0...N.t..U...+...."...y..Q..;;~...c\.[h.ot..`.i...5..".3_....St.g......EJ.%?M2z]..+..7)q..g.5t.)......j..PM+..m.! K..W.Q.....o.?L..g.w..%..h.u)R]O..T.I...K..M.D.F...&...&...sS.(.G.`3
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37334
                                        Entropy (8bit):7.994947389574196
                                        Encrypted:true
                                        SSDEEP:768:evEZR3JKvIryCcfqE4UmDB2CFKl0b97kLTWgjyaEdgbZowZBf:evEZR3hGbF4D8CgqbOLTWgGxSbZowZl
                                        MD5:CE6564C0438184AEE66195FE163BC495
                                        SHA1:F79B317A67CF62A73234488FE29A0B28B1BEFD53
                                        SHA-256:5C49459E846F226C35A6A0063074EB5EE29E2730E19364343EA18C55B2635002
                                        SHA-512:AB5F06DABF668B16E2240B1D892B8E251A13E8BD3C8F4E4BBF046B48CDCE3F2CA35357FF9A51F3FFD7BC544C7D1A6B71C2677D783BAAE483444510966B98837A
                                        Malicious:true
                                        Preview:..=......]....Pq.~.B.k.Y..[_......<.N...4....<.....x.r.A.).d...fX..@..X..zSq.....}r.#.K.....QqF...f~g...O..L$._K.B...Y.GJ......8.:..3...GGN.pq.mg..9...q)..:.".gy`....6i....&..... ..k...-..>........s..H.(...7...p..........Sz"..AV...r........'..*...B1...3b...7.ME....F.cP.........y..p..I.......5..[..~..>nT.GvG....7G...t../......1b...8t...M.n....!.H.mGv.-........}.Wx.pZ....-(C%..{..{[~s...F..$..K..K.TI!C.Z..........Z....Hd0...W..,...I.t...w..x~f.w.....Y...e6{d.U.....d.....~.w.pb....*2.9.d..GkxE\....!..c.K...OFp.....s.G9..'.A.x...Q.%.t.{.5....&@..\v:.?.....Pm....2$.M..f~..}Y.`......q..O..8.:9wnt7...S...\.b..]...K..+...lAA.J.#:..G&...*~.g...a....a.y.^.......M.%dE%.TKf.....l..m`AK..'.CK.....=j.C....<1....J.+#.a....vw.....G.].O.ToN.2.|D....\.O.K... .........S.......q..sw'n.hm..TZdZ.".Hv.H..<...3.....Eg69.i....L.+...)j>n|&..; .i...g.V....j$..`.R..5.|..YE"......%y.TVW..~...O.......'J....N....[..........NbR.p..LiV..:pz...........C..k..*=G.>,.....#..a
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:mumps avl global and 21 byte data cells
                                        Category:dropped
                                        Size (bytes):37309
                                        Entropy (8bit):7.9958275631535045
                                        Encrypted:true
                                        SSDEEP:768:jk3vUIjUzVuwtBhn/rL7QYw97uUcuH0v90kco+4NvtHkwks2:A3vJUvBhnXw9Zc00vPxnZk/
                                        MD5:CC5A35FDD32DD2AAE86EC5E8406788C3
                                        SHA1:1F4915787CA4126D01B8EF6241C476E6823BE7F2
                                        SHA-256:5F2616D99FB700E1C46929DF9E9E08710198402E2D85F840E3455ACA1BC40880
                                        SHA-512:DC9038246F33A58A62E356B0073AB2BDD5A6811B3C16FFEB1F8A5CD18F637C780296EF207E394008A9D7E04BC49B01D61D68A062F8E7A98C8F221B11B4AD9B5C
                                        Malicious:true
                                        Preview:Y.......&.0"+.=.kW~F.2Z:.....t>.<.....2O......m-g....Nj........R......H.........4......c...A.D.=..M.C6..?....X..z.....O.oZi...cpA..M..r.L.J.p.UZ..Z.QW.a.Q"k...@S'...sscj..*}.dV...C~..9O-.f9...C.d.?X,.}...PM..Cj...C.D.....A...s:.....eF.,$..l:.jRM..aj..e..etE.....E..,.|.....>...)_m1Ult.........S....-s?P.r.@..`....;.X.2>H).\q.r..>x%V..c..u..zf,..Z^.E.(3....7.=.X...=,..j,?.<...*).-.L...h...M=).w.\PB......cN=....}V@7.,.-.c...e..!.e....f?..`..iQ....s.h..S.Ds..Z......8..$F.$M.ho]Z.-G.V..r.1...........y....o...?A.S.....r._...m+..4...-08_$..S.3..!..Z..........Q.F,K.c....@V..\.[.Ow..tb...28.....KiM.)8..Pc.Ew..Ed8}....bH.-/W.g.7-..ch..j&.....v.>.hr!.X8..(...5..G......./ .V=6.0.e..W .....f.Q.=.D...&.r....s)z`..17.~..:.....^;..Y....N=&Jq..(..Bv..>.9..m..G.1.3...2&.H.4R9...a.C.p..\.Q....dA..K..N.x.^"j..XV.9Z?....n.....>.A..ws7.2..;..".........&...V=.4.(|G..[.Z...........@.-..>K0K..< &........T.....*....r78....d\k..xBz..,..k.....`p;k.._..-..%B.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37306
                                        Entropy (8bit):7.995381512874404
                                        Encrypted:true
                                        SSDEEP:768:dsrVrSmsiPQ6QadZG7VMrbDE612rW7dpHzP1G+yOvpgDHsVO5qB9GuLsTQ7x:dsEms/BaGMrbDxtfPYgvpiMV4qB97Ls4
                                        MD5:4753D0717D50F83AB859BBFD442EE31C
                                        SHA1:F4B39B89F0F37858581FC47ADB956677AC2C7421
                                        SHA-256:FE30D2439728B5CB70864BFA1AA2CF8A877A3CB3027AF44B4FCB502EE01CCD82
                                        SHA-512:5F7C739A5C5290D325FA89204317ED86FBED5C7937C89E5F0E612AE66EC4EF746E65A9F9C8BF6416D85B0DF2CB38D7E9FF8100BF8B3EEE817C50B194EB2AB162
                                        Malicious:true
                                        Preview:d.....:.f.s.v.y.?F..O._.VZI..M..ID..'...2..B.H......m2.%;`N. .{....f....<.b.,_..v.....W..,.:?OQ.jnZRN.g.."....5..PY...~..4.=.D...>Hb.pN...'_H.Da..v9Ow:..y..&;.d......v.&c.F.....:3....[.....'.=.seeqv.....iO.>E.[..w.t.....(?U.{....b.1.@.o..T^...2Iq3....P.......O...?.So.\..e.}..J...}.F...&..-..vS)Z~r.u..+@..$.x...|Vm...r.Qc..bN...!..e....r.0..a.g"S......YL.GzF..vI.Y.:m.......p..;#........2..[.....d.=...0...G]].?.......3T.Z...Z. ..&.0H...,6..../..fvH...K....T..i......Q...Y...B..f...M>].e..Z..k.d.q...%..y...$J.6\&..=8.W`GVZ.........).G.......^1.....W0.3v...H.#S.=..Snd....S......L...k.F..#$..r.?;e4.'u$V....C.B..n.!.4....`/V....E..I...ZO..h9.Z.'...z..</..d.y+[aw0...9.h/k.H.......FZj.u..w..B~.....U..fs.2xM...B...#.{4.z....&.>r`.....0....T.Gw...26...vjM.....P........9d.......h.S.J.g5..,...}m...SxN......Zm.....JM.i.....t....6.g..x=(J..x=.^....K....OS.4...S}..`\x....+#..u..b%..[44`./.......3..iG.......3...=...~S..............+P@....;O..RS..r...."Q.....Jq.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37430
                                        Entropy (8bit):7.995558774979988
                                        Encrypted:true
                                        SSDEEP:768:DKoFLp56XVFJ/YDPxu4+2oG2ckTLo4DyLjBx8a:DKQp5QVF+DJuyXv4Wp
                                        MD5:026BC13031C5A08BF68D8A31522B1C38
                                        SHA1:CC3C1693FD78196A1D2DC7D8217935C1EB7316A8
                                        SHA-256:27BA1AE6474C53EF6A1586B67D62922688AFC86AB15AA0E6EDCA327E66DAFF1C
                                        SHA-512:E81D97A8452DEFF0556DA4253C9D690B49C104547A48B54FF621E5959BDCE37E99DED7B0E3D0A6F7414341571A81E83ED90403FB22E0544D3DFD001954BD1E78
                                        Malicious:true
                                        Preview:/..B..E[r...@EIZ..X...2E].{..u..../.R;.... h..2.&gU.H.W.mRS6...++l../&......9u.....o.].......9..z...: ]....].(..2.,.{.7.%..7F.3,8D.......6..{......:...I9..Yf.4.4..]..J....cX&..&.......[.....O..U|......'.%...g...pn...c.E.{.i....s..E~_e....-.W..b}R.B..N.u..K...........E.....^..@.M3.S.?.\U3~/U.H.8..!...9......S.?.M#....%rs ........n.........1..$!D.E.!.).....%Z.j......r.Eb...._..|Of..ArM.%Jj.......??J..&......Bw3.*d...h.aH...c-.X4A.w..~..W....3V...>.....Z6...&z...].#.+M.j...U..S#.F.>.,..~UV...f.?.....V&..7XO...X.dMo.Mw}.a.1.............$..#...|...k.A.....85.7..[.........KuQ.E.|..........v..].p....q....DES(L...cG.C.R..N..Y.W..d..8.s........M...(...2P.....F..dZ....#...T...*...!..7.M...H.x.....Y.B..U..l...q..X.L?2...i...{...@..0v._z.E..]Q.a ..:..`.(.pL...-.(iR...H....d[...^....xo.Faq..Y..;..;.w._. ..wz...s.\O^........B..t1.......?*..4...n.N.l..~B.s.[...>..J.E./..R....p.#.{Cf9...:b.s..).Y..V.s...}....pj.5{Hr..@E.X.].g.? ......'.abNm
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):7.168645575747171
                                        Encrypted:false
                                        SSDEEP:6:w/kHZktNcUG8TpotvqwrA+mMFp78frSJVgxGnFY22w20FCnBR:wC8Zm/5msp7aE6wKBR
                                        MD5:C30F4B7CB15D344B571A2BB3C70CD2E8
                                        SHA1:AF91CE6226217D24824546B3BB89F864F55281B9
                                        SHA-256:CB73A34916F6CDFC345C8276AADCC54555665014D262580DADF758EDB9884963
                                        SHA-512:0035AF03771AAE2A0CA3DF3674F61CA298B6024B756F11DB08BCC726E146B38AC616F4A85727CBFB2E58C7EA5C9AD3FEFBD41F6488B6656C67A8C2B916C07448
                                        Malicious:false
                                        Preview:...b!..!). .N....1....s..`....?._py(....!h.......d..@..SV.(..2..n".8=."....gK..F....):y.m.Z...A ....*ao...s....%v%ZO(&....Lg}......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):7.131145066164253
                                        Encrypted:false
                                        SSDEEP:6:9xHtX4BtNcUGE0mMJa1EH+p78frSJVgxGnFY22w20FCnBR:9BtX4x8hI1Eep7aE6wKBR
                                        MD5:DBFCA39703857F58EC844EE20A8DA8CB
                                        SHA1:34CE01048D2E7CC3E8F72674881138D7CFCF1692
                                        SHA-256:82DB5DA3216958A1A965874DD11EB647D67657973AA8BEA86E1CC71607E12DD3
                                        SHA-512:020A97B171ED49D07208C2F22613687FBD4F8C1019684E542F234C7F5DCAF76369F683C302D7E03B81B1E5BBC562D0E68EE35D0FA65405F6324209EF5C901D2F
                                        Malicious:false
                                        Preview:y......!). .N....1....s..`....?._py(....!h.......d..@..SV.(..2...N.......h..;7..,.....a...,h.;..1.z....&.c..|.%...W....\86)J.(o}......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):50307
                                        Entropy (8bit):7.996175019981137
                                        Encrypted:true
                                        SSDEEP:768:IZNLK4lLh0sPO3zuRhcLrvrF3qerYV0aJM6Ldq0ocOqm9o8CSntSGNpjh:EPles25rvrxJOq0sqH87ZN9h
                                        MD5:9C0841789AA2E20B354A796022C1180E
                                        SHA1:99F675842CB45CD1CD674B4449B70E3A609A0901
                                        SHA-256:E0CF81637AAB3DED1B37813AD82DBF243CB96508B66B3DA777DAED35E5081A31
                                        SHA-512:4A5DA78577376CBDEF50F9A741F9B132E7EB2B2B7FA96BFB79C3BD51A2F00300E36D055EE766C92C3F05957E40EED106258C252A58785E480DC46384A5122CF7
                                        Malicious:true
                                        Preview:%.4o...[...Z.iv.M.t.G~.D...8.pw...IBJ..F.v." ..p..@.[....~..],.jd...............TF.......M.`j.VS+..-.7m>..w..z.{.q&w3...1....+a.. e.........V...4....Q..`..s....qzkL$hC. .k.4.[..._..JL.9...qS.;...p.(....o...{?.5'.0...b.G...u.0...2......~.y..+,oy...;.6w...6..p..O...|_.R.)...k.i.Z.........a..S......"y..*.1P..q.....x"}j.........=.&X0R...a..l.....u.4._H...$.....&..0........(...F#..:rl.2.[...".P...6qJk.....2F.....q....'W.*&.p.k.q..*^...d..CH......e...Vp.M...Pu.....M..]..U}!...S^o.*......<"z..H....s.....\..'L...zD...`...R.$.....&.M.kIrw+..*QT.....^;...:/O.BL.=k....y&....(Ke.../R.e/.+.....(.tdw.;Cq..V,dK..0...Pp{./..R......V-...B5Y.`.z..u.,lM`..U-yj..8C.{......Nx5r....n..fmXr._+.@^.r:...>....L...j~..~.z..h..].Q^.=4( .(.B........3Bj..j.?.JAS..U...A....v ....J5.Pu...V..FZ%+C.g...bV>m.......+av7j...NXa...b..M:..D.2..-.Z.|,S.#....!.....c.r.%.....i.R..4>....>g.4;.?....|..-.}....%b|.#..E(.......0.x,...........Y.A.....6z.Xb./Y.H..DHy.lj..y..M,..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1124709
                                        Entropy (8bit):7.212500294597132
                                        Encrypted:false
                                        SSDEEP:24576:aohjaCFUfCwABWSHRTyZk6i8r7YfoyFxz8GhkD/:aohDUNw96Nwf1xz8Gu
                                        MD5:24AD8936A6B7868BC27E6211C7E076B6
                                        SHA1:37C4C43B0BC08D88927B72B6FF90A4E074ED0D85
                                        SHA-256:753AA406F169DBCABA7460815DD629E20BD9A8082027713E7C2CF731EFDB3E35
                                        SHA-512:1739E99CC778EF273901E8BE434ED1AF7FF191DBA6A5DEDB7AF0C5EF96B66CBFFA532F0A968A61AE98DF3DEA5609A830E9CE82BE8BB71F4A6FCFA6934BBDFFFB
                                        Malicious:false
                                        Preview:R...5]S.'..b>../.#.%...f...6..?.Y..Z./a.B..5.."uJt...'B..k........p..J..."..o.Z.H..LsU1...6,....1#..W...T..J....:J..L.'....2....I.........#.m.].X+..S\$.d.3Wb.Z...?..V.V...q...{...@.3.Jk\:........,%C.8h......K.{.:.yQM<.............K..a..7]..[...FSk....[..-~]r..(\.H1f.. ....[.OE.J.....L?.H...r9.s;.>.P>..!........4Q.W~..#G..]..........+.`..u-K...cR......L....J4.,.B..;"n....U3..~....76U3.V$Q .8MG~.]P.D..0(.[H[..-M...r.\.oM.k.....w..>w.4A.....$.<...>..S.a...p.!.m%5....p....%....q..|?i..<v...<Rb...,....s.....B.LtzJ..<...7.N_N...,.....^..)......u_s.v.f.....g..y...a.[..n......v.C.Y...|d.0..J.+........e......p......k........j.Z....(..:.Ec.8..A.]8..4.F..,_....B...8gt.....s...Wa....O.$l..S<..I`..@...b.....zH..g$.)<.1..G...byA........U..Wn.1......}.!.Z..)..n~\.1..Q......I!.'.F..J.".DY>.r.@B.,.v<..C.K..?.....q..~X..n.....$e&b....."..!.......KJn.D...oW...c.n.k.....P./eJ......U.Q....[[.W..B.....qh.....-|...0+..lemp.e.[JO...x]....}n..Y.@...e.d.E..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37430
                                        Entropy (8bit):7.995621298901134
                                        Encrypted:true
                                        SSDEEP:768:O7RMlJoCsFUDCWkgSOrdIEyAAet+RG0OyjCAO+hJ3YdyHVdnQB1:O7RQwF3WrIEhAlsA5JSAdQT
                                        MD5:2EA0FEF8B9F2567999E2509F7D5DB159
                                        SHA1:BBFD21CC9C5B9E65E20A2D6DD01DEE51416257CD
                                        SHA-256:E11909D71116DDCB5C8996B58E8CE25A68AF0B018B108DD9FFBFC6C8AFA25138
                                        SHA-512:B12BD4BACB955C091969C52D2E9E06A7C29F97152FFF18CB069C585DE2093FCED193B1A2485BA16D3B35618846F3B6700A99A9B9930909E77A11BAFDAD299721
                                        Malicious:true
                                        Preview:p....)...qV....b.A..+j..J :w.?..>.Y6.^.c...2.UF...._0F...\.X....hy...py....r.../...}.A....i....E.|..l..D0NW..ch...Ge......%....h.B.,E...[.....q4t..|..@....T#.S....7...1m.J.M*....?g..>..W.?P...Z.&...ht..l...!..WGT..CW...A..1........Z..@.xC......{...0.L.C...u..T...5X@. ....+.....G...Y.+.....S.M.......(-"..xh.3.............N.s.q$+W.XY...1.<..hs..^..7M.mf.\..-10..8........'%..J.G).......%.:.:...H......^L+X....k.z.^..<..d....N~K.|U..c^.l#1....U7O...TR..h....T.....U.... .tzi..d..R.s6vb..%...FS...j$-"..p.&.+.;t.w;.0.....}...e8.D_.3.C...<>G.L...\7........;.......mL..L.l.~fgrI.&.<...z.`N.L.@..k.....{.u....i...Sw..y..N..._...{p..)..J.......l....=.v.Q..,.....j...dS4>.s'r.0....%0..GP.UDx.sc..G...!...4.......gh....q.rA..A.....L'...w.3)=.v...%..J..0.2.....b3....!...j.-c..e...A.ToX.P.....T9..._.|........:s....[..#......=[...C.Q...5.&....`..f.D.+..........r[._......y...`n.....Y.T....._...".E=....7.vA...0..@.).2...}&.......4Fb..Z..O......C......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):7.213097611707435
                                        Encrypted:false
                                        SSDEEP:6:ZMktNcUG8YHWtWvh5JzS5p78frSJVgxGnFY22w20FCnBR:ZM8y2tW5qp7aE6wKBR
                                        MD5:0570359E4FF8F061BB66D0248554C431
                                        SHA1:8F89873952717139BD7CAD2AE1E297F151446FAF
                                        SHA-256:3D1B37DBEB5754656A5721A05D27EB91B5C54E5EBA16A65028D533BEA388B375
                                        SHA-512:37F4EC9426D2BB51430C7A7CD9238352F42DBF5A37912572717ED59F38980CD68BACE57430ECF34806F1BAC2E4BD33D8CA53FAE254B994D975952B92ACAEAD5C
                                        Malicious:false
                                        Preview:._.....!). .N....1....s..`....?._py(....!h.......d..@..SV.(..2......u.......|..7\..$......2......,g.c..*..&......UE..E..5.}......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):7.11980522351391
                                        Encrypted:false
                                        SSDEEP:6:Qt4BtNcUGZk/yHKLw1Qj5p78frSJVgxGnFY22w20FCnBR:Qt4xD/kKK05p7aE6wKBR
                                        MD5:DB30EE8438771999362763AA57E46478
                                        SHA1:EEC26A9DEB5BFF68EA30910A4FF594C8D74CFD4B
                                        SHA-256:F1A2CF04122D1FBEE56524480F368711F8BB5FCB292BEC2F624CE9221371515C
                                        SHA-512:4EB187CDEDCCFC82DC7F86B02FC41426BEA0AEE2A04DE7B8ED77688C411895278485202A1EB08BDD0E60339F9D23AD133C4B07F8D4AAAF0DA85F000F88B95045
                                        Malicious:false
                                        Preview:..,...!). .N....1....s..`....?._py(....!h.......d..@..SV.(..2..f.....l./X.>Q..Y6.R....xb._].^~....A..#I.Y..\l:..R6\.h.....%}......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):50307
                                        Entropy (8bit):7.996501832935546
                                        Encrypted:true
                                        SSDEEP:768:JyuJGR8xE39AbOlorlONYG495YgUG+FtVbHHqzHXmbDI+t9WkCwbvV7ye5QBSxy:JyWxjOlalBl1cvHKj2bs+ts8N2Hwy
                                        MD5:359840674F3DDC8590ED041FF7178DE1
                                        SHA1:4125A2695C757E691106E240B0B1BF86EBFC9D37
                                        SHA-256:010DA7109A4F008FF96203804FD5FBAA589A23934808775230865780B4043B4F
                                        SHA-512:29A3371182EA91A208B35D6AFBD82B3E4AE691FD5A7E9940CF5214256FD4CDCB4E6A60845769E3E11FBF4E5FC514003A6E18F90A4EC189847E22CB1273D37208
                                        Malicious:true
                                        Preview:........]..u....c,........ UE.7.....Y'.c!...W...8A.......z`.. Z.P..r....K:.~..,..}".2......B.qz.60..T...s(2.........g.I.;.`.&.$r..Yp..7.U..T.Z........twal...""K....R.P..R..4-8.m.t.[.h{..a0..Bd.OJ........E.r.,.xm+@...%,.v.7...*4.;.@...g.....+..F.aU.....O...5.].m.om....w.o.A..<......@$..F4..R.b..........A....r.i..`.z.....n.......].cj#.....H..H.`...V.EhM[!....."...%..a.T)'..De.>>..4a...l.._L}E".SZ.v..2...a.[}..3..,]...(-~...>.[...T..2....X..g..H.8.2T..(m...N...,Y0%........s.8@..7'..X.gn.......O,...^...czAc...k...8..~.O7.p[.A.8D...aX.......%s...6........Jt...P......FG...Q.6...../Lz;...0.q...}. ...4.}.T.].1J.g.G.d....j..xm6$Y5A.....G..G...J.N......<j...=....q...|..~..N...........J7..i..f.V.z.O.t.Z.w.a...Z.Q. .Q......!....>.,.8....e....=o.. -..qh\F.KA...J....7[.2.+9...1Y...d.joP.F.S.........S^f..M....?5.t:.V1.[..e...~...O..n...X.....p...'.....lA..r.`..*f.$..#..s.Tp>..L7...)..^...gC...2..N.........l.._.CF....N.....R.../.d........V.^b....k...]hG...(C^..*
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1124694
                                        Entropy (8bit):7.211986312781989
                                        Encrypted:false
                                        SSDEEP:24576:gjWBjt7ynyXCdfI8+ufq4N3es4p/pr7YfoyFxz8GIjBDQ:gjWVouYQd4os4p/pwf1xz8GO2
                                        MD5:B62AAEEE2837EE0D04D304F32D8BFC93
                                        SHA1:383C11CE17D4F5DBE2B217E68268BB91B65F1B09
                                        SHA-256:FB8D333C086C6AEA4FA77F4A3AD8B516F98AEE696BE90EBE49F8629F6D932E90
                                        SHA-512:721C4649C1B9DB2287B362ED90E50A68E2DFC027C40A70A1ED748C9F522831CE409F9CEC377F3CD8BE0BB2ADF626B873D0CE9B8B1196C4A3031B2025EE1562FC
                                        Malicious:false
                                        Preview:..I.p.......4....$...Y...-..w..:..R......$.31oR.....|cS....."...41......+.'H?.....sl-g.....K!...c...c..}.'.....*.L$aNRZG2V....,.U....'6VT.._.].%....y..5.Z.c...p.w.3...........,...A.j#J.5|T...........Y..M/P."92...X....e.h..4................7\.^......K<)x....'.../X.(..ax..=.....f..T.o+...8.N.s*..[.EL..W}......L.t...6.....\.H\.\....1db..uLp.,rQP4...7.:.u..m.i.....C.../.F}...F6I.Q!)y..$..L....R.....&^n..cR... L.g.R.Q....6.........(.......Zc....AS...R#../.P.z.}S.B{P.......(.BE9fe.r.+.-o.@.$....hQ;.p.}..x.q.).A.-..9.....(...:..|TG.}.*....=.1.V.M...'....LE.........*j\....8k{w..g.t.A...B45{).V.!):&..>.S......W./J+\.,.;V...C0...w.A..*E...,..uw..r....K.N...).z..=...W...qa..*..x....V3.)(...&...[..^.....h..d.w.K..m...M.M..,..W`.Y.....CH&.}..._v.*....XD.= .._3W.....{.z+...>0...U.0j..7.5Xf5..p.z>..8.t.`.O.c..Rg...?.Fd.h.A...S7E...C/ej. %.K...2......j....|...P..........a..d.{....[.q......re,....&.Z.._..|5...+..4.*NUs..\..v..... f.?.IS.V
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37430
                                        Entropy (8bit):7.994702178343875
                                        Encrypted:true
                                        SSDEEP:768:+546s/dOgjorPNSmAAigJlsQtvVAQ4BQsiFScx0SgxX1E:+54p/wgaKLgJ2IvKKDHnj
                                        MD5:CA6C28FA8FF1D1B48AB25C5A2B4762B2
                                        SHA1:BDCE51F107BCE9151398ED7055CF5290C82940CA
                                        SHA-256:10D764E4076B902D9CB350D56FEED826F3AE56D16D3D01160F4BE0ED5E1540A6
                                        SHA-512:09A0E0EAAA3069FD5C8AFE2CF43FEE53BE72932F432AEA7C1DA61813CC7D034E154B457F0D4D5002A24CDECC640CEBD3ADB5026C45AC187CB74F1F87F9789366
                                        Malicious:true
                                        Preview:......f..Bwa.6.......].{..*.L....h..Tz....e..C.Z1...\.D.2.X.8...B8\..-7.l..X..,=......G.}> ...odw}...DjP..G...'...!-....6:.d.F"r..0......f.Fh.wL....+....Z..".j....9c4......fE..S.....G"..W...UW.\.(._n.<.`.SI.i.m..%v.w...w._.Jl.,...6...9!..j....fA.....h...P`L......Y..bE+.......~.U.@.....;..@U..J.I,R.`i.=2..C...I9w&..[......~G.=...,c..l'..|LD\.o.r....F.*w-.K.;0../.G.v.'..K(.1...8i..i...tyE.b..L..\N ..W..2 N.I......!........ob..6.F0.0f.99!.N.G..IM..........H..... '...3.-N.....x.%+O..b.k...g...fM..!........7T...(........(2.....r<..{...({...<<5q....Z....&.....*..)...P^D.B..AY.s....,...O........s.Jm..*.X..c.......0.Y.......U1.....t..E.+.Zl'.50.....)):.........j[".|.P.,[.6*...d_....bM....T+X.F3....O.......7.C;.Zn...........57.))).>.n...:...3....P6.ZV...=ua.Vs..U.].*XE..E5.%...l..!G.....Q{a...G_.]...:......+a..._Ub).c..O.Lk..s.&....,."~.O.S.8...L=.H.q.QY..3.(L.)4RF!]h4,0.......C.z.k...R..R..=...$1.yz..`a.c.=.R.......P.c....K.......?..sW.. ..J.....l.6bI
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):7.130388509572513
                                        Encrypted:false
                                        SSDEEP:6:ojktNcUGORyQ9Jk8aRGgUxsvRp78frSJVgxGnFY22w20FCnBR:oj8nJ928aqsZp7aE6wKBR
                                        MD5:9E1BA6F60A6701431EF067D7BD53BE71
                                        SHA1:6D850EF259DCD19EEA2D26C65F9CA41FD9A77130
                                        SHA-256:82803FBD933200A8189568C5FFC3E263B9E42FCB8904595D9C9D16D4BA28EF98
                                        SHA-512:FFF801D341265E6D0D9F21436563A219BDC015BEB6783E173C1E4FF78FE9B6CDB30C13DFB24BBE397C0368946BF5D4589584633B04047DB65E4BD8B628AB578E
                                        Malicious:false
                                        Preview:..:....!). .N....1....s..`....?._py(....!h.......d..@..SV.(..2.......,.....c..<...).4.aE..b...M*gR.5Dck..((V..6.b;..z...K.(.}......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):264
                                        Entropy (8bit):7.1960891836935215
                                        Encrypted:false
                                        SSDEEP:6:4DX4BtNcUGyimedHuCZLsp78frSJVgxGnFY22w20FCnBR:I4xI7OC+p7aE6wKBR
                                        MD5:6B0537E97066AA999C30F1844CC2DC63
                                        SHA1:A5EEBE3F188C970497F509555213AD4342CFD56F
                                        SHA-256:64873075C5EA4FA3D2902F47D7B0E8C3A97803BAD5251B9C133BA923FB198D74
                                        SHA-512:39312EB2A0BD108FAFF43FC01D986332C5D11867B1A698E69EACB8DEA3AF8CCDCEE1945815C04BD071CA1B5D836740BC76919ACD27F82DDB655A45B9C0D55428
                                        Malicious:false
                                        Preview:..9....!). .N....1....s..`....?._py(....!h.......d..@..SV.(..2..B...J.. .kn.F.C.$B.....w)..b.I.b)R.qH&3X..k..t.@..A...g...4.}......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):50307
                                        Entropy (8bit):7.996036986484346
                                        Encrypted:true
                                        SSDEEP:1536:AqXC8vasch3d58oi9aaRtGn3JDVTw3YHAhr:FSQVY37J3JxTwos
                                        MD5:5257A645CE781795F4F6120621A2EA89
                                        SHA1:8FC4FD13115AB986FB75980CB8A7511AA8871455
                                        SHA-256:BE4346A84D84E82EDE434399BC48D77D362FA6EC524123ED8CA6E79DD23266E2
                                        SHA-512:CF5374CBAC2146447D2CC33BE0BBC6E657FA2DF097AC98F8052B358D46E00B5004D23FE45D8EB0B47E6EDEE0ABF5E8DC055BF8092830CBD176F5033FA8EF0EA6
                                        Malicious:true
                                        Preview:....5..B...B....@.l.....RF2.A...w....5..B.~..:............n..>..Q....#\..c....BK.D..[..E......!.N.y>+.>..I...}..f}s.*:..JE......X....AA..{..8.;.8..6[..@i...y._n*DG.745..>....S.....&>~.nY.q..\..L.$.y.$...@.md.o....B..T[.r.)W.K$ ..D.'.i ..cG.;.A..&...,N.N....F.n."|.._CU..H..{........&....+.~......"@.7%.&....1.3=.k^^.....$...4..&u..\jW..:..}:...:..*........'...d...MA$YZd...CG......*...K.~W...W..J.qQ.#..im,;h....t....[\..#?.....7.......y....A.X.`.\.}...W0v.37..E.*!..V.;.D4.q.].C..7...c.B|..R..9..........`VX....6....g.lpn...#T.,.lvg..$.......w).}....V..3r.`.%.08....8.q..[^.k.h....z......Q.$...`O.....{.........)5d...?...A.2:....6......S...M..2h..<.i..N7."vR`....4-."...l.8a.q.....<.....L k..,@...s....NBm......>No&..m...o!.~.....92..K.([?..%...0......7.....2.D%.in..b.S.....zm`c.g...m..7.YM..6..LoY..U.Y;.=.2+..1....>.[.8.3..7....s.2@\.)...Q%.4.KpU.t...N<.t.2.:.b.Z.lm.a..V.y.{....c..M...._#..L.ld.36.8pk...$.3.U"Y...Y...4.u2P...j.8L...~M@.~*.b:...|..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1124694
                                        Entropy (8bit):7.212331672417311
                                        Encrypted:false
                                        SSDEEP:24576:SGZzzycpINLkd/Gc151r7YfoyFxz8GIjBDx:RYLXc151wf1xz8GOv
                                        MD5:C38A2A8AB082019F0640321E584F9218
                                        SHA1:445080D4429DAF3F59601037A1CFA50A68214C5B
                                        SHA-256:9B3A8DDFC119185367494ABB67A3019C26A52F03CFC929FD220894EEE4CE388C
                                        SHA-512:082014045E76E90756B69934A05768D2321F6427F7DE16C1C6FFB7510FF9AF3CDFC54A1A612659E992AEB45260532D91B9190D7B4B190A32903113FE490483A6
                                        Malicious:false
                                        Preview:..N\..G4..=.<..9TQ....*...f5{j......t#..].W.lx..zm{j.m...../.~.J.s..:..`.U.^..`h..H{....._.O..Y.2.DZ...z];........r#..z..,.ew7..../b..tqW..U}.v.0c.......JB.mq.5[.2..KS"..X.....P..9..?..........BS.`......1..,+.q..-.N....l.GmTr...Q.w ....c.m..Mn.....i..n<.s..T..w.G.LT.A..;.l.tj7nU.i...].B....Y...%..t....].....9(......pb."WG..1......4.....5k.M....Nqp.b5.+..Y.g9f..4..y!......)...B8...-.........%...z.{0`V...E..9.}.Y`...~\..>`K(...V....~.......m.b..W.".Y~l........h{..L*/..K.4&:.....A..k....a..'=M.a.4..bVO^...T.G.U...u....{`.H.K.(..../I...x].<...8'?.....}vl.....G...wYQ..x.q..*.P...........5K.M....R....0v!M\[..D.....g....[._.*<....t.......U.&.+~1...~"..-...s....Vz@...p..o.k.8.i..=..5.4.... ....M...9SZLom.K...;..!x...a.A..D..Zn....lX!...k?D..........a.d@.Uw ....BSh....M..-.H^.R.&....<..."d.....;.W...dB...(z.o..).#.4...(a.(..9q.4......A..s...G.L.'....e[B.5@q.Dh.(1-..k.8.(M".1L....9:.l5.o....n>..K+.._}..@.....<F.Y..yM(..J......~..O."...U.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1426150
                                        Entropy (8bit):6.58930463054928
                                        Encrypted:false
                                        SSDEEP:24576:xHSstlphzkGqQXkJ8Adr9yEKzC79ufKZDXkmn63mlDEyjMV:xfph6QJKD4N
                                        MD5:434E45E3658E7FDE2DF7E6CBCEF45E8D
                                        SHA1:02FCD23509F35F7D43E40CE2A53E2423D17C9DA1
                                        SHA-256:545FC4A1A6851BCF4BDAD070CC22EA4FF5F8F78F21A6F76787DE0F9F0451D86D
                                        SHA-512:8750385F10E3AF4C17102B96A7E163EF13EA98A90DD95C52C5A45B4D0F98238CC2B4A8315A86F63CC51D2D7DD3B9800743F235023899AF9A98A1C78AC0848D09
                                        Malicious:false
                                        Preview:.$....S..[.l..`..~.[...:H...d......7.....H..et.\.u.$..HAp.^..f.0...lk.:.sf.HO.Al&........!.....z.R..%...-@....6!5.HH.....&(.*........|...+..3.....<S.......Br..4..2?.....P...r..T?.l...J..!g........3..>..j.U........-4.t;....c...a.Q_(......I.j.*.g..w!N2....Qym..1..P@..;./.(...p.. .............I...P>...9..=.j...P......h........i..P.&.F.Y.Q)y..Q.......5.a.m..{..&....f5..WY.......F3....P.....*..L.hb_..-V....Gwc..;..{..I.....>%5..#.e)...O..>lI.U...V.@2.W9.PiTjc.x.<po.:..;..<... X.....(f%r..DU..%... .=.G..................p.Y..r'..,r.]j..h....}.......)..Y`.}.9.8...H[.\BM r..|.........jr....h<.c.....c,....EU\....}.f.-h...?..{..........w.|...Z.^g....:.lF~9..o..j.@W.W...[..W.YX........r..X.h}e.9.......z........1.x.^?..A9..$X`Nd.D.H...I.sJ?.O51.....(..^.C........h...h.M(.....h..n.N..#.Xe.pV>\.".......:^..3V...wqq*W..[..y....o>...;..Y F.^.u~.f>.*.........&2...........gEy.J..;y....5N.c*.BU.|...O(i..K..&.....W.,[~"|O.b..j<.`Y.a..=.........t.6(.)...9M.qE'd=w.^......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):351972
                                        Entropy (8bit):7.999530453002796
                                        Encrypted:true
                                        SSDEEP:6144:wF1Gj+JXrSyAitxdywzp2uVWpyaoIT7THGJn5uAm6jsE/VGogsnUFUrTL:wWj+5myAiVrfQyuTuF53JR/AsnUFUfL
                                        MD5:11BFAA2B227C35D754FCD151B6EBC3DE
                                        SHA1:78872BCF8745D1B978622707D92510D0B25F4655
                                        SHA-256:083A052ECE506CC9B522009A2E48A278F10CAC1B873447A7C3AE165912D2694A
                                        SHA-512:2DDBBD48BE1179E5AD52839A956C0935D734275CAC28D900AB8BC13D8F8F6D203002DEBDF16982E2D67D0882F929D8CD298476F7D3D00BAF6B33AE4DA5E8E5E8
                                        Malicious:true
                                        Preview:..<.....P..@.7......D.Lt.JXr.a...&P....*..nji)x..V._.4.....]!....qQ;U.W..........G-X.^].3.......!o)0.....].{_.~....kk...[..Z.d.'.u.....#%......'_.W3..'{.a.+R.E.._$..p....a..,..?.....7h.....].r.@.!.../[]R..."X.....m\R5j....h.;.p..N.....+w..g....&.."..........=....U.g.ZeS..u........X....nq./.bh...GI.-..vV..Y,....H?.H.....x.63.$1...Z....1.xK...LJ..P.[...b..:.4.>L.J....z[.9h....fN.b.$....Kx...h2........}...}...vhUt.<.:..OL]5..%....DP<.1Vq!....'e.F\@....wr^[0.v4..<.....d.....V/N......:.x.7M.8:..^=N1.C.........O....D.v..S.w..y...{..g.O..z`M...D)....:...t....k.....W.6.o>Jf.L..Sx...O..._......&.N..../H...H..X.......p.j@.L.....d......le..MK.I.ri......r.z:.W.9{..z..=..V-o..M.;.+......ues..........`...m.>...p..d..v.R..:X[(...[.......1r1.B55A..OF<.IC..zF0K.Y6.{.u...i.....M........q......t.ge....>..Sf...+k..........1g'..YQ.._.M @Wc..$K..G..X.&.....9.S...'..z{..|.....j..0.o.CB. .Z..#}..'_..;>G..(vQ)v&NSE....D.)...KZ,..PR.M$.2.$%....\_..........D.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):243736
                                        Entropy (8bit):7.999295435563425
                                        Encrypted:true
                                        SSDEEP:6144:NKJemzgT2Vru5h0v8ct3lc6xSOrb5fjer99SKX:NyzgT0yP0v8ccMBwpX
                                        MD5:DE88A5FA7715FD5890C31297429E90CB
                                        SHA1:02280A86E543027DBC13F39769D27190478245FD
                                        SHA-256:5C98AB34BAE887B4C25D7189C2323479A0C6E0160430B405245CC898B9EF0677
                                        SHA-512:8334ADC266C93550262B8E63D3A1C4D34F3A74DF8528FBF6933A4E530983CF53272459E92C9458CB36F3AD3C49E2F5CC53FAB9B61AA3ED26955006215F4ACD72
                                        Malicious:true
                                        Preview:q.\4.lI.jW.....Y...@..h<<.7...o.};..P.-.L..:g^.z.8........`N.M5......uR!..W...n3.Ry.g..D...8T.......G~....RB.......].H...w..a.O.hS..1d...@c......p.|.\......Em...nO..w...].....6HU ..D...L.9".y..H..-g.S.^....a.d...^...\...J......>.......fB...1.8W.U.N|...c.)..u......'.!...87p\...........2'BD.\.1..<.(K..D.'..$.t..U.'].<H..&.U..... E.I&..c%.H$..a.......A,.f..5...iD..I.`...l...1,.a....@}.R:...i.Scgpfs..O.O......bLI...4.Q._b.[..^.".........FF..<..3..9.7.......>.).Y.....NG.,.Z...].7:......B.'.~a.HQ.[L...".x.,.U...!..m.+.5.]..-..~..C!.o].[..B1n.9....G.Q.jk.K.d?5;.u....P].....T.._.R..;..dF3).|....+I.*.......K...xX...'Z3...H.....}@"K.%&..H.%.....AIK.Z.......1>..+....r...%..iE....@.b..L....@H..S...EAS.D...5('[.B.......g.Fi%r.G.(...y&a..K@.5.....W.....G.\.g...u....7..o=5.h.A.]..\$N..=+.gp.....@4...>..Z...L....]...w/...\=X.v......1mJ.f.J..zE....x.$.sja.."{..0.6c..NO.!...O.|.n...WV.=.g.].&.;.......h..g...XLP.e......c.~p.....J.>^.V#Q.~...&<{.....!..G....Yt.t~1v-.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):693
                                        Entropy (8bit):7.702357195580424
                                        Encrypted:false
                                        SSDEEP:12:t3BphPRTasYJTy9vIUwV92PZgRpMkvSAAUydKo5Z40K6HiubeFODp7aE6wKBR:t35pTahJsIUwV9giRpJvw7dKkZ4p6CjP
                                        MD5:1B8A2376E52D39AF86EEA177322F9C95
                                        SHA1:12F4F5739B7997614B0A927360C7517BDB22D9B4
                                        SHA-256:97B3024B23F3DF39D7F8EB8868CCF4CF17D0E56079E45FDE375AF6FD74062CDD
                                        SHA-512:E85C8E14EF3EEA264B704865CBED662B41647D021868AF6AFEC6108D265D696DB179A20F9A396A197A6CF2ACAE9A1B387E74D1525A0DAB3912CCB79BB1313C90
                                        Malicious:false
                                        Preview:.f.W&..bH..$....In.9..i.j.a..[.%.....%.>.....@....G...2.....,...j..skM".).........7.....^{.n{IM.....J......].k......7[.\=.|.5..h.....o.'.X.......i.mZXv...1.f2s..q....iU..v.gdot..9.D.........hu.].e..oi>.i....dI.O.\>A......=b.Y........n{%@.).z.....!...K...I..{...1.{.../e.......$.]...".$T..TS.x..\j..U).....8{.M...o...&..<....rYKP..<{r.=./......D..Le .w..^F.0'..*.1.gB}..'p%.C.R...............9..&...+X.#.r;e...L......<d.'.W.j). .A....Y/W.....(.5.aZy..}..b%./...H.I^Vyq^....Cd8..)U.(...E[..w.+.".'....R.\.Z........`..t.7H.i......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):406
                                        Entropy (8bit):7.475987057814537
                                        Encrypted:false
                                        SSDEEP:12:YKrFpUdHTkvgKs61zVUsKMLNQqGWAp7aE6wKBR:YK2zmgKH1zhpQ3p7aOc
                                        MD5:E350B104429E4B3B4ECC2E9D844AAE0E
                                        SHA1:68484E6CE5B3A9B1A54978CF1D13C13C52552420
                                        SHA-256:FE6A0B52D9B8722944BA8078F597F99B8FDC6EA35239A966C13614E566647A88
                                        SHA-512:FA3CDABD65D2F1EF4E766B65C0E43DD5A2411D0F6F1E41F6B7ABED03432AF37BA4974D447C199C2F6935D74439544C8B515E1A84215E9E503B4E5C8D4CD30C4B
                                        Malicious:false
                                        Preview:..N..2.4..B..k.fY.a.aSZ...........u.<.c-..{......t..F"...gv.,..>.L..H.[..|.o0...).c....Ug5....]......#u......a......%''.1.)....y.i...*j$:.p2@....F...M.W.j). .A....Y/.....xCw.X+..}.[a%.,.........Y.0.^..R.g{p..@.2..J..E9.....rT...X.O.o.V[..g..G^.D^]I.2gZ..{n......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):533001
                                        Entropy (8bit):7.997440129818625
                                        Encrypted:true
                                        SSDEEP:12288:sEj0TPVyToCojTj/RklU/8f4YSfpYxMz6pVpEh3Kzgc439/Y:FEVPCUPZk+CAh6pV2Oe39A
                                        MD5:5D8C13E7497C04186A6BD65B23D7CBA0
                                        SHA1:E6CA32E7151C557004768B894FB3EEBED1DA8A2F
                                        SHA-256:862C8985455B1FF520B091678F7BF64E2109E4ADDDCDF54CF3EE82B18B959664
                                        SHA-512:1A2629606E5D7181D833BD754831A8840F890F2C66A01E557832C28F8F2F9272BA8764A80278F959CA0843603E58DEAEF7CFA7CE8F137891170E7D84B8E405C3
                                        Malicious:true
                                        Preview:..a.I+.t5{......o...s...7.mRb\y.v.....<..'/O.x..4.`.18..+..O.......$.....*.FbSFq!.Pu.k....Lk.:2n..R.K..$U.X&...|.JPq.....X..@.......L@<6H/Fw.pqE..a...L...X...Oe...i........$S....F%."...2.)"......y.9....f0..k:.k.P&-.......r.v.$.|y....c[a.Ga .#(.....B]...n........h..[v...l.e...... .G[..:.I;x...Nt.?.cV......'Hnj..... .....o.s.S....3....s*..,...H.4.s...Tb...J&<..M.A...l..(.H;._.32.....$~.+....}.....3......q.F.6]..@r.....i(.`X.....b.i_..)T.._.yH..H.c....T..T`....<~...u..+..[.H.....j....z..ig.=x.q'L.ke.N]{~.+X..+.^..D.....Q..i{}tk@NN..!...j....I...L...+o..Z..*.R.^...F....G'l....NhQ.(....<<.}R...`....."6...$..=S....@.]a5.b.;R*.N.....n..4fI....~!.tv..eqW.....}D..F~..V.. ..........bJ.....}..Mb......,.......S[s....*.^..GW...`..2Y....#(.^.e...@..M.C....E..f7'...#...o.....$X..T;....K..!..fNtm.h..t...uU...*.jD..".8n%..t(......._..p.......06.....~.`~SgtM!!...j...@....P.8...p?..|`y.Y>.[r.6Z.h..a.2Jh......(I..|.[{..'.......-..X.(.%'.......G.J.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:SysEx File -
                                        Category:dropped
                                        Size (bytes):44748
                                        Entropy (8bit):7.9960295961520576
                                        Encrypted:true
                                        SSDEEP:768:G1GlvMrPz+2j9FJ3fmWQI21W52glUY9K1I7b+hMfjTT3BSVy+Jitosf9iorudfnU:G4lviZp/QXU5fKYZ7jXBSVfcoKATdfnU
                                        MD5:60CAC75308358A8C8A8119E2FCC57DEB
                                        SHA1:001FA025728E444315A8DEB7949249A2BF0F7E6C
                                        SHA-256:CA731F4A5FFAA2FE14FD2C7A22BD4E8C9EA53ECCF635E13C905E2DDBC1354098
                                        SHA-512:EB8BC3BB2C11050888A5BFC454CE6E15575B71ABB0B10C3E565C3B901B78EB3285909192647BD4A76549B28894DA96E07CCAACD4A5CA825E8CF2E191EC40DF0B
                                        Malicious:true
                                        Preview:.Sk.9g....I..];-:........b..../.p>..&...".$|.a .yf...B..A....t.EuB.<\..|K.....g~..g1}..b..>.1.U.Uq@..G..gN.......~..Be........'.a.`..QYqm.BgWf.M#._..y..0..\..3fJ/.^%D.v..x@...<.....gK.$..fdJ.^R.D.+o....92..P.K......|3..s..../.K..iLjscQ.E.+..=..8=*p:$1.......T...v.ibw4l....Qr>.LP....9.,....J8..`...<..80.+H..;.5m....a..<.......%..[Rw.+fQ..L....Yu){..t...<...T/...LIsiU.$q.O....~J".._.P....A#T.^.+t2.C...t....JM....]Jq....&.*~U..`..L..IGR`Za...)l..I....]j...Y..~.......U.-....h...;...p.1.|+ B...s.ZFG/.R.....gb.p.oN.....=..J..J/..kY.n...ZQ..\..h......q....?;M..8..s..r.QV.....*..R. ..i.......o..6&.l.A......D...u$...d`.=........E..v..a.........!..G....W|.{....@a.q].P..q..[1...B.N...pP}.equ..2..'.,.....0).JEEb_...w..@..(;D.....ZU....G8.......+;..K........oi.)..3vK_..6j...h:.3..7.d..s..........I.....cr!...K.g"{..v....k.Q.!..ILHJ;. .......b_....+.n|1......$pwr.q...-\+.d.*._.z......b....<.X...F"K'.Y`~...i...f#.`...e,.....q..%..Y.....C.r.....m.O
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):103964
                                        Entropy (8bit):7.998322919127899
                                        Encrypted:true
                                        SSDEEP:3072:8XSQ3dZPh4kaki7T8wEUXh3TPab22iqYHlBnaOiI:8XSQ3dbAT8eh3TT26BnaE
                                        MD5:3E3F495F20DB4BB73EA8840EAEC0FC5A
                                        SHA1:6F0599A56C23906FDCC8EC29DC02C261212ABA7B
                                        SHA-256:C8E8EDE2FAE651E9FFD766733DC44FA8D40F38D05F8C84D487F7B508B0E5B4BB
                                        SHA-512:6961B2BE77D6A6C68A7572D4876BC1C3313525135A3E961FE84F5BBD77F7D85D632422F5B619CCFB67AAB5347256930057D78CBA0EF3FA892256A23474A71309
                                        Malicious:true
                                        Preview:.....5SKC.6.....H..UMOn..s......MROT.I..p.j........TY.KPp./K.....f.-z>$.a....p...4..v4:.I.....^x....g;....F..B/..r.}g*$e<....*Q./)Fa.Rs.."!..5p.DdD..&.M...g...G^.M/..........*...........],...2.lS.0m.4.$.>0.1.'9.Y2.....s.2....#B...rO..C.^....F.......}~.......:....z9DmnD1....C`g..'.M.N...%.lF.......D.P.$...e..'W...`.7..DA.e3.....2V.07.....m9...d]...T..~..y...\..I^t.f...$.fw7@...>-...E.M..?...B..B..!....n"r......IVUm...\E.#....)..y...].x..!o..w......\...}..e...X.B.k3P..(E.?FWP"...O..g..(.Jx..s.....F..'<.&=vM.k..l.V.....H..-8.....f.....C.I....f...Q..U.v....v..@3..@.p.u.w...W..8u..1h.q'A.E.......b2..#i.w.k..;..IfA...;ek....?..-.....$....&f...6........n....:$@P.].u...snd.@.7t.[#O....-.V^.dE...{.-<...iP....7.)..\6.I%.v...u..'.........V.Zv@......s-T.s-...[6....J.Xw....w....).R...Q ......T/k..W34...U..w4.....5.VM.X..W..E...5g.....Ir2X......1..r...P..fmR<;.O~.lL9d...CF...>.......m......x.6..."...{......l..X3.<.R.1...........`..$.).:..]..^.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.974120308594144
                                        Encrypted:false
                                        SSDEEP:192:+N3NQjbq3T3hvl/Tw7oC1RCt15w2fITFa2LAnKese/nJNJkHpS:k9QsxKvLCt1+2CFa24K/e/JPcS
                                        MD5:36A8C579EF14E3F0A377B1EA5E8D3F3B
                                        SHA1:1C4B2A47FB1207387E2B0B697EF8534D6F37D545
                                        SHA-256:13E6FF9951CA143563C02EED3515688BD06E1C1B68BBD02351DBDDA58EBD4E28
                                        SHA-512:096AED0CDDE7AD9FECA05751ED1BD21D915E5D81300FB145E7214443963A623ED0CB0B49A6F94A18FBA82960C1981C1C848AD1604EB5E988902093DD5B7A3D31
                                        Malicious:false
                                        Preview:.....>.{..u..=7....5..=}..g..W>e..4....."..I:w..Jk..a..... q.;.J.G........32...?+...)>3..I.$...a.S`d..........Y....>...&...Y....Vq...<|....36.K..V.......t..!x..*...lS0......@AK."....M..U......7.. ZM...U...>8V.c..R/.m..r...y7.q..+.X...N...S=.)i*'..v....q..?...Y&.u..<.bJc.....f.....BLS.7n...>xIR..nG#.........@t.I@.U.7...qH..j......I...q*..c...i..@C..Y\....?k(#.....fy...9...3H..U. V..xx.........'@.0...L^..i...I...H......N.......O....z|....!.=.bb..EWe..>.i..@1.......*(..P.{....bt.(.u...e...."B-...^..O.K".Q...qY..hG....2.u..{...c...b.sv.b..g.*.h9<*..w..KT.:..$'..R.......Cj..;..L ...r..S.._.kB.k.U.......b.7.k...p.=.$.../..v.g<h..5.j.R....;o.......H...... ..S}..u...'...b6j.7.vw........J...{.B....8......;...!.!.K... `..HC........i!...<9..]...#...".{`...SfS.............f.....q....j..Y.....3.]r..p%<....t...p5o........A.mbxw.s5....9.........s*.......V....._.8vg+................j.Y:FG'j..ry..[..nQ.hH.pu...g........)I...]...|9d..}\...M..a'0.D...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.979095399141489
                                        Encrypted:false
                                        SSDEEP:192:N8jxQQMR3PU2bnoUOtFMvqXfxJ4tDvaFc6hLsioKCTxK6yxk0JFpS:NQx1C3PU2boU65Xfn2DvH4Lsi7qx9yq/
                                        MD5:B41A324AE4AD4D42C64CAA548606D426
                                        SHA1:2F8993B208CCECD0503733069F849BA6554FB32D
                                        SHA-256:4D1C50D27A1A58CFFBCE4649E3733FB13AFFA6928D098019E8294391C604CE19
                                        SHA-512:02B662E0054E2D43A6C94455E89E36DBB7E554985EFE3F1E48257CEAB47CCD75C16A249385CCA6F846495524A49A8A30249C59C96DC666DF9A43F96CF19C737B
                                        Malicious:false
                                        Preview:.../......b>lt,..<..M3....k.....{)...u3.u&.P...8.'..P'.u .|L...u..E.\.._t].P.k.......4p^1.........[..]....`.I......M%......FK.akJ..X.0....7....X...,K..OpMu..-.\4S..p8.d....z..;.)..ww..]:...2..P.c2..4.y.cN.1V.h:o=.^.......`......."...p....;5:O.Y[.;Hd5.'.$.%J.e.....I.Q...5m].1...#edM...a^..3.kN~v.'..S7...S2..f...P...z..^8n.d4.\fJ.2.eFs.Gv}8.L.}Rw..{q..o}...R..t......w.......B.nl.K..o...Y.....u.N.k....ndV..*.....do....=.r.nb..0.)6..$....Xa.8........ ..?&%hq..4...Qf0n.'T.A."..v...B.t....l.....5Nj....R....*7.cf......V+2y.?E...).Y....!.[..W.>..#b[r )R...0.q.B..).....v.........?...l..>..Hb......n..4.2B..C.DV P...|.{.,x.7b%.8[..A....s.q._E.B.q..A.Q\..:..".d...(..v..V..zl.....i.x5...MYZ.Z,1....v^...S..{......S..............&....X.L..DYSy...C&.G....'Rf.1...7.V.".j..d-.S6.SD.%..g............Z.U....GP..{z...jQ1..(m.!Q...B*......N._....x....i.}5...\.QT....\!&..\..Q....m..II..=.r..S.x......C...Z.y.ZP....n..n...*..e...CGp....p...7..a.}...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):551
                                        Entropy (8bit):7.582832213253865
                                        Encrypted:false
                                        SSDEEP:12:ywNUMKjLq82b7CNOLOs1MwqKA/ANQ3mQ302yWFqfUw2GFz+A/BUxX3A+p7aE6wKn:ywckOyJqhYymS0pWFv5GFZ/BUp3Zp7aV
                                        MD5:60E2CF3EB85D567B29F7BD7D21A07768
                                        SHA1:771F1B2E92F6DC741311B5E2E7FA2BA6169F2DB1
                                        SHA-256:E0E080BB1E8C6BCB638CF628C918AC83C0EB79607F6CEAB7FA0102FD8B3728F0
                                        SHA-512:9F599FC135B4D8D86253BCFBCF0E12F683DB9F2C84B5A35B93E5B3FBE810C4E0A9263016C232EA86984EDB1C8AE82AF1F0C4E057C13B89595B2AF4DADCA778F8
                                        Malicious:false
                                        Preview:(...=..x..$2j.:....zK...:..c/....H..n.;..v<h...7#.5.'.....o....0..',.*.V..&^....D}..e..4...<q......-....?G.f..g..Y......G..o.m.&)v....M.:p_....^<..ySC.....w.VZ..y...:Z..kQ..%@.*...r.K..S.OM...<..C......*?......X..m..,.8T#...AIRG.I.................?..eR.n...p.=..Ah.`)......dd.^v.R.@.$.@......O.9..g.(!.).......8.rQU4(..`...(...:....p.t..9$$.B.;..m.........]E.ZK@0......g.....x..Q2...j.'.g...d ........f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.97809453272435
                                        Encrypted:false
                                        SSDEEP:192:z/pzE95NgEWkngqm3skiOvdM+iETOVUXFtESCY5TelV7LgaFNXpS:TpzW5GEWkgykbBiECVCFt5CY5UVI4S
                                        MD5:F511AFEF78DA208673E0818D98D844C4
                                        SHA1:68A329FF76ED0171D7D587F938CFF615F3328E39
                                        SHA-256:4B98FAE09DD4043F5EE08F03A7A5407A10798A071A117793E43DA8525A2B3A37
                                        SHA-512:9486EB9D8ACB3CC26E64361E3164B16F3B42126F2E9C8A94FD1C831CC9E898CC1C2262DA408B397FDAD22B7EF7A7813B714F5EF24EFFCF825F8C5FAC99F0B3B9
                                        Malicious:false
                                        Preview:.>........M.=..Y..ZV.)......I5...N....=..$I..S.b...|.E?D..}.zi...h.&.b..44%....*.....h.B.PBo...d.Z...>......."......bUM.l.l.....h.e.~...mM...STO.....4.j....G3.~.....c...f^.-.a..F.v)...Z[.UO....5..F...R.....b..9..o_.,I.U?.x&...\.o...U..2|v.....0......wC....W.*......9Zu\i..o....p..C.Z.....{......R....b:7...DN...3.._F...=k;y..[(.Ngw..`.zaN)@.....R._..N....3(j<[.d.3.3...F.d...)n.l$b....n......."..D^....$.t+H....&.aV.p..T6..c..%..)...%f(.d.X......s>(qW....X...f;.B#o.U6...v~.C..x6....p..j...=...&.ad\...E......:...x...z...C.n.s.P..".-3.=.C[....9!.:OAIMM8.A.Yo......3zX@J'..Q.......d.Z.7r...._.....I9.:...lc.M.e...Uz8...Th..N."rr.q.}..1 X.5l".}....%.=.\..r"a..VDu.....!V.5..m...1{......=.,...0ck...y..HiX/.T.O..*..ecOQ.`......_.........F.,.....7.'.!.d.:G.HGst...d.R.t...bA.......8...MF..KHya.iC..S%cK{.>A`{...3.FI`.X..?4....W.&.....3..].Ju...d...f.?2{.)G.Lz.l.._k./Tj..q..t3....w(of..h.Xai..z........\.WG^2.....}..f...%W.'..][\...W.J...P..}..v..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.977899109801838
                                        Encrypted:false
                                        SSDEEP:192:CKnROv/Lh2h4L7jtMDtyLBqhf1XggT7VggDe98IWeVpS:Cv2h4L3tMD48xnVIKIWsS
                                        MD5:D146FD69A2F0E5A4C1622733ECE18F3D
                                        SHA1:B0C6506623A012A655BD72D701AF5201A45EE70A
                                        SHA-256:86C99F0F238727797E109242AA19F82A3F42F2FF646ED48E500161FCEA726C83
                                        SHA-512:3631B7B3DAA47E80BBA7F114EBE5E59FEEF12060C4C96A6B7A877B9CFB39FAD46B239EE07725DC63B5A2E11D0F01782E48BF517FAC50472DA36C5965B373956A
                                        Malicious:false
                                        Preview:.V.2...XP`.i..j!.c...8.g.K*.E..|..pFj,n..%..c.I8w.<C.H..q....|3.b.*.E.O...P.G.....S..6.....!....MP..%. .Q...b...L....x...3 sQ..*vx...6.W.&.E.PE.A.Ou[...T..x.......+.W.4.L..v.W..=.$...hw.9..H.c..E.Z.*.t..aH..F7..Is.t,(.3.b;..7^\z&(h.k......,.#..s.)F;.Z..as0..:%..WKgT..!.2.t.H.". .Y...."%....,a=A...W...C.......~1..t...<.E@.w4.A.z..#H..{.P.....R....R;.7....5x.......'...:.....S..z.....g.*.Rk...!.[.>.6.c........2...;..M......N...O.....^.r....Q<>.s.S.5..GN...L..Ig....8%..*uf..^.q..6....$....M....j.....D.$W..n.%.GcI...6....z...Z.....[.Xmc..Q.....-.)m.^m... ..|...m.cN..5k.H6 ..I..H._x....Ad3.........R..t...1&.......)..J...b.....5.O%7..yxi.....U....x.v...H}S....._..W....jSW..........:-.*.........B*Oo.......}y.l5).. .m....e.!s./W..&n..4...O..2.J........Y.........X..h].[.....T....:.A+L.."Y.:.....b}....V..U...;..q..Y.Sh.......]..%o......;......,....~.p.h..g7Pa...4}Z.Y`....z...8.......AY8..-H.....XR.U..'.2.1..rg........5..)...7.S..k.n.H..U.R.bX"..!..Ku.1..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.977714675200819
                                        Encrypted:false
                                        SSDEEP:192:86nDRxN7EHy26lo/5UQwVdNGBVxrCKu05dDjXwQgOpS:86DtEHElAwXAV9/bfJS
                                        MD5:7BFD9F1383584ACB99481A9CA2F22063
                                        SHA1:849251F84FDB90D1CFB2FA58CDB7556683C9382E
                                        SHA-256:D6F3AFF83A42DB0CD9DB1407DF51FCB1864E942A28DEA78FB62DD8B967A3DC4A
                                        SHA-512:66EAE23B7167CECF41A5A803AAB57AB98BD4AE362B58774BB7BE3E470E36C72EE1678789DE0E00F2FCEBE9F514C73AFF839B6869AB74748E2DA66E1ACE0A08B8
                                        Malicious:false
                                        Preview:......S|I...%..Q9.'T.j.i...).....2..'..y.4...F.@..@.|...)..-V.H..Y.".=\.t..(7..7..PI`.....fl..I..].9t.'..N..! ..hZ..[Q..X.?Cc........X...l\....n....{.......HgJ.A..$..|..]..;$..C.....pi9.DM;!...v....m....?,..H:....[...v:...~..t.e.C".O~...m7F...;.g...%.T:......#2X,k..<...........$`U.k.a....my...!..z..q..G...8...B..*:.:?$"..Z..C.s.X$P.....Wat..6..n@.t~....a....p^bK...T........T...T.}.'.e>~!AE.E.'<Wf../.#$.,.=.......F....R.........:4.\.K.......G..@..../..|Z..2B....b.T.-.].......wb....8.....V"| ....1...uk.1).L."Lw.B1.8B......W`F....o..$....;.h.p..........4-0........X.J.....t&{hq!|). l/A...\(.....>G...k.....eW.n\A...=}u.............2.w^X..'%...%3.iXM..r....{..Rgh)!................I..|.$t...k..1.S............UOP..p'......>....f..k.\|.A@..W.&...b...U.....F......J..g.#~.DT.JJ(.l./.....@..@w.I'zqh_o...bZn..T.....".&]..Re1T.'n(x.7...0..S.$4.L........7.#.z.'..aK....K...\.R'.zV.:U.N...WA..O..r...|.F.l.sSlN..........Z.....q....?.Aa.=y...0j..2...f..._RA..1./..7
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.983540435054554
                                        Encrypted:false
                                        SSDEEP:192:EIz/bjr+nNIvcNUzbNVDPp/1efo933X+A4jFBsGmgdJvjkZomIdV5pS:Bz/bjr90CNVDx/Io9O/ovgHLtdZS
                                        MD5:74B518FBCCC2896717E8C57374EABB91
                                        SHA1:850181DA09A926A6EDC6A254FADC6449246A5FCA
                                        SHA-256:4E1C292C8BFBBC74475458F330853D691B020623A3A067FDCE36E1246A97544B
                                        SHA-512:8CB0A24FBC23A8A9503DB378EDD2D7D96CA5959827A7EA6915496EA2E1CD4F8F71A665A2065F8E669E607E4E7D9120DCB31B69F746F65F3C3430778F9D6B6F19
                                        Malicious:false
                                        Preview:..{O0..~..q.....]4......Z.KN7Q.vb......_....6.{..].#...Y.-..6.(..].0bu/S...-i8c...A.3.....!.QE...t.KR.6...c>.'$.O.<....vZ.x..........W?.(.n..).".Fa....Q..".....;nj.......M.<..2.k./.d.:7...\..(....i..B..\...._.....1.C.....O{x.F.t.;...TS....p.[~..Y....\[.4.4B..r.....!.=..`N.../x.f.8\C.Q.A?1...LI...%..d.&.....^..xY;.B..o....z\D.-_..........W.K.Gu6.....U3(..eHt}....BL...].;|&..ae..l~.._.{...........2....R.."!....Y4RH).....).1'..x.H._.k.yB.@TU.9Y..zO}..j..}.(....].K..wG..V.6.\..5......|....lR .n?.l.......2U........5.x.[4<....e;h6.k..a..o..k...n...^z_.S'..kn@.o..=I.o<]..V..............M2.6ZF.\.3..0...*..v.?.q.w.9=..M|)e.1.U....(..,....{'.$....9]).'.......a0.S..."h.k.J.iK..z. .H.g...u..!.N..#<.q....M..b....FD..<"...3..yu"...U.R .2..+4...l.A.Yf._A'...|..U.Z..m..i..K..V....s.%.pP.CE._..J.Z..1.e.J....Qa.g..G..6.+........G..._...L.....xn....%TS..b..(..5rO@/4..6z.mc72...g......*.!3.!....5..LI...Z>.*w.a.!.f.z......h%k.y|n.C3}*!R.n..L..+..2`W.L..8i.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.977569339236563
                                        Encrypted:false
                                        SSDEEP:192:84gBdn/MOTpNjdcaroHnjI7qe2/GtFh7CkRZQcHtDVVpS:8rBd/MOHGYoHn7G3h77icHttS
                                        MD5:97476DE90954904AE2EDB1C3ABEA9B9C
                                        SHA1:4167CF8495CB75CB4A75E1AC1BF2B5048867B8C8
                                        SHA-256:B600F45A19896B4D600D05FF7F68C463F2692922894E7BE7C1774C1ABE0DC25F
                                        SHA-512:E60A3428D9D7FF41CAD23278F31FB3CFA9C40D1718F140D22EC32030FBCC7B1E4F6FB41D7934189C2E95EBBEB79C534E85ADC57DD563CBD5F9C1711C46C49440
                                        Malicious:false
                                        Preview:...=....Yh".p.P.ZA.\.k.Y.... Xo.U...}|H]..*.."..p..X.....XP.^.2.e...<..V.r8i.L.pN..m&e....^......D.ia..b$.E".....A....(.X.../`...........w..7.....0q....i.@~.S....$.(.*.....n.F.w.jQ..8.(....8^..,b79%;.?(..j.....iM.Y.....qo....C{..'.W8K.~..]$.....U.F.....G.n..95.a..XF.NT......C.0\q.<.a.9...4.a.&......fCA.jV.*/.Xgc.......-...m1.Z....e..s..w.c4.....3..C...(_.q&.*.<I0..n....AD.sf*)n.....T_.Y.`.t...,..}u..v)........r...3..%sI..vJ..V..*(x...7...d....'...%!.....k...,..%.3./......-..16.l.....s.....1....V.<..`;..<.}W..}...D...F.u..3..*....x......B.~8Ar..5.......m...c.u;....K..:.....'....d...[....:2.k._..mm...tL.G..........H....F.V..{.'..K..T..."".bS.".....v.. . c7.L...1..u_0.C...T.GPL.a.U1...o.F.....Te.6.....B.N.U.Q..C...Z..X...9.$.ePpG.."k..p.5L.-...ru.;.F.i.{%g...8N..<.....Dr...2).9...t....lk..`....0..%....Y.H.uGM5.Pr.f..k.:E}..A(9V..|#E7.\5............q...c.L..........Q.+.^.6..?0n..T1.3g....N....0.@Gb.?\.....s.....)........u#A.j!....Hn
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.981514326728935
                                        Encrypted:false
                                        SSDEEP:192:8lfF28P56jTgwEOx5oMdg100YBYCGP2gwp2/r0SonpS:8lfF2Q3OIMdg10PBYiwzzopS
                                        MD5:5DFD4B5DED0793E190B23C62CA7BBCA5
                                        SHA1:B2F94D16F7CFEDC8360175DF49C05710B4BBE364
                                        SHA-256:3F4049E99D6627838364E0BF01F76D542DC4DDFCE1B2FEA1714E0486956B9975
                                        SHA-512:D061421560879475D9D819D9B67E8CA35C8BA22645EB71BC2B800A2F13280BDC74D4EE565B46C7CC891DFD67AA2BEF716A5998AAB9EBD36C2009BCC3A00723E4
                                        Malicious:false
                                        Preview:..9n:.H...!.....RRV...X.....^...[r...TL...u.X...4"...(.7.f...k.X.c]4.I%$`.L.u..z.W...1.A..*(..qLf.y).....!..1..m...2..g"3d.93:*......J.!N._N..z.h..0A.">..Fx.r....C].V..(H....T!....).......2..j.g.$..}IA.}k..0.6..k.a.k...I+...&..-..,...*.J....qL<..:...k.m....3..@U.7.:..|..v...bX..%..3.Iq..0..Zl....>.}P....W..F... ..Y.z_ ....o+.@E.Y.Y.....V.....D.b...?..c..8..2.Da.=/.....@.F.Y;..<....X...w...l..Q...+....y....[@*......8.Q.f^...CX....e.^.....Z...y..F)z.9..Vt.....=...,...8.....k^.q..F......v.q...6.&.BZz.3..aL.t..YT..?....p."..w(...=l..g..t.>...*.@...-..s.}..@b...y.tU......~...5......P..M*.}X..x.uZ.prO.r....3..d0.\.6.-..5X]5.N.B.L...DF..4."Q..T..&...:..x..\1f...d..j. .*Lx'...q.B.....l.MT.D.,.{.W.;....;.aT.Vgr.&|......e.Y..Q ...W.<...t.....6/G...A &..z\P7..\RM.[...N}%.~u.....T...IH..(..R.S.t.K&.....P.....>....vW..m. .`yp...F).#FpMuS'1B.&6...;./..5.Q..iu+]...2.......4B.=..t..3.....F.z..P...d.4Y+..+(|%..GcV.../iF/$.........Kc......0
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.976006958659849
                                        Encrypted:false
                                        SSDEEP:192:Db04VvHnnFGCkgk06lJKHc0huqb5DzMpjx3YLbEvLtYQuwhpS:nNVd3z8loHcAuqaiEvL9PS
                                        MD5:33FD5EC1D96DA3CCD7B5AD0886530607
                                        SHA1:64E69A889BE28D2CE5B201984F02BFEA40B178E1
                                        SHA-256:A250E53F2BB3AA266A410045DD2C29313D681F33A5AB213336A5358129EC6464
                                        SHA-512:641A446E999E3E552EAE5FBB8C774A762710F558E27B3616037A86D08FE470949BF5BB712722B4A1DB11476D896A15D46312A6C361B12CC9D54A55F0CDF37E0F
                                        Malicious:false
                                        Preview:.*p*.wG[.., U[2.V..am..y..P.FL...n.4..PH..#..f=...<[..dM.W.,.dE.1.v..l..S.6So%.T.......B..L....^..7....x...9......#6.0V...$BT-....K.D(....._....n.....ED.......b..E......9N.eg....,....".Ve..x*..Zi.tr...9..*....L.f$j;.....l...2?x..2..2.|...k#..Z......7....-z..(+NX.9..w./P~.r.Q.N...]0...+....}s5...80?..u.8.......5.6.&..H.........~..Q.....3h.-.$y......S..5..>z.A..g}s..[..Ne....... ..).X..Z....{9.~.p..]..9..AZ....W2.......*A.v..W..%.|-.[p..p>..}R...}.E.U........HO&.h..i&n.eU.=..,4....Y..n.lc..u....:........)yJ.m....*......n0F.T,1../0.d.......{Nv..8.I..0.z.7,.....n.%.......t;.d..$...O3Er......X....Tq..Z.....F..'4=A6.d..W*......`..%$.w/:.......&..\..6\.....au............(..j..&3M.U=T;....$.E..eCV....V...u.!.. -.+.C..XC:..HvC...\..r.\.t...[.."Ij........+.....0.|(.N..D......,......@.|....a....h.....#.C.":..ocC......L.....KiIX$.{.WBQ.9.......X......dg.v..[..}..}...Fx.,l..f...z>.XzvX .A.......6.......{.h3.;e.wd.6..k2Ib...E..........
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.979231478190534
                                        Encrypted:false
                                        SSDEEP:192:rqjOlx/HYpNFW7hIn8Gt68yBi8lZvkerYfbo2QsNapSGpS:mjA+NsVY8izyFH8erobIsNabS
                                        MD5:ECFEF7F532C4B7170C50A2D0F1A75589
                                        SHA1:AB0688E99ED9808D4C93F29CA36830CE126FAACF
                                        SHA-256:48BC3EFB675483C50C965A7F309E8CFE5448D86444674B0C1E0A6C045B98F51E
                                        SHA-512:A91E5637BC65AC1F0DBCA42F69D474893B6FC418A30BF1E6F284C3B6BA39FBA45652AA0F5115B01A296D717476DEB9098933A347B36A51D5D2DA4312FD75B1CD
                                        Malicious:false
                                        Preview:..Sl.J\..J...mOL6....@yJ.....2..f.uF.d.........".k=9CQ..XV.d.....`_O...Kn...0K3.......5p.j..>.,.<....{f.n4F...V_"..T..XJ.O.b....A3..$.*....'PT.......3sgO..B+..ih.'..I..Z..5.....=:.j).@.v%.~&.....Vg.0.%...@..[.O/..C......a.....7.5.....$..-..QOP........4Jh..o.......C...]q?......A8L......z!.'q4.M..B...{x..n..-..;..Hz..'t..{^S..-...uR.d..... ...%.j.j...J....n.W..a.+...A..b.s...Y. ......i.4.....X.Si.... .S....M?..xPg..`...W..S..$..n.......(>....v....C..|n....b......Xco..KVNR.c...o...1.].......6.. .w..........1..2...ru.M.... ..e..,.\.......P-fRj.'...{~.......f.?..m..B.=.....U.PRn.}~....3.....N.'I.!.^.6G.w.-T.lH.N.T%<?.`...`w.&`=..=6....k.Oy..-f....e.'..?.*.B..b..T...O.t..M....y:.,F........!:....G..P.a...l{....A/...._.'.JJ.VnG...?...&....i.6{.^}.8-c...j...<E..h.h.N.'_L!*.J...#...`y+..'.K.....w.i..'.....N..{J....K.2GQ^~+8..L.d.9..4..b..P.....D^.C.T.^</9.u..2W..(j..<>}...@F..T.^.#........N.h.6.....;g.)5..T:..U..r2RY./q.^.(9...%...&..3.r.`B..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.975634036876954
                                        Encrypted:false
                                        SSDEEP:192:not1Yqy64qsNhyz38HTelaKaMM9TxdUjCxnqcrOQK0Wmc/5XOpS:nojYq2DS78iMPdUjknqcrOW4eS
                                        MD5:25ADCCEFBEC68B547CFC67138576DA1A
                                        SHA1:967A11E7F026A2A9332B8E0F12FF8F49A014D37F
                                        SHA-256:63606234819199E8198B3BBBCCA465A74A8866D20BD36E773AFD11E7DB01A0D2
                                        SHA-512:8CB2AA1F9956464C58BDB4EABACCF1B34E0384895C7C7A61612E1AD34B63A4093513D5E8051D646BC6E555AD2F0EC5D6427FB4113D6D2CED314B9859E8261CAA
                                        Malicious:false
                                        Preview:1.r...OGiE...v))[:#..!]7!|.(bV.x..@ss>U.^.B*.@..Z...?.. .I....) .q~uz....Z....$.V.........j.t......`..;..5..c.'..^.d..x.J ....9..)....p.......aA.S..-../cn8......A.s.Ai*....z?.(..]B92.m..x.o....lW..5 )...aC_vY...G.....D8M..:.}.WG.9.Q8...}r...'U.............f.P.\T.f.&.\x...k.... ...V.}..........e`..b..2.............J.-.o...a..d....3.{a.VG....../...j..$..jA..a.F....A~...|n...Q..O..V.e.ov.<.<O..}....LdBH.L(.#.....Ua3......e.Vpj...Y.c..q....(...9.......B...(t.aW...$R.O.j.uZ.$R.t....*..?...X....5r.Sv.P}....fQ..........\d...t ......z..M.@!w....w..~g5.|..j....=.....$..`...X..FZ"r..t....g....M]%`.4.<.....t...d.x..]........3.....:B....aO...).....5(eZ..)3..kV3N....!.h.[.mu..D..I.2.....jM.4.o..)3.Jb....q^.sQia%m....CS.Y.#..<zM/O....1..j...*.q'...HV.R.d.......iW.."7......1<>.RC...B...R]N....3Z..~.h."I.RD.....E..O..iF...Q-...q..........m.i..0'...5.+...Y.a....'.f@..j9]].g8O.K....v...I..C...8.>?Q.h.?..p.|Ob.?;.&...q.$4pFI....U.Z.,.^@...9.,.....k.k_.....k{.'.0..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.984870751545482
                                        Encrypted:false
                                        SSDEEP:192:Sxb6h5E9e0OGVJV3EPxuIdlmbSJ1Q1M7nx7aTWmeeu4pS:bh5Eui3Erdlhu1MxOy11kS
                                        MD5:3ED1E1754AC2C00F3653F2D12CE22AE8
                                        SHA1:3A256160621C95EECEA203D58B0A12C5EEDF9DBC
                                        SHA-256:C11D3F85D1DF12895059A52F5FBD1366C1989217D7ED705461E9AC08ECC848FA
                                        SHA-512:E5181F27D7318371BBE0DE62687530D6A42A5A5435A9EE28AEE7DCDDBB755336B3A827F0A48B45884CBD54570293C4E6AD54065679D7A27EC990686921515A6D
                                        Malicious:false
                                        Preview:..K.kK1.....\...}O\..3W.j.......D..fp..-....R.E....<....@1....ijZ.n..f.O..{..x>M./3F..PW.n..>T...IuC...!.,&...U....b./K...W.....=a)Dl4t_.=)R5.d.."B..I_L.EK.9H@......na.c.?,...4A<.Z....L....k.J..g//..y....u.&..nA('4=1.s..... S.C.....z.spn.0..........v...9.6-5......K^..w.....H4#......,'..@)...0.xy.....3.v....[<...).x...:l...fB....xl5..Ph...;..<,..3t....f..w.d"q;H.S...i.gg.K.8.t...p..PB.$..[I.O..W..*.+...c.5#.XS.Xj.C.p.x..%........'.}..b0.N?..N........U....a.....}....A.%.0MH.D.P..$........?.......#.e......`.b....#Y.m><.......^...r...]^.. .1.U...#..@W?.c.6...tXU.ls.m....$}..jMg?...Ix.lK........pt....V...|...ky.c.4.8..5.....y#.y...N.......P......X..r...x>.h.b..(...2..gHM 6......v...p.>..K..:...a0...Y.vI.X.P.t#.u.D..7.C&.~...&.DD.2=.FW...#......z...q..EE.X..HMr.I.2.......!.n...KBtO.#....!.....Q#..D...]..{.Z.......h-?..W...._..0.3E...\F..IO....,2.8..[.+8H.. .H..G.........EH.DyM...u......-....'.P.s..Z...,O3.<....v...`.V......`G.t.!-;.e.L..Ar.3s..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):8431
                                        Entropy (8bit):7.976953709760937
                                        Encrypted:false
                                        SSDEEP:192:3IiMaDZ3SbpY+Md1U2f6N4UGJ0C26yT/NW8q1sUe4yc9pS:YiMCZGpY+MDU2fekJ72vTXIZe4ycbS
                                        MD5:3B88826FD3FDD0F3D4DA9F6DC5F2E718
                                        SHA1:7F523E082F46DC28B281062475B27FD2AFA0A93E
                                        SHA-256:D39FC2B3F9141A4AADB7F7BD389548B95062A794F92E74EBED6BF528AB9F98E6
                                        SHA-512:EB13847899CB558D9CF4B440B7D653F6BC887906CBBD7AFAF58162CA80A49FABC8CBCD91DABB27EAAA9330E9454EB70141A8C2DF48973604154997CAFD772EF8
                                        Malicious:false
                                        Preview:..LV...w.6.s.j.N.Z.Gx...z.39nS5.....49.G...........?..!...jK..j.#. 7.4...x.......7.`..~.<.a...P..%....1m....4..W....vKo..._s..6!..%...XNZD...L.LHT.vZ. |....\..y..q....8..q..D...<.s.2..}.Q...Y.m.p4Q.n...H..0...._\........C.'....(..O..I..O6&......84=..J......M..s..aG...S.M..Z...3]..^0.7WB..)vx#....7...9.*....XK......NpC.'k.../T.IQ..X"5...k-.7*...........9.0Y.X.E...!z.k......8.....f...t.0hk..-.R.Q..vP.4.V.MSJ..Y.4..eF.......0..s.\... ..F..10....'{.&!.s.. {G.....=g"[[....544[/@.....2..O.q..;..P.. Z.F....a.....@f.\w.F.`.P...Y.!uP.|)f.`i...`.....T4...8....Z.+.....L.iC...C......IJ]dz.m....a.$.......y...Fq...n...&n.....W<...z.2..8vZ...K.b.t.12..|A.fxd.)._.7D1.N......u.\....k...z.#...p..ZwR..+..3|.<..jJG....P.;...._i`....c^..GnN...T.....i.......e\...`8..>...<M.O....[.....2.P.......h._......88...O...I..SOC..@....zq.....1....J.u.-..=.Ge..>..Az...P........n._...c....'...;g?......\&.B:..F..!......B.....7lt...d.{..J.{1>..d.....z.......f.Q.4R&.As.K....8*.b
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):19463
                                        Entropy (8bit):7.991066664292152
                                        Encrypted:true
                                        SSDEEP:384:+HjEfAxpDkH6x6SIbty3LjGW6KO9Zu1coFkCL0GKdS:ASINkH6ZIpy7tOzuco6k0GK4
                                        MD5:178C37A334F55158B315347FAF738039
                                        SHA1:4BED724B8640F8E9296A228B75467DD60DF2F8B4
                                        SHA-256:250B963B097A636302AE43979DB485C3891D2727AEADC914127C78AB00315674
                                        SHA-512:55691F25DF6BD66E329AA60C5DE474DB0A3227492812607CA86C44150D61A9DF2F47497FB613D9843510B8E5965F25C4ECC8B2C6447A3BE0054C8FD4B9595647
                                        Malicious:true
                                        Preview:..vZ...WD.....P...h,..t..|tE.....w"S.........K..|../..O....g....|:BA4e.<.#....;..........0.....CH<aa?.<.4.6.......PX...E.2%XK..!......`j....t..x...;<k)2....'...s4g.B^j/L.<lJP..q.mQvm(u8....f8)T#j..:p....6>F[.f.m....~..d9.`....C...........$[......\S{O.N.D.g...K......b.T6.X..\..8.e'.O.s.N.|M}.zC...R..Wm9*.-..:.......8F....rd..d..8._.....N..92.?....F.G.LH.=NV..Fh.n.z......GsE..:.HD.Qi.!..E@..5{..dl...:..r........!U...#P.....Lkl6&0.+../..B..zS..J6.....>.V..:..T.........1"D.].O.....|.C!R..lffF......l.W.tu..D|oY.6og...iF.y"4.zM.%]..\..:_..O... H.B6m T.tV...P.:...|.8u..j_.:6'..Y..]......kd_3.;......t.E...0.D.(J.f..w..)x@9O.w=.H'!:.q*...y...ZB3.U*.7.r!dk......FE.r(.y#..p......N..3....z..........%A...B....p`./......}...).......9..h.Z...1Nt....,...]^.....{|.$.V..4..&h.c.'..P....<....{.Eg.Z.%..@...h..y..j..}>.+..Ue....*....s..(j....46../...;.,&.X..s.,.O...-....e.6#.+..V......^.G%...4..=]Y.P.e.f../...k..`>..-}H.m..x.l.L....:..A....).....TjP.i
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):171204
                                        Entropy (8bit):7.998916546054135
                                        Encrypted:true
                                        SSDEEP:3072:cK3I3Hj7BYkPg6NceZE9SXgBBUoGGGaYrv9JcLtkb8iN5jVcEY8:cSkDEGoG9PlJcWb8iN5SEY8
                                        MD5:92C51560B9DF4DDFE4B02B6D55BC41DB
                                        SHA1:0AC25F37EF05AE4DED68B1C01BE60DB725879F8D
                                        SHA-256:577A01315D81D837703DDA2F881BEBCFE6A1A9587E006FC04BEC7B4F4447FF90
                                        SHA-512:74081DE55B5A22894DF42670EE6EED3BF8F0707AB4A33CA4C26BEE8B1D50A7456DDE401DD2E08237DD3C98C5165412430F876A542F5FA22EE1AB9ADBA0D583A2
                                        Malicious:true
                                        Preview:ON.L,[.M.Tm..-.....l.k.}O..R.Z....lx...U...5..Ou.\.H...-u.?H..w.W...}T...#gc.g............Z..J.F&..bEL.[=.MZ.T..4.@qi.H3....<..&..M...s..ks..Q...`/:}fz.q...s.V...GSS..]....u+J.M..8..z..d..lS..|.=..d..@.S.`eom.#.C.H3..v.......^..af...z.;...c4.....r...>..E$.~.r.`. ....3o..7. .C.)..<..~k(R.....XI0.u...{;S.. ..Y...LG...Q..].\.SF.G.wIg[Tn....Z..!...`.Gy>...g.>3e-s.....q...(E.H........0..k....."&'.y:.n...^..]..#)$G.E. c.TE.vZ..Ur9..R.G.i.Q....../Y1...6.e:.D..e.......$.J...r..%Pj!......&+ L.....X.B]..<p../..RNT.c.+..Ew%..{].Jj...k.i^9.d...R.X%.07...p.#...L.kH|!.b..I....?6_..K7.....x...v.....e\ek.|k.._.+.F....;:.......H..V"...zn\...w@."v.....B......N........4.KJ. n.#n.....0. u..:bM.....|.....i...........0.....a9.vB.C!qY..H.%u~.@.K......#...l.u.:4#+.F.$....;.w..h.#Sv..X<.M.(.|....i..<{.!zH...0t...eC.....t.dL.2.C.....,[....A..a2}^.\.q.._....H.r.)@..<.v!....siuXV......$.w.fw.....p[.~...9..J.A..h.V.8...d...r.R...*Y@|.t.)q{8..U.&.>?*q'.;u...M.Eg
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):174432
                                        Entropy (8bit):7.9990668875642434
                                        Encrypted:true
                                        SSDEEP:3072:ssFU1A6SROlbd60wKBPXxYg8KiYjKJp73lgo+6h3Rs21NMDoJ6:vgd68oKuL73XhBs2nRJ6
                                        MD5:2E49955EDC422EA5EC4906A9D900C36D
                                        SHA1:E1AF5C7970573B9149B25EDBDB631236BCB716D5
                                        SHA-256:9F58419525ADA5561B05E1BF1623B80A3FA71E0DC4DA4D152D5E966549966375
                                        SHA-512:7CE74E4E9C7F09AC2DF4D55D93F163B972E7F767D57AEB7FDC5994A094B12BEFC918CF59C447896E7E043ED4E25AF4EBA9BCC03E2653D2897759B5CA445C5B4F
                                        Malicious:true
                                        Preview:..f...S..8.%..2^.w......<2.]....5.L.W..........{...z~....R.[ ...7..@h6.W+....u.D..F.....^j......tAX...;.w...j#k..T..yt..T...6S...:....U6v&........'..)K.OK..m....|B.2.o....7H}...}..n.M|..^.+..O.@..#-.O...![j.c...i>i...t...;M3.;.,..Am.f...?Nt.mm..P..0...hc|gd(c.3....Q.&....!.l..?J......K.z<~.F.JI..&.SZA........b..`5...d...0.ro....JC.:/u.r./..2..,..Tj<....w..1.W.)....1...y..."..>..).u.@y_DI...c..a./?7.%X..hD.I..F................!.T....d\....e.8..L..Et..?.....4......+..(O...y....M..-.....G.VY....t.bX..?,..+....2p9bT.N.<l}........"~.....F.X+.......jQ.h.....Id..q.|._..&.W...Ow.0..i.+&$...bv...z.4.V......O...%.4>!.m..Zl...h.8..f..;..$[E<.;._. ...=.>..5..].R...9l.m.[...B.m..v.8'.bfFrup:.L.....5.h..H...lw^..i^.W{....a%........}.%e.y....qfN...8;\..x(..R......y.4U9..0.$.0......$F..5y....q...t XT...[..5./,.0u.........k...iy.t\S.-@.q[.d.S.. .....W....(D ...)....D.._...IW....}....B..4...y.......H....j.`......C)K.U......q.H.$_,......D..t.*..eE.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20971520
                                        Entropy (8bit):0.014990073651081301
                                        Encrypted:false
                                        SSDEEP:384:vMTdt3q4LE9vab4d4145BE4t4w4Oc4E6OGc9j4bHz4ZBb4nPR48D:vMTdt64LE9vakGu5B52d+Uh98AEK
                                        MD5:60E6E480FBD0DB5BA2268D0CAD54CE27
                                        SHA1:F4D0C6F55106C727524552A76759DA7FCB747C70
                                        SHA-256:4747209ACFE1228F1F73BA6706F7251C167BB53F0EE8E82AE9A496800236603D
                                        SHA-512:AD9E611565A18C1D663EEF00F788095E3090F29A6B5BCC794090B58E0E056FE2C2A8E3282FAB5D2A1B90C78DDEAEBF07C209B6A5D4E85EFAE8AEE3AD22EEABC2
                                        Malicious:false
                                        Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..04/25/2024 03:14:40.586.ONENOTE (0x8EC).0xDE8.Microsoft OneNote.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":19,"Time":"2024-04-25T03:14:40.586Z","Contract":"Office.System.Activity","Activity.CV":"mHPMKQEqxk2iLnaGGcqoig.6.1","Activity.Duration":329,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...04/25/2024 03:14:40.586.ONENOTE (0x8EC).0xDE8.Microsoft OneNote.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":21,"Time":"2024-04-25T03:14:40.586Z","Contract":"Office.System.Activity","Activity.CV":"mHPMKQEqxk2iLnaGGcqoig.6","Activity.Duration":3814,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.Failur
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):20971520
                                        Entropy (8bit):0.0
                                        Encrypted:false
                                        SSDEEP:3::
                                        MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
                                        SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
                                        SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
                                        SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
                                        Malicious:false
                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16834
                                        Entropy (8bit):7.988156581481047
                                        Encrypted:false
                                        SSDEEP:384:A0x9L4eRaSan6cCH3YF2YyWpY6Vjou6CdA2z7xjex4MWvGtImMiS:b4SaHf8IQmzVEUA2pjeeag
                                        MD5:A02D6FC4F857A02F3FAEFD5F2C5770C3
                                        SHA1:EDD337D52A28CA6A17DAE9CF675FF0B1D660B4D9
                                        SHA-256:741112E88FB8296E30492DA88C62C1C5AFC88670050CA025ED4544A535710D7F
                                        SHA-512:EF707E485AEED9E94BCB3596A3120447EE7901A7A4CC49C449823A5A26A1B1EB66CC8DCCD0A7E78AB84E3727D3FA46B9FB6F495575BE2EF4253FF9ED52F25E60
                                        Malicious:false
                                        Preview:n.....\.6...?..2>....$..(X./H,D........N$r../.K....B...... .;.Mo..C.....5.....'.L.=.=3....$.mi.V.../..w...;...P5I0j".~+W>..5.9.@."|2.&...90..Qw.U.q..W.!.P\.,.N.F.D}..Z.m.@*..................%'.*..Q...W......'.%(........$...(. \G..U.j..>e..YuD.w..xK.n._;z.#d...8Er#.x....q................=....'S..M{...I......`.{......nd..m.%.#2...f..z...=.[...n...f..1..s#......($?c[L.)0K.....v.L...8.qG..7.D...(U).6...9BF..*..M...u1es.s.C..)3.>.^.0&v......n...(....@t..M&..TwF.t.{.k..g.Z:...M..@..5..\..=...sX..~7z.V..N....^.~.2..>.G....f.......Kde..d......y.k.mbJ.V...fV..E....LWY.+..U...... ..'....7|=zp...N.Wx..<...}..M.u.#..W...a......~..9.6B.W.o...J;.....<.....l....g..K...X.gOKc...A...'.D...jgx.....C.V}..]I._.aVI.Y..F...0>..E;....2d..%~..,}..t..:...A......kC...Z.==.!.~..F...6h.DPzVW..x..x. .z....po{.H"..~".cRX...DU...3.=......M.w(.LG.....}...Ii..7.........heA=.V.Nk....C0i..Kk.+.'.&....4.y........y'-S.J..\..).mX.3/.L..u.j...5.U..q.Xj....HMr.$q,...%.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16832
                                        Entropy (8bit):7.989771104345296
                                        Encrypted:false
                                        SSDEEP:384:K4UIoCVh1uq9YcrQkJcrN1rDjpiZeBzcq3yz2UcEw6Niz4J5l1cCqcXQ/BvzbS:BUIokh1uq9IkJcrN1Pj2czcq3yGEwiiw
                                        MD5:F23AF31000136EFE3712C18F06F96113
                                        SHA1:36BB0190E0A83DE9382CD46C231CEB235E903196
                                        SHA-256:244A44AE178F860BBF9626C66AECC8B2833CAF3A20C2B167771A25EA72093D85
                                        SHA-512:E098257DF36F90D3D7D69B1E4C916DCC1EAA1A63431AFAAD06E95D476F633C10F9876FC5BB20E1273A354EC460239197A53C89A38AA5801BB3B54D12A8997E75
                                        Malicious:false
                                        Preview:.W..2.Z..B..v.......JU+.[.9.EUt;.........h}.I.|[d.*!.g.....u.~...3.'.U.-..%.......g.P...;...+k...@Cr.*O......u"6.#vaD."O|...)U...]2...tK)W.....1..H00..l..x...Gy.RiK.h..>#U...}.:._..vw.o.QW7p[3Q...$..(.=VDI....n.z...i..'.3W..v{.J.G.8...W.~...?..../$ x.>q..].g.[..L...D......4u..a....~.f..K,^1>\:..m./..gt...P..z.E.F5....z:R .HL_uAX........u.7<.r...B.N.p^.c.3..<>8$.....!..........\.Q...=.d.A*P......c.T..;.0...vJc.U...r.3...:..E.S..(kO.U....."...F$.P*l.D@.R.+iv5.n\\K....1U...y.6.@~?..I.!..7.....x..j[.0.F......>o..Lb...p;$*...A.RV(l.53H....5..:.3...{Yg.......^...9R+..;..E.Z.I$.Hn...p....<R....U.:_.....82!......^r?w.\.E..V.t..3F;@.c.Z...E..-...........S......v..H.....o.y^:8-....AE.p....+..H....Jx.B.'.u.1.....N<..j...X.c....kE*;.c.(.p...#.........P...#.{<.B.r...2@....A.......D.!VHo0....S...n"'..Q"..E...Q96..q.......Y.t.*....@.*f..bE...%4*...3..&eV....w....!..Ryk\vX..s.......V_.....!....v.E..l........T..V..'..2..%.g.e....... )..F..u'.....K..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):16881
                                        Entropy (8bit):7.988802359545019
                                        Encrypted:false
                                        SSDEEP:384:76SNCVrB252KnW9Oeyn+HPmjuI7DFLKBZZNVYCuccHslPBLyIjsyQ7bQbeUgWS:76xVrk2U9+vmiQtIBLx5mbQb41
                                        MD5:F003DDEFD4B8E4B99C27C85EA0BC2AE4
                                        SHA1:E404D0D650F0E3C41DFD6DE00BFC24FA491477E2
                                        SHA-256:854A318ECA6E67D75F33D8D5559710D769CEB8F31C3B0E6E07702E87F3E153BA
                                        SHA-512:C4BFF8A2E7B0BE903548404D8126EA4D6DD698E63F6580211C11DD803F9FD379C1950BEC07C52A34A03B49D4A69D015E6E18AAB59A5E614BCFAF4D6A9A84680B
                                        Malicious:false
                                        Preview:E..ZU......|...X..(....D......D.=...{o%qT........{9.[.%.....O...0i.'.=yV..*.1......R..;%..VE....CO.......e...?..M.......@.3Y.T....E^..^...&l...a...X.V'>g...d\I.....C.B..[...s.YO*.7.......1?....a.4./z..s.......@...pTXg..P.ZR...E..8....}6&m..g..!I.C..p...}*e...rAz..Yc.GY...z.......v..%r{fK....&1...g;.0...iB`....<..K...sj.>..Sfn.JN.@>J....+.<".q.......!O.@.}....}%.u.F.|TG..&..+.X.7.....a..|...:.4}..o...R..i..2nQ..4Wn.0..]...B.........7L...Tu..,.f....7.....f8.....@...&.7#..W..2......>.....A.Y.Z....!.L.w+kINx.2.K.9_..&.u;.Gb.2..W.B.(i..K...$cJ..AQK...N86g.>^.7B.6.q.o7...r.R.6...n#..S.>....-.J.1.....b..;.ed...T.~..../3...!z...v....g.@........$....l"...tb.....|..>..o....d..:..I.b...[.r..!.5])4^.*........R^..R...3....`l.@..\...m.y...g.$.$..P.9^..&l:..#.t3Y.P._.y...-P...wk.U.7...._.....%P....z-N[..)......9..?...@o....F...'..m......a..........u.0.-...&..G...0.Q.F.J..[..kH....O..C.....)..(f.Z...4..&I.KGzH.a.........N19.!....@t.o.YI..v.....8.,.d.p....Pxm.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):24119
                                        Entropy (8bit):7.992156585342594
                                        Encrypted:true
                                        SSDEEP:384:UetS1fJiEN4nQXVohGuMw4J/c3I4b2OUwGPiCjwXJO2e+CtWby1jAxz1aRAyZfRT:nM1fMDQXVozM3AI4COUP0a+Gn6xpaR/z
                                        MD5:BC7694C443E9A7AC8DCD12F7D8498840
                                        SHA1:DAF0F59825CDF3A65B7C433BC6688440B6B2C40B
                                        SHA-256:DADFA806D680218F8F30A0CECEC554C1E349A728702E82CC74193EBD0538E2BF
                                        SHA-512:A8EF805A65ABCDD6F87283E5B4E8AEA5BFFE336C3AD01AFC763C78D79233EF717A58B2C885D68DB5C8F6C0E840BDEAEF1C41D4D04BEA36B8155E581ECDD0FFC2
                                        Malicious:true
                                        Preview:..HZ>B....+..d.#^4.^..Xl.Q.."<n.'./..#:...qb......4....@I`.4.fl.1 Q.|..Z..eg.:...~8...w......."...y..Oq.u&.'u%..Qg..1I.........]..Eo[..m[.u.>[..G...r...).i{#..x...a..M.$..$..>-.M@se..#1m.....-...r........6.t..Y..i.(.|...@..I.J.........,.}.....4.$j...La.].....i..O.N..;"."q...C.|..&9..mK\.r3F3.E.e6...#.E.}zHi.9.~.....-R.W..o.5.....C....,.Q...C...(..&'`}R.b..[..l.j.....4a....R{%#.FI.D'..c..]....R.M...%..>A>..`..E..-.e.v.+....E...j...%t...F.H..h.6.....3.....d...0..f....e..*.9....gR.(.....@..O.|.....{m{...z...."r(...#...Z.H..?.l.]...'..]...%MC.,...\.py..1..ar-#HQ_....U7..R.s7D...e......[.V{..P..(.U....yX......[>+.c...Y..E...m....Rm.....7...X\..y.%J1J[...g....K....q.........7...........a..2z..$....:.C....E....~..@...fr....a.D.BT=1/....."q.....C.....^*`..uN.E'c..8.....U...1/.N..i.OI.%.}....v.......%. Tc^..k3...IN.`.a.bD(....%..`....(..b.[..,..HLf-9J+.U.c.....D....g..>.w....r_....I9........dI....%..&I_..K.b..p.k...|v.oj.t...t.h..|...........
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):2511
                                        Entropy (8bit):7.931588720056087
                                        Encrypted:false
                                        SSDEEP:48:/8SUJU3d1UBo6Ae9JE7YzGlkA+YVuQiRzqDLcg9L0r622SZJMxjDCT5DpJc:yJ+danTE77lkA+Y6Rzqs7trnMJD8DpJc
                                        MD5:FBFDE585EFE0E62DAEE946206A4604E8
                                        SHA1:172413790A4537B72BF914E8C7F6D4E716251FB6
                                        SHA-256:EED867E7EDC43F6C1EFB2D3EEC1C7095B9D4B09C1AA8DCD724199A3B7807AD88
                                        SHA-512:25772CD13B276B4CE281E02CEB45D93D825FADD46AC5878EF0070F6ED489DA060C518DF5EDB4C3D021D84DF55EB2374E6CCAD527CE48151B97D2BC341D5D5515
                                        Malicious:false
                                        Preview:H.'.|.|^.F7+.).k..cf..W.....0.....R.:..]...%...F.h..2.!...T...Vp....%........Ak.....|:..Eh.wH6..MTyj...f*.....W...V.%3.f......PfG3.)....Qb.8.-.`.L..f.......A...O./\.......N...:. .....i........,....]jPO#W..4%..2.^..>..)yz.jT....y;......0}/.P..^ao^.;..'...j.`n$t...4.....@$s...=."b.;........j.YK..... ..U........~,........W...U..`k........$...~.9../ ...<.~.@.9.R~VF..:..^.GF..(....o.0....FV.n.VDNN%..@.@..1..u...LH.0.d...]Ci....J...7..E..q..1..X....,....q.O9L,u....=d.p.).:...+c.Of^...xq.fnj.F.{W`G.jb....w.$k.[...9.>>.&@.v..Y0..0/~....<.C..)=.Io..b.....)....C5,..P..x@...Z...x...:*..D.o..MQ..V...a..xv..c..'. ....&.t>...2....PY....,Q.i......&..\.4/*.VmH.N..*HO.yr.J..S....,.......s.C..%x..8.E...@z....B}..w....e..dT.:...:.7m}Q,YG.7...z.$....E6l/e....{.>..@.j.%.....&e.~..HB.?..SAz`..+t..i......../.\uB..Q.;B.5..-.2........dU..e.)..6s.#5x......>..(..g ..@..5.j......(...%2..{. .vK.^.+NI.$...o..]./..f^y......U.u..>..l..uD...+X..D...K.........t...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):201270
                                        Entropy (8bit):7.999056185878428
                                        Encrypted:true
                                        SSDEEP:6144:azeLHL4KI0QSa6dzNbg+w023Tx+NjL4BtQ2w84eU:azU4IQ0sN3V+NjLmtJ4eU
                                        MD5:F9759A3AAD56F62648257BA1CDAA3DEB
                                        SHA1:2D88013855979E3E4F75C010F5617A09B31D227B
                                        SHA-256:3CDD4BADE7328A67A781AC0C2A638FB03DAD86FDCC21DDFBA016DCFD109FFE10
                                        SHA-512:7A4D630E65FF9A4FC1C635C0CDDF39D1D1FEE2EE91C6BB2C336E46608924B4D332B9FF178140EE77FE67310B12ED67680F0229EED617DCC57CEFC221EF6234F5
                                        Malicious:true
                                        Preview:.$m={..Kd.'.bO..j..A.......;.N.p`Ac8_z.L.-....Q5#jn......#7\u...?..+/..'.".....%GbR....\....<W..e .ue.@4.B.X..Z......rS.+..\HE.UO..;..lG.._.B.q..u.oB...*K.AT'.5..B^;..c...aTu...w.......YUy.p.....7...\.t.U.V.1.9C..k1.6@../.....g........:..z..2..p/.t........@.N~aT.K..j6.M.p...:O..p..-.....,.iw.iHrn+...!VW... .I..e(.Y.+l*.'.p./.d.;8.c....j..un....E=B.w.....S7E.R...V..zAF..\W$~.H...S..d*.>81|.L.d..3...L...m.vb(.80.}.m.|KG.......'.w.....!J..3.o.B.F......L.......g..Q.c......7d.7<X....E.I.:.x..`....-.D....W.y....Jr._s..U......8VX.@..O...<.........hPR...}.gU...S..x...L..P].D..u.8:v.i....PQ.......@"..c.../9....&....G.#2...bf..J..X.E_..r..h..6.R.$...KR.~.rKZ1...c.!..y.n.z.;..D...A..%uq.."...$`KG....+L.I...O.i.#..&S..i..r.@`Y...=......[1%Wa..`.[.b..w6..-P............y....Q.?..$...O.K.A.>..}.~9.|.[T.B.l..jR|.O.....NSF...r..c.s.B.<9w....u..+....6Y.i.TTw.C..6.6...^Xw......i..;...6......-..^.<...n.y|.,.....q..`..?..).e.....M...e......BgE.....7..%p...W.dj.Q ......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):59147
                                        Entropy (8bit):7.997073766325449
                                        Encrypted:true
                                        SSDEEP:1536:bbEcOl09hTEQI1aiUPYSlN/TVZREUevPiLv8Vzk9O1n61id4Dq:cluh5iUPYu9Vv4vUv89j1n6XDq
                                        MD5:5911D3EAA5F389F6AC04D51FC1C34161
                                        SHA1:2F928BF1CC84E80CFE7FFFAC8595217DD3495307
                                        SHA-256:87DC8CEAF15C68C52819AB707757A70C2C1913DB948D8C323A08CDC0350D74D7
                                        SHA-512:9D8EB34C72BB3AF94E833EEF269FB5D7906CE798E9CF589FF6DBFEFDCD999CAD06C679918030B097212DD5554FE3A58B0F79378DCF0F2F5C3AA36B83908D4056
                                        Malicious:true
                                        Preview:......e..... .../.mo........V".p.H.[.Y.....{r...~*.5f.&..\.....T.V?...v.+R..M..}?Eu?........X....M.Vx.. R....)."..@..}......;..>*.H.I...~..5. ....)...8....).d..nFp.8pK..."..J.LG..I.$l..g.../d....$.k.d.Q).K.....8)v5X.&.G..&...u...I.Z.B.c8....9....0YI..&k]........bZ.4J./<]...T.mOX..J...l..]K..a</j.fg6.u.&....g..~8.g..Z...`.Q$..m........jOG`..^U>ohY.7.NlC.~..V.....vX... .;0..3.. \.1.;..R.e..t.^.>}.....1....?p...B...i'...B...R.H\.e...M'.jB9...$.Z....%.{.....N....N.Xs.:Ey...\.....q.5..1...J.-.Lc...\....@.Jb..hWG...W.......NQ&...gN0.q..bo.F?.g....G.....6./..q....b.....s..THy....jRKD.1........WC /..#....-.U(..8!..6.`.G".(...s...Y.d...;-.4..*._IS.Qa..E.)....)_h/4..f.w...`..T.[q.yv?N..Z0m.....7O....Y.}...Sg...*.._...X.:AY6....#5..hRZx......u.>)...>x..C..........c C......"$.{..p......-2*7.j!l...J......O8./.Td..9q..&;......rhM.l5..4:Kc.0......>^.`..Q.3!;....?.?L(.....J.u.P.../L.......P..o..=.7V....{....BYuv..T.Ws.s...L.."..l...{J.E.wN..4.`e
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):47044
                                        Entropy (8bit):7.995549300403031
                                        Encrypted:true
                                        SSDEEP:768:u+BV2fOkKKoYDsqCmdXUt9VcbZHDAgMCSdWhoosPZXMTJp9SjQsyY72ciHTlxUS:u+mGkKKoQsqCaEVcbZBadWhAPO9vSjQx
                                        MD5:FC4A96F4CC09A25ADE63A335EED085E8
                                        SHA1:3C9943CFBDD30D0827EC7D5FD43EBB0963218212
                                        SHA-256:6E34E65A2F0A77CFB29583431517EDC56F4C5F658DBE8AAFE2ECA3C641C1C27B
                                        SHA-512:EFBFBBC98E847D5E3A0BF685A8558F6BB0D6BBA4E2B0C8CF7B668CA7CC2EAD7BD073EDEE21BA2BBDC04C7C25326157386AEB6A1557EC6CACF777D2FF5D6322FC
                                        Malicious:true
                                        Preview:.f:.o.o.[C.tGB?N...[.p.....5...Q..vV..O...v... {......@.......F..f.Z.*!.i.B...3....:.}...w..|...w..e.....,.....5.6.fos...gmI(}S@.....8h.8j..r..+.x....,..w....&&z^.....c{.....j..-..S%..}..D.......l...|...PClE......NK.C...%.}..3m?.5)."..r...}.W...m.....aB......Y3.m.>.q.... ....7..a....A....."......f.U*Q9.....@pY.d......*.D...C..s.=...%...T5..V..'.7..4..k..Uh.F..*..D.t.$;......./.6.ik.O....&....f'.\J....")....y.&j...:.1.d..4.0.6Tj..u.g.....<........5.......*...$]...d..F.]Zp.....$..z.d..u.%s~....O.56......... .....boB..!...3....f].k..`..>.O.G._.g.=....1..i...e..F..N.l....:y..h...u..B.`z[......W./........c.....O.4+CW$]..v*.q..Q./...4w&...}o ''.",.....Vi7-cm..[..Y..../e.o..Xm;I...!5j.9..\.nx;....e.[~\.f...A.....L=...l.5!.l.....^.'....kB.!...81.T....pw.#2.+. .dY......8.....)......7..zdK..C....Z6N..1j......M.)...-)...~.....fjKv$.>N....Y.u....PJ...Sh.E..%....f.._....#...,x.....PSg....Mp<:..z....".&.@....N...$.%.F..V.f. u_"/O.1.yb...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):23033
                                        Entropy (8bit):7.991859523569571
                                        Encrypted:true
                                        SSDEEP:384:I57HccOd4jTntnei9D+KDXrj2lECgXt1AkvQtznmmL/YBAstf22lM1iUE1S:I58cO4jztneG+KDmxMt1XS/Yistu22l
                                        MD5:3595DB922EAE224ADFFCAD442EF96C7B
                                        SHA1:CD6DC51302554E57607489EC35B59D902D9A0B1C
                                        SHA-256:EA9B9D1B470123F3C1250AC52A2EAFE4C9F2D2DF00CEB5049AFC48CD3BF84495
                                        SHA-512:120DE0EEFE5211828A3AEDBB7B96F0FADA2CEC1021DCE3C3A09ECE45BE3C9061282206077FEF663E874D158661D70B3A2EE65B7369A8EBA4E83A3CC424698DD5
                                        Malicious:true
                                        Preview:..Q.9x.C_...|F.&.........a....3...).\\..R.0s.hC.p.D...D.Y.P.u..M3.\3.L...~}....kkE..xpW.. ....7..\YC.....)........w+..'.D..:.d.._<.....k(?MS...Sw...U...b:"...*1...C@.F.w...f....i..{.SX"...@.G`^.p..0N....>........J.I.....W...Z'."\]...l.. 1...u$X.....kH..;....&...G.Nl.....&....Lhx.....fr.4..V.R..........k.c..3/7.}fv.......fn+......a*hz..n...P...u....~...E....^a).[y..e.X|....]%&..xk..fgg1.r.lg....I.....W....6O._s0_....~Xz..+.F..z..&.&..N...=.e....NVR-B.6i...uNN)V...xs..v...A..&m..."+..yV.K..p..xbQ.....p'k...xV\..A.J{..3..0.M.#[.\RV.n>....bn.O...x..tmjD..k%.C..>G._y.#.....91...s....{......;tk..h..}.?.!;...7... ..W.M'....Y........../.C....7.v.P.1..?'.k*.oi...a`.W.GWKn.:.#.:d..1.....a.......U..M......Xu.[fO.UAY.".&.V.:b,1I..........6wW(.8..Y`7s..S...F.#.*f1.qF^."r.;.X..g..qb=.<....w.d.....6.N.[$.{#,..0.,.j.FX3.b..l..4!,..7.....o+*./.....,7Z.B..9.f.3.f..WL.....T1..E"..kNk..f..dY..8.H.........=U5..o.....@CM..q..z..e......X<!E.1H9...i?'.A44...h.....k
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1674046
                                        Entropy (8bit):7.9995384215195715
                                        Encrypted:true
                                        SSDEEP:49152:y8zKxnUBt5YXBI65GLC3LRYI+Sk6h6ePun:ykKxUHOI6I23LRYI+R6VPW
                                        MD5:0FE6D6D31354F6ED11852C7C6B8B9768
                                        SHA1:831D5BE293D638795166DA7733E5BBA4E0847E43
                                        SHA-256:158BD3CE390201D50407BA91B12727E50B79FA0AD99BA03AB7539FFB3A79F33B
                                        SHA-512:75A1C5C6643F48721557D19A05BA8281E3B3711789BB57CE4F5D7EA634E8EBD2F194C5C47D431D8A53063A22057931AF4575FF5B9BD0A25006C1EBBCA2841ECD
                                        Malicious:true
                                        Preview:.R.....>.Y..)...<~2.L..y.2..j.....i..`.-......p}...a.....O',z.@..JF.....a'....a:-..&nXI...Y'9..F....7...O..?\.)..p5.....=..6......}.o...R.6..i.p.T....2|6.Y4..F.Qv....RH...U.:.Rj..j.1y....;.HY..TD.A.JEd..%.W.E.g..l.j....q...].......P..O)Q.vL....;a1iL....S.eSK.....Tzk..-d.s.1........o.7.._s..W..=.%@.V....!..%...u.-gN^U...g..H......yU.~!....r.5fx.}8..q.(hGa.......`..@.sl.....M.o.k.+.M.E...4.75.J.(.....^.dC^......%h..X...>./3.........v.......h..9..}f.!v .:...L...z......^.q....d.8..|2.-..oT.D...It,....VZ~..,>.`.....{.8v.....e(a.......aF..B...lZ...pp..gE..c2..|.o.c.P.....X.."F..0.9......n..l....A....6..oV4L...c.....u.R....3...2e.$Q.YH,...o$>/._X..."U..q.|b3....H1........Y..r...[..N.....Z...X...E>......G....X...!..>.Ao..kP.......L.?.zj`..mu..U|.uM..]1..!l..Z.X.1.C.1...r..N<...@...W..p.`......./.V-..Y.CB.I9.(..z...=m9. .....ZDs.H..ZW....c...a...Z.W:C......E.&:9..^tw.Ik(.Pj.X.A.}..bh-..v6Z..........L.\...r../^..^@..?*.I.i......{......_....5.].FgM
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                        Category:dropped
                                        Size (bytes):22203
                                        Entropy (8bit):6.977175130747846
                                        Encrypted:false
                                        SSDEEP:192:5q3R1VBvq3R1Flrk6Q0QPJJrR39joOVMJ25d1NkMhIwobbtAAAqYnLJZMJYZ2AC:xw6Q0WJR3FoOVMJIIlAAAqYnMJdD
                                        MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                        SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                        SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                        SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
                                        Category:dropped
                                        Size (bytes):5465
                                        Entropy (8bit):7.79401348966645
                                        Encrypted:false
                                        SSDEEP:96:X0cZneDWlIKmXwxacOHHI6EhzNlSSDDgafbofgt7mGrw:XleDWlIJwQHihRdgu8imGk
                                        MD5:8470F9A96B6C6CAD9EE60961E96D19B2
                                        SHA1:AFE1F01FFA4E4CB06B1D770C9C59DA75B434D1AC
                                        SHA-256:2DF453410796AEC7B9EFEC00059B6CE64BCF67313A95AE458BA600EA5DE14811
                                        SHA-512:CAE5C2ED091BA49761F0348516D53491E578FB165F32F93AC7DAD927383E9A398B06229FAC6A8233777DF708E5001AE0037A1FA960293BDA49892C40B37F2240
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................E.e.............................................8...............................!"1...2A#Qa.$34bBDSqt..........................................................?.....`0.....O...3Sd..@..5.0....Q.pw....;....!pN.DR....`0......N^...k.=.u.e.7{.b........?z....zV...M.....P:a.SPj.....WRK.=x.2.h..2..AS..s..A..|.Z/f$D.YX1pr......}G6._.~..)j...+.s.r".{..q..-.^@...#w|.H..*.K)....g...y..`0......2.w@.Ro.d....@...K....}...&... y..f.y.0.|DC..>p.[E.2......v..N.)Z..4.RF.D.8]..Z.|f/..+\ID.r/.o........0i..*.G.O..uj..RN. ....j...xnF...Q.Ls.U.c.D0m....z.k.P;f...b.=..L.hH.,./;.U..`sa.I...?*...I....M.0<.u....!..C..U.T.....s.Q......_..7K..*.....?....R\&=.<.u..oQ}WZ..Yu...{Fe3.h...@.s..mW.G..^....1.W.#[.q2.&u.c.G......`J./..X.C....M;.....3k$}.i.3...#/x.m.Oh.}FH]. ..5NNDIS.-.M~...6..w.d....P.;..k...........v*..T..L.P...s.!B.4..w
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                        Category:dropped
                                        Size (bytes):59832
                                        Entropy (8bit):7.308211468398169
                                        Encrypted:false
                                        SSDEEP:1536:HS9SYFtN0+CRa9mfJy4zBAiIJhzrkHDV2hJK:yAmta+Tyy4zBIJW5WK
                                        MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                        SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                        SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                        SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12180
                                        Entropy (8bit):5.318266117301791
                                        Encrypted:false
                                        SSDEEP:96:k1bHyG/fKOOOOQJUg+g2S+kEm6alfsfsfn32:+bSG/yOOOOQ+g+gOab32
                                        MD5:5C859FF69B3A271A9AAB08DFA21E8894
                                        SHA1:3156302A7450ADFF4D1B6EC893E955D3764D4DD4
                                        SHA-256:B4A8E9A67EE0B897615AC4CCE388FFC175AB92D9E192E6875C79A4E7C1B5BB6E
                                        SHA-512:4CF518136EEBCA4F400A115D9B7BB0CAC9FA650BF910B99E15F04A259B7D3EFCFFD6796886FE09DB08C37C332B14BC8500845C09C8EAE1F2306F90E98D3C99E0
                                        Malicious:false
                                        Preview:.PNG........IHDR..............;j.....sRGB.........pHYs..........+..../9IDATx^...dW...S=.dL$.............-.`...'...x.7.D...(...$.?cO....9S]=.v...Z.......{..wNuf.&.....a.k5~...._..\.yk..v.....}{._.Q...5...._9o.n.....}7.].1v..t......q....3.<..0<.p.......0....s...... @....... @....... @....... @....... @...X.'..U-..... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%@....... @....... @....... @....... @....... @....../)m.. @....... @....... @....... @....... @....... @ ....`.)....... @....... @....... @....... @....... @....K.0.....J....... @....... @....... @....... @....... @...`.....\.... @....... @....... @....... @....... @......,I......+..... @....... @....... @....... @....... @........z...r.. @....... @....... @....... @....... @....... .$.C.KJ[.... @....... @....... @....... @....... @........&`.=X`.%
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
                                        Category:dropped
                                        Size (bytes):52912
                                        Entropy (8bit):7.679147474806877
                                        Encrypted:false
                                        SSDEEP:1536:DB/nIviNJD9C8kfJj6TkVr4q24FsUpjPc021si:DdnIvi3D9C8Cl6Dq24ayPCz
                                        MD5:1122BF4C2A42B4FA7F29D3C94954A7C9
                                        SHA1:3750077A830FE21735A43ABD35C63BA9A4D4B0DE
                                        SHA-256:423B0DD1A93B391D15B1DC8D8757C3BF5725FF2E7A59E6E3140033E2876B67F6
                                        SHA-512:4626EFE2EDED2361D6296B57F994DC434CC9D02357A8A6A67D84A544FB8A1CFE0005EA98F846AB963BED7F2B6CE96BC9181182C9459843A52A98D3A731A4FE73
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:27:10............................f.........................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....]+\.9.9.P.d..Z.?~>.-...]6=....*.......S.9G...b<$..Z..........>.v.o:.o%.e...z.F`...[.wo..z.....k..E...5....G..7.......c2..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 77 x 627, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):5136
                                        Entropy (8bit):7.622045262603241
                                        Encrypted:false
                                        SSDEEP:96:djzuNKb3XHco17p2wolIxIx7lpskdsC/ddWNKeabJbMojpxLDTu1:VzuNKb397pwlIxKp7qs3bJb5FBTw
                                        MD5:FA38AFA965141EA3F17863EE8DCCDE61
                                        SHA1:2B4611E651AF7549C1AA73932B1136B561A7602F
                                        SHA-256:E1CB1A0EC9BE62D5445C73AA84DF38234002A7E164EE830C9DF24997802CB5D2
                                        SHA-512:A372674F5CA343321BA9C413D346070709F7685706C9C6C3DC7F61846B59253A5E6FE800DBA10AE870FD3887439B2AA106FBBB51751E92A163938A4393C43E28
                                        Malicious:false
                                        Preview:.PNG........IHDR...M...s.....}8nv....PLTE.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................z`.....tRNS...................................................................................................................................................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
                                        Category:dropped
                                        Size (bytes):129887
                                        Entropy (8bit):7.8877849553452695
                                        Encrypted:false
                                        SSDEEP:3072:QS1x1rXglsteJ79wHi4vNQR5yBlUdOSILe9hSj9jeWMPjdlOJ:vvglst1HiwWR5yBA2LeS9jd1
                                        MD5:737E96E41D79D3BDACE7AB4F8CBF6274
                                        SHA1:E6202A41A4F86B27D9EBCAEF7670B16C0ED67CF2
                                        SHA-256:7966F3D8A2D61ECB49A35E163781858E052C0B122A18A1238AFE27B57E2850E8
                                        SHA-512:D398C8521DB2FB3F8456FE792CF37472F3B851DD7298DB20E2DB79144F8E846D051878E77E5EF5D00E6840EDB90C6E2D97935BC1023A15FC45038CCE731E9895
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....iExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:13:06.............................:.......................................................&.(.................................3.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................u.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...W..I:..*....a....Aa ...w.T.M.v.........3x.......8Y....$.."-..m.I.0~sxB[@..=...:..\.Y?....@O.L;9i..U....?.5">+9.s\Z..vN
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):59707
                                        Entropy (8bit):7.858445368171059
                                        Encrypted:false
                                        SSDEEP:1536:k76rvGc8WKC2/UX1uEgVRY/jvv9CblyL/T:k77Z5C2/Ow1e9CblCT
                                        MD5:47ADB0DF6FDA756920225A099B722322
                                        SHA1:851946B8C2BD0BB351BAEECA9E5BB6648A87D7CA
                                        SHA-256:EC8CD7250F3D82E900E99114869777EE859EC73EFFABED108815F65742078C3A
                                        SHA-512:85A9920E1CE4A2FCCEBAFA425C925DF33580FA3C3C00178F058539B2FBC0163866DB8A41B320E2EF2CD217F00FFA06A1A831C728D3F9F910C9EAC58B5DA76E2D
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..A..Qaq"....2........B#..R.b3$..8xrC4&'W.%e.(.c.d.5E6Ff..h..SsTt..u...Gg..H.....................!.1..AQ.aq.".......2..st.BR..56.r#3.b.S.4c%...$d.CT............?....3.7...G:../P....z..K.:6..w......6....... .z7...~.....{gdF60...9....{...'[N....m.........z...g{.......7...4..1..=.z...._..p...m..Icd.~.v..9.P..0Z(.<j.......R6zm.....v.z...>x..)=g........zo{..w..f..y.t.....%.D..#.}.I.>).H.QM..cLD..x.../.^y.{.............y.=^.......I.T.......U..0_?...u..og..3.ky..K....6w...Dc......~........ik.z....N...en......_.....x....._u...4.{..P...>.....}.......>.R.....m.....[mt.....}.........|.....m......~....B.F.]C.36..q....yg...{]...+.DZv.9<.o..;..N.n&im.,....w.3...V.s...Y..e#$.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
                                        Category:dropped
                                        Size (bytes):4819
                                        Entropy (8bit):7.874649683222419
                                        Encrypted:false
                                        SSDEEP:96:/hnQiz+ET2/hDi+tv34VtpWfowTHgegb6hhLT1NTS:5nQ6TAhLtvIzMvbi6hhF0
                                        MD5:5D6C1F361BC04403555BE945E28E53FC
                                        SHA1:00C254F7B3BC0289590C2BBDBB39C8EC2E2B2821
                                        SHA-256:131D637CDC5D0B094FB9FAD17F4D2A1ACE0D03613588155AACAA2D1CB4E16DA9
                                        SHA-512:34D2C0929FCC3CC10D0A2121BD55BFA9A07062C2A7B8F101071164C946895DBCB2777641E79DE4193D57A3F0778DD4F1351FAF333B7E4B4DBE31A32DD69C51F9
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................<........................!1..AQaq"...2B...#Rb..r..$3CS.cs..................................................!1A............?.............u....p.p($.Y...9,j...V.*..S86yh.G.#m.5..9...6Y.."C.R:.[..-.7U3c:..].;.....f.?%..<T...&F.Lh.N...m]..x.D.g<B.....k..S........>j.K....#U..Z....<e.:..8....o..xq.[..4v..U..y...k... k....A#..A...pn.jJ.I.7:..{.b..ns.t,...8.Td.I....m.I.5Z.).-.. ]..X.Do%.....?..4jV.`llt.E...5...u.|..\F.=.F.r<...5dV....xc.%..&...4,...f...3..H.<......eQ...P.J....7...lLc..?..-.fR..7.#.6.......}:.]'.ny..........e;u.Y..$0...i..-....f..9(....}..T,.Inb...+=Cca7....WULA1@.s...4uY5.N.f.c..].ks.....3v..~..k..m)...f gNE`S......#.....Z..6.uc.m...#k.s.f*.l.$6..?..xC.Cm.`...N2..&H...._.&.E...[....f.Z./...!.a{K..#.V.5..v.B....1...9..B.&....%s.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 650, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):647
                                        Entropy (8bit):6.854433034679255
                                        Encrypted:false
                                        SSDEEP:12:6v/71rwqZMXVs99W1YvpLp/Fvl+f43ocLtuplb+CrGotLRd:+wqWXVs99rpLpNvr3pIx3b
                                        MD5:DD876AA103BEC3AC83C769D768AD39FB
                                        SHA1:1833603AA9B6A7E53F9AD8A336F96CCE33088234
                                        SHA-256:1262DD23AD54E935CFA10FEB1BE56648E43BEF1116696CA71D87E6E033B1CA7D
                                        SHA-512:946DB2277213104A3B29EC4388578B05027B974A3093B4CCAD8847397AA51AE308BC6A199E5705E1F901D6E4B1BA34D8DECFD6E5B6685184A307D749D7CFAEDD
                                        Malicious:false
                                        Preview:.PNG........IHDR...(.........xk....`PLTE.........................................................................................>.S.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.)..1..7w....6.*.H`T6.ha.k.............b!....Ba..C..P.4K..@.....h.E..X....PX+.P.-.....@@"...o.O4....xZ<...B...B..,A..y.s<......b!....Ba..C..0_p. .......=..,...i. ...=.j..N...........{4+...xZ<...B....|.....$.K<.vyE..X....PX+.P.-.:... .'p......\,...i. ...=.j........K.....%J..S+.....q..k.H.@DD.s...:..J.K.DDL.\.@`,.DD.:.(]..N....KD....A M.....F..S+.....1.sq........\.t..;..../...~k...4.DD.:..]..N....KD........@DD.s...:..J.K..[...Q....V......IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 39 x 579, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):515
                                        Entropy (8bit):6.740133870626016
                                        Encrypted:false
                                        SSDEEP:12:6v/7su2/c30mqkg9VgFHe7Ll8UmJX/N+1Zmkk8f3lbtI4:4mc38gFHe18lkk8f3lbth
                                        MD5:E96BE30D892A5412CF262FEE652921CA
                                        SHA1:8190A0BFE21D04BC6F3A406E91B87CA69C03A2DE
                                        SHA-256:0E31DA4DFCFF4A36C64C1CE940362D2309769F36369E4C43C317D5F2FA15658E
                                        SHA-512:D647F51ABBD013226A6ADD0D551D058C633F867F9AF5A9E099B85D6E291D220F7B85958B07381CD4C7C4F72356DBAFE2A86932AE398E28C56CDDF0744E92EE24
                                        Malicious:false
                                        Preview:.PNG........IHDR...'...C........b...`PLTE..................................................................................................bKGD....H....cmPPJCmp0712....H.s....9IDATx^..I..@.C..<..?mo.#C((.J}...~..B...b.I.i.\<.e.....(p.I.EO...q.x.......dRz....K..b0.:.<c.o..0.x\:...F....I&..ap....."P@....DO...q)p*..@Y.CL2)=......1.........4....._.G..^`..lDO...q...X....SL..z....K..#.L#..I6..ap.Ls.,....7&..ap.p..lI...,GO...q.....k.n1..4......3=.f.x.$..4.....o....x.$+..0.x\.,&6...............IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
                                        Category:dropped
                                        Size (bytes):12654
                                        Entropy (8bit):7.745439197485533
                                        Encrypted:false
                                        SSDEEP:384:JheN2cq6MLu6MLGu54cHeNzhcmhcDu53eNE3UPkhrxvu:Ji2Wix7fzVsbE3Zm
                                        MD5:4BCCCDBB4273ECEBE216C84930A8D0B2
                                        SHA1:FFBF617787E27BC94D9BAF89F2FE34A2BD42794B
                                        SHA-256:474F9A8C25D5E21192315397EA995B1E11E2C1608157C6E0277688091BFD136A
                                        SHA-512:DAD73A8C0E293B88685C0C71EF15E0DC95EE39B7FC9F849DE5D634173FD9FA0AF0AA96742D9E94BE03556AA4A817D5001C95A6736EAD5D5DF03661876785EB74
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................i..............................................E.....................U....V...f..ASTc.......de.1Qq...!Rb....Ca."r.................................B....................b....Ra.....!Qc.....AS.1U.."C...2Bq...$#3%&.............?......3.....~......:..g..s"......:..g..s"..ic..Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. :..f..h.....Vk.f.. ..0...Q_..X..V5E~..c..X...@u...cTW...0...Q_..;.m.....@w...Q.+....*.4W...lUFh....v..._..wn...dW....y._..v..E~...*...@wn...dW....y._...v..U..@wn...d..{`;.|U.2g...*.3...:.0?ViN.z.@w...4.M.:m..`~..i7...q...I....J.`l...W..n..PQTiB...6....+..sj.*."...6....+..WA...x..A........(.N6`..AD.q.....'S...t.Q:.l.......f.]..N..0.. .u8..A........_W..Y...}.C...~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~....&.E~.v..?U..^.r..}..Bep
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):53259
                                        Entropy (8bit):7.651662052139301
                                        Encrypted:false
                                        SSDEEP:768:dCiCBBenRYWDBCipMYGTbYGLHbXxoP/qEF+MU50qyJ30h2W474S/Aq/xc4674bi5:dCiIQXBCiwbDLHD0/sFyVel4Pi4UgE
                                        MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                        SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                        SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                        SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 39 x 600, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):2104
                                        Entropy (8bit):7.252780160030615
                                        Encrypted:false
                                        SSDEEP:48:2PPEOtz2P/LJtVRaqBG8qFOPvHlcEXgkuwf+j:2PZFSjJDjqFOPPlXgG+j
                                        MD5:F6C596F505504044DF1E36BA5DA3F09B
                                        SHA1:BCF17EC408899B822492B47E307DE638CC792447
                                        SHA-256:EDBB86F160050FBF1F9860276802BAE292DBFD0BC98E3EA90D43D981E9F0C54A
                                        SHA-512:E8D067A1932CED8746FE7D665EEC34EA92A98AFF3DF26FFA9DD02742DDEA3C5654124A88A649FA33DB596F96A5FC9CB2C693D03132F1C8B254ACB56DB4763BD8
                                        Malicious:false
                                        Preview:.PNG........IHDR...'...X.......:....PLTE.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................{.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^..c.%i.F...m.m.f.m.m.m{&....X...9.....M.WUW.d.N.O...E$...$...)H....n....N.k..v.....v1L[w)w.}..!...Y.X.V.D.......[....;..[..;....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 556, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):977
                                        Entropy (8bit):7.231269197132181
                                        Encrypted:false
                                        SSDEEP:12:6v/7QiFJaY/z+obuqFA4fypjQSbtBK+lcqNGSbb7XTJArRRzN5DjNRkPmu5cCbR2:x0QY7xbjy9pY0JPXLTWroeuCCbX0
                                        MD5:B7F74C18002A81A578A4EE60C407A8D3
                                        SHA1:70A7D4BB1B3ADF4397D168AD0D81B286F88EBDE0
                                        SHA-256:95F59A0433050180D4C0E8858B83363D51BEA6752A8B7CA516A8677854D8F5B6
                                        SHA-512:13186A7CDCE80BCA9D2238666D6D7A989FA1887EABFA5D8A9A63EEC304DFD4BE8EFF652205FA56E1D1CEE7D3680AF8C70A952AF73AB3C246400E8D4EBECBDBA9
                                        Malicious:false
                                        Preview:.PNG........IHDR...2...,........A....PLTE...................................................................................................................................................................................$.y.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^...0.D_.......cck.....%a...X.a0Y...-..!.G...[....(.r.H.$...1 .zq.4V.e|a.6.X..4..kl.%....=w....6..TN.....{.4..T/.z...../.....3..!~..t.#b..^.....E!.SFb ...-.....^...,..C.!.b...i._c...s.X.w.. lsQH..H.gKc@@...i. ....m...;Ci....@G.; V{..lO..\.R9e$..{.....P...E.+.2.0D.B,..P...56.?......K.6..TN....^z.4..T/.z...../.....3..!~..t.]b........E!.SFb ...-.....^...,..C.!.b...i._c..Y.O...?.9k2.M.?5 .n.P...,...d._..%M?....6....,.1..R.4.a.R.+..U.Q..P...vd..T........j .]@....."..lJ../.90.4...Y. ...9.%...{......Hc%.....i..%M?aG..H....o.q.......4.......X.d9.r..CI.O.5.Ri0?.s\b....w...>/k..4V.)Y....P...vd..T........j .]@....."..lJ../.90..2..MP..l..?....K.X.....IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 171 x 552, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):10056
                                        Entropy (8bit):7.956064700093514
                                        Encrypted:false
                                        SSDEEP:192:edmu1fpj5DVHuooK4EpGLbAdT+dBXYBR8D1V2p6KwoPR6KUX9ojwRpgA:2Pp/B4LbAF+dBo/1E3S6JScpgA
                                        MD5:E1B57A8851177DD25DC05B50B904656A
                                        SHA1:96D2E31A325322F2720722973814D2CAED23D546
                                        SHA-256:2035407A0540E1C4F7934DB08BA4ADD750FCB9A62863DDD9553E7871C81A99E3
                                        SHA-512:BC7DC1201884E6DAFDC1F9D8E32656BFAEE0BB4905835E09B65299FE2D7C064B27EAA10B531F9BECF970C986E89A5FD8A0B83F508BBA34EB4E38B3F7F5FC623A
                                        Malicious:false
                                        Preview:.PNG........IHDR.......(.....!..t....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................4.....bKGD....H....cmPPJCmp0712....H.s...#.IDATx^.w`......$..B....... ....fz5..6`l\.8...Nsz{.//y./....{.7}g.....e.....~.......s...f.....%c...6....O.PJ...Y.oi...9..'j.2..6.-
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):53259
                                        Entropy (8bit):7.651662052139301
                                        Encrypted:false
                                        SSDEEP:768:dCiCBBenRYWDBCipMYGTbYGLHbXxoP/qEF+MU50qyJ30h2W474S/Aq/xc4674bi5:dCiIQXBCiwbDLHD0/sFyVel4Pi4UgE
                                        MD5:2EE369ABB7936F8C28FF0ABDD224EA05
                                        SHA1:FE9D304A7B49E31EAE439369ABC548E265149636
                                        SHA-256:FB12D59B8BE911247BBAFDD416852E8B74B028005A141CB4DBBBA109B4B6ED2C
                                        SHA-512:5CF396CA472C32AE988600176114106CB1619404DD899A3867A5AB43DC90583B771EF69B14EF50E56A21F038BF51D8463C6ADD2DE9D4CB523F6290E24A4DECB3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!1..AQa....q........"2..R..Bbr..#S....3$.....C.4v..(X.DtEUV.....cs..Td.5uf'Wgw8Hh........................!1Q.Aa....q.2...."R...r..3.t..U...B#S.4ub..C$d.5Ee&'7c.D%sT..............?.....?...k,lk^...M".Yo5.Qp.&s}b.m.:...W.x}.*.a......N1..d-n.-..^..b..TZ.W..."....F....^......ve5...^...2.:i...........~u2pK.z./&..u..L[I....Y....@y{|>..MN=:....Q[..H....a........|%..4fV....).....^.9b.f...F...p.=.W...aZ.........Z.t.n.....z3..[..lVh..\.N-.._.sK.y.._e.G.jig.a.7^....u...*.p.5.a.].........u/u..D.yl.XA..f.z..~.x.....N.....b=.uv.2.t.'.N.-.H..n.v.a.A[.Z.....T2...._...:....h..l.E..sm..a.3I...RE...fWb.Ek.0.#.)..Y#T...........u{....U....s.].7_H.2.`O6...P......}..4LR....]4.mid...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):34299
                                        Entropy (8bit):7.247541176493898
                                        Encrypted:false
                                        SSDEEP:768:BrSX4V3P8AIc4KLkHeXRUer0zrhOmXfvG0yH82I:tSXuIc4K2eBtswKsHg
                                        MD5:E9C52A7381075E4EBC59296F96C79399
                                        SHA1:BE295AD24D46E2420D7163642B658BF3234A27EA
                                        SHA-256:D56CEFE9EE2FAE72E31BDBA7DD2AA4426EA22E3CEB22EF68C8F63F9F24D5A8BC
                                        SHA-512:95CC96DD4459EBAE623176033BA204CCDC50681A768F8CBAE94C16927D140224E49D5197CAE669C83C77010C5C04C1346CF126BEF49DB686F636C5480342A77F
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.......................................................................................!.1..A..Qaq......".#4.2r3.$.%...B.5U&6....Rb.Cs.7..cDTEFVf'...S..dtevw.u.........Gg.....................!1..AQ.aq.2....."#3.4....r..BRb$CS.D............?..5..............#....v.q.m.}\..{....;...r....h.....J..q|..'.;\..6..v......e...../.k..|.8..i..|..]..3e.m....n..Z.GS..n".y..w.-...[a...7A.....i.4.)9\..~C...=.........s..\V]c.D1<./.g.l.&v..~.h..]....zb>G..y:vNS.\......LU....t.{*..Z#.?..v-...wn.rR...P.....y\=.v....../..9_...m4...V.|.+.o.#.......xj....}..>.s.>C...m.[;.>.p...=^.i.X.(..1...{.F#N.W...xi.z...4..u[{...yO.....8..}\..2...KlX.nbya...2.&.F...R.b.k.7.GV.x.h.y\.Q..O<\>......-...=...r......\......Z.Z...Jf.'....z..Y.q>.p....o..K....h..R..c.lg?......A.Z...Y.q3.L|.'5...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):95763
                                        Entropy (8bit):7.931689087616878
                                        Encrypted:false
                                        SSDEEP:1536:EoES7mhTyzabUaE77xAOmq0zVruQlttNxlipxVWssMU2YhRy2v6pKKYhQzwMc2:zz7mhTyzabUa4b4xuQlttnlGx8x9h02M
                                        MD5:177DD42CA99CAA2CCBF2974221680334
                                        SHA1:35FD86B3DD082A6D4930C67BC0E05D3B5817465A
                                        SHA-256:525A857D0EDA855A64D3619DF58B1C2D013A73E60FA0D49B155ECFCB2C134C7C
                                        SHA-512:6FB6D9A6C97B1115C3246690A2F339CD612899AC25ACBA00296EAEAA0A1D094E7339D670969764FE23EB7C08FCDD01C6F78FBC0735D504D5E02AD342901719B3
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!..1AQa...q......."...2..B#Rb3..r$...6..C4....Ss%5...tu.c..Dd.EU7....................!.1.AQ..aq......"r..2...4Rb#3$B.Ss............?..H..dV....U..-..0]Cp.%O.Z.Y.e.=/.q.....j76.w@s...5.&&&5...n..w..>.1....;.vR..[.......=.......KtY]u3.g18...).r....&.IZ'.....g..4kY..X..b.......y<...r1........e.._...X...w....op.m%Jr31...S.Vo.._....OI\]....F..V-....\...2j..X.....y.p.$4.....&#..]..n.V..x..P...F..C.f....])..~..Z\.....,..#..v..v...2V.k.SuaydO../[.*c._..oTV<Z.s.[...o.x..>....-....v...#....-.X..L.Z./#.XG.-.0......%w..H.@aZ....C.}...N~.;..R......5.D......I.... .R........s.>..ks....(...S...9....2=. :^.. p.+?(....$..Q..I.........=|..`2. v..t......U*.8.u.. ...'...*...2;u....& 3..$.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40884
                                        Entropy (8bit):7.545929039957292
                                        Encrypted:false
                                        SSDEEP:768:MCBOA4d+ElOXJ/3pI7cRBiL7L6qERqGz65WXzZqJsKQSbIsTT6XB:hIAU+2cGdLX6qBG4WDZl4Ihx
                                        MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                        SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                        SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                        SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
                                        Category:dropped
                                        Size (bytes):2898
                                        Entropy (8bit):7.551512280854713
                                        Encrypted:false
                                        SSDEEP:48:N9YMTXc4gpw+EIWnqQ5G+NE9VTzRFvS4+Xh+AKrNx+JuCluc3Eeky8etajhDCFex:/hDc4rPIoNEzbS4+XhOrGJu1cUHeoVey
                                        MD5:7C7D9922101488124D2E4666709198AC
                                        SHA1:00CC44A1B84D4D94A0ACE8834491EB5F65D04619
                                        SHA-256:20016E5FA1A32DCE5AF4E92872597E36432185A7BB2E61C91F362BD68484529B
                                        SHA-512:882944B2CF040485899128E03B7499C540D481E45FE8017DBF4FE0330157B2D8ABB7334DDB31C112BA0EFE3722A554883917C54155A7F60044D2D7F3D848260F
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......k....".......................................2...........................c.....TUb...Sa...QRqr..............................!.....................Q...R..!..............?...$.)m.1...%%bV.J..H....-.%a[...I"WJ..:.X.:TT.$.......N.-NR.E..-NR.E...9..E....$.k.....B.I,I)..J...kr..+)..I,Yj..YbI..+,J..e..Z..V.e.$V..TV.X..V.YQZ.EQ..U%PY[.[.R.EP............................| F.. ...j*...!m.!j.I%.j.$...YeEYYEEUE..eY[.hEEUeEil.....%..el...V..TUYA.U.UTTUT.Z..UQQUQE...V.,...UlE.U[.lEP.P.@......................................R1...AR1m.....#..$:.T.p..IJ.t.....A..AH.,5..]F!a.XJFaa. ..a.!*.aa. X.e.......bB.b..,HX[,!..,,.c0.,..U..X..(,,...B(.,..4..B.`..".a..-......"...........................>D..IKEb...t.....)u.....)K.%+L\.J]i)*b.JR.IIL\i)u....T............T.....qs.it.iJ...])ZJb.....X....U.A...V1..B.R1....X...,.c...,%X...,%#0...,H
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 600, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):4410
                                        Entropy (8bit):7.857636973514526
                                        Encrypted:false
                                        SSDEEP:96:E/pQuIhKZ7u06dICH3AroiTe8DGTl55poBUmLNjpH7MvDHjfm:MpdZtPbknnRPpkLNVMvu
                                        MD5:2494381A1ACDC83843B912CFCDE5643B
                                        SHA1:98F9D1CC140076D1AE5A9EA19F47658FD5DF0D66
                                        SHA-256:5EEBE803E434A845D19BC600DF3C75E98BB69BD0DE473CEEC410D1B3A9154E28
                                        SHA-512:0E64CC3723DC41D94910F7ADFB6A0DFB5049350FD15A873695614E4A89ABD78B166BA4E9C8CB95E275FB56981539DECD2A7F28FBC25E80DD5E2DEA8077CC9489
                                        Malicious:false
                                        Preview:.PNG........IHDR...2...X.......E.....PLTE...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................B..(....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.].\TU.?3"...(..L........q.Q...H.*j......W..Xd.ie.f..%.XT...em..m.m.vkik...>.}..}|..{'.U..~......}....s.............,CVu.x.:C..5...;.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
                                        Category:dropped
                                        Size (bytes):11040
                                        Entropy (8bit):7.929583162638891
                                        Encrypted:false
                                        SSDEEP:192:u99+91V42ho91V42ho91V42ho91V4235z9pUkDCyixxo4PS6b8tEy3BcWWhhSy0b:ubKD4/D4/D4/D4uzX38u4PNYJ2zhhmb
                                        MD5:02775A1E41CF53AC771D820003903913
                                        SHA1:2951A94A05ECF65E86D44C3C663B9B44BAD2BC9D
                                        SHA-256:83245F217DEAE4A4143B565E13C045DBB32A9063E8C6B2E43BB15CD76C5F9219
                                        SHA-512:5A1FCC24BDD5EE16BC2C9BACF45BCECF35ED895EAC22D2C4EE99C1B7E79C8E8B9E5186E3D026BA08FF70E08113F0A88FBF5E61C57AF4F3EA9BA80CE9F33410E9
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................v.E.............................................S..........................Aa..!12Qqw.....3568rv........".....4Btu.....#Rs.(W..bg.................................D.....................1..2.!4Aqrs....Qa......t..."3BRb....#.$S.Cc..............?...K/h._+.N6.-.a...5...;.r....,...0B.s(..zp..4.%r|q..E.Q^.../...C.R..?u.q8XN.>.e..:..gJ...._.n>.70G,..(........3b.&.5m...Q../...7Ie..k....e.l6..&..`Gt.P.Y^r...=..Y.e...N.B...O.#..J+........u.V;G.'.....V.]8..C.]..........E.....c..w&lX..f..\T.J?...F.,..m|..93........,.....+.R..WG...%.....(@.....p].iEz<.8.^...J.h.....a8P.1......(z..y~.........H.Z^.>..<.....L.k..IG...R.(.%..m....&u...B|.....@]ey.W.J...!d..R.8...[..>8....(.G......!.)X.....,'..F2.Z.t..Aw./..Z..#..i.kK.......b.i...qR.(....RE.............O.XP.#..(...9J..]...,.2.[w....KrW'...tY.......{~.:.+..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):14177
                                        Entropy (8bit):5.705782002886174
                                        Encrypted:false
                                        SSDEEP:192:EbgGcV/hlvpfal7rgYa8S7auAxwfuSTmCSNoFQ6NO7L:EbgGcVnpwimnd38FdQL
                                        MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                        SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                        SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                        SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):136726
                                        Entropy (8bit):7.973487854173386
                                        Encrypted:false
                                        SSDEEP:3072:SIXmy5Tl704vW2ZKkvV8UU0ZWUF0BJwySIdgz816YzDc1+opecYPn:Sny5Tl704fZFV8UU6LGXwyS4xohpQPn
                                        MD5:4A2472AC2A9434E35701362D1C56EDDF
                                        SHA1:16FA2EA2D2808D75445896E03B67A93000EEDDD8
                                        SHA-256:505F731CB7707EFAB2EB06685B392DC7E59265A40B55AAE43E5DC15C0A86CBA4
                                        SHA-512:5E28D8FB2AC62ED270968072A30013334461F7CAE96058AF9EAA6E10912989DC47112D2133892BF61F7A516B77C6FF71BA2A000B750A9F95C787E538B09595C2
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQaq".....2B....R#..b3...r...C$...X.....Sc...9.%'.(Hs4Dgw..T..5GW.x.)......................!.1..AQa"2.q.......B..#c........b6.Rr.3s$.&..S...C4.%5............?.........(......(......(......(......(......(......(......(.G/.GE&...)..P.x..B.({i2Y;.z?G...Yfc.)H..^....#.....}3..Sc^.H..+...M.a.P.....GS.....H_.3..<....1f........1.<.\..nn-..s.s.\9Y....=.......S.0.......N..cA..Io..r.3..........ay.....K.....,.;9..Q......xO.Fa.2..>........{4k.....|....?U....3.8..._/3....#.. t.y......yY.......e.<........#.....B.....Z.%.Y..S.ye.W4...l.......X...%.@y}>....l.yi..D..W......L..._D.Q....)...E....n.%...*..K.4#.8`..I....h..h.o..I......-...hB...3..u.(5..........n...,.@....a.t.9.....@.s.>.&...@
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                        Category:dropped
                                        Size (bytes):27862
                                        Entropy (8bit):7.238903610770013
                                        Encrypted:false
                                        SSDEEP:384:LTawAZvhbrXzDc6LERLQ/b5vXOl6pXQ/wD5OUMrdRUUhCplQg0ESSz:6wm/vT/b4wxoqbdUhWnSs
                                        MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                        SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                        SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                        SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):25622
                                        Entropy (8bit):7.058784902089801
                                        Encrypted:false
                                        SSDEEP:384:EhK81gTCyJ/Gf9Aw3t8w8EtdPeGDh6bEi1Ie1u4ZbvgwTwrSRh7ZKNpIGY:IjcRXwdJvtdGsUbEi1IeY8vgwTyC1+Y
                                        MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                        SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                        SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                        SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):84941
                                        Entropy (8bit):7.966881945560921
                                        Encrypted:false
                                        SSDEEP:1536:X3sWfhTVd+xu6rA6SOONM0/YFXnviDwoPCaNSm+z/ze/fWNj7GfigeKyCGzw+QKW:nsOhdDJOwY1voPCaom+z/zeHAfGihCG8
                                        MD5:CB84C108A76C2AFFCAC2551A3C1EAD56
                                        SHA1:8BB7C2A12B056C1ED12EBBAE5BC9F60CCE880FFE
                                        SHA-256:139BB0E79F89C3DDEF79B1716A5FBAB4C07DF5785FB3CDF6B4EEDDBF6C078452
                                        SHA-512:6EF85144E9A7ACD0FF2E52A5FF42093153EFB69127B1C8549EEBC49B6CC196A46B65EE39A2CAD0206F6A41476D8B5B35D29EAC9942B8F84972B32E14CAFEED27
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d....................................................................................!.1A.Qa..q...........".2..BRbr#.T.3C....S$.cs.D..4%5......................!1A..Qaq."2..BR....3...b#.r.C4.............?.......m.q..'O.....r......_.1....8h....?.....O]~..k......GO...''._...!....o........''..g..H?k.......1...?.....z......>...+0..................GO...''._.........}.O.Z|.L?...........?.........[~t.......}......NO.....v.......J.......?..g..H?k......GO,m..r}o.z.....}......dC.9?..g..H_..........?.....O]~...m...C?.z..f....W.=u.B..m..C.-?.a.....3._.?.......o....np.M....g..H_............9?..g..H...../..kO...''._...!~...o.....0.M....g..H.........../......O]~.~...o.......7..+.... ..l?.}........&....3._./....?.........W.=u.C..m..C.+?..o.W.=u.A.^.O....:......_.........}..t
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 623, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):1569
                                        Entropy (8bit):7.583832946136897
                                        Encrypted:false
                                        SSDEEP:24:KArPoy/sSfmBL0EGEsRgeTLLXFnViAAEslVorlP0i8OmO57EnGAkYelBKMN:9oQPTgeL5ViAe8rQs7HAkrlc+
                                        MD5:07DB3F43DE7C1392C67802E74707DAA6
                                        SHA1:C173ADB1999065C5E1E6DBEF934B4D4D7AF0CC23
                                        SHA-256:51E05999A1C9F17DF28CB474E57DD8E64BDAB824874A532C20A23766A01F8967
                                        SHA-512:E509255519D4E521E82332FF418DD5A6BBBC8476399A0D9C3D81542C1CABA535B2D79E5BC90F73F9EE8468643302137671934ABD600FC696F16161C91FEAC111
                                        Malicious:false
                                        Preview:.PNG........IHDR...(...o.....>.c.....PLTE................................................................................................................................................................................................a.o.....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.Y.. ..........}%.../].`<..y....V...m.....<....)..;Ki..'9...2.:.c...t..V..d.t;-y.Z.=K>B.."{Lj.~G..|..ENC.!Sw,....";.p..g....E.B..S.-...k..P."..E......l[./D.-.....Q+.G<>.+..b...#..y(...{a.M..J...<....v.W..F.qm.`.....(.mk.nX....l.Px8.0\Z....7G...$*.....&..Z.VJ.~......J.2|...2H..../...=.)q....ZT" .,%..h.p....Z$.!........r...Hh.f. ....P .d..1d....2.3h....;.A.... ....d..g4...A..^.....2.ew..."h...y/..j.h..B.......%.2.%..{r...+dG.=9h....P1...A...c...^h.]Q0.8x....q .!3....ZW"Z.!3...G.vC.GG..".&..X!3.|xB..V.P!.+zS..NX!3.....Nh.y(.Z.1.h..B...Z+....l8Xcu.B...K...@U..@Q...mB...x...&L C....mB.....@kC...Y.,.... ..e\F.B..........y..e\..:$(....Z.a...yn...f..z.~Q.{o...].ln.r....^.@.{..c.7..{...
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):55804
                                        Entropy (8bit):7.433623355028275
                                        Encrypted:false
                                        SSDEEP:1536:gVvci05lhVbfBcWvBLeynluexaWqzww/u5:gVUZhHDljaHww/u5
                                        MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                        SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                        SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                        SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
                                        Category:dropped
                                        Size (bytes):27862
                                        Entropy (8bit):7.238903610770013
                                        Encrypted:false
                                        SSDEEP:384:LTawAZvhbrXzDc6LERLQ/b5vXOl6pXQ/wD5OUMrdRUUhCplQg0ESSz:6wm/vT/b4wxoqbdUhWnSs
                                        MD5:E62F2908FA5F7189ED8EEBD413928DEE
                                        SHA1:CA249B4A70924B73BDA52972E9C735AEC35A0C5D
                                        SHA-256:20ABE389C885E42B6EBE9E902976229BB6FD63C8C34CB61AA70B8B746209F90A
                                        SHA-512:EE8D1821A918BE8714F431895E7223D08036E88A4FDB9A5485EFF246640EE969A69A8AA4E2E9DDC35BA75FB6D4E95092A286E90B477BD6998C313639C2C31F25
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:18:09......................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................!.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..P.v..+..n(a..Q..S\6....Y....D......} w#.b..]l.5.RU..k...... ]$.$.........f........?.z@2uU...7....?..|.Q..I.&.. ......"T4)wdH.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):65589
                                        Entropy (8bit):7.960181939300061
                                        Encrypted:false
                                        SSDEEP:1536:2Hlrjw3xL//DPgff+9j6yPWvHMHjkbfnwHO3AW3GL:2H2zDUU+yPVHITwNfL
                                        MD5:8B48DA9F89264D14B83FF9969F869577
                                        SHA1:E1BD58E2D80FEEF56DC514F3F0B3AB9669F22F95
                                        SHA-256:62AD3C277E54F03F1ADB44062407346F789E63859B7AFABFD64BE6AF5E9F66EC
                                        SHA-512:03B783EC968DF3F648504D068D64DD1AE110E28110FE5B3401C9D04F44897DBE0CBB5680D42CA4C665FA94A6CED4B559106EB3C06C9BF2C5B14951ECBFFAC8AE
                                        Malicious:false
                                        Preview:.PNG........IHDR.......{.....;Za.....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..Y=.+I....t.y...,^vv....;. "|. .i7.....$.2g..']pH@p..]b....H.H.......d'@ B...U.xm..3{3k?..5n.._}U...3......~..>...g.....f..t...t:...p>..Si..d:..k:.Lf..t6.K.i....d<...x.8\.8.+lc...)i.$.r.....x.t.BG.R.cm.c...p.:&.6.4..K.......^...~b].0....oBYv..u.'.=.K.Q.g)6.....4.!.M......4.=....G.%.Sr........nxC.F..t.U........1...J.t..eQ....".... |...81.$D.!.>...........$...^.vY..EY8tb..'.P.g#O....S*..0'.V....x.W..........k.......s.C.S...J%.iVb..].........3....j.}*.z....+.s..@..K.....\x.C..e.Qq.....;N.....;....,....^.*..$F..{G...8.#....8'..&....8..5.....3(P._....S......|".....u.cr....+a-....&V..x...iI-<|a.{E.c.X.......?..&.C....'........(.x....>...M.?.9..#X......l...0...Z.F..<.z.0}Q..Z1..........?h..`E$K.2o.A*c^.......*..D..uL=.}.#*0.. M!.A.C......|_..(.Y........!E... .O...`;....M+..x.u~g...q>...N."D^..K..x..D.`.!.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
                                        Category:dropped
                                        Size (bytes):22203
                                        Entropy (8bit):6.977175130747846
                                        Encrypted:false
                                        SSDEEP:192:5q3R1VBvq3R1Flrk6Q0QPJJrR39joOVMJ25d1NkMhIwobbtAAAqYnLJZMJYZ2AC:xw6Q0WJR3FoOVMJIIlAAAqYnMJdD
                                        MD5:2D3128554F6286809B2C8E99DE5FD3F6
                                        SHA1:FC42CB04151D36F448093BDEFE33031A9B8D797D
                                        SHA-256:14FA2D16310485AA1CE41F6D774A3D637E8CF8B03C4F72990155DF274FDB6BD9
                                        SHA-512:D8531247A6E89ECABEA9C4A78F596CCE3493334EDF71AE4F7998FDDD0F80705948609C89756AB56FDFAB6D04DEC5F699A693801A772CA2EE2465BDD2CE5D2D5A
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....XExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:06:24............................&.........................................................(.....................&...........*.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...H.....Go.Kxn.b..g...........%?_....O......q......7G......%%.V..8zm.].v?...jJ~._..>.......O;........o..rI.A.....n.a.........
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
                                        Category:dropped
                                        Size (bytes):59832
                                        Entropy (8bit):7.308211468398169
                                        Encrypted:false
                                        SSDEEP:1536:HS9SYFtN0+CRa9mfJy4zBAiIJhzrkHDV2hJK:yAmta+Tyy4zBIJW5WK
                                        MD5:DCDD543A4E0BA2C1909BA095D46FFBCB
                                        SHA1:B86C89537138FE07255354202D3EAD0B53B3C54D
                                        SHA-256:28F334B77068F71F5F92A95695433B950610204A0E5580CE567DB8FAD4993ECB
                                        SHA-512:5408C3259B7F3288A4BEB04342799AD5FE3A6F0EC7E92353B29B7E7E538DFA9903B39637226919E0421BC422635D25F5F8069DC7441864DC03E1B909BF5C2C84
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....fExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:08:07.............................S.......................................................&.(.................................0.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................y...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?......;R~+'....xh..~.n-}.......Te................^B..IU_....._...S......h.......!....9...A}6V=J......C..c.....Ug.Wh......
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):52945
                                        Entropy (8bit):7.6490972666456765
                                        Encrypted:false
                                        SSDEEP:768:cjvqR0XvFaGCTJffi0tgybmWDoTw71kHUAnjvawrlp2+NUO8dWSNl3PF2PjK/q09:cyRffflgybmWoTw1UUADHUbU21MjpAD
                                        MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                        SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                        SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                        SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40035
                                        Entropy (8bit):7.360144465307449
                                        Encrypted:false
                                        SSDEEP:768:MQhziQo1RKGlyyzYjlxuxwRUj/BN837xRmwH2uDTCn8qXFQziN:ThzrSzalg6O563l4uTC8q1Ig
                                        MD5:B1DDD365D87605F96D72042CB56572F6
                                        SHA1:ADF71DAD1A62B8A58A657C2EDBDD665A19EB846B
                                        SHA-256:06E09DE80C3F32254DA4FE6B2CBAD7C05EF144DD54B8C65745E195BBF7317A2E
                                        SHA-512:9C686092CC9524F34EA6CEC9AAE936A6225BCC54DE38DE1786EBA8F532959A80FF885E8664A09E4C318D7CA4B278E807D3D1F135BE55F30979B844FF5EC9699A
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!1....AQ.aq.....".3.5...2B#s.$%..Rr.CS4&6...bE'7.c.DTtU...d.eu...VFfv.Gw.....Wg......................!...1AQaq........"2..4..Rbr#3$...B.s5Cc.S%.D............?..^.f....R*.N{.{f.....O.r.V.;U..~...U.(..>M._.yI.{8,..^.t...s`...j.O..U5t.&&..h.G.6Da.;.....J.......E..QD...C...}..N...tR.....~..].J:.V$.*.r......]...W......4.[.)6..Y_.....4...........m._'HR.a......]U=.....n...0.W..]..K..){.+...w...f...<|..1/.|.....b..-..y....]U#Ctn.7m.._.|..2I;|....tM....q.q.}.N)....'...9&...nR...R..}.........m._.LZ}u.../K....9.~..?.{....V.#..dx.Zk.:=..:.j].....E#....E~w%....J..[S..[......gr...vb.r]..<..ut..i...[P.w....:..Gkn>......#..m...9km`......t).up.....w....VOR.{&.nQI..}...wD.7Ey#n....MO.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 176 x 513, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):11043
                                        Entropy (8bit):7.96811228801767
                                        Encrypted:false
                                        SSDEEP:192:YyroOCsBI9pkCFsHHX2RE6VOlPuIqmBtJNBfAr+ADP1IATaNeTyZ4GF+WQQ6Qwq2:BUOCsB2kCGH32RiPDtDBfArPDP1I/eyM
                                        MD5:8E9AB9C28B155A66BC5C0DA5E2A4EFB5
                                        SHA1:972E61F162D48F1CEE21963ECBB2FE439105DB55
                                        SHA-256:B243A24FA13BC8523450E22F408F9EFF15301C938F8CA52A57018B58CE6785DE
                                        SHA-512:12062D69E676B3B34AFCEF25AC17B40294282D5BAB6C0110680293D7CC96EC17EBCFE104C284E64A30EE3C483E319E9C37C03F6EE82C79632180E45C7A684E8C
                                        Malicious:false
                                        Preview:.PNG........IHDR..............`....`PLTE............................................................................................... .......bKGD....H....cmPPJCmp0712....H.s...*YIDATx^.]...,.N.8.i......0..e..y.......8.6....Fo.........=...F..._..........O..{..............3.|.L.|.............>.....v..n.1J...k...."....7........J._.5LQ`..k...._Z.W.x:..k...g..._.....u<.Q{...1...q6.cs...l............30.g...< W...a.5..>O....9}..c..........s|I.).>.fo4.<q......>...c.:.u..co.#.7,.O..G./.K.|..q.p...(.(....iH.......m..+.7...../..{W.l....b....?.`^.q.9L&.>.hN2`1..m...]$.0J....rBy......{.._...G....;.r.Q..;..,...9..F...t;.+..2.Ub......V...8.k..5.........'[..s.H..).......%j._.&.....BN..V..q...T...#..........0.E&.o7....$..m..8g.f._$..k.8...5......HgQ...L..\.........)B.I.r.(..8.a..$N.9.=..o..Q..(.e.a..O.....c.= .......$0..X.S,..(p......$..l.c.I...=."......g....^..#~,&.a9iK..ZNE`...pFJ.@Wd?.<..Bt.E.......e...i.%d...}.!..B......9.........B}.....5...;..hL.D.....4z.....|.)
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
                                        Category:dropped
                                        Size (bytes):64118
                                        Entropy (8bit):7.742974333356952
                                        Encrypted:false
                                        SSDEEP:1536:ORG4azGOKXzkEmR4bdRSbxONOoz0khbSb4J/5GZK5SWUlRwUYdv1M:ZXzGXzJdhRmgHfIb4J/5GZK5SWUldYdq
                                        MD5:864EEA0336F8628AE4A1ED46D4406807
                                        SHA1:CFCD7A751DFDBE52A20C03EE0C60FDFFA7A45B93
                                        SHA-256:7CE10D1EA660D2F9CF8B704F3FAB2966A4CE2627D9858D32C75D857095012098
                                        SHA-512:0CAA0C54C14571C279A75F0D5922F78A17803CF6EE1724D66819F7F5944C0F5B25CB586BB686A52808CDF2F8FEB3E4864052A914884054EF7DE44124A8CA951E
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:26:15.....................................................................................(.....................&...........s.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................#.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....NC+n....<.=.7..&.8A56..@^.Q..\\...E.>..".&G.......J .'....$.I)........0.../..mv...D....<v0=..ugc+..l.o...=.c.......x.&D..{`8...v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
                                        Category:dropped
                                        Size (bytes):3361
                                        Entropy (8bit):7.619405839796034
                                        Encrypted:false
                                        SSDEEP:96:zDqnxqMt6gGr/Nln5ANln5ANln5ANln5ANln5ANln5ANln5ANllHN6:CxqMQr/rn5Arn5Arn5Arn5Arn5Arn5AN
                                        MD5:A994063FF2ABEB78917C5382B2F5FA8C
                                        SHA1:BD5C4D816B04A2B6596DFE38DB01228F553FACCC
                                        SHA-256:D72900E8DA72D1A7F3729971AA558E1E9B6E9CF9A0D51E83852E567256DBBFEF
                                        SHA-512:CF2279033DD3EDFE6F6F9E5C517BEBD9A52863EEFD90F57F7A5AE0E0485E705254BE7ED6B50E6CA142669687727AE85E2E6035F69930B75F2E6D3EEFA961EF88
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.......................................................................U..........................................>...............................8H........59...$%&7F#'Ddf.....................................>.................................58EG........!#124$%&ACFbcde............?...n.p..v..a.~.._.>......#....8.....w.G...&.W...i...%6m..K;...4."...=..?.~......P..O...j.l..AW.jo..,..=d.h.ta..../.."...z|).J.......Ww._..<Wp.3+8...-5...G:..2.D..I>o..K.F;-.....#...`...6..T...M.....OOgV~..5...np...P..TYr...........b..{r.2.9..].DA.%C....=.v.z......CK."..R..l..y}.i..;.{....JzS.....~.?..Z....=c.h~*..p.@(@..G.....O.]...Hsd.xf".V]..S"..w...4e>....3*U.7..|M.x...|\......FD./.cIe.;.bId..+=...w.......[.k>....}.u...j.xZ.....Q4..+.....B....1O~\......I..h....LaXJ%&.w.<C...n/`.W..U.W.U.}~...}>..^.0.J.....@....LN.b.......5W...m].Eu...:....G..:4.=4ixx..@_0=.mab.T.U.....w..~.V.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
                                        Category:dropped
                                        Size (bytes):3555
                                        Entropy (8bit):7.686253071499049
                                        Encrypted:false
                                        SSDEEP:96:/h3JeYCQV5Hn++9HBdAjU78S/mjLLwqnqahJD:53Je8b+EBdAjm8S/mjLLRnphJD
                                        MD5:8A5444524F467A45A5A10245F89C855A
                                        SHA1:ACE68D567B02B68275E0345C86DB1139C0EC1386
                                        SHA-256:7D2B01F17354D9237A6AB99D5B9AFDF0E1CC43687125848B0C2DEDFB44CE3843
                                        SHA-512:8151B447B60D110C32EC1EF286B941FFC09B99140F41BBACF5A1650A385FF4D13C0DDB2878E9A470FC7CFCC95A1AB6E44F6DE72562B0FFE093DC8A3C3C7FCC14
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222...........".......................................2........................!1AQ.a."2q.B..#R...3C................................ .......................!1.AQBq............?........)&vD.)3Hn*..X+....r...tmL.k..(.E...R. .Z..&...,fJ...!...6..S\t3.=...g&..Bqe.)_U.....1......-..fl.................J...u.i.mU..K..v.w.0O..E.h..D~K.(..9.,8..E.}.............i.\.....t."v..q..C............<..|3.........................*Q..../c.....f.}8....D..|k..Z......0..~..c..e..m(...|.c..'.5.5............==bx.5x.8...T;....=.--.pc...I;.V.m..,(....}...NH.ho....Q..U.E$.~...w.t>.S\....'f.{.+.g._.t....;>.....P...........-..G.h..2...J.% !.E97Ir.D..N....j...oE._...._...".?.......#".S.........Q.Tc.I..*I..k.......=$.........sk1Jp.\K.....F.3.Q..q..J....N..[l.&....OR4bB|..2ul....J...B.$&H..9#j.f.n./........?R~....B.I.@..........m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
                                        Category:dropped
                                        Size (bytes):140755
                                        Entropy (8bit):7.9013245181576695
                                        Encrypted:false
                                        SSDEEP:3072:i/aDiblRsFcOco8dofE5Zx1+NQI8Wh9aiOe5NTO:mnbM+TxaAi98W3aiOwTO
                                        MD5:CC087700C07D674D69AFDFDA0FA9825C
                                        SHA1:F11113DF69DACDB255C6CBCFB29C1D1CCE40B346
                                        SHA-256:A7FA7F092EFF43030A56342C39A765F8D5CC48C7DB815DDFC8C1E5EC40117FAE
                                        SHA-512:843202D975EFA91E73287052A893584B6E5AE601F91612B56539AA2F73D1AD3F997FCAD1E711E0F483A2E91D46D9643D0B026B43F4E94116A5D2FB6551536034
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:15:20.............................\.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.......J...\O.,......../$..........OE.m.o......T....Z..l.g.-....m.?...Y....3......"....].j.X.k.S.k.....4..R....{....?F.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
                                        Category:dropped
                                        Size (bytes):29187
                                        Entropy (8bit):7.971308326749753
                                        Encrypted:false
                                        SSDEEP:768:RwjBOlCk+nYnGagKJWJhwMJiRO22ZIm4VXvXx1tA6BQs:i8snY3JW7uROlEfbtVL
                                        MD5:DF99CAAAB9A7DE97B63343E60A699AB6
                                        SHA1:B84334135CFB73BC6EF55F85926770D5AC6DFEA8
                                        SHA-256:74C131777E7C437FD654427417097BC01B0813BA8E1E50E4B937BD50A1BEBCDB
                                        SHA-512:5D15AAAA8B71DDFE01A7C0ADE16D9E1F5E9AAE484BCD711B38CCB103ED9564CAAC23A0031471167B660E15972D70179C2A387509B213C05D60261042A0456025
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................................................C.........................................................................e..............................................`.............................!1Qq...2ARa..."#.....3BSbr...$4C...Tcs......%&DUd...E....56Fe....................................H........................!1Qa..Aq..."b....2R...BSr..#...3..Cc....$%4...............?...b.d.8T1.;#.S.DO...~.R.......3.xe...z.6..."m..k...;*.'.f.5^.....m..<$....8.R.j.D.v..>...*dT..vGbt...I......sEWp.r3.. ..G...6.....w...l.S..q...b.....-R....^Zu5+u6...A..Z].:...5..Uzn.,l.L.....?%.*.S.+zVg7.=.s.Q.....8..:,c.......ZE...>'IF..W.0.d.......c.e.d.V.t..S$.DNR.[....g..#i.$. .U.SK2.....k...J5u u\R.....T.[4..A.O..,.T..................] .i...B.m.^f....._...{S.....<......:..|D...+...NA....Y.^f.1|..%K~1..B..^...S..v=.c..g.tX[..kTJ..t.gr....R..@.F....5j..2.K.9..g.1N.....*.U...^w......>+.l.v...@N....%Qd...t.Ni.....0;lggm...K".+!.,.....[J...>..?f.]._;
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):41893
                                        Entropy (8bit):7.52654558351485
                                        Encrypted:false
                                        SSDEEP:768:pZvVQkUbOHxx3pvVmO5rsP5gUdXwFMuv53knzyncaXgRDqPU:pZkijV5wScXwFMYknzucaXgRyU
                                        MD5:F25427EFECFEE786D5A9F630726DD140
                                        SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                        SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                        SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
                                        Category:dropped
                                        Size (bytes):36740
                                        Entropy (8bit):7.48266872907324
                                        Encrypted:false
                                        SSDEEP:768:3nwDxjTvoE0Rjwit4rjucDILWg7/Da0JgGQ8e1S8SA/Khos0:SxjTmZw7nucDILj77a0JgGQvScb
                                        MD5:9C205C8D770516C5AA70D31B2CA00AF3
                                        SHA1:9A1002F0CF7F92F1BE2BB25BAD61CEBFAC282482
                                        SHA-256:E111F96490755C7D71E87C88ACAEA38AFE55BB865B1A14A83C5BD239648D5E2C
                                        SHA-512:A3E105208B32831265428572B0937DD3C17B793D8611B2DA8D4939F1BEC6050999D375E3F6B87D53AD49DFA0EAE737B0141D37597AA42116C310761973D4A134
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:44:07............................c.........................................................(.....................&...........n.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d................................................................................................................................................."...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..o...4.gP.~.c...K{...V.=...].<.........vS.........s....(.t......X......kk7....~-...yF}^c.Z.\.G./.?t...>....:.>......./.ib..).
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
                                        Category:dropped
                                        Size (bytes):65998
                                        Entropy (8bit):7.671031449942883
                                        Encrypted:false
                                        SSDEEP:1536:klZtmExaFrtWgpc+Sg+DKeplHClpHfRtPMbe:VEWWl+SNDKqlH8p/vse
                                        MD5:B4F0A040890EE6F61EF8D9E094893C9C
                                        SHA1:303BCBA1D777B03BFD99CC01A48E0BB493C93E04
                                        SHA-256:1F81DDE3B42F23F0666D92EBF14D62893B31B39D72C07AEE070EAE28C2E6980E
                                        SHA-512:8F07E4D519F2FD001006BB34F7F8274B9AF9EC55367B88D41D24E5824FCE4354FD1290CE4735E43930829702ED53F41DF02C673904A7091E9354C28E029AD4EF
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:09:29.............................a.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..-O..s(...gO..@...[..+....+...H.'m........L.......@.......[k...S..O..p.'{X..3......]W..w.+.V....[.-.....2..i..i$.p.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
                                        Category:dropped
                                        Size (bytes):1717
                                        Entropy (8bit):7.154087739587035
                                        Encrypted:false
                                        SSDEEP:48:N9YMzO6BOfqH/dAIWpdAIWpdAIWpdAIWUtr/SD:/hzJgfqHaPYPYPYPUt/i
                                        MD5:943371B39CA847674998535110462220
                                        SHA1:5CA79B7BD7E0E93271463FAEF3280F1644CBA073
                                        SHA-256:9C552717E8D5079BBB226948641FF13532DF3D7BE434C6CE545F1692FA57D45A
                                        SHA-512:812541836C8B6F356A4D530E5CCF1CFDCC4CA54AF048CAC19FE86707CE5EA0F41D73C501821AC627AD330291EF58C040DFC017923A7886CEEC308048DA2CE7C9
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......-...."........................................&.....................U.....1T..S.R.Q.................................................R....Q.a............?..d.. ...............................................+A...Z+E...V+E...U..R.....}........Q..Ah....Ah..b.AX..b.PZ+A...V+E...V..J*....Q...b.Q..Ah....Ah..b.Ah..b.PZ*.(.@z.?.`;2.......................................................Q...b.Q..EZ*.(..Z>.G.....`Z+E......J*....F+D...F+E.......b.Q...h....PZ+E...V+E......J*....F+D...F+E..............[u#...a-...f<.9^[...l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m..0.....l0..H..6.Kn.t...&..3a...GG...[u#..8.y6.q..%.R:8....6a.+.3..a-....l0..H..9^M..f..m..3a...GM.q..m..6.Kn.tq..%.R:l.W.lg...[u#...a-...f.r..c8.....f..m.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
                                        Category:dropped
                                        Size (bytes):242903
                                        Entropy (8bit):7.944495275553473
                                        Encrypted:false
                                        SSDEEP:6144:YVxOYlZX2kCWfYoFMXC/sBFC9r+4iEGM4rrcPoWmwkU6FJ:+OwZ2kbFMC/L99ifvokU6/
                                        MD5:C594A4AA7234EF91E6C2714CFE1410F1
                                        SHA1:C0F720D4CE3196852814D0B7347F0CAA0C6FD526
                                        SHA-256:10C833E47BE1C8496F949A6B059C2D79212A4DD66BDE62116EA337FA4FE0B654
                                        SHA-512:7313F6545A334F9E2DE5430B2DB5C419C4C8A40E075338DAFCD74970BCC6309786946E5DFB57531612BF4C6269495655706D920FD99922FDACFF9796710DA9C0
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:10:32.............................R.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................{.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?...v&.F;-v;}FH..Z...N..)Y.......h;C....G.0W..ww...MI..Z+..\.........c..4.1.~.Yo.Y6.&. q...............l.A#.~s?yYg..7ky...r
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):15740
                                        Entropy (8bit):6.0674556182683945
                                        Encrypted:false
                                        SSDEEP:192:Elv3GG8/OOs+GouFdxMlxjoPyerzkpuOo2vPMc62PaJseZC+BJoS/:EtNiwdxMlZoPhzkpuOo2PMc6rX8+B6+
                                        MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                        SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                        SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                        SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):179460
                                        Entropy (8bit):7.979020171518325
                                        Encrypted:false
                                        SSDEEP:3072:oiKXvL7lv0am/R1vrdH+9dK6zPQ6bbnGDpcGGDNMIOIMAT8q9Vc02Q57S4A+vMFz:+vlvC/HvgA6fGqGGJlO1qZ71W6CzDn
                                        MD5:4E131DBFEC5C2462273CA7B35675B9D9
                                        SHA1:CA037F444D819A118AC37D7AA3782B9BF94C1616
                                        SHA-256:2A4A3530D652E227DDD5ADC096A95F6034718F7C380B07DB622022D768815059
                                        SHA-512:C333ECEB1439D0238BF44FB7896E62DBA4C645B70413AA0F99C1F10E8DCD20C2EEE5C83F2E9DDE9A2494C85A6D8D13CFFFC4160E2F598E17867015F5244D656A
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1AQ.aq...".....2Rr..Bb..#34.....CSs.$5c.t....%.Dd.6.T..u.U....E.7w........................!.1A.Qaq......2."r.3....BRb.#4......CsSc...$.5..%.DT.t67d..Uu...'............?..c.......p..z..i.....z......kj........F>f......3N...M....RM.&..-.~.Q..'.....q.a..w...-~......g.{..&.......V.n.D....>FS!n.....@..)...W..q..Wr{..J.gf.{.M$.P@m.,..9..&m.D...w.._...-.O........s.....h.k~......(.K...V..l.-...+.9.k......*......#.p#.O..9M..mF...C.......7+.AI....4vw.;..H......e..Q.u[.eUK.....z.....[.Kt...s..Lf.4..l{.....sh.............=..;..iqkj.m.a...NH......v..H..$..q.y......c...U[Mcf.......+...S-...^....4..T..YtL.x.v.;.....<...Ik|B.$.s8......3.+.8.l.. h.:....%B..W..I.QRS..,*x.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):14177
                                        Entropy (8bit):5.705782002886174
                                        Encrypted:false
                                        SSDEEP:192:EbgGcV/hlvpfal7rgYa8S7auAxwfuSTmCSNoFQ6NO7L:EbgGcVnpwimnd38FdQL
                                        MD5:7CDCE7EEBF795998DA6CAC11D363291C
                                        SHA1:183B4CC25B50A80D3EC7CCE4BF445BCFBAA6F224
                                        SHA-256:DE35AF949D4F83E97EE22F817AFE2531CC4B59FF9EE6026DCA7ECEBC5CF2737F
                                        SHA-512:560FB15A9C12758D11BB40B742A6EAD755F15AD10D6C5DEBA67F7BC8A2AE67C860831914CBCBCDED9E6B2D1D5F26A636B9BCEF178151F70B4D027316F94F27E1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!.1..A....Qa".q..2.....&...B%6.'..R#3.$E.r457bS.DUFV.Wg(.......................1...3.Q..2Rr....s.4.!Aq.S.aC5B$%............?...n.Liq.}.{#....3/gg.1.M +..~3...q..+=..:.g.i1;P)7.....q..n.s"p...wx........v.t.f;..L/..~....y.r[.r.....n.n3..6i..g..}../........3..x.L.i?We..l.......~..<.;..6..o.....N.t.o6.l..~.......<...m.V...Q.7k.u./wq.t..;.I...}..{...>.L..3m..a....yd......6~.f..~Y..}+..<.[w..'-..?.v.7...v.u..4.......1];..u.MO.......s..p..ms.'.O-o...O......m.k.e....)t....i>..E|....,iOyD|.{......g.n...cu....=..........h.\.Q:?g/?.I.3._...t...d.n.0.%y....S.Q....S.&K.w..&wY<....%.g.v.....$y..#,i;.=...t...I6..yO..o.d..w\k...~......)..rK.......].u....N....e.s..kU.u..'}
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 50 x 500, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):2033
                                        Entropy (8bit):6.8741208714657
                                        Encrypted:false
                                        SSDEEP:48:P37XYSDTz+UUl7DHt7Ah8l1+4ZfFclFUXwobKXlZr:v7j3z+UoDN0h8ugf2AwobMN
                                        MD5:CA7D2BECCBC3741D73453DCF21D846E0
                                        SHA1:E34B7788498E33FFF0CFB00125E6BA9E090F6CED
                                        SHA-256:E9EAD0BFC09D32CB366010CDFEDE1C432A2D1D550CB7332BADAC1BEE9482BC86
                                        SHA-512:7FE2C3654262B1EEBED4F6D83DA7D3450E1BE52500A3964185FC0092041506A237A2728E5D7EEA0A3814E413E822B803B789C49CF744D51816A2E4EDE5B4247B
                                        Malicious:false
                                        Preview:.PNG........IHDR...2.........H'......PLTE........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................[....bKGD....H....cmPPJCmp0712....H.s.....IDATx^.\.W.G...=a.ewA..a.!r( ...%Dc..x.x....N.OO...3=...S...........~.z.D.0...g.2P.7.*M.#'....z.......3TPj.Z.[5....V..z'L3...a.j9..C>..9.z
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):67991
                                        Entropy (8bit):7.870481231782746
                                        Encrypted:false
                                        SSDEEP:1536:3PC0XJjsmsKuZRG1pXuZ6z3wARnV9AEnieCc7cllJcHJ:qyMBzkUZ0gq25c7Z
                                        MD5:1271B1905D18A40D79A5B9DB27EE97EA
                                        SHA1:9618608FBD7342DE6C71220A36C3F4995BA9C13E
                                        SHA-256:5B321A4D81BD499B289B1755F6450A42047C494DFBC112DBD56DA4CED2C15C1A
                                        SHA-512:C32DD26047F6B8AA061085B38AC2B8335868E1BFD8731DB65544309223A955FA4BF45B06AC8D244408658F51A1775B6F19FF0FFC804989DE706DE8EB36F1436F
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1..AQa..q..".........2...BR#b.r.3...$.'...)..C%7gw..(.S.W89.......................!1.A.Qa.q".....2...#....B.t......rc.$%67Rb3s&'CUu.v....S.d5.V4T.e.............?...?..Wj.e.e.......w/..E..eOw_.....6......u..C6h.,..;.g.D8Z..-)O..jy..e;.u.g..w..[.L""k'w.......'1'.[......=..P...S.9a.V./O....q=8xk]...........9......F...e9'....9.O.... .&.....p......c.4...mr...?.......L..'.....0....+..|_...POM=7.?.2.a....};.Z..y./....>./.C.<...;.....|.1>...........S.8.o.O...+..n2...k../.X..9...Y...:.....\...Dk......q.K..\.Wuh.!Z?.mu...R.5.A.S.h.0..[..v..+M.....aUi*.k..?#..._...X..R.&]..[..;../]L..f..V......*.e...ut&.#.J.5....c%..o.$..v.<K.6..T.IP.....6X.*.uf..t0^..-.)m$.!.q(.j.f;..WB6.b.B..R.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 40 x 617, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):827
                                        Entropy (8bit):7.23139555596658
                                        Encrypted:false
                                        SSDEEP:12:6v/7Hs2NwBW1mtjeSfaTHHy05riYUtr8y8PQvPYzzg979Reip0QPqc:oOsotazy4rStr8y8PQIzWea0Qv
                                        MD5:3E675D61F588462FB452342B14BCF9C0
                                        SHA1:86B62019BC3C5BE48B654256B5D10293FC8C842A
                                        SHA-256:639EADAD468B6B32B9124B1F4395A8DA3027FF7258D102173BA070AE2ED541AE
                                        SHA-512:E6EA855B642ED36FA82F8E469A826DC57EB0C36E307045FF8D166F67AF9242C87840833BE31FBE4706DC54100E999D6A3D3A78D0633A3114735818874AD34758
                                        Malicious:false
                                        Preview:.PNG........IHDR...(...i..........`PLTE...................................................................................................bKGD....H....cmPPJCmp0712....H.s....qIDATx^...0.Cg.;......@j..2c.=~KP.[H~..@..8...?U.g.n.a=.=.).....3..u^(.....L....5..........8.}..T.f.n.a=.=.).....3..u^(.....L..r....s..8.....W]....,..9..G?.a..`c.z...E.p...)Y.P.....#....@9.7].....,..9..G?.a..`c.z...E.p...)Y.P...`b....0.b.+~{.Pu...1..<..0._.l.@O.y.(...V3%..J....s... .(g.+.qyWu...1..<..0._.l.@O.y.(...V3%...%R.L.Q..x..R.<t.o......7.............:/.E..j.da@i..`b..Z......u.>.?...7.............:/.E..j.da@.Dj..9.W....s. .....:.......L...">w..7... .....:..."...L..."..a....D..Ya.l....E.{.@&.|.._...7..D..Ya.l.....{.@&.|....0.J.."z.0s..s....=g ..>........"z.0s..s....=g ..>..l..1...y..g......IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):99293
                                        Entropy (8bit):7.9690121496708555
                                        Encrypted:false
                                        SSDEEP:1536:Moq1jVORV5NO5xLCBaaNk4vhpCr1CH/DATOQlWvHMHojiaAMrxArLFRZPj19AWFz:eVEbouBaIk4T8uDGOQlVHvaAMkhDh95V
                                        MD5:EA45266A770EEA27A24A5BB3BE688B14
                                        SHA1:9F0B23B3C8EBA4FC3C521E875EF876FBE018F3C8
                                        SHA-256:EDAD0F03E6FF99FEF9EF8E8B834CE74F26CD23C5F8C067F5CEE66F304181E64D
                                        SHA-512:D4EE36BDA897BBD643A699A0332DD00DE9CDCC6F46D861789BAD259A4BF87868AE3B4CFAAB6DFAF29941C7055B77A95D76BAA86A4A0DB2BF3BAF7E3317F03EB9
                                        Malicious:false
                                        Preview:.PNG........IHDR...-...c............sBIT....|.d.....pHYs...........~.....tEXtSoftware.Macromedia Fireworks 8.h.x....tEXtCreation Time.05/15/06.8.p....prVWx..[Oh\E...y3kv........`.%m.R..6.1.4).o..Ki...D.......P!.].=..K...C[....f.}o7VPJIg...{3.|....d.....i..=.4.u0...n y......@j..Q..f)..mQ...4-SJ..9.d.?..5\-....:b.W..i...c.5..{..pj#.....B1C/.I.......].Su.k?.2..:.9Q...5.U...UZ...e..U.c],..2.}...1..)W./..Epr.Zt.....K.=..{......e..."...v..B.4.#....A.V1.".V}t..[..2f..Y..V9.".6.......(..gbm.P.....Y%2.c.z.:Q.2.<tYF.....u.@..KJ.;u.q:.].....$.....V....Hqk..DW.l.e.j.Z.YP?:'R..*.<........6...m@..r..j2..HK"|..L.Nc..D..y.9..B4$.......`.3.m1LE....7(OU\+./.O...%6T..w......h....).I.&n...*......#..W.41...5.#.`..I...<.?.|..*+Q.....#i........$,..n...`.s....[..E. T.w..j.,&-.r..;a....#.>(.P......f...MU\3*..;B....)..5....z..(....-...a.....}y.l..E...z>......&..g.$.....*T...N....E:./.>..#...^..E.0..%......(..@..W.X.NDM.<~.]A.>..fW.O.y.'...Z...h..).F..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 88 x 574, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):19920
                                        Entropy (8bit):7.987696084459766
                                        Encrypted:false
                                        SSDEEP:384:DRSgtAxJx7bzvAsVSqQElOT4uHmpmvNYT9aPU+QtsC2LgfIqJZnbeyRB:DsgaN7bzvAsVdK4uGQFUZ6bU/p3
                                        MD5:1BDAD9B3B6DE549162F9567697389E1C
                                        SHA1:5D9C09159F07A3A9BDCC6C4B9BD9CB72D0184E6F
                                        SHA-256:0908A4CFA23F93011176D47F45843E9CA2973030421996E8E27484781F54B0EC
                                        SHA-512:475040779AC247BB5C3E11862FB55FBDDFA12D759EE86A33E11BC1F3B656D6CD0F9B25146C0113E43E1D8001D8867D3BC3BF7E6FE21F3A0016CB1F8B70B7A15A
                                        Malicious:false
                                        Preview:.PNG........IHDR...X...>......y=h....PLTE..................................t........iw..............................................._n|...Tds...ky......................................................p~.....................................................dr.................v.............................................n{.......ap}..........x.....z...................u......................|..Vfu............r.....w........................................~...................Zjx...................................Yiw............w..|....................Xgv{.....y...........................jx..............\lz.........}..z.....t..[ky........u..y.....gu................................{..........}.....u....................~...........y....r.....bKGD....H....cmPPJCmp0712....H.s...JfIDATx^...\.W./.}....Sy...(..4....D.-.....H...% .$"D.Qr.......`..;...6...N......s...^...L.....Y{.GQU`..~...j....{...-Ax.K..&.....F..I\i..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):33032
                                        Entropy (8bit):2.941351060644542
                                        Encrypted:false
                                        SSDEEP:384:ofmqvnCfmqsp1Ue5xzMq+Qh0dffUmS0w5xzMq+Qh0di:AGAp1rmSl
                                        MD5:ACF4A9F470281F475EA45E113E9FB009
                                        SHA1:B20698DDA5E5AFDD86BB359A6578C9860D5DF71F
                                        SHA-256:5DC2367A80588A7518DB5014122510BF0FD784711015EF83A8718336584F82D0
                                        SHA-512:998B7DB9DB08FD15A293267E2371052E436E024AF8D34F96D3C8FF04B1316678DFC1674C921CB404121FF381A4FC39DC759E6698F19D42A6261CBD39469B0A08
                                        Malicious:false
                                        Preview:....l...........................Ac...... EMF........$...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC........................F...(.......GDIC............^...........F...........EMF+*@..$..........?...........?.........@..X...L........................."B...B...B...................?...........??.....n............;...<..@<...<...<...<...<...=...=.. =..0=..@=..P=..`=..p=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...>...>...>...>...>...>...>...>.. >..$>..(>..,>..0>..4>..8>..<>..@>..D>..H>..L>..P>..T>..X>..\>..`>..d>..h>..l>..p>..t>..x>..|>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...?...?...?...?...?...?
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):47294
                                        Entropy (8bit):7.497888607667405
                                        Encrypted:false
                                        SSDEEP:768:aQ10VrIBdBvDpQrQ7P9/FUOLG2vTSeG9lkCsMKzXeMBk3CBp:aC0JIBL+QsOLG2+ZAC1KqM2I
                                        MD5:7A450E086AD14BA7D89BA5DB3D3AE6C7
                                        SHA1:E7AEAFCFCE476390E18C19456BDF6529D863D518
                                        SHA-256:BDD997068701ED3A00A224EB694B003C01AC69B857FE7B4147D6C34875B1632B
                                        SHA-512:9B6D50A6CDB6081DA107A2CDDB1BD2811A5764994C8E3F67D56CA81084BE0D068C27435154E867199F38688EA65E8DE02A56DCAC47D0F5E55F0FBB6598814938
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..A..Qa"..q..2.......B#...R%.r...$&b...3Ss.4dU6F.cE..'GC..t..5eufW......................!.1..AQ.aq..".....2BR......r.#3.d...b..Ccs.t......$4T...SD%5Ue&Vf............?..M.7(..).:.a.q.......>..[:O...afQ.uCO..U.....go.l..p..YqVklQ.{i.w&.]Z.\+JQw._.n.'.h..,.bj..X.].k&.Q.>gU..f...1|....[...jQ.%Zb.......t..........*..V..j.6....Vj..i.....?...IY.P.....$.j........[l.....S.4.J9.U\.......7I..[..=*N5....xW..../...=?n....uG.D..S.>...8..3........n.S....]k.*...4.>.R.o..{..l.H.#.^....<amG.m&.......,....wDY.W.m.X....We.IR.Nu...y..Z.l.._S.mr.m...y.]m.R.MT...6.5.5}.K..#%..k].7.Y.q]...%.r.7.R^jR..z.K.T[t.a..d.)glW.r.v,.`....O..^..o:.Uc.\..D....f..D......yt.Q...Y.....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
                                        Category:dropped
                                        Size (bytes):70028
                                        Entropy (8bit):7.742089280742944
                                        Encrypted:false
                                        SSDEEP:1536:ub4bgbB7g9cKCmSzaNF0jAdAzQKTEFBQqUp/i0yG1pidLHTVX:ub4bIB7Qg2OjbzjgWp/i0yGCZx
                                        MD5:EC7811912ACA47F6AEB912469761D70D
                                        SHA1:C759BC2D908705D599B03BDB366C951B11F99A4E
                                        SHA-256:FBB4573E3BEE1B337077691BEBAE15D6FAC52432405D31396D526D7694A8283D
                                        SHA-512:881828150993A8C56E36CDA2051D89C1F6E0322643902C9506392C163E8734A2933A46486F40E5BC8C8D0164E180605E52620EF22FE14540AEA787A38B22E98E
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....7Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:12:29.............................V.......................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................}.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....H.yM..? .Z.. .^.x..p.8.A...K.... .\{..)..y....t..=.^y)..v.@.W>. .h.. ..p.:.\)(.$....$.I).....!....E..Z.....&.5.).
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
                                        Category:dropped
                                        Size (bytes):2268
                                        Entropy (8bit):7.384274251000273
                                        Encrypted:false
                                        SSDEEP:48:N9YMn9H5gXlM26vroVXWxyNnl1LmLR+rn4FOeewGhDbby:/h9SlMdgm09ll8R2/rby
                                        MD5:09A7AE94AA8E517298A9618A13D6E0E2
                                        SHA1:FA5181A7414BA32F816BF0C4278EC20C615E8B1A
                                        SHA-256:3C68C7EE798E62A4A99C740153F3980D7DF029605C843410942C7F85E794823B
                                        SHA-512:074E9A2BE2039D0AFEAD360157550B934FABD0CB86B5AF476C1FBC885EE60331F5A68EAF70BF76E23C8248A20FB900346839F4AA8892370B5889E64948DCC6E2
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222........i..".......................................3......................!.A..1Q."q.2BRa.b...#$................................... .......................!12AqQ.............?..D.z.4....;.....7...3.t<!..d.O.....+O+.;.z6.4cz7E.........U.Z)-..@..y...........}(W...<.xv/...5.ew......yN....n.Tk.Tm.Ty.vA=...T..U....h...e.8.5%....'......e^......L.g.$.~e..O.._...... .F`.....xnL.<.......]jfv...}..\G..c.......-%...#.C.|.].`..^..W..c..B..5D.QSTaZ.5A=....BU..z%.4.h.6..=..U...W.$..l...7.:...........IPQT_...~..i..x....~.l.|.n.J..TV.21.Tg.....................j.z!+.-............"j.j...)*..TT...."....T.Tc.**j..............j.z!*.h...&.&.&..e.%..TksTW%G.?".l+$..c._9..[x...TU..........i~X..#'.qm?ttO.....}*.i...q.....9..r..?..W..d.w...f;..q...tZh..0.....2.......OD%Q-.......$......56.K.O...y._..*_C.k..p9.p..O..vu...'........0v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):40884
                                        Entropy (8bit):7.545929039957292
                                        Encrypted:false
                                        SSDEEP:768:MCBOA4d+ElOXJ/3pI7cRBiL7L6qERqGz65WXzZqJsKQSbIsTT6XB:hIAU+2cGdLX6qBG4WDZl4Ihx
                                        MD5:7379775A1E2AB7FAB95CFFCE01AE05F3
                                        SHA1:3D3DDFD8AC7E07203561BAE423D66F0806833AB3
                                        SHA-256:9301DB6D2D87282FCEE450189AEACE16D85F64273BF62713A3044992B6B7A9E9
                                        SHA-512:4B5006E620E80D3A146944649CF4CA619782CAD7E8C4CD0D1DE0EBCA0FA05EACB7378DAFCEED3E26F5698B07F19604614D906C8F51F898660E2F129D8DEC6F62
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d............................................................................................!.1A.....Qaq....".....2....BR#S..br...3T...C$.7(Hx....4D.G..Xh.cs..'..t...%...8.....................1...!AQ..a...q"2.4Tt.......R3S....Br...#s...Uu.bc.de..$D..6..C%E..............?...z...;sB.yv...........]t.\...n...../....m....M.=.3G+..x+.....S).*&.J../..8..O/+..sG...p...<!....~.c..C.w..,[oHom.wc-.J.~.......L[..6...'..i_..S;...!Y.z.q].EK..M.x...i.x.+.;.+...}....#......f.)........e6V..p.;........s.)..Ml.J......IU.6...<9+9.^..l..Y...[._...2..^..j.ia...._..3.;...~..<3...;......z.^.......]..Qk.,...Yk...3.3Jy^p.}....q...I...&..t.......;..9.g.GH;..'...%...)..[..y..../...zCn..>...'...1e.Y..;....]..7...N>t..m-.j.............H^..T\.q.ru...}...eTn]I'r.^].#..wOY....v
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                        Category:dropped
                                        Size (bytes):68633
                                        Entropy (8bit):7.709776384921022
                                        Encrypted:false
                                        SSDEEP:1536:tapXpSTJDOkFGdJdBk/slsbfsw1imaapnbvD8:U2OjJr6b07m1bvD8
                                        MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                        SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                        SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                        SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 30 x 700, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):1547
                                        Entropy (8bit):6.4194805172468286
                                        Encrypted:false
                                        SSDEEP:24:dZeDNYbS+238CTUFPA6SXG5qSacX9q73eXu0vC3dU+OB2gbwHRuZ:dykp9FzBBacXQ3uNC3n7xuZ
                                        MD5:0BA36A74DFBF411FAB348404CCEC3348
                                        SHA1:4C619790E517416E178161028987DF1CD3B871CC
                                        SHA-256:2E7AAF26BEC32148B96442E8FFF1BD2CEF2D72630969F23B9A2ABEDB6CFEC93B
                                        SHA-512:90AF53DB7C413E2ADB970AC345F73E4ED8AF626E179C929E6560118F7A9E98DC7C5FF02B2B3F6C98D397E0FE2D85F3427C6928C328872149E176FA8A99E91F54
                                        Malicious:false
                                        Preview:.PNG........IHDR...............\....PLTE.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................D......bKGD....H....cmPPJCmp0712....H.s.....IDATx^.WSTA........b.0gPPP0..E.9b@L(.c.N.U>..@......;...}..B.(....$......5..XS...I....).!....D^.uE...\..5........F."o..-...m.n. .^.....q= .
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):86187
                                        Entropy (8bit):7.951356272886186
                                        Encrypted:false
                                        SSDEEP:1536:AbmHwD7za0syWMetp3TdPFzoJamVdAQZCiUit9qbYN6LerhWMzIWgN1EeaYhJM:1QnzsyTeP3TPAdAQZCi5qbYEKrhWWMNO
                                        MD5:FEE4785DF76E93A9DC2F4501CBAEAE12
                                        SHA1:8FB4527BDE05EF208FCDB168098A07707C27501F
                                        SHA-256:F091DED5E283AF6848670A3172E7C43C6099875D39B3FC69C2BDBA914F609602
                                        SHA-512:7E99D33151A0D3873D6A819C98EA8E62D928C087B7BA2080F11C7BCF746AD60A44D4FF6EE3D2D2E8DFA4BF1FC6285ED56BB83F91C2FC6FC4FDFF2000105F10B1
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................1.!Aq...Qa."...2..BR#...br......6v.7..3.CSc...$4.s..&dt%u.f.......................!1.AQ..aq........"2.B#....Rb3..t.5u.67.8.r..$....C4.cs.Sd%.DEUe&.............?............w.....c.....i.A.....3...7.......7..P......%.........?Th..l./?.;.....$}..=5Oa...F.c.A/...D.D..]..y..3e.5\%.fo2.X.*]q.5Ee.}..i..md.T....#...-...Mu...9...-+..~w5O.);..G..'.;..).....A_...M.vV..y.q......,<.3.(...._K:..XM.......w.......9..T.......?b..a-%.c;.}..>....|.,lZKCEB.t...fw|.Sw^..Y..:.J.................t._P..v..j.1.R8.R....G..W*H<(Xi........i..xcu...WM.dqM>'W..g....M.q.....+.....b'..~....>..T.~Jc....fj.X.x..9...N.w.6:..>.......&.(h..u...t._...)_k#7Za...cZ....P...Y..;.V.,..xo.....f........Y...\6...M'L._
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):55804
                                        Entropy (8bit):7.433623355028275
                                        Encrypted:false
                                        SSDEEP:1536:gVvci05lhVbfBcWvBLeynluexaWqzww/u5:gVUZhHDljaHww/u5
                                        MD5:4126992F65FE53D3E3E78F6B27FD49DC
                                        SHA1:BC0D76B69310DA9B909D3EE4CECBFE5F386BFB45
                                        SHA-256:3FBE3C1C238BD7DBC67F8CFF5F3BDDFD513C96A9851B9616477947D21DFF4B2E
                                        SHA-512:624853F5E56D224C8188F122B2C4724F867D4099E7FAAFB9C945BE7E2907900ADCF4AE97AB08909CF94E96FB6F381E3B6396D560D93EB2731E4E69CBFE628F10
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d..............................................................................................!1...AQ.aq"2.....BR..8x..r#..9b....3....CS$.'.cs.......7Gw.(.4%5&..Wg.h......tEVfv..H..........................!1A..Qa.q...."2..u6....BRr.#...b..3s..d...7.Cc.$Tt..S4.5Ue..&..%.................?...,...8..{..S.y.N....%..q.8..H[5....o..xg........)c(.eO.YO..._D..x.U.....%.S.r.r._.^..Su.h.Q.t.:.#?....x..B.S...Q.....oqF..%..8'.qx....%.2JKjF..{y.w0.*a.RMb.c.Q{%....eW'..[IV..'ZW3...[...MN.....rO.:....$.i..7....Vrrr...I.r..M..Qo..j....q.^...N...J......%.J..)F...>$.....u........o...+......[...*..t....R}.I..R..S..GB..:......).6_[^Xft...F.1.....zP....,.#....MG.T..Q.F.....)Fi../.I...,%.voEb.b.Z..V3..FT.}..[Z{....wd.z.e.....QwW(.).t..\..'....:)<W.<..&k...caRT.X(..K.....:f...]...q..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):79656
                                        Entropy (8bit):7.966459570826366
                                        Encrypted:false
                                        SSDEEP:1536:2kuUliOeU4os8ii3nF3Hxro/qxXD9u/kjYgMZqoEs6ZUldm:3uUsOXYIAixR2k7WAZV
                                        MD5:39FF3ACAE544EAC172B1269F825B9E9F
                                        SHA1:2D40DE8D90BD21D56314D3F99CEF4FBAE3712C0F
                                        SHA-256:70475431CCA3C91A4EFA3B8F04864371D2D3A45696674A1A0562FE9CD8DB287C
                                        SHA-512:3B9F3B32696AB7779864E83DC0C45960114A130BEE0CF4D0643DE57FF952171E5D775AA49141EE31A28A9B5D052B26EB421F26EA736D7EF4B3A7EC812CA411CB
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!.1A.Qa"..q.....2#..BRb..r3$.Cc..Ss.4...D%5&..T...'7....................!1.A..Q.aq..."2.....B3.r.#..R...bc$4..D.s%............?..Y..T.o.\......=.a..j..'^..s..[../........Y.......<...(..4.....7y..Ln.[9.cK.ilN...u@$.V.9.V?3..s.KL.z..w.jW.C.............@.~+.o?o8...k....,.m..9.".....q.....d....z.W...q...~...'..e..>..f#...S.....F....pU.......7..N.vfK......S..G.#.....}.c.........RXt.bq1.`.....[+8\.*.N..:......}.....r..........')......Na...&...m......c...a4_%d.............co..0.n.L.Q..E.Lt..y.|..F..4.i(>.._..\.eNL8..?z9I:hLgC.@.p....g.t......'.I!d..?1f..R..........|..4.wJ*..%g..~0bt.....*...v.......O...:.~.>~..o.x...9.@>...s.&.E.0/G.c..t.<..F.t.A.z. ......;.........Gp.P
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
                                        Category:dropped
                                        Size (bytes):3009
                                        Entropy (8bit):7.493528353751471
                                        Encrypted:false
                                        SSDEEP:48:aRCTf+0hagMrbAZMJShPdvF/5OzlQFlDF7npkDdWvVBTEnBLT6NrgCX0:D+0YgMrApL553JtEdEVcL2NcX
                                        MD5:D9BD80D40B458EDB2A318F639561579A
                                        SHA1:83BA01519F3C7C1525C2EA4C2D9B40F28B2F2E5E
                                        SHA-256:509A6945FACFB3DDC7BE6EE8B82797AD0C72DB5755486EE878125A959CC09B59
                                        SHA-512:C368499667028180A922DD015980C29865AEF4A890C83E87AE29F6A27DC323DD729E6FB1C34A2168A148E6A7A972F65A5FC8ACE6981AF1D4E7057D99681CB366
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666........_.........................................:.......................r.!12BQ...3Aaq.."CRb.....#4$c.S.....................................................1A............?..p..-.....u0$.......l......)..o.FTd..DG....... .t*e..jO..Z.U......r..j.O.,..VD./.....V5D.&......A..Zi....E.N....*..........#..M<|.2.Y.../QO.x.cTM4......+.F;V.x.de*....]e..O.x.c\Y........r..j.O.,..T...hw..k.^.[B..J.sEl.w.x.m.5%zzt0..T.......b..<\.3Q..W</..!.xh6..Z..\.+M.o.Y..1............#.........|.a.l.KR>..U......e....@...\.1Z...Y...[....F.6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....Uh....FkYm.m`P...W .V.g..FjVj.\..1Q6.t.#..Z,.x.Q..[`.X......#........W</..TM..-H...V....Tf..........r..j.x.df.f.....#..l.KR>..U......e....@...\.1Z...Y..Y.us....D.)....
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):60924
                                        Entropy (8bit):7.758472758205366
                                        Encrypted:false
                                        SSDEEP:1536:kU7O7+CFqO6DkxTgPzo2wqggrrX8QvN1I/ZLBttB9+dPFXbc:hVuqJDaTqo2wq1L84N1I/Z1tT9X
                                        MD5:D58C51D2CF586A5E14A9EC8529C3B0A8
                                        SHA1:F4811A353797C29B1E3F5A61B125C46E1534D587
                                        SHA-256:F927C7825851974A2149868146970706523A49165133CEE6027A43E8C9ABDF27
                                        SHA-512:34B963173AFBDF07432F4B983D29F10376E4771FE666E9D50B1A81DA0B9F6001FD86B4A08B9711386DE153BF6E03C8E932E2D181C8EAF94EFF34D20FCA7570E0
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d................................................................................................!1AQ.aq....".....2B...Rbr#.s.4...3$.5u.6v..CSc...DT..f..t..&F........................!1..A.Qaq....."2....B.s....Rbr..#4...35...CSc.$...DTdt..%..............?....O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.........................................................yK..xd...6..|%....\j..e.=...Y..f..I.|-....e...$R.j.......~.W#....{.....V.k.|F..z^..:.~..f......"x.....L..K..r../.;..[..l...;.U...W...X.........8.....y?..B...m.......j..Q.g3..G.K....GL.o..n7a..Y..[.'.........x........\......~...f...0\Wc.n?k.|.....1.ww;..2..?...r4uF.MXdB6..W..mG2NJ.E........u...2.q...Z..=(l)jU.X...U.\X.......O<......X.O.Fg..{.W&u.u.T~.|r;g!.._X..N.p.4.......................................................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
                                        Category:dropped
                                        Size (bytes):1873
                                        Entropy (8bit):7.534961703340853
                                        Encrypted:false
                                        SSDEEP:48:N9YMw9kGzE4xTdow1C3kyIkyM66KeJY3fOxJ:/h8HzE4xTdoUCUyxyD6LCvSJ
                                        MD5:4FC8500BD304AD127AF4B5E269DFF59B
                                        SHA1:9A5E3432358A0FCDECE86AEB967319B93A65D14A
                                        SHA-256:B4DAA90D5A53FCBC85119050B5B76962443C4DD18D7F42CDC6D4E0AD8EFAD872
                                        SHA-512:E5E07054A522EB91EFD39722AFB3776389632B8F5F923C1D29796716D68CEC93BE5E44F79913804CEC7ED631FF520CBBBAAB841E01FB90AF8E8ADF84DCD47481
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......`...."........................................>.......................tu.....45.!#$%1s."fr...2Fq..AQe.Eav............................... .........................!AQR.............?..e4.bbu."m.G......u.S.-Qq.b.a..'#..E.......u.|:.f[O..jS.S.&....=.....[.....S...N.~~...'...q....N.T.Oyf..a.6..%.I.1j.e~.4..[5.WW.Y..Xp.gn...u.......Gb.O.W..k.!mJgfq....~.F.......m..}bn4.5........s,F...z.b)..O..*...5).-.-\....=`.fP....%...A..Q.&..9.....QQbD.%.:u.f...r$.10..W.F.T..MI...9...ZQH._..).....D..n.F].........*.:.j...!6Z..S....0...B.6..Ga..S.O.....U8S_.J.>...i..?..<.P..........M..F.T.C..7.E...`.4BKcMh1j....4y...+.|.^......2[.WG.W..+......E..r/V^".R...."..6..hht..f...........;E..Kx....)}Le.A.x.>..$/).._S.n.L......}..H^Sw...2. .v.io...../.........x.>..$/).._S.n.t^;O.....n...[.S...h.v.io...../....:/...[..7yK.c-
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                        Category:dropped
                                        Size (bytes):24268
                                        Entropy (8bit):6.946124661664625
                                        Encrypted:false
                                        SSDEEP:384:d2wiieoHTRh5a1HAteZCWOZIM+L7WhNjYn:8wHFHJ+/OZIKhNO
                                        MD5:3CD906D179F59DDFA112510C7E996351
                                        SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                        SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                        SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 85 x 470, 8-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):11197
                                        Entropy (8bit):7.975073010774664
                                        Encrypted:false
                                        SSDEEP:192:p9wNdtRKcVHso6zsqm06xaqZdingVzLZ7/PGSIz/yycRTbChh/JzhbEx15RGb:mdtMcVHqgAqTinMzLZ7/uSIz/yTR/mhF
                                        MD5:DDC3CC30794277500EFE4BC6667EC123
                                        SHA1:EFC9642C1F95B5FC38764476AE481649C016FA0C
                                        SHA-256:7F5B660A1A0BF46C75AAF19B4F77A0E086DE003EC03AFC1F58D871D55AA5BA9E
                                        SHA-512:25232A84604C3959634D33090238FEC8D51E40AD84EB3A08BB8522A81BE1E83378649C014E98E1DFCDF46B7BFAC92D8D2429211CD11D7EE0334C9C3DF7C1B6A6
                                        Malicious:false
                                        Preview:.PNG........IHDR...U.........1x5.....PLTE....................................e........................................................s...............x..........................o..............................................................................................................................................................~.............................m...............................................j...............................................p.......z......................................................x..............|........................................v.......................y..........................................................h...........................................................................P..{....bKGD....H....cmPPJCmp0712....H.s...(SIDATx^.}i@S..N....h...!..)....AI%..p.L."a..)..`U..,h..:O.b.:.j+.Z).b..zN.s..{O...&|..N}...${....~.....k}.[k}{.o^.D_..W:35ly..7rL....6n0.A...b
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
                                        Category:dropped
                                        Size (bytes):12824
                                        Entropy (8bit):7.974776104184905
                                        Encrypted:false
                                        SSDEEP:384:gzPrAZvq82AP0/DHbSczEegiAh1Hfgr3ZO7EFKWHaXIXqu:erAZz200/TbJzDgiWgjZO7EFKEaXIf
                                        MD5:2628353534C5AD86CBFE57B6616D46DD
                                        SHA1:244B7E39D6CEF5B07FCDE80554D31F7DA240BB0D
                                        SHA-256:69BDB000AC7E030B0B28E6CE78F19547D235355B3B841146951AD1294429FA51
                                        SHA-512:2529F97BE62DE038445D1C86EE2C01404FB1A2D83A5D16C7B5F4E21723C17EC86FA180DFE10342536CFD7D334EA3AF1FFE151B77F2FBFFFE8E7B2A0C2A3ACD59
                                        Malicious:false
                                        Preview:.PNG........IHDR.......1.....).'....sRGB.........pHYs..........+....1.IDATx^.}.w\.n...A.H...E.J...l.......p...\{.w...e.-K.%..d.9..DN...^}..p.L...._$.t...n.=U..ID..]~(.?.)J...-.../.......0V..........'.)1X..c..D..2..A'f."...Ru..R=b..\....\.n.0...7.~".'..s!bd.|..p.u....-w'.....R.........i]..r....A.........r#...W..f{O.2~C.O........{.....3..W.}e:...~.....4.......t.Mv_....}*f..I...x11....d..6.@..O.......f.e..K.....L]..gohj&D..+.....#...#.J...n/]...8~.....zx.'.LI6..W....p...................V.F.. ...y.[.kl<?.^....N..$..7j.biU....c.51{S{.....q....c...<..x..............zG.F*.........U.w..fE.....DU.......WG7.5uC...7.....j..7yM...~jU..;J..a|LoG..x..<^.Z ...Z.....ip....._.4......f.rg..[...z....x1k.....z...K.l...;6.\..Y.#.WT.p.@{W....>.+..*..W....'v.nV...YA[.q!\.\...9..3.[|....7...HO......2<.....w.,].T^eN..XB.....M3...I.k...e..8...lZ.R...T.%......|N.w..9..!..O.-p..NA.eD_.d..nW2!...N...z>..;....=t#....H,.N.|. ......EC..............1.\
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
                                        Category:dropped
                                        Size (bytes):68633
                                        Entropy (8bit):7.709776384921022
                                        Encrypted:false
                                        SSDEEP:1536:tapXpSTJDOkFGdJdBk/slsbfsw1imaapnbvD8:U2OjJr6b07m1bvD8
                                        MD5:41241EE59AB7BC9EB34784E3BCE31CB4
                                        SHA1:98680761A51E9199CF3C89F68B5309FBEC7EE3CB
                                        SHA-256:035B26DF61855A3F36DBD30FDAB0C157C04C9E8AE2197EA4D4AEB3E82E6A4C2B
                                        SHA-512:3EE331D5BCEE4AD5D3FC9661D4AB4053F7D351591A094334F963C33C9D0E32CCCABE9334AD7C308108CE99617E064FE848DCD469ACD8D83FBE5C4452DE523D8F
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:05:55.............................d...........j...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?../$.W:SZ./...9.....-...u......r.....].c...@W_.7...+......v.+PD.I..-<1.pDn-\.....p.$....0.}V....\..>.~..XN.o..l(E....ik..o.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):39010
                                        Entropy (8bit):7.362726513389497
                                        Encrypted:false
                                        SSDEEP:768:6tCjwO+E+KW0ZtOgepcoWW4pAWQ6/KWcR474HOAZaDfK:68j+E+KW0HOgep/72/NKWcRNefK
                                        MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                        SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                        SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                        SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
                                        Category:dropped
                                        Size (bytes):784
                                        Entropy (8bit):6.962539208465222
                                        Encrypted:false
                                        SSDEEP:12:869YM8fij0W/xfuCp7ovv1bidiMn3bGi6AETQcdH8SADjoZgV6v9jUEvS3/g:N9YMWeI424diMn3yinsQeHvADu9QEvJ
                                        MD5:14105A831FE32590E52C2E2E41879624
                                        SHA1:078FA63FC7DB5830E9059DF02D56882240429D90
                                        SHA-256:D0A3A1C3CD63C4023FE5716CBE2C211307D0E277E444D9EF76C7FC097A845FD4
                                        SHA-512:8FC0ED24E8EC14C46EA523D9265DE28F85C5FC57AA54AD5B9CA162E95F79221E2AD3DD67D1293CF756B67F3D3DECAE122254134EA8D4D00DDED02114B5383947
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......a.L..".......................................-........................!A."1.Qbq....2Ba.........................................................1............?.....3.Ty\......vs....>.>..a.W..s89.d...Z}......rz...`...Z.r.do....u.W.%....gf.>.L..xz....B8=w...g.~g."HD...$..IKJ......nn..*ly..I....L...\q...Q;6.KrxZ.,...j$..ZQ..)f...q`.*..C1..cZ2]-..\.~..J.....^..(.f..9m?..C.NI.UL..X.fy.Z.........+n....r."Z...d..R./\.#...kd.D.5.!...h.3*s-+.......Xjt..}i..rK..y.../>u..]N.....Y..J......1.x./.....F6.......I...._3...k.sM.+..v;.%|.f.~.......:y....S....UKovh...W'........lF... .................
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):39010
                                        Entropy (8bit):7.362726513389497
                                        Encrypted:false
                                        SSDEEP:768:6tCjwO+E+KW0ZtOgepcoWW4pAWQ6/KWcR474HOAZaDfK:68j+E+KW0HOgep/72/NKWcRNefK
                                        MD5:9700DE02720CDB5A45EDE51F1A4647EC
                                        SHA1:CF72A73E1181719B1CC45C2FE0A6B619081E115E
                                        SHA-256:7E6A7714A69688D9FFDF16AA942B66064A0C77FCD9B3E469F89730B4B9290C3E
                                        SHA-512:5438921467D62376472007B9EBF3C35C9D9FE3EDE04D99A990129332D53EBC8EE2555C0319A4F7C0DF63516F29CEDF2171D8B6DC34C9FCD075C2CA41EB728660
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!1..A...Qaq..".......2BR#...b%&6..'w.r.3f7W8.s5EUeF.g....CS$4.Vv..Tdt..G..(c..u.Hhx.......................!1.AQa..2.q....".s...3.4BRr.#......b.$c............?........uf.....t...;..[...W.h.....-.k.f..i.u..KQ..b.F...rM%/.8n.S..=9.....G$O;.f.}L..N..U._i.[.X...3.~....S.~..+t$...c.5......{..X/..#.G...}s....6......^....o~.$.\WA?...^*w[O.~..6..~....a....~..:..0.......{O...|.s.u._w.........i...........{K...._.?.../{.....A..8....<g.iu..<..................X......|]v....D..9.k.w.|-IF.Tv.-.&.........."'.4.b....z.._.Z.....G...u.xyt./_.q..m>..S.V.Xdc.bw.T.W......g..........}s.._..?....U]_.......`......>.|'.~xH....,...?........?.q....o../..R..;...Y.G....A"?......?.<..1...w..o.M.........tco.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):41893
                                        Entropy (8bit):7.52654558351485
                                        Encrypted:false
                                        SSDEEP:768:pZvVQkUbOHxx3pvVmO5rsP5gUdXwFMuv53knzyncaXgRDqPU:pZkijV5wScXwFMYknzucaXgRyU
                                        MD5:F25427EFECFEE786D5A9F630726DD140
                                        SHA1:BC612A86FF985AB569ED1A1EA5FFC4FDB18FC605
                                        SHA-256:5A36960DF32817E8426BD40A88F88B04FB55B84BAEF60F1E71E0872217FDB134
                                        SHA-512:B102F34385196D630F198667E874F25ADBC737426FDAE0747EC799B33632E5DC92999C7C715DC84D904342738930267AB1709870BDAA842243E4C283FE5E1554
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...........................................................................................!.1AQ....aq......"......2...Xx..9BRr#.b3$..&..g.8....%F'G.(H.Ss..D5E..v..W..Cc.deu..7w.h.).....................!.1....A..Qaq...Ttu.6..."R..5...2B..S....bcs.Dd%&r3C...#$...Ue.............?..R...%.R...t.MQ*.l...v...V]..n...Zw....M....4..F.&&bb0.:]l......ay.r<..3.l.Q^.........I54.N2.8..2s...w..r6.......[1Zh....O...9..>...B......x]...r.\.\..v..~....y.QT.3.......=....r..}.l.....o;....M..C1....w)...+o1f.]...MoA.E..s5..i.\....miGsy..m\.Zj....I'YU.\tU6La5v.>.K..m.]1.......k..0....</5v.V7lY.e.vV.+./[....f..u{....s.}.Rb.Z.....Y.6]..m....V.\...Mr.=r...K...l..%..m^.......X.(..fG..[F*ly.jL.a4..vs..o.e..q.9km..w1.yg.....r_.*h.n..5i.-.{Y.l...<...'Or.s..Z....../JP.....\FV.S..............m
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
                                        Category:dropped
                                        Size (bytes):2266
                                        Entropy (8bit):5.563021222358941
                                        Encrypted:false
                                        SSDEEP:24:TuRCTP9rSTfIEe1HbcVY1YbDXq8eCI0bf2QQe0GVDQAzZw:aRCTN7HbcW1YbDXq+I07Ien0AVw
                                        MD5:DB8A181E3F0EAD4A9472099E42ED6BE3
                                        SHA1:92096AF05CC6167B1AA816811A1160B809393FA2
                                        SHA-256:E9746B4E9AE9CE7B3B0068779DB3E113E2DFC9880F25373D745D0E700E69A906
                                        SHA-512:A9E246E10E28D057090BA9F034ECE6131780D7F794C5C9421523388997C7EDFBB49BC32B863B6C6668911B359C304AA54969B48CB9234950D5CECD2A6F3EFFF8
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....C....................................... ! ..''**''555556666666666...C......................&.....&,$ $,(+&&&+(//,,//666666666666666......r...........................................5.......................!1AQ..2a...."Rq..#3BSr..C..................................................................?...X.....U...j...F.W.V]'KV.uWt.iT...{.......`.(.....V%..=.....z......V..ct+.U.B...@.............................................{.....5.........0...x4....c..;...........+......|.7E.%.9.1+}..d.........+.V#.P.HUL.E...g.li...8.>U.";0pi.]5.\..zo..."@.........................................y.6.mLN..S.....@...i..A..p.......~|V9.+.Xy.........+,L.....7Z7..p...-X...\.....:-...i....v.1...-..H....9.zk....l....^.......:.."^.t.Q.F...X..B..$............................................a.%f&3..1.5+.X..'b7bwr.).e.x....!...H...aa_..kD...b..g..p..K^.k..qX.[,.........Q...U..x...YMvj...w..:k.....j.W.8..4....c.u.}m.....o.=@.......j.S.t.|.....5h.y.%.~...G
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):25622
                                        Entropy (8bit):7.058784902089801
                                        Encrypted:false
                                        SSDEEP:384:EhK81gTCyJ/Gf9Aw3t8w8EtdPeGDh6bEi1Ie1u4ZbvgwTwrSRh7ZKNpIGY:IjcRXwdJvtdGsUbEi1IeY8vgwTyC1+Y
                                        MD5:F8CCFC24DEB1D991EBE085E1B2D7D9BF
                                        SHA1:AF76C22A765434AEDA134924C517C84107F4FED5
                                        SHA-256:7354001527AB554C44E7D6981B86DD933B7DC2E0D3DC8512AD3EECD843245C52
                                        SHA-512:818BC3690B01B30BC571E4CF45EC8D1AFCAECBAB003532644381F1CF730A5B3486862D08F7579B2D3D89167AD7DF35028881245C9550B0DA23D1F81A720A9704
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d........................................................................................!...1A.Qaq.........."2Rr.#.t6..B..3S$4..v.b..Cs.%5..8..cUV.(.DEe.&Ff...T.d.......................!.1A..Qaq...s4....2r..S"BR.3....b#C$.....c............?..D.."}:......&&...?3..W.q*.......]...m.Y.k1......K).J...uV.b.../.0.E.H..4..W_T.[t.V.w.9.x.qe.L..o.oL.....d.\.....6.|.o...}..H{Yn..E...6Y3.l.e..D.:,.n.%...t...m.........,+,..|..n.....6.*...f........6.../$../Vi..H...e.f.F.zn.).n.E..2sTn.i...Yb?6+H&...Bf..*....z.o.^7[..u.:o....t.s=.....(.s.....f.g....q9o.u1L.N...smzE..[>...+\O....j.<....j.c.W.............U..+.F/.'..W...T./W...>i01./....j.s."..Q...{...a._~OW...Rp.)*.e..W..Q4)<..'..W...q...'..U..z..g......U}...O....w....0F:.N..V.3W.|..'z0.]...j..U[v..g$D.Lc[.e...UW.m0+
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
                                        Category:dropped
                                        Size (bytes):3428
                                        Entropy (8bit):7.766473352510893
                                        Encrypted:false
                                        SSDEEP:96:/hdu7isPwAp7zesusUyYAatNG87llTONQYS:5di5tfuQ9atNZlaC
                                        MD5:EE9E2DF458733B61333E8A82F7A2613D
                                        SHA1:A86704C969F51B86D6A05ED51C6C60214ED9FA89
                                        SHA-256:BE4F0E6C89FCE91B9EBD2623567F7DFC259E0E3C77C9158742B8F64B724DF673
                                        SHA-512:BFB5D6DD6B66EE21E946E90D1E482384CD10244308562DDA814189602681DADDE5752B80519E5B8515F115A71BD6BB4317A59BE65B8B5E3474AED119F8303569
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......r.F.."........................................H............................!Qaq.."12.....#3ARbr...$B...cd...&CSu.....................................+.......................12..aAQ.!#q.."................?...#...3.Za......rV.5&...../"..i.t...j..W........d.FL.V.2K....]t.f.d.NK..:.....f...... ......2.[...#..D...ZK....p.z.E.N..T..L.-....1....2.\.6FIr2..zS\U#..........fB\t..5J..~q...D....A.......!....MY..../.HY..../e.M.Y.n.~..,....'..Pc...l...d2..m.f.it$..qx-z*...._..].cOO....n..&.....FIA.....2J2..d:<qc..6.I.G.N....f.K..Dx.-.......`....2.FZ."K7.r}..<.P.Z.da.Y.....8..s....G.....b.e..g .S.......FL.Z,&..q.MG.J+..x\..m...qN=.....)..`...&Y...S....u6{.z.g.....@......FL.ZL&.Iv.w..8....U..v...*.q.B.v_./A..#.#.g.j........*J;...u...W.Ao...%....#$.....M..^\{W.SO...s,.N.....c).,.B.Gv...."k..z."..S]H.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):109698
                                        Entropy (8bit):7.954100577911302
                                        Encrypted:false
                                        SSDEEP:3072:rDlmvIWr0aRtNCfShCWBxyCHMlcVG0Ezy4FR:rDliIfot8ahCWBcCHDVwR
                                        MD5:8D804A60E86627383BED6280ED62F1CF
                                        SHA1:E23FF14B10AD0762DD67FBA3CD6EFC85647C0384
                                        SHA-256:494547E566FB7A63DD429EB0699FE41AA8998F8EA2F758D813FE3D56C3075719
                                        SHA-512:0FB19F3D00159F2748C3A54E952E551B9FEA6910D67A54DECA8D099992E50383EADB92768FF1F75CFFAE82A7A157B1E0F77A2F0BE7EC64FD2324304FDCA46577
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d...............................................................................................!"#.123..AQB$..aq.RCS...b..c4%..rs..D&....5E6'..TdUte...u.....FV...7.......................!"..1A2B..QaqR.#.br3.........C%...$5.....c4U..Eeu&SsD.6T..................?.....O.C.....^..R<A.g...[....3.....r.0.....nX.S....}...[.?Z.....A.?..~~I..rY|N.o...9......!...o7r../-.y...'5.3.U.s".-.0.1......SS...&.Q.j.*.$m.e..:x....`}...EP.?.7..~G(so.......O.....z.N..<....~^a.e...........p9.?<._..|......~.<@.D.9..G..?.?z.y?z.C.U.w..[.,..A.+........s......g...G.^....pz.xY.....d8.y.X...P..O(A.O..~:._.......<...o..4s..^.^b..x......_a.....|{c...:..X.....}.._...[?..NK.c...}.<......H.G....+x.Z..|....n...o....`.nk.#.%x......-|...|7......N!=././..w.8x.".8....'x........w...,>....j[w8a..}..lS..?.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:PNG image data, 60 x 336, 4-bit colormap, non-interlaced
                                        Category:dropped
                                        Size (bytes):347
                                        Entropy (8bit):6.85024426015615
                                        Encrypted:false
                                        SSDEEP:6:6v/lhPtnlx/QulkWNY2V18A6Akp7eee1VDjMHCyLezyKUX5Gp:6v/7RrIubiA6AkpNhiyKe+
                                        MD5:78762C169F8B104CB57DFF5A1669D2DF
                                        SHA1:9638B71B584CD636834016A635ABF8D9C0887711
                                        SHA-256:E64FDCD0B108737D8B8F7B677029F924031D6BBAA50585D9C3DEF7C7E92ECAF2
                                        SHA-512:5ED899AAF73B72DEC32E171FFA112382667D5BF3FBA98C92E313E66C0A6975EA97068F4CD32B62283F18DBD5345C11E3610F7EEAC2F2DE71FC44593180B9CEAC
                                        Malicious:false
                                        Preview:.PNG........IHDR...<...P.............PLTE......................=l......bKGD....H....cmPPJCmp0712....Om......IDATh......@..aI...B..C..l...^.%.`....>.]..|0.....a...hb...0......q.......p"....;...K..x=...p...y.yy~J....|...\.......y..X.......'...>1...Ky..f....&........N`..f0..b...3.......`Z.3..3.....o.......4.&........SV...4.....IEND.B`.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:Windows Enhanced Metafile (EMF) image data version 0x10000
                                        Category:dropped
                                        Size (bytes):32656
                                        Entropy (8bit):3.9517299510231485
                                        Encrypted:false
                                        SSDEEP:384:qR0eV0V6zLq8fAy7TtS1O6VILpjH5og6NJgnIuu57aqP+Tg3QePV2P6hqaJDyjJg:qlzzaRpbd1
                                        MD5:DD4CA4BC0A73FCB71BEBAA3C29CB8F66
                                        SHA1:1A7085771D7941540EC94A1BD24D7CC8EA556D4B
                                        SHA-256:0401451E1D1D7DFDC29AD1B2B68A6C8AC0B706E9868BF22FAB26A01CD48620CE
                                        SHA-512:5B7D386C46EC75E21DE94DBCA922FB9A6E5358DEB3D60FEEE7B197D739F15D11050825D9323502EDFAF60720F1074DE896B23E71C44D07C9C7E943C31FDC078A
                                        Malicious:false
                                        Preview:....l...r...1...*...^...bX.......^...... EMF........h...................`...E...........................(...F...,... ...EMF+.@..................,...,...F...\...P...EMF+"@...........@..........$@..........0@.............?!@...........@..........F...(.......GDIC....s...2...+...^.......F...(.......GDIC....s...2.......N.......F...........EMF+*@..$..........?...........?.........@........................(E..HB.'E..HB.0'EI.`B.0'EU5.B.0'E..B.'EU5.B..(EU5.B.(EU5.B..(E..B..(EU5.B..(EI.`B.(E..HB..(E..HB.................@..............!.......b...........$...$......>...........>............'......................%.......................;.......U...P........................T...S...S...S...S8..Si..Ti.@Ti.qT8.qT..qT..@T...T..<.......>.......r...1.......N...............%...........$...$......A...........A............"...........F...........EMF+.@..........F...........GDIC....F...(.......GDIC........2.......N.......F...........EMF+*@..$..........?...........?.........@.......................}*E
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):15740
                                        Entropy (8bit):6.0674556182683945
                                        Encrypted:false
                                        SSDEEP:192:Elv3GG8/OOs+GouFdxMlxjoPyerzkpuOo2vPMc62PaJseZC+BJoS/:EtNiwdxMlZoPhzkpuOo2PMc6rX8+B6+
                                        MD5:FFA5EC40DC9A0FD10EB9E6355142D6A6
                                        SHA1:3D3D6A7E086B3C610C08F1F3E3F883604F06F2A4
                                        SHA-256:D74C3973C8D1F7C77274691AFB1AA934940674341D7EEE563BE75E563281BDFD
                                        SHA-512:6FAF2A24D06E6008F3579C7CEC90C2887462BDF83FAD7372FBB74B8DE90340B580E9836F309B68A9794597A598F7DCDA661C9A58DA6D8187C69083B7A17C9CD9
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.........................................................................................!.1.....AQ..aq.g..8...."r....2.FG..#.E..7.Rb..Cc..D.v.B..3s..$d.%5Uu..&6fW'w........................!....1Aa...d..5e.6.q...Q..."2b.c..r3DE..BRs4U.#C.S.T............?...u.&0...cV.T.I...1..=4....Ce_.g.q.=F.M:>)...k..pm..h..=........S....)Ja8x...b.).=5.q..0......k.M.....1?-.G.b&.5..Ep.8t...'...R)..ta.F$bXO]tW.b.6#.t.XWN..ZW......].....G....x&&f..'L.....7...\...'.8...~`.sa...............................................X........qo...SMk...'.V...i..hb.}&?/.k.:>l.^....>Y...<}...&.jY.Gn.MKejyV......D......gf.0....t.nw..XQ...H.B.....=8.UkR.....Hm..w..]...k...#Z...F../.gjWvf.....w.aZ].2..5..^...VZv..._.7..a.|...:.B...,f...............~....m.;_.....-.e.y.w.[m.].bu.b.f+.E++\.....Y..7
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
                                        Category:dropped
                                        Size (bytes):52945
                                        Entropy (8bit):7.6490972666456765
                                        Encrypted:false
                                        SSDEEP:768:cjvqR0XvFaGCTJffi0tgybmWDoTw71kHUAnjvawrlp2+NUO8dWSNl3PF2PjK/q09:cyRffflgybmWoTw1UUADHUbU21MjpAD
                                        MD5:AD003F032F32FAC4672D4CE237FA5C5B
                                        SHA1:AE234931B452F0D649D91291763B919CF350EA49
                                        SHA-256:ADB1EBBE18D6CD8FF08AA9BF5C83CDB83BF9AA179698E34E93DBCDDE12F04D32
                                        SHA-512:ECA25FA657ECE3A66D3E650628E0F65D3BADD38864C028AB6553950A1A66D7D55482C85E9E565573E9E5AAFA91C2D53235971C644A266D41EB69F8E72E3A843B
                                        Malicious:false
                                        Preview:......JFIF.....d.d......Ducky.......d......Adobe.d...................................................................................................................................................d.............................................................................................!1..AQ..aq....".....2....BR#r.b3$...C.Sc%...s5E......................!1.A..Q.aq"...2...#...B...Rb3..$..CSr...6............?......y_N.e.H7?........W..w....k|...S..d.4.>.RW5z.$.i.)V.O....>o...c..*&1.D..O..".ufbb..1...t..u=..K...m...~.....F..-.fb:i..=f..C.w.[{..~.7k....;..:..3....4.....$..m]...}....~q...9T.#..7.~..8...q.N;c..ffo.w...W..d........../t_........lWJE..).>..v;:=....Rrw#.m.n.n...E...vm.J}2N*..|.4...80.#..e....t.J..ZQ.x|g/....F..e....k+vK...M..W.X.e.L..~...j.....kz....=...n:O.:..[.L,.+R...Y..zKNI....,..{e..U.'...}.......|..t.]...~...b4......_.i..../.......m...a..n...v.j.?..Rc.$G|.31..#..$?.........h.w....-... .a.%z..u......u.A....Fm..J.......G..[...w.....:....w/.
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
                                        Category:dropped
                                        Size (bytes):24268
                                        Entropy (8bit):6.946124661664625
                                        Encrypted:false
                                        SSDEEP:384:d2wiieoHTRh5a1HAteZCWOZIM+L7WhNjYn:8wHFHJ+/OZIKhNO
                                        MD5:3CD906D179F59DDFA112510C7E996351
                                        SHA1:48CDB3685606EDD79D5BCDF0D7267B8B1CCBD5A8
                                        SHA-256:1591FD26E7FFF5BE97431D0ED3D0ADE5CFC5FA74E3D7EC282FD242160CE68C1F
                                        SHA-512:2048CBA13AF532FF2BCC7B8B40541993234BD1A8AB6DE47B889AF3F3E4571F9C5A22996D0B1C16DD6603233F6066A1A2A97C16A6020BEDD0826B83BAD0075512
                                        Malicious:false
                                        Preview:......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop 7.0.2004:03:04 13:19:29.....................................................................................(.....................&...................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................$.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....)......[]t.\Z..g......A....&D.$LH._..X..Xl...`....cZ.X.........>......f.Z.X...]..~L.S..@..I$..I.IO.....x...s.g.[f.h{9..
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
                                        Category:dropped
                                        Size (bytes):84097
                                        Entropy (8bit):7.78862495530604
                                        Encrypted:false
                                        SSDEEP:1536:cgHTEuD99rHwA5MSadIV2MApVmfJkAKOQ/Z1I7ngpDDyHfKFVITrU:HHjXidIhApV88/jIEmrU
                                        MD5:37EED97290E8ECB46A576C84F0810568
                                        SHA1:18D9FACB4CFA3CBF63B882CABCF30B203EDF4126
                                        SHA-256:140DD943D0F0CFE6AAA98470B7D1A7CB62CA02CB1D8F522DD2AC77433232EF41
                                        SHA-512:E0F57314C136211B8253EB2AC0093DED82198E7170D4F97C40D82FD4EC4123D2AAFE3EB4EBC3E7523C4DF4D77619408773871BDE15B6DC6C4049C71D5B9D4222
                                        Malicious:false
                                        Preview:......JFIF.....H.H.....hExif..MM.*.............................b...........j.(...........1.........r.2...........i.................H.......H....Adobe Photoshop CS Windows.2004:03:12 11:11:38.............................A.......................................................&.(.................................2.......H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d...................................................................................................................................................z.."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?....b.xH......T..I...S.q.~..../s.R.x.....8.a..vE.5...-.G.A.4...._......$K..d.@NC.q....J.....>e".I.%...I0).R.I$........M3.F .
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
                                        Category:dropped
                                        Size (bytes):2695
                                        Entropy (8bit):7.434963358385164
                                        Encrypted:false
                                        SSDEEP:48:N9YMsguOZgKAz2vcaQU4R8r4BU0/Rc4nbIQdsohw13ZmFLY6KsVvMdBL2mr:/hsEgNz2v5T/rQC67SoWniHK4EdBH
                                        MD5:B23DE98D5B4AFC269ED7EBFDDECE9716
                                        SHA1:10AF507A8079293A9AE0E3B96CF63A949B4588AA
                                        SHA-256:646586CB71742A2369A529876B41AF6A472C35CC508D1AE5D8395D55784814F2
                                        SHA-512:BBACBE205EC0A4F4E3AB7E2B1DEE36FCF087DDF77C7D18B53AEA4B15984A47C64E19F9B8D8FA568620619CEA0361D94FE7ABEA6E502EC6ECAEFE957F42ED7EE8
                                        Malicious:false
                                        Preview:......JFIF.............C................................... $.' ",#..(7),01444.'9=82<.342...C...........2!.!22222222222222222222222222222222222222222222222222......M....".......................................,.......................1....!ABQRq.2a."CbS.......................................................Qa1A............?....{............i........l..-D.q.~..|cS.S...R\..d.8,!.....]f$....Q..di.;~5......vj......MqCe..=.*.f^..=.}.Cm]qCd..s=..u.e..v..t'.,.....S.s..N...>.d4'.,..k...N...d..9....G...y....6J.Y.l.{Vf...^B..i.3.z....:5W#4@.S\fj.%..Mb.5.v.5......S.E..#.v.I.....I......m..H....D..|.Y|...W.Wf..o..U.0.E..@.T.....................................'.S../...Z......!J..1K..rI...T.f.>.+.N..o.....\..^u........e..q.qK.GXP..-...F8".;5J...]Y......j.a.,R.......J.N........z}<qu..J.)`.}X:..}.............B...[. ......,B.).b.......(Y.O....c\.o.e&.W.#Bo..N|..N8.#J.>1D.1..b.&....q.#..UT%,.d.....m&..^...VXA..b.nbTV~.....^........q..#./.I..=Q..=..Y.*.Ib...VZ+......Y.........'.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):256
                                        Entropy (8bit):7.155554431622167
                                        Encrypted:false
                                        SSDEEP:6:7Miy4JU09m6i0XDWw3bz5p78frSJVgxGnFY22w20FCnBR:nYuDJ3b1p7aE6wKBR
                                        MD5:9EB1142940A975235C5F9C83A0A33DC9
                                        SHA1:1BD8824610CB3A4649E2894316E37343BA2F02E7
                                        SHA-256:B31FFD3948A641F716E67155BDEF3C65ACE1F0B377A8C918CBF83DDE8CF01756
                                        SHA-512:883624B68BB49E86FB05B8CC1C4F75C1339CBC2B1CD2129894D88C3729CE6BFD421FCF28E93C00FF10D7CDDF5A141DF9EED6E5C24103044BFC4A16E0578A8B47
                                        Malicious:false
                                        Preview:...n,..... .K.j.q..c.c)......du..........".aZ+..}..a%.`7..D.:....^D.B...l..CZ...d+..( (.{..+5....6R....[..9...;..5d......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):266
                                        Entropy (8bit):7.2186561442180315
                                        Encrypted:false
                                        SSDEEP:6:HA/hHKUUHGMcqW8ItZIFJ4msp78frSJVgxGnFY22w20FCnBR:HyhHowiBsp7aE6wKBR
                                        MD5:21BC96192E0DCFD5A2B3FAAAAA2FC025
                                        SHA1:1187BF9832533791BB9F1C9642EEC28855A7ECCC
                                        SHA-256:1FC54D4DE1E8CB6229FA3AFBDBDE5EF7CF51DCE61AC7A1269FDD3B8E668846DA
                                        SHA-512:ACC6147905884C219CE884C3EAF3B38227BFAE201690C338940B1558B33672506C79B1D3255AFCC276E073F0D1E7A453D8EBA5DE353D6553DB9594C467F7EC52
                                        Malicious:false
                                        Preview:........f*...>W.{.%{.~c.c)......du........ .a@+../..a%.,......V|....Ma....v.bvs1\...k...wV...{.5....&..eL'....f9..Ms.y.m.l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):10483
                                        Entropy (8bit):7.983530513730901
                                        Encrypted:false
                                        SSDEEP:192:RPZKIyE4/p/MISr8bLg73E78fF4VqvehqaA4IeqtoFD6LetS2VlKrpS:uxEEp/Gr82388yLqnLeqjLe37AS
                                        MD5:30845EBBBF180ED52E1013C05F93B765
                                        SHA1:46CFB04E849164993C06436F89C894F2BC80869B
                                        SHA-256:122CD9E484015F7D46F6691B66DCE6A6D4BB6EDE1CEB82221C92C6093D321D95
                                        SHA-512:4D71B89419B4D443DA4136E9E5CBCB46D039CBFD8DE3AF2463F755C559D879EEE9318F1401C3B75790E6F4029629EDD72EA941D316294313A813014978A9BF73
                                        Malicious:false
                                        Preview:....,..9e7...8o8..........+..4......U....Z...W.......9.F.....T..y.t..u.}}..ht.m......#p.jz'.........q*..j..!..].......&b..B..(.....($.K....d..F..D..k..n0...B.........d~....T.8.P*.@.#..!...=,j..X.......:...y..D.....8.z..../!U...yK...6.<$...M.c..Y...B67j..."..:...$.^?.]P..._..M;.%........9.4.B...T.D...?......'.C.S./.(L8...m1. s.:............x.....Q.....(...;I..B...n.MnD..q...`V......2O.+XL.^.p......k....U.~./6@.hC..5.~+.....A.1..!<.....O..x...P..]..[G...86.kO4....\lp).Gguk.20.....V.i9.M.-n..c8.....\..:..,..m%..7"T^.I.8.m.L..E&.N.(q..0.[*.uK.....&'...`.R..n/ ..Y......X..s.o..(....}_s^....Nz)=.9..M..m..83...~..#.!..(.#...........9A.F^.E.c..'e.z..sl.~.....>._h.....]..rv.......<.aM..*g.*|Y..8....|+.)d.....7..bc..P...k. .W[.j.-.e.........?..(N(.h.a."P....Em.cd......i;....X.. .."..}V.d.h..f.kBD5..@.....B.t.9.C..%).....Yd..0.......J4...bu..t.h.2....s}.....|......J..^<*/...J.....M6.j.G....U'=6.<_....+g..t...:.\UQ./$8/......1..-
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):24396
                                        Entropy (8bit):7.9921719728625265
                                        Encrypted:true
                                        SSDEEP:384:2tux5+T5w15jHlri0xRf7ujITALKPeTkg0CaT3i8HhTy+aBa0oJvCroyjzFxzSX2:qC5+ib5RRqjIcuPeTGCaThAa0oJAo8z3
                                        MD5:9E50E20428C28F0B8D417B56E483DCFD
                                        SHA1:AADD32E7B35A68BBD96847E983B7206FA22649E9
                                        SHA-256:EA8957ACBF5695D0E0A54B5DEA17F4EDE955A568720D05842097A3FCFC83267B
                                        SHA-512:0D9C0418EFBB9C25F5426056BB717C1EB25FBD5A9CA40470DF5AFC979055B19F6E6CDFDD8F14495D90F405769A0ED75774A29518DA72D07FBB189C977459FB59
                                        Malicious:true
                                        Preview:..FS.....$...7.y...r.RN.*....U........A..iP...........Q....D....uQ"Xl.."S........D?.N...]/.$....80.........:....;..N.;.......^22..':F.v...F.....(C..t...q..B.'.9.l.iH.X....{..7H..a..0r....zB.....R~....C..fQq#B>..b.!....S.......d../.t..K$.....t....".".%..WiO...~%}.,....."f*.....M.Y.\y.]>;h..h....!.=.`....@P.'$}...A.:...(D.No#...."..QoA._...-.=.]...>....\...Rn./..rR.....=...,rG..[..~.B..aYD.....Q...L.QE...i...?q..V.../.P...SE....T....F..4..k......Z..,....&...0T..~.s.K.)<..../...... M.$|...m.&:0...L%.q.....s.i.Y...9..=.....<.9..q.E..Vb....5...?@7.^(..K...)*...W..6...L,..Y..E....Ly.....q..<5.C.Z.1_..}.j.q\.Y..I.Z..lT..qC...KJ...5..".TC(2m.V."\..j5.J.Q..z....5...-H.G.%..L";.[....]%.....w..R......m3.].Y.....3.9.?!......K..rA.2xDy........w.>..%........["p.$..A....v.b......4.l.>..7#.Nf}....U=t..H^....../...Q.......+.aZ........K[$.1.Y%UT.7.._kC....o/.R.....z..`:..?O.....F.Q....e.JN...g......i.lp...8VR.. ..R1.xl.......2..p...~.f..t.e.F..p.3!{.J[...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):509
                                        Entropy (8bit):7.605156806181844
                                        Encrypted:false
                                        SSDEEP:12:I17xceFOSu+9l8D8kKo5SQunb0QDvcl+p7aE6wKBR:I11HFhH8gRjnb0e0l+p7aOc
                                        MD5:E54F8892B5AFAE97098F8AC974559B48
                                        SHA1:09F033BEF08F5C01C3938EB44C71903321C8F9E4
                                        SHA-256:20C0C1D190D353F76BF33CBA2BF25A3CE67C570C955CB35C01E0015F300523AA
                                        SHA-512:03269BDF467031F10C9B24B5E40960ED1EF01CF956CFA9A05BF6CBF53980DE656DC9963CB92CF275361F45DC5C5A7E57EDD58DCCDF39FE5013C9DA55A24522E7
                                        Malicious:false
                                        Preview:..!.&r..vr....b..?O....W..v.l.dz/2.f.V.XIp>.D(..y.Q.?oHR....km.[.h.+Yn.@.C2`......j.Hd...!...+.:...X>.s..q1...rV...."4y..t.^z..u...yv.)..|M...0y.....S4..l....Eu.E.=..j.0..r..Q..&.P...1v$eX&o.(F....U.....36.85N....1.z.d.=...|n.%......$.J.%....5...a.\)....:.h.nW........X.}..3%.,........d........J..._..y.#...=.k.X..g....-../!..~.A.?\.. .;.f......o......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):274
                                        Entropy (8bit):7.2268372270564685
                                        Encrypted:false
                                        SSDEEP:6:kl/uhcyfd11usEz71yidFJVkkFODp78frSJVgxGnFY22w20FCnBR:kl/uvfd1AsCpfdFJep7aE6wKBR
                                        MD5:B1A5D077DFD58C0B26F2FC667B9C1E58
                                        SHA1:B61692FD7056D8CB201A880C6870AFD091793EC0
                                        SHA-256:91EBD1BE68B7CEF9FE5D20210E24904AE7CE16FB238520B1BE22A8F0075727EC
                                        SHA-512:A0F465E64D97779CD6E69C3734E57C3FBAE75DE8AA5A5308C6ED6503DDA01C02A7B309D0B9D7E8CA4B53D2D01F19DFAEC4BFE45FBCF9FFA6B2923F447C7D2B84
                                        Malicious:false
                                        Preview:.......%?Oa...MK....XnQK!Z.......p.B)......d/........".a.+..}..a%.,...&v..`..d..RY.......'.T.6%.....!..w..q....$.\.{z..,..^....h......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):296
                                        Entropy (8bit):7.2682989957011195
                                        Encrypted:false
                                        SSDEEP:6:ehrjbNFHTrqYxQ4tHM4Q1YRQgJ/Ap78frSJVgxGnFY22w20FCnBR:ehr/HTHlM2Ap7aE6wKBR
                                        MD5:4F926D4BDAED48DA2064C88C10CFE08E
                                        SHA1:F132E77476AD2B0BE697316245B88C7812E223AA
                                        SHA-256:74D82C216A96D84115F85679DFB52D8FE70FAC6A6931590CCB3899EAC4C121E2
                                        SHA-512:CFA02F1A120E0144528CB021FF170F5777626A2BCE53915CFC949067053A35C9FE7C39CD433FD059EA3F10FD9FD2F2EED1A42EF42AB4FFB263F01E9251E2EDF8
                                        Malicious:false
                                        Preview:.CN.9.*...E..*{F......&%+z...N.[.g.H.....z...e*p.B)......J.(......... .a@+../..a%.,......@...T....mR.a.(Q.P*..w..?.q.rD.y...l.....q._....Z.Z.......$.,l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4456
                                        Entropy (8bit):0.44151616269007776
                                        Encrypted:false
                                        SSDEEP:6:zJlnulFYyfhcD1RRXUn/cXJGvgN7q+J+/KRujslll:zJlujYyfmJ/U/cXJGIhFw/6/l
                                        MD5:18E52A0B472A5E81973AF549E744D0D3
                                        SHA1:60349A83CCB0BBB33B3C7EE066126B7B8584C98B
                                        SHA-256:B89BDBBFD4062F3009719721A9C6C5B46CD143A1726E6F809D20BB3F3965D29A
                                        SHA-512:8F65D22CFCCC1EDAF6FBFFF019C43EB7109100D4C8EC8D9A60CFF6C9B45B9D51EF3F41C69341004941D35BBEB84641AFF423A4EF99EFAC217705020B425E61DF
                                        Malicious:false
                                        Preview:.%c....L..=../\...9*.C......a.................?.....I.......*...*...*...*...........................................................................................h...........................h.................oH..5D....{Y.U.........2m..5.J....!.C............................... :.. :.. :.. :................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):267
                                        Entropy (8bit):7.216267924122487
                                        Encrypted:false
                                        SSDEEP:6:8XRn0qQFyIT8Yt/pOm/30VkT+Fsp78frSJVgxGnFY22w20FCnBR:8hn0AIwYRpHdK+p7aE6wKBR
                                        MD5:41DD3CA3C377E134825E45EB289D2D94
                                        SHA1:8056AB69B03646D3D62BA080318ADD8EB81129EE
                                        SHA-256:CB4498490980DE3E2ACDC6BF05DD886FEADBFBFCF8366A8A339C9347B6D444EB
                                        SHA-512:8F1EC62249DD783FC774CD14A4A779EE03E590D34BCB9037AD7BA9D62C21BBAD42A386A09F0CE02B12BC6D28316D691C6591CA5CA3C451DC3F4C9C22E9BB340D
                                        Malicious:false
                                        Preview:-yYKN/..^m.a)......J..........R.&..J..C-.........d..@..SU.+..2....T.xb.U..Q+...5.9.&..$J.6= .......+0.`s..S....=w..K.....{......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):2455
                                        Entropy (8bit):7.925089056268849
                                        Encrypted:false
                                        SSDEEP:48:qbhECBki2cvCmTSur50oqnCkRemh0g09U1LIqV3q9WpJc:qbhECSSbSuVGCkR1h041kqV3HpJc
                                        MD5:CF4895A1B8A35913057CDDBED8C84256
                                        SHA1:F420CD6F0FE72E1EB1E3BF85CE8F57964EA88543
                                        SHA-256:CBB09890126F2C997BADD19B840643B264675055135ACC82A8FE0D3C22564442
                                        SHA-512:02C012B132414E52CE3CADC94E54B32A2954426779B6719C891D330B4A6D3C121DDB684E7619563AF735DB52384E06D77556445CA7DBB59F954AD7C4650463E1
                                        Malicious:true
                                        Preview:...R.[.v. ..=.y..Aq.v..P..R9..<.....hNt.h..d......%.Q...7+...uS..1 ..H..=` ..~>..].v...<..T..w-..zI=..x%1...:...j7..C.Th..;......5WY.x..qp.G..x...8.h.p...!...\?.O....!......g.....kg.......(.....D....ej^...5.D..6.4.^...B..)..w..Nb...........;4.D....."]...NJ.v.,..J;.1^.En.H...G2......p..a..xx..f.d6|...%_.|,PFj.]N...o....1.P..=........i._Fd..azj.%...{......D......cX..;,1a...J..v...[R 6)+.)f_....:}.q...\..&9.n...g.K. Q.cl..#6.4..n3c...`...s..L....'...}...]S....C..W.........kX...s....8u.../+..w[.. ..{..g..U%..G.L...M..&........-C@..`.Q.....Q....d.O..8.^YK.87...c.T.i.."......{..9Q../...% %..F.f.W....J..@.. . ........R.........Y.^../...z+V^..$.A.zC..r.]. _PJ.j../..f..d.?..N..DG.e.g...2w..t.....Z..@..9.7.t.....8.B.V}...nu..H.%.AN....?......p.<ud;.F0k..FA...9"U.0L8rFU..:.F;.......uSB....!.D..Q;..j.F......^<VQ.a...C5q..LZ.dOO@....3..}]..p........jP..m.....8.y]#.....Oa..R...|d\...~"\g..3.t.j.d8`t.b......nU..1C5.;...e.x.?c.Z...T....o0w..H.....A..Cc..S?.>..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):899
                                        Entropy (8bit):7.76076983683082
                                        Encrypted:false
                                        SSDEEP:24:ypeZnAYr9nIcyHUIUmWboU/zjtECaIgqp7aOc:yCnAYrh9W2aCpJc
                                        MD5:C87FFC90983EEAD988853323C6AA4137
                                        SHA1:F59F38696FB7CA271F4F858B30E07C2FC7E625F1
                                        SHA-256:A193C4CA0E49BBB39F2F0547906967B2BFDFA7B8D96F119C8E667252C2426CBD
                                        SHA-512:2BD2FF68098394E7CAABE79ED27056AE7C30395CB5A1098A57B125114F8FF9D2006C462A36E261A0D683BC91E94D5820E1B3851031110B400AD8C9728709D556
                                        Malicious:true
                                        Preview:8..cO...M1k.s.H...)/7>[x.....k.......0..._m.b.cw..:E.f...:.O.....f...._~&.a.W 4...}~<..o............j.!.S...C.J.|2..].|.s...3?._......EI+..U.Z...j.q "a...WZ...]Q...Y...R....H.o<b.u.Z?....n(..k.$.R....l..CivK...$...b.{.Sq7.Ni..S.|.P.>. .3.;.....U.@.......c..^,N..e.<.F..H/.4O{..e.^.nu......C...+,W...Y.K.....G(..G...8_......%./.y.~.<.b).+4.z....3.......[.....Z.*K..0..).Z....o...W6...!/md^.c.T.L...8&.....@Q.5...Tf.b...J..N\....sc..}.g.}&...0....QdOy.....7.m..(....7.A.....E.(.Um...<....U.>S..c.1....R.....V4-3.g-..?.FTbn|V!V\....0VyT:b..M2..)ao.^......M..[.G.J.Ab......1....OJ.>0tb.=..:.V)+.m.j..?..fw.f)........90+......w.....N3..I.,6......d..@..PU.(.~a.fS.......U=..K..m|\....<..0.G.h. .1.:.D..fb.g3..g......_x......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):262394
                                        Entropy (8bit):7.999267618514347
                                        Encrypted:true
                                        SSDEEP:6144:aTzNBdk4mDCUqQBQKWul0bmyb9G8WD4iB0go1pG1xWf5WZF:yNvmDCAQKZ0bmyb9GQa0g2pKF
                                        MD5:ECED6D99E96699407CFC85E40C5302EF
                                        SHA1:06FF5A0FB8887F403F550F0168AB4FAB80671F68
                                        SHA-256:E4F00C469A6CF50517EE39CF33680D63B4FA9F446D7EAE46BEDE3C076CFB2A92
                                        SHA-512:5246922C1ED042F0B00B9BF448678AD6B673EB7DD2151AED442A52246B334307BF6DF171174E68550E3D5B8CBA41CB9A16D5401A77F27CFC29766B3213343F05
                                        Malicious:true
                                        Preview:3....E...oW..^..7.....SM..t.0..i.....i.d.^+..|b..V.A..=.$.+D.wB... ..Dr.= ...<R.8...J.;5D..y.U....('...!.P.`....,.u.`[....q...A.j.[.Y.C.Xn.=......(Q7..{A.3m.*9....B.:5T....f...........^..:s...P....Pf......t...~...........nB..b..k...C..8p./A...jv/..s.$...f.dQ{FNVNB.R...x.DX.0.:.K.....f...l......t...N..yc.i~[..'.1...v.C..U...{*..........Z..jh...o4......&5z...=....9.4...6...w.....(....^..i[G...B.i...&.nn.;.uEt.1...#I.#QH&y...{...X.T'H.G.M@.+x3.,.%....x.J..&.wJ......N.......`...$h..uZ..N..4..%7..Su.}....K.r.....~..iW..S%k. ...7...#*.*....5l..N.lnR~x.#(../Dt.!..&...b.JP.[...s..N.c.....F..U...i..Km..0G.*.............p,.`.7J..v........V6.{..A....d....$L...+.v.Q....~._W....VZZ..(.RE ...=......#:...".W...a.a;.T.M+e..N[..v.vf...........Q.....>M .U.Wo.v'.%^^. .q..4s.....C.....zC...........~..*.C..&.....>u.xF.6..G..gU...Up..X.X..Y.......bN9b....../f.........b....`}$.. ..iS.\ ......d...|.E.H....Ak...cH.....VQu..f...G....z.6*...<..(...qR[..b.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33016
                                        Entropy (8bit):7.994165072225745
                                        Encrypted:true
                                        SSDEEP:768:eqJ8k3S+vP+5o2Pohx2kuZwQP8SFQTOU0ds9NnxcT9LJqJNb6k:Ta5+n+5o2PohYZwQP8SiTOincCNb6k
                                        MD5:2FDE5C615941EA1D872F362C252F21F4
                                        SHA1:C2EAB2E1668D22613F0DBF5E34EA57A6FED3CC9F
                                        SHA-256:FE3477DAF78F5C94CC1D9A1BA0320D97373AA6C7C3868A2D3E005B6ACD87FA79
                                        SHA-512:7C628646DC9AE02806B6F3D1D0295BCE7AE920A3FB199F387DEA3FD9D41669798F8B6AE0A224F25475484D5054D45F5E7B27C16B8594D95B3999300855B9EBF6
                                        Malicious:true
                                        Preview:..3N......s..m..WO.BPuI..9`..Z...]vb...q...<..HC[...HG........VY...5?.R. ...K[.U...\.P.;.N|s.y../.O#TJ..h...ra.e...............9J....G.........(..V}.........L.....%.C....x#b.o..@..r..P..IJ.....@.E....<.....E....*..F.V. %.(.YTK.).....E.C....$ q.R.V..k.\..gAH..),..D....hiY..-.*eY......S.i.....L|r....]..X.".X.......c.F5...G....5.....l..W..5..s.../w.3...N.>.....d..n...%...DHB.#. .A...'cAX,..X!.&....Xp.@..K/....v........6..,.lZU....f.,wG.bT^.Ko......o..C..."kA....\.ku..h_o.H...Be...=..Z.:....{S.......F...n1..3.. $.>.../..0*Z.K..x.?.....T.y.^.}...G...Gu...w,...q$9...l.1).['T..c.S.l..|5$_...z.........V..6....=.U.*H.....[....[..v.S........e.!.;..W..c..x....=..U..n|.Y."..Z.O...|r.Np....(.O..H.....z<D..=..$.~V.....af.2.+h....Z.e.......iL....z..`.."i.#...i....Y.o.j,2Zf...P...U_!auv....Vk..I..#...(.Z.>i...h..k...O>.T)..$W...|.@...BvV...>..N.......MH...\..5..3q.u..Z"..gC".....h.U.|.).V..h[...-{i.E.....1.....1.V.R....{.t...f.~~....=lf.2-fcC..*......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):98545
                                        Entropy (8bit):7.9980354342045
                                        Encrypted:true
                                        SSDEEP:3072:Pf25At9NFQdRJ2Tu80cC8tGijZSppmWXc:fx8RJ2TpJIppmz
                                        MD5:1CEC88423B4136B5E6352E45798D14CB
                                        SHA1:BCE394BDDDAAF0DCA7DD95312A8249C29A826F70
                                        SHA-256:F74A50A54F8F5D504AA4FA6D69F2F31AF5E7FC2A75A89B1B79CF0895448D7506
                                        SHA-512:3BF44B8B104783CC78AA6CB3D04EAC72EC2FCCE82D09EB61AA6730AD9E087214259A37BE6DD2C9E00C42BC5558FCBADD577F4A76342844F78E3E19F8EBEB9AAF
                                        Malicious:true
                                        Preview:Te89..~.J.'..$........m.y.l...o:O...nD.O.A1I.x=[f..k...):SP..F3..X..\...!_.#.(.2Dz|../...<..7#.d..W9.t..pL.....O:.....}..!08>e.JEn...'.W.8,.o.G.a..De...8uk.....i)=.of..Dd.QV8....N.-.....L..a..H{C.%.\a.y..S...bXX.s.X...-X......d2..d...[?..#.F.p.B.k.x.!{.......w.....l.>v.......B.@.s.._.+...Gt.*p..5...9<.`.Dz.W..R...W...N;+sU{b..J...UT@.D..ZV4.v..6|..v^?...p.J@..T......#`.lzloF.g.....3.w.<#4k!Fp..;.3......(.-..P...K..R$./..A..<}.w.C.h%..7.e.....f....N.3<........^.j......>..\|.....Q..>..K.*iH.....&...am4.....A..Z...._]-..C.. ..O6...M.R.....`M....h.X...)TE....ArA..X......x..A.J..3he.e8...uK....U.. ...Y...........[..[+.8F >$2>N.F.U....5....;WqR|d.E3TN.....0.=..Z...W.-K|j.8Y.h.Jh..XL..vJ.._...kS.k...#...;.....1.$P..K.$c&U.....Hs58..@.G.x..*z....@=*...h........_&K..G..).Tkl.y............U..-....y..X4....d."..z9..sk...6....9.I..t.n7.y9.a ..)...Z.k...]....h.....Z4..].1...db.b.^....=^}.obA.gjJdy>.FV...5.)..;^..........N.8.....L0>l&{...N..4.\Y.Jqq#
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4096
                                        Entropy (8bit):7.94986420743742
                                        Encrypted:false
                                        SSDEEP:96:B/RJJhgmeYEPFan1HAqNjEcs6wOqoriQgHnMpJc:5TJSANv7wOqoriBMpS
                                        MD5:96D1E2DA62503531526C2C14A09365EF
                                        SHA1:ECE7583CD9D8E015955035D43B5E6F1688F940E7
                                        SHA-256:BEF1C6933F802D8D2BD91469A48A0850F33145F860258E2FE82F5E3864994DE2
                                        SHA-512:61519FBD8A615FB220C52E46D84064AB7DB424E6D6514DC7B92F57A6A854B61A90BDE8373B056B43B422D03B2D2382FBC75EE2971A9725EC48CA9B7B30CF9251
                                        Malicious:true
                                        Preview:...y...o..K6].*.0JTK**...W.'..=&lQ._J(...z.......l.H...Q..{........1...7R.e.........P.ZfEb.e...X......eW.....3.v~+z.4?m....%;?..nD>)...._$Nd....2.'.k|..?k.F.;.z....,!.V...l..A.]d..,......{.=bx....G.i..........e..F.rxj.Jq.N..{.a`........U.LHI..|.k..N.g...m.Q....W.6..p..$...3..S..B)}O.m..7..tGP.`.....S...~...*....XT...........'KV.^6.6.I..*.>N.0.@.d..Eg...C.I..Gs...a.......ByK_@>7....P.NH....).~g..#........)....oSs."0.cC.>w`..._0m.N..j.,U../Rf.z..|.C#..."w._C.D......'*V...7..&c..aO...)...mp.\....}...).Ib.v.=.8Es...`W..g...!.?X3..k...0.j..f..5..N.|.}*.Yy..."....=B.c.. Z......UZE..h.z...(..AQ........tW.`...>.......2....5......?6...c.$..)..)..v...eI.....o.}3,R..\.....c.5.H)..R...M......k......M.K.#BDPu.......'.:...m....).I..b.U..UA........@N.B.N.n.fm.....C.....9..k.n..5...)......c...C..Wo....=.......z5....dc..G&.......x[..^.T...].|@G....o.\....-.9l.mYpvx'3t......R,....G.q.7R..,,..5E.a.Nq*/l...~..T.].F.4...j{.$.t..pHRi%<...M..H *.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4451
                                        Entropy (8bit):7.9635932789738
                                        Encrypted:false
                                        SSDEEP:96:b+eDGEpRNHePpA1S1P1yBiT9eOJeXVkrUkBQ562a+6zGLfpJc:SszpREZ4Bc9eOJskgix2acfpS
                                        MD5:2630128E93384582AFF74817F5027B2E
                                        SHA1:08F5DD33377950A173F0BE7B965CB911A3E16719
                                        SHA-256:2EF3FACAA2C65BD991FF256B02130B65DA4E77BC644B872EA00EA108B262D8B2
                                        SHA-512:99AA378815F3439D54C67D1CD2B02708630A30F030FA990C3F4BD6FDD2B5680E397660615AB11C5BCB125A16AB88D00886765A175EDF113615869335069F9183
                                        Malicious:true
                                        Preview:6..so.....Q.F....21.J.......-.#Sw.:qG.a..O..X.=..W.`..(.:.lP.W*.wI.U..3........Rh..._.k)..........j`..bf{.._6.9b..<r.^3..|;..i..Z-...X...@M ..+...N..VQM:.B...qz,.....=..F..A..(...-..~.d.w9...#.3G.Z....h.;...|.!_;b.+..?.y$:<..@w}....-..3z. y..S?g..{.....X.f..N......n.n#X}..(.1..\~}....[&ul.....]...*..=Y...m....V.....6..Mr).i$;.:-Cx...m..A...G................3`.r.f..Z.<.R.'xY#|..a.Z,.2.i.........M@..#.\....s...H.O..C3...yV.>.Q.}!..-Y_.]..O..7.B..FH...RE...H...f....b......s.VV.B..n.=....K.6f+.IdNz.....];..$q..X...._....9k..k...=)b.S.O.,7.I..L._..}.`0.Y.6b.Pfl[.5...+...+e .jW.|...u..V9.Z1Z-...:..E..[..Wo..H.R(.b7y.....K#.M.E1.!XJ4K..oI..6...............;>.s...m..4x.}Z..x^.].../.......,..A.{...5>....Jo..r.P.....-N.C..S.U..vt3.Q..a.2......,.h.F+.P..mO.do.B.f....vc~Ux...%6A.}W.UN.P*.....E.c.....8...t.N.4j.......<.|.a.p.}E.{O0/.P.]W7k..ej.k!...Rl...-:p2.hRG...y....W0~...@...i.....>.E.oM:).._b.?......,t...................O....*.T..^...XP
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):18681
                                        Entropy (8bit):7.989348711601353
                                        Encrypted:false
                                        SSDEEP:384:kBAVcDAhkn2GtDtFPhFNc1K63P+ihXu4UbiWAE1Fj2uGgQvuYonAS:/jhkrFJFyJ3PvVWVZouYoH
                                        MD5:2B9AE667570AF8CC4C8F8B27456AB6D4
                                        SHA1:CAEC9156F2A43EBFB5FA15B4B284C156E747396A
                                        SHA-256:6E5F0637E5B8D23BB1D8401A4D73A96E4512D3E6E629B66F2BF315D8F6367164
                                        SHA-512:E5DA7A04D14507531B132F2D665B9BFD5BEA314C6DD007BB56A4C5D5C3312B59CDFED74985A5860E6AB2D551380DA35A4AF0F92F7CB3663842BCBEE294C5B285
                                        Malicious:true
                                        Preview:"h.......l]..:c..h...B.m.B.{.c...G......Dp..ck..E.5....N..2.a.Xz..c...\..;.sJ..<M....}..(...@.B..l..W......LK..N.+V2Z....C.L...q.kUN~.*.b....;M..,.......~..;...>.w5_.....DhX..5d%-.;.....f..3G....)...Cb!y.r.%...k/.]..i..^6....Q7%.3....G4.Qi..z.....w.U6.l.tS.2.Ot..x....Q@.....a*.3.".n.t79.d..8D.l..pJ......#v.~.:.Mu.|.Vk....B.Iut7H........\....0q()....'.rM......Uw7".<...d..R.K>...|7....+.1.Q.l.....g.....a..M76\...].g.s.(.7m..n.KPv.m-..w..,m......3&G.k.r.......d..%.eu..)w.......QD.....^.3k,r...1.HI...B$.Hph.\OC....... "..i...W.Oe...opd....3...ve/9\..7z.-B....1..bl....A....+`.U...-m.jY.S...C.....id..HV/.....~.)S_..q.u..s..(..../..<Nj ..M5...&.g...... .D;.}fjp.B>.^.A......f.%rQG..Z....+.E/..."..[-....._...E [.}....)Y.Y].'M(.*....&...&.N...2?...r..,=.G...o...._5q:.k..MK.KXa....k........d...+....W.a..t.j*L...........4....KJ...,.B*.z>..K..n..JnH3.. .3.GP.~5Up!;c.........:F..<....^.}|.P..5...Gbz......IT.-.9...Q.v(....)..v....I.1..vC...yjE8.O.."-w..1..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):18711
                                        Entropy (8bit):7.9917847241655355
                                        Encrypted:true
                                        SSDEEP:384:yZA0tG+BdK3s42RC4zA3GGnHUU6vI0lSj5JEKQkl7XttGvvJPtL8I+u7ktqS:yZAT+BdKc42Y4zAbn0hvIQStJBlTtt2A
                                        MD5:08B29C25A56E6DE77507956123F5CC76
                                        SHA1:7C7B6934D964CE2EB9199F75B9BA87F0DCEF29A2
                                        SHA-256:9F7FE3FF365A7A56B9813A7A851949E4AC1BB2375AA66D8777F3E4B8D3DB4CDB
                                        SHA-512:9933BE9412AFA669070B88D266AA840E1BEC38F1813CB9E7F742321EAF9A67028F5B391EC059C392A9FF13F275930C292688D3EF9742BA01C69A328920103ED6
                                        Malicious:true
                                        Preview:.:V....n....O$.....z.1./.`...4/UU.......n......V9}U......Cjrd$?...$B&.{....z....l...M......OnQ..DL_.....w..g....C..2y.O.Y.;=.#".G.P......*.W:.!..?....)w)'<?Ug>..xD.8.L..i....Lq..]>+....N..`.X.wl.Wk&~.vX(...d.&..IRN.!..rh..H....!.$5.yO64.7.2...z...'.w@Rf'*.r..AaU...o..._.q..="+.......e..{..!"..W..L#j.....>#4T...017."..U.(.=..G..X..@.....F.gr=Q.4.*Z...rb.....Z.4N....fotf.....gU2.=.M.i...|...X<{.."3.s.+$cc...g.G...>.....8S.;.V(Zw...<..Hz..mwXy.Ir.._..y.....go.....u.M..N..k....q&7...G..!G{6.......['.f'b....d..U...;k.t8+_..x.Mc.Z..K..#.pf..4PZ...oC.H.<....n.N..V....;9.9N.-....9../.&..J..o......u}!..-;nh..8..T.L.!.."mE\..j/.R>0.w...X..2)...8.}.q'.r.....j.v.:..R)..|g.:b9Z.w.Eh.]]V......1.z.....V.....Z........M6Mi.f...:g....m..[..z;.;..D.. y.Y...UJ..N-......BEs........,.Ps.M{#..Z..`.S.w_T".D..G..z...F.Q..P.%....U2..`kH]1.].NWLT..]..m...<.-........5J..J.+.....o...#.......".u..C:$x.F..n.l.......v..y.~.....E....Q..#5.......F..Du.<..;..3.....E.....o
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):751
                                        Entropy (8bit):7.735742610743448
                                        Encrypted:false
                                        SSDEEP:12:JdC+WL5j52wmMJjRz6x4dTWpUUglaLGygDLjTm1p7aE6wKBR:TpWpwbMJNz9q4ne1p7aOc
                                        MD5:4B96567F8CB1701DC8A9E3555C061544
                                        SHA1:BA78F7E3E67BDA2D67FBB3D21D6976BC1EDF02A5
                                        SHA-256:6E9160C3A6FABC6FB82F7EFF2B4470A68DEA127936B1828E63F2C73787925BB2
                                        SHA-512:BB02A27039A5E1594C0A6BE9FAE81AB6E3A6F4DF701216B77EC281381E81AEBFDF6175FC5B19CDC06291604D1C6565FAA67A1EBF24B3FDD4E3FA179802D6A5B6
                                        Malicious:true
                                        Preview:i.2I.$#....[. ..w......xF.X%T(Q<.+nV.<.....e...?...X.G>.-...{....d...).vd.]....T.,/.C....r.\...W2S.T...b.......j`......f.W......I..2.......z.}F....D...Q... .`@<.|.....}H....G.I...&.....8i...(.gR../3... @Fl...].....U....8...........q....4..&m.4.E..E...z...2.B'..|0#...D.^qqq..Cu`V..%.S0.0x}X..[&.qW6..P.j)..........Q@..er...O;.5...D.~KZ}-....1.w.F,.....~s6.s....y..F.<Y.4.Z.D...h..5(.?u.k`.*N.yg..0zJ.LD.#g...`2n.../.$k...9). ......T1.......7.m"..@0....y..:.........f.....7.....-Ro....e.$;...+._@..."v..-..T.*.....-.82k...'.s.......&...>..}......l..S..6..A'..Wo...WR..!3../.VG...w..#.......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4444
                                        Entropy (8bit):7.948456047993702
                                        Encrypted:false
                                        SSDEEP:96:EBa/5nc5Ca78AsE+eN6VGwCgdelbX5+wP+99EYv/Vu8dt2pVctApJc:Eox1a71JEGwheX5fPkvdu8z2pVOApS
                                        MD5:6C825BF75B80E638D91C235E5335A61E
                                        SHA1:9C439C53533E0991ECFCEBDF40E0F5EE905A8870
                                        SHA-256:EDA4D56868EC6A1C1B1C30E99054206BE6A2E8CE945A79EE37C40F6B45F9F7E1
                                        SHA-512:245B2E44B7039A18E9DFADC69816294A35711403233C8C711703F8792678D87BDEFC7FE102DE3620B577A114EA09652494DA4244AA827E1396E9EEAE4577858C
                                        Malicious:true
                                        Preview:...5.@.\_..t.g.[.AG..C.E`.......b".......?.qd..5Qi%S........'."..J.Y. ...........$..5hP..g-........;.......C....0.(.[..M..#..x.Mb..[..@.......Rm..C.oM.p..E.$.l..?.Z...`>..M.\..|... ....k...x.........E..L..w1Rv;.w$.67Pt....A..I....z.p...M.IX... Ap.T..@k..+`3!.0.E.x#.[..-.D..+_"w..+M..}....T.:..+)!:.....21.x....|KX....F....Z'....=&.%.(....z1....%#.F.>6T.2R.{.K..Jo7.9....D..@.....>[...`.E...C....k..^.Gq.Y..b..JD.6J..?bF.......$..C.7......o..z..Fe6/.Z...1.6d........e^M.E.U*.%.~d4.=.E..R]......S..M.y..Jy...h..Zgn.p.X.......'.uj..wL.6L.9mN.[..tj....e[...o%.........um*.;.....rFb.(k.j.!Z..._...IV...-+.....Jj.d.u\.%Q......[p.0H&.....w..g..v......Z..3....."..Z.F@.1U.l8.N. ...j....m%"o.:M....i?.I...'...a.^i}..k8|..a...2...lE.p;5.V.p...5..1.LF.Y.NX.2;z_2....,w)...s....Z.F-...G.ZB.]..........`.7R#.....m.U.r..V......8U0..-.[..S..6....J....B(...Y....T.F......J...O/.p..,]_@....j..!;.,...9...^1..&..r.{...E....1..A.^.c..|.8.x...2\B....pJg.O.<.8.Y.KM|NO}P....Fk?j.?p
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):748
                                        Entropy (8bit):7.6722723303133815
                                        Encrypted:false
                                        SSDEEP:12:jVfmYcSY63z6f8xnAv+8FcYfPzX4VPNmaMQ8aTI1XIujjqF/PiPl2Fp7aE6wKBR:jVfY6D6UAvzFcYnu13f8qI1XIsL2Fp7O
                                        MD5:49EDB3B09CC1680B98FC2303C5040C0E
                                        SHA1:FA91B74862D9405F0BAE2A595A70D3E605BF7FBE
                                        SHA-256:9056638C9995029062330133CA24BAD2A220333AD728E6A7C85A36C0306AF638
                                        SHA-512:9AD12A0B696857FFC5C12B74D0DD87266A1681F55D0F391987BA45AC3EC77B5DD3D5CC5790AE46F6FD44EEE91889C8D174E50FB44AF663030E884A2CEA8AF653
                                        Malicious:true
                                        Preview:.G.....*6.?..u.a.dR.U.G.V4.M.P...e.xtOU...z..X.....~......7zb.uk.B.;e.;..f...YuD.....y.....S.w.3..R.vE~.]...<Su$"hu......F..".;......E..sd-.MN....R..*"&.o.,.=.)\..N.d.j.........e..MmM.[....WgCN..._W4_sf.......N4}.L..=~~Y..}u....nb.]...A..e.W)i........]GS.1j`...]...'...VD....b8L&..ol.........Q...`.F.(L..Ri.........d.....,...V..s.N...u...:.!.n..^.c..LE.....H...w.x........... >.r9.....2aq.....{bTh...:...0.........+..9). ......T1..........C?[....$15... ..........h.n].....)..9/"....U..6":..*WK..v. ...-....*.......;27.rhR/..2....Y..L..5%y.d.".[..7P... P..U..o6Hy.2........:.........f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):15298
                                        Entropy (8bit):7.988363319962991
                                        Encrypted:false
                                        SSDEEP:384:2K0zyGdfKd5n1HoemNO1xic8gdFPRsGnfYrqwL+1sLekus6S:2K0WGl6n1HBj18lCmGnfYGsiy
                                        MD5:F06FBCE454DD42A23E51C54494577249
                                        SHA1:8A83D3F996FC070E207151773B92EA457E857735
                                        SHA-256:A730DAE5599B5C2A3F25EEFBC290FC35098D104BC91F9C01280A16B3CB9D7802
                                        SHA-512:FF579C6F677E24C712611BEC38ADCF098BFA9AA78BEABE849893AE5306104B9944160A4015FC8EBF78696D23239710418AE641BAFD037E46E709EFA95DBCBC8C
                                        Malicious:true
                                        Preview:.b+..9.3..5..`r.k...,.I..xX...~#.o..".5/....x..d...A./.E..)>.4.r[Dt..w...'.._..n.^...l.&b......T^....X.4..;... HQb..VS...,....\cpp..&..Y.......0..2Bu..... .;... w..,/.........NT.;..x........Jyp......z.hz..Lx.Lr.H.x_.N.e...9k:3>.X..a.{........W...*...B../*..&"...../...a:...6Y..G..F.nKL...SK....{..[.K.....4.X..=..5,>|..p....K@...(..G..J...07./.h..t7...nX$(..+XcQ..B_.`...f......n\.q...OL...GN.....>.=u.B?].......2l+.....P.....,[.W.....:.#.&.G.c..<...~...].3.....W..y.......,..Q....MyZl<......*"...6.!C.z......J#.......k.@.%.b.r[p]9.P.....&.....C.`tjB#.....[......X.5%.Q.c...0;.n.}.-1.#..SV..eZ..;g'......../"?o.).Qv!.x..V6..._.y.cS.:..q...F}....S!|:..L.B.@<./t.1(.f.rz...R.....<k^,.......F$w...VA.G..-]...-.I.x]w..........W..........gw%.YU@.T..4...`d.&v.....y..s3%......d..1.......Q......{4.....cl.^...>.....s..t.+.-...T).:..%YM..@.`J.Un.....lC|G'...A7\8y...hi.O.b]. ...w.p..v.kz.A(dm......V..,.....$.....EWz\!...v.....u./.M^.h..l...~.@.&h
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):700
                                        Entropy (8bit):7.727395473300721
                                        Encrypted:false
                                        SSDEEP:12:CwfwfF7K2YdSTkpRnzf8M4Dp7qffjNwbh1AuKYLrdrh6JCp7aE6wKBR:CIwfFNYdSQvU5Dp7SjUhmAuJCp7aOc
                                        MD5:33CDAE5146D813B631AC4AE0D1934A6D
                                        SHA1:CCAF00453634D27557114A2E843D6B9484DCD8AD
                                        SHA-256:550E0A355AEE1C6FA1D935FAA913D0C18C5E2D5C2B92BDA7C35A5711D38642E3
                                        SHA-512:4666AF950BF90E7564BF0BDA6664DDC9AAEB2D3E0C38D00663D0E7232414FBBD7C85B20864DF6E978B629CE6CA46DC07AF06694A1EB3A8B5142E59FE0991DB3A
                                        Malicious:true
                                        Preview:.7.......\...Am....FP..........P@.....6......|=o.Z.."{Gl.:....=..1..g....u..8.?.N..W.1.L.'.<.._-..q.0.N._=.fFO.....?...g...V...6.%.g....Q=.f?7*.0..+...[..yx.+.e.....v....".%!,...^/..o..W.:.k.CmZ...i...L..z.....`...$...jL8.%"/... jU...S...[..]B..........}^@.%..bJu..C..!`.y\....p.Ws$(..e...ant....k.Z. d.!.:x..=<_..T$?0.clR...Z..L.0......B.]...w$._%..}#..=.....Y...._.......%o......n....x\"..Ko.}..L...k..n.@@.?+....c$....I...FyF.n)......dn.tv.R.@. .R.U.......@%.~........d..@.....![.*.l.K3...RC....!..#q..{.1.C...E...UV......)..5.+t.....s......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):755
                                        Entropy (8bit):7.7240545468542035
                                        Encrypted:false
                                        SSDEEP:12:MUx7AUr/f6bntSBq311JQMgQYf1sBa06qPU+11Z+WunoYfep7aE6wKBR:MU1J7lBbMgFTlqPvp+gp7aOc
                                        MD5:3B0B3AC89C324E7C412DB8C85B0FF720
                                        SHA1:EE463FD574987BC72539340BCB88E26CAB90BC96
                                        SHA-256:9CD47EE2A595C39141FFDAC78ED2AE669EF4478E167AA00C2FC3559070655DD5
                                        SHA-512:E44C2DE7BF17918DC82A54C59464D1E07B35BBC70904889C580B262F18C9BDC43B77B7F4A04E9F4C59FCE1A866ED05FEB809E9ED404617823BEF9CEB6539D4D3
                                        Malicious:true
                                        Preview:./.\...`.<.E.`Wn.L...}.X...,X..1.H..qt./C............j.....;..?P.AD./.{...Cg.+../.=....2K,n..X...WW2;,ldrFH...)N..> .$...g...../C.....v.k.T*.`.....gD...P<.....aG%..O.D.i.+i...^!......... ........K..n....V-)..g...6..^.c..D..r..8.R.$\.LS.....b......iO.T1....B|.~..".?.j...GoRX..v.R*Q..,..>.. ...k.*.! .........k<..v..b.c....d.....[..(.V..p./..uH..t.F..3.]..-.......&T.....!.].<.....M-?...-.....I..I....&.=.;.^k...@..<..j..nR.Y4.ako..G.%..2.%I...{Isz..0.lV.8+....@.0......n.l.t.Q..b.Wh.l.4O.-.!.+....A.y(N.4.....E.......".aZ+..}.Sk...&.t.6..w...l........6DR.7......o...i{...........;..r..6.`......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1946
                                        Entropy (8bit):7.916535358042388
                                        Encrypted:false
                                        SSDEEP:48:5304eyPF/Kz3hQOXYifJT3QGcx+qtGxDNN2mpJc:5UCFCDh1I6T3QGcx+qiDNN2mpJc
                                        MD5:B0FFC82A87E6295FC05B919890AE24B8
                                        SHA1:FE0EBBC8416C33DBB2BDBE7BAB9F38B707FF843F
                                        SHA-256:6B1276D520A9C4D48B88DC771667F79FE54B72AF61BFB150308EF9CFB536D608
                                        SHA-512:545FCC5F6A270DA158076EEF5463F3828D1A14D8C940CA58D29696BBFAE12013432EF5F23A365FC6D400379EF93D6B6B2CBCBCFF15164587FED7A129DAE9522B
                                        Malicious:true
                                        Preview:.0P...k>....'.o..IiA.t=..@*.....|...{..%..i!.,.x..q.X;&.../.."....(......=~.0.w.5.,... l0.....y(B4..o.6r.t.-.z..w2,z%...co....}./..H.@...+.~.m....d-.......;;..[.c*..4.].9y...E...m..R.%.-.....:.\..D.....wv.5\.l.P.qE..q7F..9b.V.t...........#.Lp.0...._.z..g...:0.(X..)....p&........V..zX8G.1..8*.....}.B..K1.....iFUB...K.c.....$......F...N........a..!J...E..HS....{..(_`%x.2]w..p..4...B....DY........=K.. P]..>..N...4.t.B..d,|...,...~....J:.K...-7........a./".0x..@VT.i. <.oy...q....+...,i...9wo.U...Co.g-[k/.K_.......e..h......}V...c.....l!...c...f .+..[..(.X.B.O...A..).....W@..b.....F..3a..B.0.....z.I.....R...W.....N>.w.y@#...)..A...0.1..J.......q4..i,;..e....."...J*T......s............n.....".9Q.s.p*-D3R..m.eY..S.rc8.1;.,.Rj..F:&..DV,q....=^..]."n...d..x..M.:..8..;..r..3...`.\}-.'..J.f[.J.x)(,......(.X%......>..6"p!>..o...j.......l.C..:.W...D.VG............A.L..).0.........h..1.<.6..3.C.k10..b..1.P.......s...........7....`E.A.NU.L.o..*..!].kZ
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1578
                                        Entropy (8bit):7.89230724691196
                                        Encrypted:false
                                        SSDEEP:24:PbGTwlk0WgND5RtdUy8HvMAJRC3bhjLZA4eZUrEJINosDcUT2MNDp7aOc:TaatdcEAJRCLhjLZA7ZfcDJDpJc
                                        MD5:D5CCE40E4FECD7239AC695DDCF146F13
                                        SHA1:82747EDFB1E3F1987EF0628321D17E1EB75AB098
                                        SHA-256:97CA522F88BBE9DBB5C089CBF0260AE4FAC2A007405573AB1091E6071D64E01E
                                        SHA-512:5B4FA1ABF951A21A8F7DED059486495614B44274ABA9BBCF985E79F5F44A6C5BDD7BAE43DD85E4C7FB930584060756BD9D1A083143498B010C3040E8B77B9A45
                                        Malicious:true
                                        Preview:..l..)(3..nK........S.....@.$...<.H:'Rg].=...|....T8....#.@..`.,.... ...w.;.J.*....57...9.i.&q..U..yM&....%L?.u...*...[44y.OD........S._..d1h....|_C...=...b)...#(.?.b.....e&V..1 .Y...4.;.Ez..u..U....;.}.....[..]....sz..I.v#......#gu.\3...#dG(U<.N.$..#...q...-.C.Q*........MP.C...r..d............1E.%,...8...&....Av.....V.h./.8.G.s.3...D.>.}..E.a&.. ..W.V...b......r..s..<.c.wg.A.n...T.2Q)^X.p8.+....G..v8.Py.o.e..r..o.E.}O..~R........$t...T.Jw.Z..P..J9..7........WC....(..l...2.........{..,._.R......Th....l...u..r#aK.M.F.B...Q..m....Gr...l....z.C.[.q.....A@U....D.U9aYH.Id(...12..HL...l.:.Z....2..e.b.m....:.q[.!..i.uF.).4...'%...r&[0....._.........'.D.............)h..v....".....9.x....{.v..=r..ow....N......I..;....../..$..XT|jI...:.m.}=b...@.[~.f&n.....e..<`D...8.......\.......5$.5z..,3.l:.J.. ..D6...[9@.)......v....S.'`.....t:...5.#..W..=+.J..^...I.1....|...Q!c..<$.....X.$.f|<...B..k.>Z.J.3..9.@...S0V...7..J...}@........T..^.....i..3.#e.]++
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Secret Key
                                        Category:dropped
                                        Size (bytes):1581
                                        Entropy (8bit):7.8793787026734625
                                        Encrypted:false
                                        SSDEEP:24:TP2Rat8w4jAJ/+6JIAxAMxfkVJAeXMI0aav+5t4OE2Efp3up7aOc:TP2RateAwAmMFRe8B4kOEtp3upJc
                                        MD5:7F127A8E53319F92961B1F451C5850B1
                                        SHA1:3108B36DF2AC97D1748C1C193DF0DD4FA0E99027
                                        SHA-256:5CBC6560469EFF8CF5CB68C05320F7799E47F9525ED5698C3241FE08F04AB2C3
                                        SHA-512:B498BCABA98979C1324A922F43E0F0A3EDF7B1F0B6E62C7F5B12CE8A87C4EA66839F76465755062ECD83F87A4146A349802D98D1C09CD6F42CBDE898173E91A2
                                        Malicious:true
                                        Preview:...,..9..t....a..n..>..2U'.. ..........E...1L.lA....n........N..3....h{.W.....|OV.h.nzK8.w'L.....!.......F..".....4$X.E.e)<.-......0..M......w.X........b.......'%G4o.'.9L.@B9,....c.......J}l.h.....q.F .(..S.+.X..J%"V.....Z.[.H.)...hyT#c)L.....d.!.]vC.8.b&.*..?...9..$.][|....6*.......J..PIS.R.s...W.p...sg..&..._.:.|./C.a<aVc.... #..XP...w..4D...M_Qu+....I....@)...!..3..s...&..PJ#%...L$.x.(..L..Y..V.a...!...;..c..C....[K..>.6.....?r'd....l.2.........v......[Q..%o....1.#7C.S)ih......f.H.Q&..j..._.u... ...J.d..^....V_...!...2.;..s..n....c..K^..@.l....v..~......1<....=Z....Y....{...B..>X#w.WwA=.2].NW.U,.6...[...].D.!...?\..L.8Z../..L..N...%.7J.Yn.T-`...Gy..o..)......(w]..v./n.0,=}@g...a.>.)....[.L....&;......R..Gs..7G=Ex3D.....&..Nb..K....T.B{)....R..)z\<..G....s..+.J.@F.A.ZFt. .i.....,UW.Pj........j...[......q.J...R#..)p.W../f.d.`8..X.;.g0n....=.....s_..^''.~. B6....&[............T.....~..\8....`C..pey.LM........F8pf-..$?Ir.:B
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):3839
                                        Entropy (8bit):7.952788635563897
                                        Encrypted:false
                                        SSDEEP:96:eVPJkmBxQKLFiafgU/RbjB/hlX12aZBB8OS21POXM1pJc:mJpyKJIQbxhlX12aZBrSAPO81pS
                                        MD5:D0AD0CF4953C9DD45E4AE5A530234A24
                                        SHA1:1B8C90AB961707A37A9FD4A55D26A618A0696901
                                        SHA-256:3F8BED138325DC9C17196DCEC005CC2D732FCC71AA34FBF519CD44A6905517AA
                                        SHA-512:9FE2DDDA82FBFE17244E8313C7C94840534D9C3815C98D519EB6BE3DDED6B347BA7384F32352A88E567281A21DE303126F764F29846215E5E2E9AD004B5033EE
                                        Malicious:true
                                        Preview:...)C-.$...w........BT./.:...j[..?U....N..a=qkAv....o5.....H....[.0?%aK...7.!j...y....r.Mk.,t...."....!j....(...F...&u(W........fg.J{..A.Kw..0;s..8.c.^c/vo.==....$.'.....1bj.i.N..E.(.....F/.7}........T);.*d......?..:rY..yh..T.....Y.*..\..F..<......AE...%,~qU.+.D.m..K/@.e.l._....J...;.L(.e.G.o..)Q%..J..wV2......0.y..!.X...+..<...s..S8e......IV~....L.Q.b9.9r.....M...3.._...'].`.Th.m.T...d`HO..*..@V.S.|..........@N...d6...........C.....f.H..[.$...k/.X0`t../..[..Y.H.?.."....|.<)..F{....5K.....O.Bm.&.l.....r..)z.F...Z.:......%...{....d.......L....@..... $sJ.=.?...g...[....+..z...o.....+.........).\.'....B<...Sp.v.>..wyIf .\.Q.....i.\q.....x.P....+......X...GB..>.q.../...:.Em.....ql.SW.]....!.....O.3..nhdh..8Y.=a.,..L.X<.K..t.8.aF.(},........."G...|.+.w.......,...@.wI.m...$5X..9..GO.U.D..h4..0..DM...`^@....6G..a..u..RH....y.S.kHj.'.......bya.&".De......j.r.JPCY..*.2.t]. ryP!.......Nl.).OL....I...4jN.%...\..a..X.....YO..w.^x.........Qa....{..$L
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):407
                                        Entropy (8bit):7.484597830700673
                                        Encrypted:false
                                        SSDEEP:6:aXLkf8A3E//8/Yu+NnMT111d5uiwZc7YI/5JR4b/YBep78frSJVgxGnFY22w20Fi:ab8EMAhnyTdclZ2P4bwBep7aE6wKBR
                                        MD5:099DD9B1578C9081E23D0CA9BCDB1DD3
                                        SHA1:0CD1194F649AB9344D9834A963EF23A13850B447
                                        SHA-256:788E9C4657307B36AAFC3C84EEE0CA9FAD44FDB3308F4403C83F21BD552E0505
                                        SHA-512:930561971FD0F30DA372B18D2907C6A2854C991FB297A1515B97FFB027D519E65AE103EE0B5871317B1894071918C9E3F5EBF9AE586A8038DA27AC69C5CCF3A0
                                        Malicious:true
                                        Preview:..5..Ecx^.b.\'F...s.;."$...L#.T.....^.Y.......=...z!p..=.FC....k-..b4.. ...GK.].E.. .\....L.^..PK..y.M........L..Y.i..9z).s..w.k'..../.d.lb.[o.....W].{W.j(...A...2h..6...H...)..c..aw.,........d.oz.9Q...=.,a..R.[...Ag..d.W.?6.~....L..A6...c.G.....Zh.... .p......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):288
                                        Entropy (8bit):7.229622029262394
                                        Encrypted:false
                                        SSDEEP:6:TQoqzvfg9g/HoEBRKvnzJDYy2q4YSCrsp78frSJVgxGnFY22w20FCnBR:ODfg9AIFvnlUqx5sp7aE6wKBR
                                        MD5:E0A8F7BE5F4FDA269DECD7004C812100
                                        SHA1:3A6328772112643824DC0812B0130C3A6D3D0542
                                        SHA-256:65FC09A8A925FD35707352433231EE2028E0157C3D106E466792C446267FE092
                                        SHA-512:27F2CDF9040EF7A0A93DB04DF851B87060E40E241D7DEB34914C4DA171586D9B0C3E19D7C014F9D20E1A21662B9ABC31C8800969122F861BB3110C5F49142C48
                                        Malicious:true
                                        Preview:..*O#.D3.v=.t.xX.g.^..At.....*....V...}......6.X.W.{). .M.....YnW.q...".3Z+..}..a%.,.B..EkZ.f......0x{.?U^.Nl.s.q.|.l........v|)..L......&.ve..0g......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1346
                                        Entropy (8bit):7.868448963721683
                                        Encrypted:false
                                        SSDEEP:24:2uZO4Dx3Q+IO9AejYUnn3wgXjvWqGYJ3nGToxvl9rBVrLlH00mj9NDHagiWzNbJk:5ZDxApFiJn3nXaDYsT8jBVrLXmhNjNiH
                                        MD5:B7C64374EFF7485021C2840AA8E4EBD4
                                        SHA1:90557D37FF389B74FD8D8AA3BEC098267EF37250
                                        SHA-256:D7ADD16F2C733D4F1D59EFA81DF5C3E7188695FD4D80D8996793ECAEBE53529E
                                        SHA-512:B8E239D3F9B03BC7808BEEAACB6A31699ED91FC273BF1B82A847E1C49D6FF803AEA3D41ACD36FFA8E05975F5BA203F9D65B4A2F118A78F84D33B63B38542BCBF
                                        Malicious:true
                                        Preview:._4..O-..ts.HD9!...S....+w.........]...0.5..6/..Y...8.dUV.*"..{.e.........)..d.M1.h.`.mV}........H.q.....']....~uR......tpN......O.Y.a...,.._.D.\.....c.8p.#...B..*.mEA=0...!d..._..;...F -....m.$R.u..k...,ul....q...#.*^.%........1.1m....u...n@-..5.^.8...d ...au.+.`etL.............VB.T<..q...Jvd.QD.:... Nn)n...-@\0,x..(.'.tXos../Qo...._..!..#v...'%.a.r..,]...h8..P..@|..wGy...d.........,..}.NvG..t.7.....D|.s.....=..&)l.Ns.-9h..].?.w....Dp..Vr..erS....P.....5......Y'....Y........]J....o.[|....e......g...V.t.W3.6.v.Ma.._....."..Z.......V....\.W%......g.WR..............%3..%..:.;q.P.....]M..V..Q').h$w.A\'1...p.l..._.h....P.YF5..gd.5T...Th...q.{...L^w...(..!... ..3.e.5.Y|.P./...1.#....,..FoJ...(.A..^q..~..x..E..!....b....}..>L..P..-.E.K..Ps.l........u.2.z...L..E.xJ...ZR.....u..0.6e.D..#(5...*@...q.....gS.....zeL%..e..>....~....C..).s. ,E..9j.|...A%r.a.W..H...`.Q^7......%=.7;;...p.....i.......e.9.x.`..).R....N.6Gvs.X..;...hl...5...$......W.i.u.NXG4#..C
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):37072
                                        Entropy (8bit):7.994998111539849
                                        Encrypted:true
                                        SSDEEP:768:VAxdbt+TW6OT+ovU5q+fcaR9sSYLCp6pZXdN1YuZZOFXp7:VUdbqbOc5q+fJR2p5auZZOb7
                                        MD5:E77891E325A2A3573BBB1ABB892D7780
                                        SHA1:23B1F527614C84525A7C0A7DE6B7AEB423F36002
                                        SHA-256:AD3DDCD61202BA7357F476434B445DB99F0E4C68245B94E26887718DF7A6DCB5
                                        SHA-512:79B5BAB1DB88FCBABBF33F4BEB9E9F0D25E8E94B807F054A5437F9BEB9B3DBEE86EE4F68DB418023496374FE40CADFEFB002EC8AC340EE46BB83BE6D5FA1261E
                                        Malicious:true
                                        Preview:..AO..B..b.....4.MAu...u...$.(.....:K.........Q..DhEh...."..o.J....;h.k..=.3.!K.v.....7.D_JX.e/..%....r.QfU...[]Pyt..........$/t....m......F...;.y.......S.+8...fm.p'._..#..A2..o........<R..[..... FN.o0.soIq58..Fx.+.u.o....'.&..I~..h.nbw.n5...B.0.l.~.jf...=w..Zm...b....4...D..L.Y..x.C.....=.......t.......qs`.....p.;m..:......9.@nI<fV../J..R....>...]=...^....a....x..2..B...@...}:.Z....2..7....Hq....k>...w....?..IR..A...L.$.=+.f@.7i.......(..^.....7..O:...)..2Z.....HA5RA..2......O....M~....{...VTH...l.{.}..eiM.O`..ur-....G..MU].Q.5......7.......2....U.w.).=H.)....D..i.yH......k_..B..b.#".....NP....f+.c..^.-k.k.k...;....irLE.{...4@..f!.`.....a Y.C..t......{Ek..R.........Z@}.em......rN?{8......Wq.../y.`.u..+.....E../....&7FY`..'=p9.m.\.K.....b......*./..?..E(..~.<.%....8.)'O.j....s.hs;$y..._..sn.....:.L'4j.O}..:P./.@J.....S.J..<.......T.Au.|.s. B^V...@s..X.A.=...B.E......M.....f..'...Z..o....\I....1...E...,..Bp..z..R......0`.%{..~S....U.O
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33020
                                        Entropy (8bit):7.994744008372888
                                        Encrypted:true
                                        SSDEEP:768:cxu3qS2OYMjKGJDPWhQ80BX9kGYzfYnbYw+M212XchW+:cRMYfsWhQjXb5Yw+Xgchz
                                        MD5:E59F3F6F6FC8B7746534DA4DA114677C
                                        SHA1:9F9B2823AEEA18220F4E3BEDAEDA61B0A67AFB2B
                                        SHA-256:B652D1BAD854274C5270146E4B692608EDE839252069603B3FD676A50A55AE30
                                        SHA-512:6550D5CF04FC58535904307C89636690C2B73E6D4DC2749180F0E0F2418B4E71C5CB911AA6306D7111231A8ECA9C6E725D69869D852848AA043A6AE47295C8A2
                                        Malicious:true
                                        Preview:...JI...._%.3...L1YO.x{..=.Rg...A........8.....M......{a..r......S.....'E.D.....Su.w......@.;......W<v.5.!u....a.....|<...=.:...p.~...]...Z....B.A'......k<.uk.O..~.d...3.-.$..P..4]......1B..$.@`..I.u..^..>.V...+...%.I)8Ra{....t.=/UZ..-........'@...&s.2'.x&..0.t.#.5.?.0......q.bN......& .....1O..a....w=...........(....#=.l.Q...,P|W...lQ.......+.....c...Ot...vSBK....'._..f.Q...-........C.<x.P..KEVvNs.TV....f+p*.{.../M%5..pZ?..........cV.*....1.."9h:.H.T.t.....g.qR/...i_...y..6/......7.d.L............['.A.....;n.1....k.W..9(sP......i..rZ...u"<M...{.a..~..$.I..l....gC.g$..E.8....E...;c.9.)y.......mh...k....!I_F..........qC.H.`5.}Le}.....mA.E.F.....|.....A...K...|2.H..#..Y.Bn.-.qp...B.-..T.e..cv`\.#D;..3..?[.....)..-.J...6.?r?[...d..N.WD...@..$..".L6...p6."..t.mO....r!.dR...V.......l.?..`.\.H.,h.I.Y.L.Y3.Q.p.(U.........^....}...7=n.....*........v...".+.z=.E...P..../s.=. .......8\.Ri....{6......E.x#t[.p.'"O..<*..Zu}9?.....-.L}k.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):5243126
                                        Entropy (8bit):1.264550696437232
                                        Encrypted:false
                                        SSDEEP:12288:h7bjlo4GqF7GoQYZrXjHqbnZwMniC9uaApZ:BbyqJG8rjqLZ7iCaZ
                                        MD5:CFE31B4A0872E4801804A747948C1667
                                        SHA1:9BBF5D0784AA6ADAC0F565A9104A7558F99F7A1D
                                        SHA-256:086B893C984646EAA68E13D3350D04FA1734E0580228A22127489BBB2CA066E2
                                        SHA-512:876D78A1713CA455F215984FD6693FD0C8C74B9F80961410EADAE8FD1F19CE33F4AAAE09282DD3517527EE661ACC7753B12955030DE432EA558172E093B7D02C
                                        Malicious:true
                                        Preview:Vk...i]B...C.y.M5KA..yD..2.H..B\..|....q_...E.h....A....}.u.Bgt.{/g...F.-..K.o..9.....X g^..D.#{E....E.{1).f..w........VD...I....../..Wt..=..v.....zj.7?......A..V.3.=8.....8.2..L..J.p..a...L............9....<..ki.C@.L......8H..UL..:...]..4.qB.\......r......o{.Tm.........6...#*G.Q..u^..:.....!...bs..A.3.%/Hz[....|..A.....G...&..h.:.....2Hc]ex...p...SC5$e..C:5.Ku..*.M..Zkz.C[}.q^Fs.>.b!<8...p.>.C...z.,.&*..-........"1......>R..t.R...v.RP...C.@.b.I..bT.y.......".C......).....%....\u1.M=...[......!....S......F.....ys..~R......M..k.aL.M^.&..Bju..m.f`.M.h..'%....(..lY..|3.f4O..../l.GB^.....D..35"..k...Y.2.....1.....l...b.a#Cn.Cp.../.T.o...ka...Y0T:y?..,.K~.y[I./...R..>R.j?....,|. .6.Qf.78..s]..i....}B...\%...8.....&.%...d..../.........8.j..<n......5.5..w.g..#j\..(G.sm]D...o.... t..m..3c2..\..nZ...5.DBS....x.O.k.b).d.7[.^<.....ihG...-....^^....^tt....p..b.).R.*. ..n)9z......:.t..MJK=...$...5;{..#@.V=.//.....8Y./.A.....b...u..1"xh.yv.6.;.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):622
                                        Entropy (8bit):7.685710242633695
                                        Encrypted:false
                                        SSDEEP:12:RvLhjISzTCbAS4wxOR+fhcrnRLsWU7jGZDKCp7aE6wKBR:RvLhobA8xOR/yWUvqD5p7aOc
                                        MD5:5F9F076D36006F628200CB334DE946F4
                                        SHA1:84E9F07EA76B2D26A9C0148DA45797F84C454B9E
                                        SHA-256:17A202B1550B0C4D52C19B535A1E9AA7EFC80B1E82F15771E244DD25F6EBF103
                                        SHA-512:A70796F3053490FB44D750D45752EDCBFC6F8081514FFE6B0D1C2E7ABE0FB00A6581A165693D8E52EA0DDD4186F4CBD793C64473461092AD76AA34CDF4F61C1B
                                        Malicious:true
                                        Preview:H/c...uk.M......|>UX.-l....p.(V.d........j.x...FR.|..;...i.u,{..XZ~...;..M..@M.b....Z*...%u.r...?k..Zf.......{q....p>...hZ|$....4W...MM..e..&K...O..w..QX.D....7j.l..k.~:.J............b-.A.*..y\..NE....K.9......q.........3.:.6w2......j....Jd.@u...Ls..2......0iA[...k..~..|....D...c..&q.s[S...*4%...E.V;Q).c.+......S-?=..6...W<d...?........r.......Zg.1K!ZAL.n)......ds.rv.R.m.....a@+../..a%.,.........Lu..=..q+[..l.9.....h.NH.(r.~.#...{...+...d...R.....{.IR....l......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):295145
                                        Entropy (8bit):7.999371078393531
                                        Encrypted:true
                                        SSDEEP:6144:6uuMkeRl6x254HQOVczoxJprgSckDF6YZ//19Giy:duMke76x2aQyczox8xkDFNX1Yiy
                                        MD5:C782AD38BAE5894C7F395FE5AC7238F6
                                        SHA1:C062C4B6AF4FAB538FD457D019D1C23E9ED0DBFC
                                        SHA-256:4AD51B43A3B449F3EB10873A722BB2889BADFDE1344FB85ADB0FC83A70FD0351
                                        SHA-512:EDBB27A46506E7ED90F26510A3AC9643659965083000E860971BD5720D51BCB620962556EE9BA94ADF5C9ADFA71037F55F360526A155F852B6F5E570A1FC30C2
                                        Malicious:true
                                        Preview:v.~..F.....2.....4../[K8wSt./@;=..Rt.z....FD.G.....`...-C..... ..Dx.^.Ra .M.8<..Z.@KV.H'..?:....B..+...Ot ...$Fp..i$...C...).a..#.M........=..`..4.W..>.Mo.`.x.J.XM+..G.y.h..A3./-LOl.......Ilh].T.(..v.Q........6..`&...r.%.e%o..o-...q..zc(....7E..@.4.....;b}~..:#.u....}".=..K.y,.W....T.E..N>.-.}.]>.).t...`s.K#/.8{D..:.tG.n|x.\.....3W....P....&.c^.....h..w~.V........Tx..z.g6.....o...C.JY..l.'"..].9......DSY....^.B......M..i.~=.....\.....;X{{ho..ve6d.y.9..d.U.(h'..M...j.J.0..{.4z]..z.m......[Gm.....oc..7^0J|9...3.'u.S.R_/jk..`...D.}.4..[:....^e.d;..m..~Td..8.e...D.....M.J..hj(<2..i.{.u[....R.W9.....8..P\w.rF....n..$.e.q.klr!..~p...6p..J.@B,.I.U....c.......m.......5B...r.E.......=..@..[.$.H.Q.^V.....z......MCz..B..K.z=..i......b.m8s.T#~C.f......P.,......u....V./B.z.O...#.B8....@.Rl... .9:.K.C.c....u......H......r.....:j..z..I.+vp.p...........A.....<.`...m.. .e.Q..S...B......>./..?#..#...5j{..72.........S......1........d.......;Ri!...I
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):98551
                                        Entropy (8bit):7.998026415955619
                                        Encrypted:true
                                        SSDEEP:1536:dIo23D5cw/Ma6IL23zD0n4ZipMGsys8jtETqbSVcrNWS9uSOhk1/F:dIT9/l6IqjQBCGsysk2KSo79771/F
                                        MD5:EA4E00B756975ABEAF52EF3FBC045135
                                        SHA1:7B9188C6B527D7C0EDB7CC06EFEA249FA8404156
                                        SHA-256:074E00B1009856948A958453A4C8DEB547149C58DD1DD5284CA1208B521EC38C
                                        SHA-512:8786691FEF76B33DEB8D4EA6C6FEAA6781490FCF62228BBA1C0A75DE9844FC75CA5B896D6DD3A30D880771DF4A51CAF52A77194D4E7A898C766EB4F3274AF4E9
                                        Malicious:true
                                        Preview:....j.'m.B......D.5.....#E".....>.....@y4^?.J_%.H.......f..~...I....C....%.{9.S2......E...;.../.t...w.;..%q?.k.Vo.[K:^.......;......../X......)....w.8..::.7......+5....R.Z:.......2...G.Y+jL.".HU*.2..+r..-GV....S.{..TN......O..Z.Tz.F....m.v.....c..'W%....^6.T../\....S...*@$!.T...$..m..PU.T"9v...e....8..rINI.&..{OM|k.'.#..[.......;@..J.....|..y..%k,...!.%..B.j....x.2....N.....h......._..I.e..z.)t...1.r.UI.}..R'mN..I.f.8~9"..W].."+..;3|S>.O.H....gs..k.s..v..q`..>..2.w.`.....n*@..v........5...d.R...7|..%.}...2.1.*=BP|.....`.l...Z..v.ug..w..P.#..S...3../.f^"..&{.....;....@...7.-.,|Ch...j".....[.G.5.R..f).h.7Y^......9.}-...E...Ubvr...!.F...x....c..Y.......YI...(6.s....w......B-H 3r+.G.Lw)...R....&z(.......h. ...@......:.OP.5.^."..E-$1.\......R..ZYN.0..|..B.e.D..g!1.2..?P.+..].Fc....0....GZL....e.$.@;...*Mw.}.1F.1..'.o..~....K....G..+s.[\;..b...8..[9=..s.#hf.)Z.A.\.@...$a`Rw.7.J...k...................G...ZK........k..&...Ed......1..-
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):754
                                        Entropy (8bit):7.727618490748598
                                        Encrypted:false
                                        SSDEEP:12:umnoH522vPslYDWwd3G1gc0vri7LGe2VBouJ8JVuKPtRSvcLp7aE6wKBR:umnoHcYbG1gXi+eCuJVuKNLp7aOc
                                        MD5:7CC9D539ECCF21D2EC47AA04385CA82D
                                        SHA1:A4D0AB8441035E288ED2FA0FECC0F2F8D65CBCA6
                                        SHA-256:C3E445439D0BFA99F10BFE88E7803AF462871A63C39D1A4A9DDD7E8384910619
                                        SHA-512:5E93AF01E031F84BBE6DDD326554F2E0131BC333F658CA12A4DF24B47DD576B40C45378A9AD54E8C3CA92841344628785DC8D563292F6913EB7040E028BCC2AC
                                        Malicious:true
                                        Preview:.h......Q...u...1.R.l.`XaY....2.... ..".CC*..`..5..>..h.1.(**....J3.O.k.y==TF5./X...1..o@c..%...f.A..y...`.lG,.I.L.:..u....A......1.<Mui...PN..SB.f...Y...U^.b.l..K....Cg..P'...n...R...............\.)..2.NG....I.S'.tR9.....P>2.....Wg..gdLR.3H..j...C.PAw!3.:bw+......`*.Ne.g...H...k..?...YK258%.PH+..-.....Zt$x.........I..b9.{.s.n.t..".b....jAJ.I4..6VZ.n.....su.r.X.9.f.....s.X.T.v..lq..N.......I..r..{.0..|..?.....6.B.@e.R>.........0n..._a.[a.H.=.^..T../......j...P.....Z..i4.,.:+.;F"n.".R.tM.b^.....$.9.&T.d).....-..1.......".aZ+..~..a&.,n............U......H ...{...Q..:"..YT.R\.6.#>..$C.D..r..K...f......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33014
                                        Entropy (8bit):7.994294071936
                                        Encrypted:true
                                        SSDEEP:768:ZapV/JbVjenfCA5kMbC82J12OMMaXuxwoaTHEWUbGxYFnjBo:ApFJbcCmka8MVTkWUbGxcjBo
                                        MD5:B6C6F81CBB5FA6F0C45AF88ACF7BD118
                                        SHA1:D85E218D210C1BC9A5AAD8698ECD8DD52FC327E4
                                        SHA-256:B09818AC6834A0F5D8EF7050BE5B6D765D511C9D1053DC9C3061903EEB560F17
                                        SHA-512:E58EE8AAFBCFFDA40D1205D896FB1A00217A7329A4738A8146114DAF233B61B4B07F4CDFFDB8508A324D1859247C51780E5304702868ACC8A0885B7C645B7F08
                                        Malicious:true
                                        Preview:"..u..`.[xut....+B`@~......h.:/"....]....#'Lk..PI......k..=&.C....h.+.....q:....V.....Y.?.f..q..d...r.D.....Ag.....IW4...^..~.l...FJ<. .b..N-..F.@o....yW...#.X..jT......3.'.1QkV.3^.r.9J..z;...,..dq.JT..HR..3.v...!..B.gI..-v8Q=....7.u.Q.H"...m......h......4...S.j.!.....P.q..XM.4...F.z{..._L.t.;(...o.....>..x..'.p.@.\...{..].......f.h..../d....&....s.Jf...s.a..5..g...5Ak.G[..A.H...C.i.h..kFx.{9.k......wM.+E....u'..9....F$.....0..S`.'(...=o....m.?.Y|...e...Ig....|......f'e&J..0..p......E.T.3.4.H0.0.....a3....'.c.@...D.3*....ep....YZU^.w.%^..'.....4.....%....#....>.!.Q..2..."...k...f....?Sm....F.r...q.".t..".{M..D....dW........@.@.\e.l..}./*.......I..m..i..a6..>w.Z(K....].>..y..c.Y.N.E(.,.......v.x..`&..i...3.....A.^r.2...af,`.v.y...~.x:..}.yd..Xe.._..}.qD..0."L;..A.oR..+`.......zY.........:8.0@.a.)1k....~..e..xf/%.W.)n.B.1.:+...B..\..dC"..g{....D.*.`..%..P..(..5.R..b..&./.j.../2....m...."....rG..n.+..^[.(..E:4...T.,..0'..i.G...1Z...S
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):5243120
                                        Entropy (8bit):1.2695729858991018
                                        Encrypted:false
                                        SSDEEP:6144:veQmIhzYexNl4ODi0xcbtXP0NdZ2aIIyZM5GdjHey/GTBeAHgnmH9Aon8SR7hEb0:hzliDoZ2aIIyOajYBaKz888BMJ
                                        MD5:C7ABAEB1F52A3077B45F79A07A67C4CE
                                        SHA1:2D57DF6FFC5E062193688A34F6849DE20892ECDC
                                        SHA-256:DEE4CCC4669E81603FE2CB7DDA4995393D3A751DB2EE5BCC0A0DB3E4DCA8606F
                                        SHA-512:35D0E613AA57A8E5AFE1009412BE1166C0713B947EC20AAD3B0141D2D0B591E4A9EDFFDD6B18788F29F51EEC41FE944AE2E3B479DDDE196F1A1723E595D7F707
                                        Malicious:true
                                        Preview:..%k5..yq.S8.e....1.Y...+ K=.......L..h..s....2...{...s-. >..N...5.r8q.@..I8.k.43.z.e}1.y.q*._...g2.n...H...k..c..Q.}..?.._...\.08h..8...6u.AL...R.Ab.....v*.#kP..-...y#..xjE5I...lUs...'.t...'.....zY=.z!.}U.[......i..e..}K.j..D.TR.B_.+..{F?.5q.?.Q...[x.ne...0.0...Mk.....U....0...i...........\.y...........Q>E,....H'.al.A..7...b....Z..?.......J.....t.g....89(.IK.o.SC.9w@.... ?Kh"^..av........2e..7.Z...C\.t..ZLYL.`...6{..V........ ...rK.W.Dt.u..]q...]vS.A7z.XT..5...sG.\/..X+.&...."...6.X..v...13..S.c,..5:.[m...k....g...7.?..ka{...:7.Y^u..$...>...t.[fp...q.....V.......v>a.....(Rp.)UR....%....k...+wFz.$...-r+.B.|..k..$f.O...=.g.e...r..xV...d{YZ3..K.2......|+.... F...H:..n.9....E..(aoA..5..n...:.Y...a....,..(.....s.S......;zV(.'...G..J.G..;y(b....O^...>.....Sv....Idnr...0.../.-v..,....<......5...^..6....i...v..,.l.j.3.x4~../f9.! 3O.s%A...M..l`.e..%Q.#..x.$@8.....?.....Fd.49b..FE.~Y.>._....:m.F&N'.x.......j}.3.M..G....:Y.nFk.y...4...U...4....z.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):9738
                                        Entropy (8bit):7.980248721878999
                                        Encrypted:false
                                        SSDEEP:192:VFkr03NxF3+7Dht4EKvvoWlLMM+eYVlwu4EsN0efhIlh3TpS:VFumNxx+7dYvdYVyu4EReUhlS
                                        MD5:8455A343D282031BDDBB2AF7C6A9E3D8
                                        SHA1:1423D7F89A15A1DCBCBFBB3F7F9C10349C8FEE7A
                                        SHA-256:24E6100A4C692147F7862F40857C185B3063DD042D757367D04D6B00072230B9
                                        SHA-512:8C1C87361FE30A9938E8FB4990D43004D095D8E08EF4EE3915145BFE0102A39ECCFD73B001365C0611A24EE02AB30337869EFB1E5CFBE2AC4EB9D88264A33B33
                                        Malicious:true
                                        Preview:-.F5z?....e.4MD.%.L...(.V.9v.^.(.Z...awu...(.[`o;.Q. `1.....l.pEm).....b....O..i.(3..y&r.o......HY.6.,Y.N,.{.......&....=k.+V.k.Ik%].;....U..p"?....[H$.y......;.A...(.`."..c...+.xp.=K....|...B....-.om<....?.....:.u..,.p.*.y....g.m.L...e....{~.W.u.8...1.....;.d.sm.!T...{.>.P.....g..%:#...o{.....-..1..T@p...1.Q....(1..U.>..+.'..9.J..l.._RT...avL.....d.f^..*/'.).(X.l...0.....Y.W~.v.T..A......K.,...R...4.!..y.?M.j.....w.^.......I...20....;=-..>.N;......P.t...-1G...?Zr..k....&....m...G9Z.3...ps..?.....F._'O~..M.i..W.T....+.XS.a....3..G.0..N.\.u...<`.d.*S..g4...gL.`{...d=.i..?....D.4Q.J..z?.|2...m.P..Cf..s^75.a..J...v.F{.,`....4.P.3..i.1......~..>3.y.$.....y[..}..Q..N..f....z..M.M~.>jr=..@7..'.K...$y}-bf5...P.o..O..'......ef.g.',y.".z...X..+r.....6....>]....?.v...+..Td.``.....+..e.R..y:......Ba...:...t..A-.[5.;....77V.n..kT.M..W.4X.o..U...};..o.....d]V=o........^..7xh...........U.,..S..0U\*..&.[9..s.......6...........1..<...G...iQ./=.Ko..m.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):65783
                                        Entropy (8bit):7.9976197996286995
                                        Encrypted:true
                                        SSDEEP:1536:cahJ/O/3DQ9VNIzYzFLeU+8cuL9ztXVPHwDD:ca2wH1wHuLlxVPQ/
                                        MD5:14738D83F9C6CBC7694D2A1D9B0811DA
                                        SHA1:7F96D2F68F4A3ECEBCCB815EB1055BACEC458189
                                        SHA-256:D454678965CEE2E29B4AA7CB938D069463DAFFB31170266086756AADF00E19C6
                                        SHA-512:BAE48293C29F77C9C28DCC056E554965BD4BC062BC3F5ED2D4FD71611AE26F45C03B5F872E47CFE9E4E2785BF078EB7A6A7BBE98E6B83B46DD19B1030E95BA8D
                                        Malicious:true
                                        Preview:.rm..I..J..c.s......]..>E.(.)..L'.:./.C........!.*..Y.[B.E}u...Bq.....T....{>.~5.'.B2...gb.D...nlw....}e ..Em.gf......Uw.....O...].=l..?.|.d..8f..N.....%*.xMT...._Ez..{.u.T.z.l.CR..8a....S..)(....V.:wNL.i..$N~..@...)..`g-p.... W..n.8.6X..p:.a..RL.H....8..H..c8../.:..U.<g......|!....o.c{....d..Rq.....r.K..fNi.m.e..hn.T..?x.........3.z0..4..2.....ZK....t.....M...O.u.a1........W..`C.wL}y......p...[.G..D.z.u........R...w.....7J.g..:~?.6.....W}(.`\.?@y.Y.......r7.....S...n8B...2.....`? I...G.-D.x..D...........& r.{i.q<P..a..5g4.....9@..\.#.7uG..k!r$.7.jz..U&+.....a..[....-?].wk. /.....o..8m..............W....7R./.m//.U.i.}...4X.....[C.....C."`..{..GZY...,HREk2.......f..7...c..b....D.>...}..........g.@MX.w.-'.c.&...T@.O....U,-..}.....q.vpZ..O.2..,hz...<.dc.....j.....f|.:........[......kX...M.W.5...2&...#.!u...:8...Ib],..Y.j.eg..$....|-.........}.>e..a.nL...#F..0H..PW....j].!..."...^..~Ac^D.h:^0ss.ij....CRJ..-s.wj...|....N........5.<..4..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):762
                                        Entropy (8bit):7.744763692972093
                                        Encrypted:false
                                        SSDEEP:12:tthHnNIwUrXHIUEwi0AFO9o7tR7zsLk8A+z0BQSbQB1GzMlcp7aE6wKBR:7xnN9kXI6i10Y8IKSEB4zMlcp7aOc
                                        MD5:CAB4F726FC9C5A55464E798707FD1AE3
                                        SHA1:9719578090F181E9A013255A94A4551C48503CFD
                                        SHA-256:06541EC36FF1C7D10F55033D34FF404645BE91DD55B00A005328457EE0CE3A23
                                        SHA-512:2C50F5D3CFFAABCBA3D8FC9BA818C6ABAED0E8FF32030988B753699DDCD13D8349781FC5D2CE28E8D2B840C98D27A9578DA2A592586C4EA94496E861B7F2C24F
                                        Malicious:true
                                        Preview:..[...:._..I.+..P.PE".k_...w9M.A&.}+..R.*a...2.....]5..v.3.6./..b..#...Q...}....).Y...3'.W..X..<cJ1M.....wp0.......+5..bm..x..J.l.E%0!06(..+.f.W..#..R...<s.U.).. }..'^k76[H}.....R/U8.]R..nR.:.....!..._.l...M.F..\..a......v..!..A.r....5I.G.{H....H%9..C.v...r.|.a..'...)#~...0E.......9.v..9..z?.d..^.....-%.S.).n.0..#.!..1..wAT.W.m\....as..f.~....8..VR..,.Ny..K....^o...>..b.#8....FS.&-2...<9.y9u......T.....UZ5..%..YX.{....qf".MY.E.<Sw/F.5&.G..U~K..i.S......i#=....A...l)....q..eY7....)..`,i6x.h$>..8....5.......Q..QU4(..`...(...:....p..$S~.....H,..R..t..Ap.e...A..k.Y$....]..&...1.....av.gM7...).......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):74081
                                        Entropy (8bit):7.997283481802318
                                        Encrypted:true
                                        SSDEEP:1536:HBJcLoDXXzRRoTbTExOugb72UqqICVoDmK2F4e/R9HAiC9uPpGRt6AP+2toqOE:HBaLoLzwQAb7ffVoDmKpGgpuGRtpDOE
                                        MD5:F75C8A427F0D84E8565E7ED7558C42BF
                                        SHA1:948BEFC424D8E62E77A66287D4CF3BB6396121D1
                                        SHA-256:4658DAEA36FED914EF7A9118BC14EC5F2F953330305B307BD6718F5879401A28
                                        SHA-512:A5642B07F37F37DFA285858A16E40E99449E1DD88016E2A518858D90AAF090F3D0EF7F70596BD3C2D452E60503E9341899F42032CC980070EF78662FD8312796
                                        Malicious:true
                                        Preview:$...y..J.O9g,S...F.I..,".......y......-.B...9.LO..."V,..R.53...7..1X..R..F...e..y-A.*[.$uk..,..P.....4.[NHD..[&1..l.J.@...($..F..0......#.J.<..'8...$ ......<.!(..O...=m...<I".q..~.....`oD.3..Y..].o......C....H.5.g..*...4F.n..C..V..) ......2...J......2P.m.. ".A'.XzF{..w.[.u...Ta.NY?W.$.._.`.uM.$..=C..L&.W.:Q.N.........d.............e.Q.j.7.*o....V.<.;.o/r.>q....J<`N...^.^.m..X.B.y3+..e.~...eb......n.J.E{.u...h..uQ%...Q.....?..W..k#9....7b.5l.H...q.z!..UNh{?.l..(...s......M..I0qy..!......y...i...[.2..C.ML@g.L....Nj..&H..>,.S.s.9..i../...u'.....{..DL.x.........msd)....2...B82..(}.x|nB....;E....|...;...q.h.X...X(....w...V.}S..r.I........7... .|............._.0......g`.E..g...'p.|..TH..z#.....g.Ir=.V.2...3.0.D...'&....6.bG.z.O...D.A..M08....F.W...9C...e5{.>.i.......4........`...CDH.2X..%>.......h....{_.+...N.?......4....n.g$..... ....R....}r.B.H.....F......|.4.Foa...R....L.L........w.....c.,.3..H.....$.L;F.f0._..Dv...,.{"..m5?..2....w.S*...v...FU.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):599
                                        Entropy (8bit):7.6223154313637345
                                        Encrypted:false
                                        SSDEEP:12:t7Vlhj2gy0Wkjxpu87eNt69nYaG4ZoC4N9Y98oFVRfAp7aE6wKBR:tVygykjDu87LoC4NyxFVRfAp7aOc
                                        MD5:0BD779CBDEA95A3C74691BAC65DBE15A
                                        SHA1:C87838CC33D0C36CC849A2884601EB96BF03B842
                                        SHA-256:0A75815C83220A8E80391F386DBF69DF8CC3F7E590EDA905EE86966E0DCF3720
                                        SHA-512:E3BFB7C07A917B5CD4186C42EDFEE0C2C61C80198DCC00837A8B639D18BEEABA664EBC3A6AA38DD1FC776C9E2D7B250F2E5CFFC2072567A426277E1E4C5E67D6
                                        Malicious:true
                                        Preview:c..<..rA&,..y.Wy..*^.-a.s....[D..X...4.....q.;YK.2_4..e.....bg.%j.~.J}.d.u.!w...............<.4.9.)Tn.&...M......8Q..D.v./$.!.(,S....,..U..6e.1.j.V.\....<+7.., )..O`%..........!.h.m........1.....@.q.%w.t.1...<.r.\.1}..Nb.vy..g..U.46@.!!.k..6....Z....m.g........!...zps......@R3*....'...f.0/mA.I#.;t*.(J.v.4....... ......)........:..UW.j)......d/.kw).......CG...}.a..,B.......d..@...s...H..@6 )..%...7.[.|..~_.].i..P...5PUF...T4.w...4....%..t......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):541
                                        Entropy (8bit):7.616682156605647
                                        Encrypted:false
                                        SSDEEP:12:NWuKlKOCKt/fR3QnE4QUsV9yQsznhnaW4nZODp7aE6wKBR:NWu2Kef4QUsVYLaW4n0Dp7aOc
                                        MD5:BA75CC155BBE4D1EFC91633571BF2188
                                        SHA1:E10F9B053FB6D7AF221ED6D310A10EC7D138E48B
                                        SHA-256:7B88CF0726C9F81815592B2A6589934121A3F67A24968581F372935E23C7451D
                                        SHA-512:2E8DCE3EF88C8FA9D79143C70505D4DFC0358B188C16F30DAF5D9D0AD0C3899C795B6983965059447DCD586AE1C089BD4534EAC91E35E8BB89AEBB2AA10E22D2
                                        Malicious:true
                                        Preview:._=...:.K.{.}...i..3...3..;q1.Ep....u2F._..D;5.@.DJ+f,.a...Zu7qzcd.......m..a,.+..Yg....Fx...w.%.F..>.J..-3...zV..1U..(.9..4=.......+q.8,j.%..........I.....3.............h.B".......(}.dS.X..I.....K.....L=...r.].4E..&.e..Aw$a.I.N..Z(........;.j{<.[=...u.[.....jr...Q='F6I|.W.j(...A...9.2........K.........AE..........d..@..SU.......m.f'...at*..r.-.eW.g.....}.@.@7.....W......Q>~.r..8-...w......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4585
                                        Entropy (8bit):7.958301577153752
                                        Encrypted:false
                                        SSDEEP:96:6RzQ5aY6unf888iW+WRb7cW9Z5wCp1OGdpJc:J5aSf881WpzKkpS
                                        MD5:61ED824A7F6082B4B93F31F4452A6A18
                                        SHA1:50A6D6DC797D2A96128D7EBE6421FEE2E2508BAD
                                        SHA-256:9E692D250F6396BC3520ABA6AE422B8FCC3739AE0ACD624A483F6B108E05C370
                                        SHA-512:E05A68FBB0F99080A4FEC8EF7769B112C37D7F32B3BC6E36D9C6C8E0EE2368C4A4E103DD9172394702D3C562B521EA85DCEB35447E8272F4D07FBEE1F89C381D
                                        Malicious:true
                                        Preview:.@.....l.C.Y.t.......\`.l."g=...d........Oe..z1..E`].C3.1q....~.....Z..)...Ox .~.....+.u*.qn.V...m.....Q...'..{.P...V.F..+.m;p.Q...q.R.}".3.;.nF7.. .xs@..<q.62.H...9}-.(...._J...o.5.)8..$..}+P.Q...3E.2_.....l. .IY]V-.D.:...(.)%~.y..Dv_....]S..F...g..<(,..p..a.<.....C`]F.35.&4..L...'.y..j....W..]..........(..C..7...n.p..c..H...fq6.....B.b...'...2..J.8.$#TbsB..\{.+!.DVd..{....J.z.*..0.`8T}0?t.$...5....].3.....Oo2.R`f.M..\.+z..8.L:...7.?h.R.mR.........|egb....Byu..QD.W7.E~..98'S..i.....Jj.......uI.o. r.G.S.7.@f.5p.F...j.-B....M...a...*`.....-H..FJEb.!SAc>J..i..uX...Z.k.,.D.........j...}..4....j,C..{{;#C.],o..f..{..G..X.+ ..9.V.;.m..O...x.i&ir....3.q....u.B..8%.....q...$.`I#e........|...pA....g..t.1.^Gm.. ....Iw.P.gh.B..7...X.W7kL.........3..S........C.nY.....j....@.|O..I>....'cJ[X..J}...\.L..W....Y...`.....f.o....)l[k@.].m_.[..7[...ki;Oj.....{E.~+.8.k.........D.i..9:.LPK..K"..;e&B.v).;.j.-...Hn}.D......]..5.2b..I...19....j....).v&-1..."Bs._.N+>Dd|.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4605
                                        Entropy (8bit):7.9603054619495115
                                        Encrypted:false
                                        SSDEEP:96:Rix7eqVqJXf3DjcJN85z5p4Q4zuA+vbTQn6llzpJc:8ecqiNU8JKA+ZHzpS
                                        MD5:6DB811950D786D467C405C1FEE4D9ABB
                                        SHA1:2C12E4D37FD75FD9106A6A75C53CADA53AD9B6F6
                                        SHA-256:16CAB9B876DB7FE44DBA50F96AFA15415B44E0286D6D443E9054BB2029FD1D97
                                        SHA-512:6FE1D979B1F1CE59DAE7A18D61D018837C234A4EA7F4FA77E7095A8F38A77B8E18670AAE5178DD3BD8764C3FE9349453FCBC1F833CD75E33847C19ACDDC3C712
                                        Malicious:true
                                        Preview:...c.:.X..8a.A.....o..F..N.K..sw.......n....3.,.....>Z..4g(.9...r.<|...u.M...LMx.&b8W.P...v.d.8..j..K.....N...h...wx..&+....WWl...w...T..|.u...qXE........Ur......36|).tX.}.(9...z....7.q.....6.O.RJ.........Q.....r...$.1..z2=Mg..e...1>..I=U........8...k....:3....7..d.A;1u..>Tv.4.45E."vE.B.wf....s..O|NB.2.>_.+...(...#.=.0......)....5.o..+..y....5<=..P........4..2&"|.(^.......P..aR.D...r..j...'=.W..]8m..h.~.~J.......tl....d`. j...[.J.?.C.4J.)..YS..)...oGC....&.c...].b....b..5..8.M.E....q.r...<...`#.....e%Ov..U...amANKy.Q.l..v..3.qr..?2.t..AD.....@.`:]g?.y....n.)..J....dO}A... .15..NN..............F5`e............-;....H_...v..K..{.(J.O~..8....5u..7v.2....?.i|..`.$..K.....2....$z=.s.%.R.r....4.P...<..A.m..x\z..D#3.. m..T.M...H:...3.......j...Al&.N........M!.#..q..',>[.@......f...4..C/...x3'..b..P....<`^....V.e...7........1~...Q...z%...tW.+r.2Fj.0....&.$oM..cFS....jS...8...5...fr.. /\.fj0(.~...U3.._gZ..N_.....?..l4.[.J.0..w...._...hRHg#6uHL
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1466
                                        Entropy (8bit):7.887807253563502
                                        Encrypted:false
                                        SSDEEP:24:oKGyuF85wsmwGAy57R0XUjq+lgTnF6oOZkSMutLkdMg9xHJpI9JmEiuAg/axBbpS:ozLFrGjkgTeieSMg9xzI9ouANppJc
                                        MD5:C2C27DF90F824043D491973AD5D55C2F
                                        SHA1:867C0B111915C90AB2D3547523078C4CC40886EE
                                        SHA-256:0834749726701ADC678DE3F47DF9E82147D6FBB8B72877A754F098FDCA378127
                                        SHA-512:722645371EE68A894A257A5DA2FE7BBA4292F2ADD20DA2FBEE1413ABDE518A734C2CB61AC38A00E04C6D309DCE5599AE50702EAE5DFF8D439FFC4FCF7D425C07
                                        Malicious:true
                                        Preview:M~.|.+../I.....T....;...Teq.D.....K/.j....O_.r..D..h&.o.8w.....a.._m?%.h..O..Z.....k ,.D&.~*aO...?.q..Y.u.f..(.g....!61.YdJK..V...f.c..l..8:9..j+G.R^.A...z....C..<j.AT5p!S....*....D*E.H..J9..v....sI..R.f....Z.t.n..3O[.....G..............tM..h...8.s..bzA.D\../....\P..hL8........#eS ...Nm.Y................=><S.W...l...tT..d.W..8....^...W..e./.C-...!....p<.........HG._O.p.M.}......U...A.w..lu<'.jL.N.....pk1.u.h..B..v.F.cEZV.....89...0.sg..rG..=5..Lt...5K..d..q.|kr.....v...:5.....9n-..jo.3M#......#t.PZ;.co.H......+.....mS_.7......h......TaN.H!... >.. )`F.aK..h.......V...j..;.=.......lCg....,..A-..;T+..UB...{......?.3!...0...F.=..PE_6M....X..R..i>.....J..6.....c.-.E]..#.o...)}.I.g@......Jt2.....&...|>...L....%......I...........-.K...a..]^.5.z...K.v..X....(.w...qM|]..sr'3...-.8x..Tt$.<.*4vG..U...pBx...tLv....)gAI.f.3|.G.#..-~...%"....0..@._....~..9.......X6..J.. ..S!`........N....<..m.......A.....Ij.l...7.......s....r.G.y...%............
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):286
                                        Entropy (8bit):7.2212603996762565
                                        Encrypted:false
                                        SSDEEP:6:kFWDu3PhDJu3qgaUgpxsBxdNFp78frSJVgxGnFY22w20FCnBR:5Du3Phw3qlFGxdp7aE6wKBR
                                        MD5:5716C5077C85947DDA4078949908B8CB
                                        SHA1:F1FBC2DBD961A04073E1E6277F980EB80F0B86FB
                                        SHA-256:877FFCBCA2E63BE8506DB68C9BF718B22B0319E5ED533B6D435E5637E5E68644
                                        SHA-512:21835C1E3C9D1AD364CD26F2D55CC09A29C89B217EBEA5FD0B5B424E729D9637C44E2117D2BC4C2C54722D459C2D9E0C7CBA78301D9D92507FE6891F38EC7C02
                                        Malicious:true
                                        Preview:.....]E.h...M=s&KW.g)......d,.qv......L7.i&...X=u...4(.x........B:.gU.(..2...+...9...&.\.K.0[..X.E.....H...Z.(/w.aY.ZU[.+.d.1..`....... .Rb.............f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4340
                                        Entropy (8bit):7.952716431456326
                                        Encrypted:false
                                        SSDEEP:96:IPcalWuPxF1sEl57TSinjS/4MVZnDKUJtYYeXIk+7hCZl6jHKW5pJc:3aLhs6GKmzvOSeXIbYZl6jHz5pS
                                        MD5:26A4C9E4DD80E8BED4BAF4F5B70E5FCB
                                        SHA1:22694CDBABBE1B94006E4146B36B373DD587DDC1
                                        SHA-256:DA1E7433C43F1A49FA99D9D984E5E97CA4BEFC0FC7CEE49BE829A9BF3776BB52
                                        SHA-512:C94C12BC467EAB0FBFB33A81448BC70E6F43359B47C62DFE6FCB4BCFE0074275F59E62D179676A9CCEC53D9605BB17FEB6E03868AEF5CC28646CA1BCAAD76F09
                                        Malicious:true
                                        Preview:.\9o>..Q8(?.@.%.u...Z.W..:oh...Hc_....6*7.........'S<u.QYm.`.J...tMt.u.d.!.Z7b.."..I....(...].<.*....Z%..i....@..?...c.......]..;D.eE@n. ......=~H|.4kp..M....9.l..@.'.o.*p.I.Z}.7..a.a.+..N../c...fq..vwV. ..P.......<.. ..5.Sb..4....[.@-.0G......r9...y..|....~.....I.....\.9.d.!....`..r.....^.....GHr'..y..E..l.z...DDKw.j6_4....!...`..M..4.WkU<.H.F.X-F,..qkTTJ...IF.#....d`@*.~...?I..w..C........(T+..f.vJ.f) .R....|..l5....._-....e$..mR....-..m^z...!0.....#...l.Y....;.Q....P.i...~HI..j!.:...I.I.\k........].)?...29..?........%l.T1....N.?..}..p..P.O.<ps....NF7........K..M..m.7......-^I..Q..-q...S..[.mB.v.a.6./:.......*y......j..z\...#..h^.S....E..1$.b...?...[NKr.$...KB1&!hU.C]...........9L.W..>|.E.-L..r.&.k.Z......d...@n0.K?..@.......{.-.W.7.'....=......kNSc.)...W.....2`.......]...-6,.b..8.J...&%w:.y.0...}.=_C.v.R.....Q.>.b._.b28%+...B#..w.1.^p.bh*.........3#..f....X.....<..;&....7.0..;0...!..G.a.uth(W7..v...,.>....4.....5.'c.._{..D.Q=..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):131320
                                        Entropy (8bit):7.9986226793354485
                                        Encrypted:true
                                        SSDEEP:3072:mBxZDke9lrpQYtNut6ax0iweAQQ98v4r6cE/pQT87Rc+Yq:4tX95pdnaxFFA198v4r6b/l7yG
                                        MD5:0B7F9B348E6BB3B513ABAED473297310
                                        SHA1:E5C9514D253985798EC7E64E03151BA72B158E78
                                        SHA-256:88E7034145C86C0A7EEB833532D1EC7D6E6D4BE61E47FEC9863E12FAAA2F7B73
                                        SHA-512:66C829C8D0532BC9A75A454472041FEBDAB15773BB5F8F0894ABD8D0313586C18479459B6145F6C1D0E6E9EAF3B6F70BF466BC643B83EC3F6257787010A60BFF
                                        Malicious:true
                                        Preview:`...f.N.^..YD..~...UT.LC.<..h...H...U...~2.......x.....\...aZ.w..3Y...P|.....;S.Q...w.W,z.....$.[...G........S.....<X.......H..~..l....-.!...6....{vL...dpt....JnW..q...}%\B.....x.[.}V.G2.$.kB.......M9.-..(t......3Z....s...2Dr.......4....*l.....0...E$..y..p.V;....?.<..I..G...$."..,..|KF...R}Y...!HhT...>.8..<CJeB..9...4R.V..2J?.Z..8..5....pWV...'...&i&dl.xru."..d[..@. .;....|.P..n...v..g....U"..&V..5...UD.Kn?..I-stQ.........My..}.8.DG..4.....CV..'....v.c:..w.Pn.f..{..}*B....Q...:..Cj...(o..L...)7M.sUC.......zN!....uQ.8...#.Q.d.....'..hB.P..y.?........X....%....-..%`$.e...T@..2.......Qsq.).nn...7.<....aKz...V..-...\....<b....3..a..T.|,.`..J...y...h......5..lC.J.....h.!mG...D..<1#...Po..b.-.4.N.)...p...R+....0.yY.[.O.....E(../.bp^.....-...KEKC).U....f....7....=..7.uJQi..P..g.^..k.uz.S2.[.**....!ow/.......:....+).. .n.95tIe.9...D0g.1..xC..y...*.n.(KpF....+^.3..D..=.J.;Z...(.E....U.[..b...!.D.R..]..l....q\.....T..:.BKT.#..b..? ...:..WO".
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):275
                                        Entropy (8bit):7.253513842924552
                                        Encrypted:false
                                        SSDEEP:6:8ydBAoQj6D2k7wA7pMaZ1Dp78frSJVgxGnFY22w20FCnBR:8SSo2uFZ1Dp7aE6wKBR
                                        MD5:96EE9DB8E7DFC00862B4CE8791D9917B
                                        SHA1:C900A577451E6C78BC63EC29C77A04CAF6451C00
                                        SHA-256:BE46FBD7ED3B5FA38A2C925A3D1B373B8830B9871EDA3E61AC808B10A7F1C345
                                        SHA-512:CA9F16967F761A3736DDA6ED7667BE53E7D9258C7FC7D07397016B46B322CA9E61FF44E768FB84EF01DFFAC30C15C4630608A5231779D5D030ACBCE69DDEB1F1
                                        Malicious:true
                                        Preview:.~.....\L....'..T...2d.=..!.-....~...b)......U.M9......5.aZy..}..b%./......+.NR.4.. .......E...Z........_%/._.........Rj..t....2Asx...i......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33050
                                        Entropy (8bit):7.9935011127657445
                                        Encrypted:true
                                        SSDEEP:768:Sb/w3MsKzwvwTJ/JsyP+/NA/ywHbwlHrIvIVcj5x0:S7w8/PsA78EQyx0
                                        MD5:AFDD8B2B9BF9F8C677CAF12BAD337B31
                                        SHA1:A8EF7EF93C8AF5EB1652338378ADFB541098BE10
                                        SHA-256:BB154BF2D4938EBDC2E977F3468352007A5C493AC2DA3ADA442177DEE15C3FFF
                                        SHA-512:B2C60BA3E7F5DDF1E70DDCC500923A0655B8D8641D9131A3B2C41D7F45E2B0DC1C81B8F4D08D94B1F577DF7161C55017E3A45057ECDF8D53EBC2C72137F0A4E7
                                        Malicious:true
                                        Preview:.{.x..=X.{"...jspK.I....y...dI.. ........,8...S...%%.Lv:.).....o..e.:0..,}^......d.............=.!.".....P.{.s..ULok..D..}V....#2..N..z.q..3.. 6.r..,~..HG.dT.:.q.V9....:.)...?...'7....6N=+k..\.t...d./k.......bj.D+.....i]O.N5#BR.<.c.K$A.%k...+..'.yA.....~..4R...w.F! cM!..... ......!.Q.N..>.r.-..N$n.Chw..b.m....\..|.I...|......W........c...R6....Z.Sg.3tO.&.>.....j.1-a..Z-..,....AR.O;..G..n....D.........|..x(...8.S.S.pR@....[..,..{.}....z.W9....0"Q*...oQ}-..f...{.X.......6.e.>.%....(...ED.NC.....i....].......[T...../Q...,._n.4....).^Ri.1.....x..1.m.....D.x.c("._.=L..yy=`......~,.*........V...I..Q...T.g-.?..u.........0l?;...[.8it.S9....+Iph..2..N.}.x.=..'....O.;.>t.X\..r....}..9..#..+.R.<(...Z...;..8.}.@Y.L..3.....9<x..Hu.v..?.........\..........S.n..a....p|<..p.$.....3..*.l....z}..S:.t.c.e.J)}..2.......m..+.B....Y.$P.Mv..!.#X.&..)._....].H....<.3........Tc.En.rk=..u.9.........1L...f.y..Yn.....6....C.9@..Nl....i1.tu9.o.v.=.;.bgFN..... [..._:.K.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49429
                                        Entropy (8bit):7.995906460820194
                                        Encrypted:true
                                        SSDEEP:1536:oGLPJsYQeweylvoRbFCjX6ax2JTf2aT/G4beKz:1sHeFylmbFCed9z
                                        MD5:ED1D3BFAC419519CFDC927BCA92D6B84
                                        SHA1:2B55478FF092945EB3EC36EDCB186102FE7D369E
                                        SHA-256:D75985AC04C2FBE04734FA3C40BBEDD3070A2E374F15EE0C45D0ED78C7BF53D0
                                        SHA-512:7482FF866E73BF7A715179DEB5946F60D7473F68C99DB1BCCACB65AB1D88129328EB864DBFB82FDE1B997666E32B4B3EAA3A9F6F805CF468840D2F54FFC1E818
                                        Malicious:true
                                        Preview:/..Rh...L..~..h8......3^v.&G.S.. .........y.ddX8r9..&l.W.N....R...7..wqDD.+eQM.F=...@..3.ky..,..DO./I.)-."F.a....S.m.%.".,.A.G.l...".gTG.}....S....!..:......ak:+@;..#.W.H..Y.6.H..z.+2'..Y..f....b..k.H.....ERs......&Y..W..Q....^>fm"....0....E......2...&....%..#I.4...%.cH-.&.50{.......+...x<..E.......R@q#.i..R.m....|..x.:.....r.E.Q.....K...@UKQ..$.}.3do....|..H[.v^.............~.)..p..=.w<.0.F3{..:..B7.5.K.....V...b}........K.Jw.L...Y.{....E.).lK.fn..Xh.....R.Z.!......7.?._.........K.`x...*"0.Na&.Y....r..s....Aq..M.&..UBY.U.......T.B.l.7...].W.O..".~Q.T.~.hV.....#h.].....#L.*r..m../ ....t..........s.a....V....4.... ;.........V.J.x`.8..;..#z...4.L...n..[#.......Q....$M........&......7.,.....T.p.\p...As>....n.......kX..-........G.H!...T...n....!.....S..-c.z..N..j.S...u.o.rw3.r0.{..b.O..$..cBHZ..(-w...#...9....1=..<.......sY.v...cC......uR..q."N.*......B...",0.cC../..Ya..Q../.........sJ.;.JP?N.*..1@~]6......O...@.dq.TsE..8g."&..K4.e
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33042
                                        Entropy (8bit):7.99532894319517
                                        Encrypted:true
                                        SSDEEP:768:JwSa1ULtzX+WELrFQSQO5AdRmwPeRB9W/cZTPDla7:JUULtyiSQ6+mxRB9WEnla7
                                        MD5:1AC21033568E5E19BE7928C3B21CDC55
                                        SHA1:7BEB8EC97331F22690969AB04559F81D410BB067
                                        SHA-256:0987D439B723F7A74D79D67D0179C1134383ACC9291BC82AC85537991752FBC0
                                        SHA-512:54521539EC81CD654B395E8A7E1A3628956F81EF1F388836FE813BB71208E0ED4588AA237CFFCB0D1BF4F82427D4F96647D51B9ADF07700A1F1DA80C3B907773
                                        Malicious:true
                                        Preview:g...b.P..v...B.W...c..m/'.(.s.......d.....`kr..B6Wa.....|...y........@c...!..$pJ...!.....R.4SN.....feb9.%.B.?.ou...s..dqU.2.~.c._n...[..H]..q.\..~.A.M>....{..&.F.Oa.C...x..D..@....RSd..#...b.c.3.je.;`W.-.x1..|..q.|..#.j........!..u.Y..NI....... .qH..P.yn5..(`9.r.R.W....e,.%..z{X..D.;E......n..>7.K.....iA...G@.Gw.P<V...lU..6.z.-.beX.k...lj..TX...?....;..e..U.v.....b.].%<...6...l.t..P&I..q...5F..^_..@...c.yLw....7..TH.P!.Aq...~..b....o.B.j.*..z.AQ......1Y.R.)sy.N=*@..u....6U.O{...r.....A......T.[7'==,L..w. O=W.a.g.........k.v/.E=2..6o.F.i....E...>.j.v.D.*`Q>7.GMI.`..]............... }F.BSth8<...{.5.Gm.n...W.w"i!...#........;|1I.*...VcF.0.y../.....).Pw..7=lA...k.......&Z....n.qH..!...h.....!.=....I.......2G....~..^i.QH]..V....0..E...=..$..rT...4.g....0.....iZ@..4N..1.~o.O..jr.E@#.`.~7.gl.-;L...-........E......3.T.).(.....,$.K.o1.j....<......b.b..'O..yec...U_..w....<t......CR.Mr...T7SVK...<1BR...4E...,.AC...^.V.T..y......rnA#.........p0
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49421
                                        Entropy (8bit):7.996345991889982
                                        Encrypted:true
                                        SSDEEP:768:6UAFuG1Kva3OMpRR4SLH7tg7GA4wXu9mKVSSAdCASVXJYfjtrLXhXA:6UAaa+m7UGAnu9EBdCAKw5rLXhXA
                                        MD5:DCA006AD0A7238B67A30E42E5A762105
                                        SHA1:F263AEEE446421D259F1B8226A6CFDCB2BA6EA8D
                                        SHA-256:C2D8E87DDB55FF1D2A71C7790EBBCDAE621D06D3AF718F0ECBEDF0FF78B36076
                                        SHA-512:E295EC6C293C8379EBF4E995227C8A53E3607C65450A9AE2179986D9DD429ECB56A951F5BB24B13F538A20C2D2F26BA4DE910267E8F55B2808D669592AD4262F
                                        Malicious:true
                                        Preview:.9".78j....M.6..5..8..^[5;...A2.h.*..D...H..b....".....;.'..H...6......x.p.@... ..`..8..f.;b:q.\.6..<....h...?.%.......yp.....q.B.....f>......Oz............+..h.Q..kv.Q.9.!......9c.5.g...\....j4.Z.z^oo|.6.jjZ....-...y..........fU...j4_......!..V..=......V...a..b...w.f..UA.H..2Y...78[P..$.k.>..PS8......LY..V,.v^.A.I..I:.!h[...WY7i.H`.@...O.7U....._../w)D...p....Q7...&r..C..p..1...+.?..kV.....4.R..|...d. .d%.S.]1...cs.F......_A1.....I....".|v......`t.g..........S..a..r..a.5.~... vF.7...../;.c.7,2..a.H.....j..=V.6...Q{...D..,6.H.:...C.^t.....B.*..^W.N.....w<...F.0.......^Jk^..y4.I...d.P...KQ].]..i.]L..5...........}MD.cF|.....t.l.8..Tf..!8..:9.\.<...#Z...2s.`.:~....1^#)#....=.r.#.F..j..... ..a].l..W..<....KP.C....Iz.u...!..==.v.:.T..:C..'.1..+B>...F:....]..$4..}...'- ..C.J....U...B.......Yx.......'.}.Cs..".......%..6`..<..{...]+.G...;C.l....K.4....."...td.s....{..A..hQ.........H->..@S.a..*.C......0....g.h.~Y..t.k.H(..;...I@c..m....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33046
                                        Entropy (8bit):7.994662435412351
                                        Encrypted:true
                                        SSDEEP:768:FLwK2nPS49+bpQd1ohMFExPR4qZtkF1JXqF4U3MuQWmP2w:+/nhUpQd1owEf9C/V64U8uQWmP2w
                                        MD5:CBD1086089DE1835845270F3827C2CCA
                                        SHA1:D779E3A464F5BF950C7EE48D590E45F8E65676D2
                                        SHA-256:641EC1A7934B3D05A38788AEC216D57778E5EECD41A9D886EA19099D755EA305
                                        SHA-512:42C83B4CD72EA3F963491868CBDD763C9A88EECEE71B9D47A759220F3844167BC77AF2DF85FC09EBDAE531B93CE1DB5E8F10CE9FF7712A9F367933D6BF5231DA
                                        Malicious:true
                                        Preview:C}...1.7..'.P.n..H<(. AK-{...=B..=..&.,....q.Q....@..*..6..FZ...rhh"B.....4Y.$...Cm......{@.h.Y.e..0.....Gt....k.,.8.-.k....9[....W.....lK.c..5A....L.?.pSw..^...R=....:g...!.....)aU...X]...'...i.....t.C?.w..T.].<*..-.Q=?.G..n#.......%...+...A..e.N.8.m........../..-m.e.....@_H..s.o.J..O..R.&=.2..^..O.v..!..{.O.J@.X_8lw/cV...,.....K......."......32|JR...-..w..N...d]~.(y.g.k.VsN..`:..#>+.6........,....w.,.!.s.y.y...`..;T...bLe.X..-.C.k..Sd...;G?.P.....s....M......c%....W>...C6...["_.`..uKD2.{`.o~&V...-........7.<*.jN.u.Z.Mi.\&.w.q.~........y_.`._Q..)c.."d..... !M.*..u....e.c.......b..rh.-....zc/_..s....g..i.{..,n$...k.."a....._.po...b_..s..u.....a....?.^Ju..xS......+.y.....(....'.../.....I\..U.Z..N.,c...~.*n...yGO..X...8.b7L...q."`p....$ih-r.1....$......=W.....k...b..8..a.v..-?.}tQ.....q.|.....7....l..ZV..q4.O..W.)..WZ.s.}...M..%.a5..v$....../.......!u6..S]......5.....4..*r.ku........!..mZ..+.e...(..>?.q0.E./....M...zH@..%..s.Y..f.X.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49426
                                        Entropy (8bit):7.9963489395528
                                        Encrypted:true
                                        SSDEEP:1536:ZELrFZA4IDx0bvBhGE/eK4BUTPm3djRib22z:ZEnNLvh/XD+tMyS
                                        MD5:640CDEB0735E26D632889316374A5551
                                        SHA1:26B90091938E8F43EDDC7AE48E082CCE437B2E20
                                        SHA-256:B65F391133FD4B6FDCEFC92F4EAD6A81522C3FDE9B1AA9A7B0F2FD804BF72F7F
                                        SHA-512:33B48A58C41C6C949E44E95AFDC56AF8B79AC1D116CA83C73CAFF1C7804FBC1CF4012561C3329D267AD353A02CF3481BB2FBFCA243F94C50C00B162AE3035054
                                        Malicious:true
                                        Preview:...z.....B*.^8....E.....(u^.=.Q&..y..{........x...`=.j(..RL......e....w....H....\.1l.S..h.\..XY21...>.I......%.3.>y{d....H.Pz..{X.u./&...Q.}Uy.E....... ....wa..;..5.6Ou.....J.....Zc..md0.%X..G.U..d.:...b...8....>L..f.]"..^M.'.;.....;..B..)n......D.}ha.\T..".F.........d].......r.,n.j./.U...zF}...Z2......~,`q]...E.V._.....d.....1dV.f........^G.H.. ...a.E......./O: .N..+.^...f...Y.*........k....t.~6.}..=zx[..A[4.w..+.].Z..s.dsm.%..+a....Sr..Rb....G)...d..}.....68..K..9.[..e.J.K..&.'3_J\.:.E...|.R.3.Nw:..:.<./.y..1@.....I+C9......Dk.=X...:...\..]..,..\..........&r..pc...A.N..d..`.....:!...+....k.K..]......D.3@o....4...Of.1S..e.o..........<P.7...R....*?m..q\m..w......!.........]k..W+t....X....x........~.c.#J....Y4.../.%P_.|..#H.....(.7....e..Kq_...f......^:....c.7;.Wm.7..._sy...?b...*.!".p.uY..I..J..\.5.U....FLn.7j.x..]..$j#...O..L&...{./.T....bcG+CY-0.El..O..X...`.E..%u.w.H..$.s.U'>....T$.n...S...5.5....1.C...]....7G............6..a`
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33033
                                        Entropy (8bit):7.994629040497328
                                        Encrypted:true
                                        SSDEEP:768:Wx++/GJMk4oFjxbqWAM5patmIKwwagBb0wBCyo/6uYd7U:Wx+JJ4oxqjMsPKwgyyzo/O7U
                                        MD5:545D128A1CE4E7C6265CC6DFD0DCE135
                                        SHA1:0AE531A56349FFE69EFB8DEB3418E8746B56D8C9
                                        SHA-256:733F3314897AA2AD56A76B2B2DDE144A1F55BF1AE45524099A499EB9F52118D9
                                        SHA-512:127E02554CDFB5E5FDBEC2E232F764B2CDD55BC113CBBD8223E7B9C839CAD17D81552B49235D1E18A0CB422110F97B42DACBF1AD0D47CABE745CA4CB13D4D220
                                        Malicious:true
                                        Preview:..cp.~...4h.D1W.A.}....'......G[J...s..@z...f.3L..P...c....yN.,.a...I6.q.LQ......eL.&. 4..R...P..+..E.._....X7f.D..mzD.L2W..F..L=<...qK..e.....X3.a.J.....p.(.l.=h.U.#.P....'_..l.s....*..n,2M.M.X..s.A...-d..2!v.U.0[.3..g+w..!N.........6h).....RA.......o..H.4.4:..!........qWj..pT....-..w...W.M).....^D...7...0.'..0G.f[.x...?.....dVi....:.....o.mw....+v.r.J8.f......}..?..1.&P...8{8.. ..CR.rj........8...a....>........~..s..psj .....u........+f........T...f.`.q.G......B........`a|.3l..7.CW\.....).`......HC..$....].EL.s...s#....;........... .`n.."....E..iq=....h..W..S<X..T...8|..j.js,9q...s.v...L.q..rK.2/`C..s....@....Qt..i...</.H.&0>.A.$...#...Bp.u....i..j..!j...b..[t<....T$.ec....n...y.R.'_..1u8s.%.W....n........=....[..y..t...F.l.. .M'...Y.[0g?Q|...w...{.........p..e....J...d.o..q.Q......{..:e.H......?..l.I`...^_...C.J>..t...<.9..<5^.._..!...=v......-.n.....?....'.[.].2AfC...KUr.. PK1.:.7e.E-.M...#..a.2....fI..]h.\4.,h..7=P..!S("Y><
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49412
                                        Entropy (8bit):7.996217460153102
                                        Encrypted:true
                                        SSDEEP:768:8ePEpRAqPdlkDMMMR3NGh4eFWeS2Nj4sTWAGFONWtPX02YM9FQDKLCvC6:8YEpyqPjwCbw4mW7eWFk2xe2LAC6
                                        MD5:9FBEF3DD526610CA4A0ACA71B4A51481
                                        SHA1:0FD9D2915C9861D986B1E9173AAFEF5CCF051BD0
                                        SHA-256:30797DBCC0DF08B638A634160BFBBB042C84CFF2054EFDD5111A7FA704F41F6F
                                        SHA-512:5C05DFCCE86020E0F0D5F7002B39B2BF1A7512689D814FE890FED8820D8874C1413D2AC8D744FF94730698DCA7C41D62F25F7EC157ED89557AA9FC411C3B53EB
                                        Malicious:true
                                        Preview:rL...Q.Vk.).....K .V....Dy.}.n.).q.T#.0...H(._...A...\......2(#.y9.go.g.8...F.4E.\G.j.pN.H..2.._....I.:{.[(0*..q.....!.....3onz.|+..C...?..?.@..:8..Y..,<..n..v..+......m. ]....p9..J..c<.;d[0.k.*...xZ.&i...q$.......].o...1.........N.k+..W.I...d.Z.I.....^....u..5".......'L.....q...bD...ph...._...MV).&wu........$..lt.0..Hj..Q........j.n.j.0u...<+.....k!%NZ.-.8t.(..luF..9..T.d..)v....L?.vT!...I.2..d/.J0..-^.......}.j.Ug.d..J:Bz.1...7...A...jA-..N.......t........;.SKE..(..9.xP.U`=`69k...\.X.....y.qe(.!6ty...1'.wavZt..?..........R8....B...i..C.-,...3.fxe..p.....P..y.8...../.t..B.....y.|.m%.mFO.N....0.}.....%..)...Y....6Bl.?..........b...i....{.)k..D....u~.&..@...C.R5.M.y:..Bm.....F.....\.a...E.....P.......7z..E.i..0.<.A9.D....Yn3....pj`.....*....P$..IM..j.<.2....6sW..e...~).....lpT....5'K...VP...VX....w...rR..5.q.u.....yV]..1s...s..@.....M.......V.....py.H.".4...dl....B..qjG...f............T.J... .a.h.0...<...I....fi5'...I....N...X.%.2?.......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33029
                                        Entropy (8bit):7.994174354653695
                                        Encrypted:true
                                        SSDEEP:768:GiLgCQbZyWUYuoRumLdJkPqLpVvsFBLF1zVGRt/8Fpq7zg:GkWUxoRH5J8yv8fJ0tyo7zg
                                        MD5:126A987EF5480EEF1391B15E0D4AF631
                                        SHA1:282B58925F8403B7ED2F47A8DFB1AE5E64E95EEA
                                        SHA-256:DFD0D98514214F7C240C0E39A9309569C84AB522CF0AF26ACE4421E7DFEAA152
                                        SHA-512:23925B7B973A518F0C1B839873E0C8008CDB6126C85451E67F62CDC97BAC485758B9CE41FF7B582AE219E708D31C8C42F1AD525504F511B45BBA5C3632A39B40
                                        Malicious:true
                                        Preview:.1...BR3....1..B~...F..J...nr.v..[.!..3......wx..^n.....y.....".o.d....8.f....P.lb..$._CT..a....t..B./.1.?*.!.U.Y......-.+...'.[X.XN8.+.(+......5.K....../L.2....:.ao..}....n..ND~...@.p...GYHV..6@..R...,.........2-<$~t....K....i.G....$.....l0O...T:1.vX.|{........?...u-BY4|?.v....Q3A*....4!n..].j..L.Z.-.....7.y&...U./.G......z....p...':[.@.L...9B.CG.]J7.....FiBA..J.....{...tA....P....r...S..N.(...-..*|.?.UgQ.iiF..#\..;.O..~.:YPy....[.....F.}...v-...>.!.....R8.<J}{..S.-w.8...*g.*..Pd.:.P....H...g.....p.-...t|z...C...._mOC....D.h.rp......*i./@2M&...^8.....F4.uO.ZK!..m........%..X|W.jp...T...W..yI.~.pE..f`."k.+.e...p.44...I.)....j.."..Z.G..8)7....E....H....R...w.........J/.............h^.&.BjS."r.!.../...R....t...m.. ..Q.;.;.K.U...aP....Kx.x.."Z7S.-o.,.U.`.25<a...Y~s_.../6......c..$8..dz..@0.....ZJjk.z[H.L`K......T6..^..[....|...".t-..!.a..4..6\g.|.....I...[A.V...@H..Hk..N.DG"..V...U..V.YDU..4....D..9..._VV:....{.1f}P.o..:v.F..Q..<...J.&...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):49408
                                        Entropy (8bit):7.995795744411666
                                        Encrypted:true
                                        SSDEEP:768:X49MX8JLeSfoXNnGAcwCQvFL//CMHk6JvtD88GmRg4inXjNZxXNsY8SzJ2Y:XGs8cYo9GECi9C6fJBImW4KTbc2oY
                                        MD5:4DBB8A86766D5FCE2F6BD22F7E62AD01
                                        SHA1:FE19B592615DE653BA315A231A0F91CFACF7D671
                                        SHA-256:C9B07A5B0864032789A1AAE9674F155DA94DA40D6610EA885F4E1239195085B2
                                        SHA-512:3AE41ED192E0CCF11AFBEDE6965C4CD686EC419E8C2764DD43D92A5B93E4DCAD2129116258C3236E8C48BC99297FCD2595CCD188D4F5248EE83BA7A5F6163A30
                                        Malicious:true
                                        Preview:LV.,........|/....;#.|?....,g.N4+.I:u......A.|m^oyv...!,...?..l.?Gg.:..>..A.WtcM... ...O.H.~.....#.<.....j...z.U...O...J..........A..T..=N-#.;.......j..f,...w_.c....G.t.d..e..M.v4.!.v....qG.2..v._...0...a.'Z%..F.S.WHG^.I...p..}........_..;C....... .jP.?@....#.:.....T.nPDc/..$...36.f..^...._.......q.[..8.+.$.......~.H..:....n..... .[.8.i8...{..... 3Q...6<.w..9..:.4...M.*...x.....%[.2....!L.......S9c%L.....b.o.......b.b. A...iR~...!Z......r-...E...,...X..F....|..uIt.i6..~.H..Y........9q..\<.!...(.Evl..<9..R..IC..d..qL.l.W.Q...hG.V...f..X2.@....;..q+l@.x&......\K.g..-p...T(.dm.....O..5Y........\..iZ.......>..]..U^lx................1..%U.wv.nd..EA..q...%E..ZQ;.]G...>QC.t.f3(..vTab(.TQ...Qh@7..J.'...5FC....a.o.x.4....|k.L..J........5..RP.jv..h.F.77...i8....l...6..|....0.%.h.%.).;dw&...(6U.k./......d%R...H.q...@.....H......c+..[T.%a...........XL..`...Y.~.0...3..i.P~.4.=<).UQ.D..{nT..^..0..RT.T.X.:.M.Z2.tx..E.`S!....mN.oy..C......F._V.G
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33042
                                        Entropy (8bit):7.993815083490882
                                        Encrypted:true
                                        SSDEEP:768:vkyLpdfIxec+uDP4yrTEt9tt3Bd2uDbkcb6Tyzb2Afg6:vRdfIYcpUyroVHsA7b6kb2R6
                                        MD5:AF2C286D21F0751632C01A2EF92CAF54
                                        SHA1:7EAE818236C6DCF4965B6C8567D632A177C42612
                                        SHA-256:0117DCC8F108238D2F91B12ACEF7AD9CE1783F944841813905F3800C689C44EE
                                        SHA-512:E4214CDF3A5E4FB23482D9B3944AFB9CB554253C28BCDFD9EF60D7ABC701A244C81A8A772A83893F251EA153B6D2D24F0E3EAE4C9BB035783E79C69D06815E9B
                                        Malicious:true
                                        Preview:6{5..n....U=.c]..,..I.y.4kE.[....h....>7..-o...P.b.<.8.g.......6`A.....%.XR.y.GXZ.2..e.z.j...........h.mAy.Z..I...oh...o.F..s..FU.7....!.....*v....1...8.G`.....+..F..{....49<u.q.H@...)..~..j.feK@....>..iM..A./...#..N..6..a....zz........_...(C.^5.6.V.2."inL.-...!._..!F.a.T..>...g".{...n.A.}..E.op...6@.<._...(P./8J,D..2z+.....y[.xl...|.Hqd.._......B......wG..%[....}(.V.v........3.J0.~gJV..P...X[.x....ha6.....y....*p...DnI.....({.J......+.).%......H_.w...D....S......Ro.......c...I.....4qE.A....@.F.G..x.F...~.%+.v..eW.............q.c.....Fc.(...`5..9/.f..CN...AM...h.....-..q.....R..K:....H:;Cj....#..D.e...t...$.rY....Bi.w..3..;:.%...Y......?@N._K...*M.p.=v7WBZ..l.....CL..X<.@.@..p..*lC.k(.uW..A.dU...u..n*..w.. $.J.0..H....V3-q.|12.\X.kR.C.D.........e..u.|.f.@....[...b..l"..]..F s.f.s.\.5\........CU.>.$.!...PH4.8...v.zi.N...A..8.a..T..-....i#...V.0U..(P..t.w7..j........n..l.NG.U...."....p7..-......#.....R. ..c....$g.....fv...<r^.|..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):573709
                                        Entropy (8bit):7.818952014333598
                                        Encrypted:false
                                        SSDEEP:12288:XV2GHWlN3JbitAXcbm9Jqrb2rdbAWgSYKrvw+/cc256rw:lL6iaXcbm1Bzh9rv6c9w
                                        MD5:B41AAF4996D37EB255AF0BFC4325C0C1
                                        SHA1:D35AC1C931700B471542D37DB73245A9A22CD4E7
                                        SHA-256:0C476F3AC5CA2AC4EF0AF1F66D0AD93F338CBFCD2CF49F5B602464EC1F92772D
                                        SHA-512:677B015E627919E10556C9C33A94A61E215C7C8008D6EB2F1FEBD294D2709E1C50549232A0EDD6BFAC52B4D02DEB2CB56D9BB3B9FE752E184219D64F82A37AF8
                                        Malicious:true
                                        Preview:3.4?g........z..Es.......#.*...k..m..x.~l..T...8....<$:.#..&...;..C.8.h...w.......n,..^..io..dF..3J).T...O..+k.....fidUhO2.fo....m...=K..P..\.....j..>.......si.uA~.0z>..*^[..hb6.aT?.u.....CWB.*'...l......A...+{....7i....uB...B'..JA.S.....|.S...w..*....U..,.. ..-.-....O....[..[l#-A..H..%HX...j...e.aA<rsk...%..........(L..7......2...UF.....?.G...sw.."....i..*`<.....@...T.........q^y..4}....7.~...<.8.k.|. <.:.b..o..?.g1*..&lO....s.m.~..dN=.Vh..GIS9....2S...f$|3..}K}...!3....S...e..c.+....I.q&. .l.B%6..6.(.$.h..UM..........v..,8....L.1?=..m....,...8.e...v......`.Y..57.}.*'..$k.....yN.u.X...$.t.Mc;...\eKB.Q.........u.].CW....Z ..M.2.8...m.+..r.e...V..)at.P.*....S.).N.8*..U>..p.f..d:w&;.h.\.O...Cv.3....j\9.YP.th..PO]...2t.>o.v..#b..^...':/....%....V0..c.>..W.....L{...'......x..6...v.f..._^Qt]O..fc.S.!...>$O..1...)>.}....C..,Q{ J(.....P..o$...(,..oz....eV.9.]...I...\z..65.7.X....N....\....X.... .r.....IJ...B..c2..I..9.ii.~....:.Vq.L..cj
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:true
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):4807
                                        Entropy (8bit):7.957375166645475
                                        Encrypted:false
                                        SSDEEP:96:QuiF4wE//l15vowF9sqlbOCUDN+qjUaWf3bwS950OVabsDesknguNtotGiMipJc:Qgf9vfs2JUpjUBLwm04+gesC9NtowTik
                                        MD5:17EFA460B7FA912C13BB4D3F5776469A
                                        SHA1:D259769F60F1A9D8A844AA7F67F092005204DDF7
                                        SHA-256:13D4284AF9B93151648E1C3DC9A1DBD87CE3D6D099DE66599499445A351F0A92
                                        SHA-512:7E3CCA0026FD7E65EEC9BBB279FB693195BD4738D76EC11E37DDCCB1310EACDB4718917367A3C2C80CBEA286E8EBF911AAF4C5D3BA823755EFA847C2BCCEBAD2
                                        Malicious:true
                                        Preview:y.Z3jv...q.A.F.p.^.Z..]..V.....3....8.....QEC..(...Q... +..\..k.......v...C......83.~=....K.<w^...eU.....n..:....m.].....1..n...;....;...K|s.&_.`.=.U...~...&..`....aZ;\..?.......^@K[..,......>5Lt..7.....p......@...;w.)..-.c.m+$~eG%..q..m*......7...8...z....|.w.U.....d.1.`.(.oC..'.|.3.pfR.Q.,......z.I...t. .d...pD..U.C...M.....t....(*..s.J..<.....?h.N....^...N.LU.6..M..%..pb..]..u....v......D..>G..u(%.e.a.....Kt?Z]'.@k.........O.5....Zs../.......i..Z.z.).wa........8........J.....}.8y..b..CT.$7...0.'T.d..4.;..%.k.....R.h..`.Q..$.X.....A..2A.Ut.o....6.AZ.o.T..<6...U....... G.5......)d.."O...'..v=.s.SG+6..(.F.a.:....+\4@.tL.:F@.k.Z....K....8....#G....q...I.]...>.....\...S...R..-[-.`..j....d1K..:.C..w.\.....%Z.;S>..oL.....,./...!..4V...........t..H.P..r.&^,Q.~.Aj..Q9h......H`e!us..%....(\.*...V...w...#.....J....%..<.z...X4......A..}x.. ......&l.y\.v+'.Wf~..l.th.R.].2T.2%...^.)..|..#.>..'..r..!Z.o..B,..F.6..Prz..t..$....&5?.Z..6..z..i
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:Dyalog APL version -22.-33
                                        Category:dropped
                                        Size (bytes):288
                                        Entropy (8bit):7.232679614405575
                                        Encrypted:false
                                        SSDEEP:6:HLWrGQG9RGxusEz79e3kHDe0rKDp78frSJVgxGnFY22w20FCnBR:CKQG9RGEsCAUHFrYp7aE6wKBR
                                        MD5:CED56190B769713332829DB8FD89D261
                                        SHA1:7150F3A8DAACA02830E5D982103DC076DF07D09B
                                        SHA-256:C8DB5E1797325832D981317DF66A668A213A53D5B8B007D3EEAA64F0BE583441
                                        SHA-512:4123D017EA26D28A232037E185DA3288C337FDDFFFE7F4642CC75328FF7C622C18AC73B6125ED80C851DFD412C6C7389F083D2AA3105F5B0EE440EE403759D0B
                                        Malicious:true
                                        Preview:....v.i.%..%...Q..9....:.......<..x..Mk.xo/A\KDzWpP.f)......dk........".a.+..}..a%.,..+t....^._..t.\.g.xs...:...|@zn>c...8{U.gH.8M...i...U.....lX..ah......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):33022
                                        Entropy (8bit):7.994977599583541
                                        Encrypted:true
                                        SSDEEP:768:mgEewuGF5oqiW4P/4R7VXLuq+BfJ1AN95MZtENTW1V2jePkRjX:mg85o1W8AZVXqzJu3G4TY004
                                        MD5:EB3B151F6B96C54641642DA7D463BCF4
                                        SHA1:A87444D39D001B05B1C4B1EEEAEC0B6DA52332E1
                                        SHA-256:E7579DB0FD5B0FA3A79C607A5D77ABF843A3EA23D7CC2CA04A4213FE196474BA
                                        SHA-512:FB0359793295E702D27D183688345DBD39BF7D98FFEDB0A6959021F4FC5EDC99444D1F34D8ACE16CFE786F12C10B53EDDC29C56A58EA2BBFC4BBEC37F35243E0
                                        Malicious:true
                                        Preview:..a....?).........a.!8RA|g ...?..$ ..a..7."z7r0.....YW~.lV..4..o.......#o.2-.">...t..<..v+...p.'..{0...2....9...0|.a.g.c.l.E..1.#X.sQ..H..pH3.V...vo.8.%..F.@....97..F.,n...)w..{F.a..:..8..~\..s.g.._....W....k...Q.....DJt..]..;.C...i....b..FCW..92..6.....El5F.B.9.D.R.!l.<.J5l.sI...U.L.@.....N/.....Z...J.^d7!:.9.....-..s.H.....R.z...x9.......e.I. ..+......!.._G.1Y.$D.zR=..M..k,..53.x.p...]...'}..n....c..=..U....W...U{..|.4.QM+{......-...P4..p....k.?....a..+....0.... .y.W.E&.....0.bZiD.L_g./q.j.PiGR..U.P.`.I..l\B..X...6m.0D.i.Vy.4.`MBA.At..[ L....9.........K.w./.A..e....A.#.h..>l....W...l4.5....V..-0D...&... ..,.e.d{N.i......6.E...> ..l.((F../w../.$..a...@.'....}..|S.x.H....{..2F]<.........&...&z.R.>R...\?..+..`..."z.....}..>.R..#..j.....?..O../...o..w...?.=sf../.o.?z....`......\...Fo.x...."..}xl..%*..P..`1..%].. |c.Z...q....6..'.~....K...]l..m........NZ#.......W..jr..FQ..............MO!...v.=#.K4.y.1.h...{}m...`U..*.../..2[.../...h.*.w.a.n.$..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):98552
                                        Entropy (8bit):7.998209068327642
                                        Encrypted:true
                                        SSDEEP:1536:LXOUIzh2fR0fsv72aGGjfgeJnq9ZLfePxrePsbYe8US3CAtAxebulBW:XIzQJv7HGWfg8aDBPsUASyAtnulM
                                        MD5:EA2776FFDA24AAB4865AB504D2AF4460
                                        SHA1:D9F847AB733FA4ADF4029B80EF811ACE7AF107C4
                                        SHA-256:E319D08F81275FCBCA4CD6D15F9F36D7B4E324569404146174214C2AE44880AD
                                        SHA-512:AD0455E64582D24C0C79A5C5BCE7A8B7387C2450DA4CB131A17C0229A5866573AA8C7E21053DBBA67FF8EB462966B0326F8B748FC98757A62D0EA06CB6DA6D5D
                                        Malicious:true
                                        Preview:...D.......n.....:3K...)...=..5.R..7u.L..K.F.../I..R.0w.... ... O.,x....|...T.......;..u....Du3m..% ..I....r`R..vb\.d..m*.(..V....l.La......;+J..7.z..P..j......B7^....5$.....x...#.(..m%.M'..5z.V]..j..z..E.D...V.SZ"../.}..4..~.8{...~...U.u.er..Q ...>fFZ....&.....z.....F.....6..O{)xBgbfj...,....E0..@.g...(.<.Yo.LnB.Qrh.R.....yE...?.W....r.h.'A<;P0W.."....i......./...$6H._.S.....A\.....B.,l.X....e.....=t..M.5......8..Q.!....XL.+.`W.5.\. ...0..&_......~@....Ca.......4.>.X...-...*H..v...T.lY..dLM.=....2..k..).7g....@... ...q.3.......R%P..XYnqF..y.&.....Mv.$.V./.&.......$...W.".'Bv1..s..A/.....^..#...9............-....61.......hx.}.Xa._....d^..,J.r......!6.=.}....a.........kD...9j.CV....<T..u..J..&.S.e .W ..W0....C#.d.@Uvq..yc....v.EE...:...c@.{..Ea...Kl...$v).>ozK.h.><S.fS..;....ZD.N.<..S$@.{..JG....m..p.k#.MNF..b...j&.r;4.~..}\- .....{q\.\....v...._.7.j.-.r....Q<.<..%....H.....k..2S...|....X........['k..V.P.........I.I..9..q]>...?J.5..@.p2..-..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):384
                                        Entropy (8bit):7.397844420166074
                                        Encrypted:false
                                        SSDEEP:6:QCQf+vg4FSNzozWi1mQ/3PjEY6WIq+OHMDP+4l/DiJp78frSJVgxGnFY22w20FCn:Jo+SZIHsQPPIY6WsOHoKp7aE6wKBR
                                        MD5:261C8D614E7DBE81FE72764A90ECD556
                                        SHA1:CBB3654F69FD7E0D020C949EC0CEB9A6DF8C6F71
                                        SHA-256:BC477DEF7A27F0610FE20F1D408847E0769ABDDF147B9EC2E46B0143067CA9D2
                                        SHA-512:A52502B489325136EAA719EC4805E88DC60FFA652B65CAD6B93C932DDF9357621FFFC8ACFAF650D3623EFE33C3D9699FD734D71460AE4F3BDDE282236CC07564
                                        Malicious:true
                                        Preview:..R.'..8G....#.Hf.~.B\..'...&..]._..."..]......].>....[...z..E..MK.m.....-.[.r..F../ap......*pC...Q'....._.../.08.l.@...........P......\.z)......ds.dv.R.y.....cZ0..}O.a%./.......0..p.}.M"nm.....Q.h.1..WA..."..UH}>..8[.....7..&..zh.K<X.E..6m......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:modified
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\ProgramData\2172.tmp
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):199168
                                        Entropy (8bit):7.997425080589691
                                        Encrypted:true
                                        SSDEEP:6144:94HMVKnDH9FUpbQ4HMVKnDH9FUpbQ4HMVKnDH9FUpbQe:K7nDH3CR7nDH3CR7nDH3C7
                                        MD5:BF0B7C0C5BE63D81A6CCBAF49B17EE42
                                        SHA1:C05008520055438662313B92E5FF57A0C0163766
                                        SHA-256:6BEA0E0E32B28FE4F3DBF919500595DCBFB2FFE7CA789D7C74E01C09B3B7D43E
                                        SHA-512:83A786E932D6BC7AE4054EA70640D9DE1047B43410FFDAF0E5FFC5723C19CE33CFD7A64AF196F0E7AB72022F872DB822C09DE5357F9E4783A86032E4ABBD3A17
                                        Malicious:true
                                        Preview:pi....:...a..P.Oh..\.7...X@G..\G.-d.R.NuD.. WOLO..^>.......R.,I@E.#....|l..e@.Yk.e..&,uQDm.!q.k..#.OGP4.Z.'A.t6t.C.9HI.....!....V.aR.].q..!..9..b.<.......x...c... .*...........RXOc-...S...$...c..*...m...'+B.s.J}........" .+o....Z.1....1...Wn.f..2...LW...+..0...2....s.`.....7..H/.u!. .~C.n..!....0bK57b.N.....T.D.L......f.|.V..=}.....U.4..7^Q,5.....9z....f....JuY ...n..jg..n..&.S....K.....J........r...qh...[.3.Ls.......C.....<T..v^@eC&{......E......*..p....h..'Vw...}..8K..w+.l...ZwJ/;B.5...Y..`%.{..an.V|-#,C.e...bC.........{...&.M..8$.bv..u.]Fcv5..q..m*.~.F..2..D.I.{_.U....e|..!m..44D.<"..*.L.Cp|"...47..r.0'...d..9...........9c..z...q........[w.>i..gQ.....GH....Q.\.,...}}Q....{.)....D.f.iv.e.U.|..0Zk`.t....6 ...........(."....;.y......9...K(...b..q8...*..v._..xcE+gsE.......N..l#Q.T5.D:."a.OK...)U..kgTDs.@.>..y`;..y7.)......^...1..9....."......>{..-.....1..w.>]6...e...X..W..m..tRq.....NBV.FF.H_....r...T..7_fp=.......hHT.s...f.G1...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.836415188401908
                                        Encrypted:false
                                        SSDEEP:24:RMo+OPM6E5H2JzkB/rMJeQ5IcnW7rg1jfUKhSSELD+f0fnU5IFiW9Ci4Wp7aOc:Ko+4HK2JYxM0Qvnh1jMQSSWcIFioCi41
                                        MD5:268DEB34A96FAFD2599ADC0C8DF3F1C3
                                        SHA1:A6FA0C7065EB331BA5517F03E711D1696CA6EEBA
                                        SHA-256:C3F3E1BF562C4FB9C8B6573C27087363143839DFB6CCAE2C54EA4D222BEC9D06
                                        SHA-512:06D93EFAC43A605C0E8884E15563C989A1DC1876E5788130FF181E4FA01B0F198D1D14684CD2B70E3C31EEB8ACFD7FDAF6D16ED2346D3DAB899FEAC43CE97E5B
                                        Malicious:false
                                        Preview:...Eo.JS..+.X.....P.&)Cf.h.P..&w.j..r....NT....r N../.k9...Nu.fm...(...@.8.M6e..`...3..S.%@O..Q..\Fw..N..cm;.._......%..O.;..:B.[...+e...W.f.J........^..+..l.r.tX.6N.zL.p.]....N....:<..zg0..pE...6...&..1..Cc.....`[.0...gz.t.).TM....8.4......D.l..G.W.H..m..h...........|..r..I....D....H.V.y.I.....j....#(r2Q........[.)Aa.D|.>....p.I>..U....@.[Y.VD....n...2..&.:....I.p....e........C7.^>...x..'...B.E].8....[...eZ....{`....s6L..>p...E....r*..UK....G.B-\..<!...k.....5..y..v...m.....N+I..!...X.K.~.t..>.T..|..'.H.......Z..PE$..)P.............Xq~..Z...ZW..rEaM..L<.,P.].V..T;.Dd93....Q..`.T..J.2..{...(.Gh....(.....Q...\.I..^...U0O.._3.u.9o@.t..l...7.6.D...C.W..q..i.X..ar-j..w2.<T.yL....Xgm!#u.M........(.?.4..G.W.OV8.tG.F.P.....A.....S...1.......j.#.B"./.C..x1.....V...f.......rCm.X.$.E.".$FS,...m.`...T.b5'S!..V..7..6.*i.Uq...Q&.1.....+V*JR...A.......Y....{VQ_.nyE._.......'..<...y.JNNZ6.!...c.T...mQ.... ........y^..H......v.1.^.c.q.er.-j.T..j+...h...A
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:COM executable for DOS
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.851969609331878
                                        Encrypted:false
                                        SSDEEP:24:ciNW4Yzn1Tqr7UCMDqFJ2hiQxG2sy7UnsPsj6fYc2CEO9p7aOc:TNW/nFs+DswiQxQyqsEjmYlCEKpJc
                                        MD5:C4E0FA8C54E683028FA1BBBEA230DE20
                                        SHA1:1B29235D165B6845D1C8D64F370FDAFA26942F69
                                        SHA-256:F50C137E2D39B7B0F0FE66C19785DF9F6750E953D75B872DA0B57FE8BC6486FF
                                        SHA-512:60612BC098C2436685EBD414A3E31D791489A7CB04520AA2F6DB7953EEA7BD06E04466E855187349D8F6CB3288C1261B865075E49FF2D0BF69531A1D4280910D
                                        Malicious:false
                                        Preview:.....k...E.....0d.%.......i...d....|..3%.>..>...............S#.L[/L....F.6.h.j..R.K|*.......M..Jr....].k.P-V..;.0..G8.....m....e.......|.U....4.'^.........g..4..2.7.0..#)+..D.sAq..C..../U....h..}...a.......S..q;&*.`.!V.#0..........7d....v-....$......M&......)cm....H..^.o.S8,_.e.lzNd.3r......@.4..%..>..2....U+j.......}.#5..;-.H7.:.....=..}X._Q..w....y.p.~r.zsb...4..E.S.....k...'I~k`.Q+nz..=..@A..Z....H...Ei..z2.*...g......[..B.n.....?.RV.JNt.PG\..5...bE$O.Q..r......n.]...p....7.d>.L.m.....0...:.%f?Fb.l.:..#.......K..F%.....7I...c.mk....4..<D.N..!.1.U.!k..K..{...5..cvH.l..F.YUs.M....... ^avUT.82z.k@]....&...L...:.._[b0"..;..@.ox7.%b\........!T.lx."8...2...bq>....6. .;F.....s,=.wxk.!..Q..d.k.^N..A.L..D...`.+9/.........y..F|......w..#....`...#.gwT.U.2.....@...-5S.Gz..|=...=-.8.6eO2...@......c{Z,e......tV..b......B.....EjH......#.?.G.sbhW.3...8...`...>.......w....t.@.JI..@F...i....V.T.&]..g\ .t.G..Kg...&.N."...D+.M.z}9ev{H..fQ.....N.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.830697483557725
                                        Encrypted:false
                                        SSDEEP:24:ryT2ghkRnT/AaCp1BM+bzQsP2/PhjPaxoaYnoyCFPsp7aOc:KXhinE7/uuofoyCFPspJc
                                        MD5:6800C2D3ACC56FCF8B0F6F5C375E4F87
                                        SHA1:AEE0FCD892D60CDE6F98599F97206FB89B197ADE
                                        SHA-256:B0FD85F700AD644CCFD0CDAB3697EE7D7545C4942A51C9FDF20B43F46032C43C
                                        SHA-512:6C96B4CC101CD95B6C4E3DD5904FBE6A4F2DCD3FA2A9A0C3E6B0B768418B7C9155F528D7C1E2198E56AAAB4A72E4C0A31146D90A16750F6078E078DBC43325E4
                                        Malicious:false
                                        Preview:O5Z.'q..D..KN..#.I...52C.Q2....<8..k..5...|R......R .J......f.T.4\.a.@..W(.o...p.S/k9>.HW...[...M....&-.J...T.7..F.....BA..n..n.z..T.]....X0.o.j..BNy...S......a?..Id*a...m.?y......d8ri.......n..M.{Z..".ui...Y.y.0.#..l.h...?...c...H..K.,{..&O.d..........JyIS...s..H....b.c.6.H.BK.V.....j'......k.#.....&};UUs.)P.T..)...c#....j.U.A.....oT...H.......o..xy....h...$....X.O.77}Z#X:..s...!..f.....I'.e.[..`...NZ!..P....0.....p....a..].LR...p...b.....c...+rJJ.....+5W....D.6j.(T..0JQ...M.~..t0.Vi.Ax..@DH.1\.$p..oIVM.5..5pU.^n=Dk.f.k......}o?Q1.P`.~)d....j....;]...*.O{o3.W.....`...k.o(.........p...b..C...w.<..6...Q.U..F....7..`..4.=...V.R....z..=.o..........J......3E.].t.V<.t=.v .j.R#0Oc.......'k..)...~ods.J.j..m.P.?E..Bh....X..-..fN.C.Mv<.xfj.,......K.(........n.2..W.20.E.<........ag\L...H4F.."......o.[...@[...."(6..|......Z.}.L..l..5.O.E...O.z-.UC,..../m.k..p..k..4.N..#....*u.....<.&.H....,z."U.ra.uB..^7zA~....q.\..3..E.u..."C.$...bCW.....E
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.86539896185132
                                        Encrypted:false
                                        SSDEEP:24:sGkIV9QLRHTWG9sVh6VxwbvcVpiimGz6hfx+pboNwh/yh6p7aOc:2IV2LJWhh6TGc6imQKfUH3pJc
                                        MD5:018584841299CE397114F6B3E7C84DF7
                                        SHA1:B74FCADCEDD73FEDCE8A5D8BC5D0E652FFF95FD6
                                        SHA-256:FFA9E40230A82AFC61A1C77BFC88718788599B193FB27E3900DCEFC69D60F742
                                        SHA-512:0C3C63FC6B430418265DB5494387D0D00EC3D73A2633D0801B1DA25C7CE882FB0F59F4813838D7B19C60E53285730B83A80B89627C69F27D26C7D3748CBE08A5
                                        Malicious:false
                                        Preview:j\.F^?......QpOK..Ys..../...(.tZ-+....6...)W.+....p....q=..c.R...?s%..8......X...^.!\'.{vW&b.f ..$KN.ZZ~...UQ.V.6..j..Q...0V...........(.Z..to7-O~....=.....*....G...f..'..C...-NHc.8....T.="..#?.1...%?..vI.....E.y.,.......Z.Sl..>e.8.3......=r.zJsU....U.".9..-..{..g......l.2.y..2)i03.5.C' yv.K+.@9.......).I..4?./.8..8kn..;...c._..U.&"..........l.........l.c..,.$....;.C...{.\.Gv@.....(.sQ.....i..Hw..Lxy"...,...\...`.V.2._..F.-. .7.ks..A....|.@...w.....,Y....w...u=.D..r]3WcnG0...O.b!Sv..fV.......__..k..v/J.-6.......]O.=.tb....e3.[D.....r.T~..7.tU.(_.y\..x)....t..K)....I...Q.5....R*.....B.1.G.....D...c`L.A..(.9.._.y...`..8[...V.....@k....U.*6&7(...'W.^8Ux..........h...x..g.iDu.......~.......Pk...^..p...~*y.1.5yr.f.e..y..K`.z..J?F...M.b.....\W.....c.vE.=.c...:..J..*TF)7.....@.x...f..jQ.5.5...!#7qRgv.fphs...Z.S.Tzou..7...."...s.q.....1....L......G....Y.^?Q..:.9"...Z..sH44.'./....e^.....=..K.....Zo.8..?xQ./:eA....P*.8B\C.....p.L.?..=
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.841745996937077
                                        Encrypted:false
                                        SSDEEP:24:hkzHYzKawCXkVHp4ki5dvOursbrkKUWk/X02pFV4Sp47hHaM1SI9glbZ72UEp7aV:mLF9CucDyDUWk7pFV34NZ13gtEpJc
                                        MD5:342B8980760B93EA05F356A7AE6EB0EF
                                        SHA1:A5F7D40CB0C8ABFCDA10789CACDA225AD41584BA
                                        SHA-256:99DD3DDB6091CBCDD728BDF3319CACAC522303B222AE2FCB9C6BC05ECFBAF594
                                        SHA-512:067800B9A540EDF685D34013063786661D3DD3A3BEC0E5E91533068F76A651527D247333C4503F4CDE8B7F7C9CCDF58991374B7C7CEBD7E65A3DC18D8957C0C1
                                        Malicious:false
                                        Preview:O..'o....8..:.....PA.......5."....?u.}Z.H.....D..?U....V..v.6"....~.n.!....(..}C.......U./Yyrye...i.. ..m.;jDw?U.......3..D\...c6|jH..B..P..b `. 9..2-t..p&.<. ...~D....c....!#5.....`.I...b.r.u.".......b.C.^../...2+l...F#7...}1._.%ZO..'....v08_........I.%htY......5...V.U.J5..g/.*..4"N..(.. A..W.V.........$...)H...0m.}.0.j3...?.Xb.`.........V..sf.._9......[.F.W:k%......3P......7.._..wz.E.HW...}`...".k3...._..^Y...V....0................ ...).atZ..S...i.zb.......O....CZ...{%.58>...!.\..o......[u......(mS^P..l.U...........".d....d_.. ...v.BH'<.YJ.. .2..Z.b...ZKk..tJ.0..$:.+...us......0n..N.......#.z...iM.....g.N.X../{fec.....eRf._....A.'H.&F9...k}...f.WjiXs;.:....;..qoD&......J s...#.0.....xx...g.W.7d.TV.....Qh{...ps...W.I$...Q...WX.T.1..'.AB....4........E.-...I..[.S..'.......[U.%.,S.;... .....O....9=......hyV.I......|,.T...^....R...\.'>...b.C.Lp.zV..DP.kl..!..5j.=.j.Q..oO.Y....P.!=.PH...0.!..!%R....t.K@.f...6{.M...%>#88`A..,.......9..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.8586160669801615
                                        Encrypted:false
                                        SSDEEP:24:wnkzhzuda2ZZQ76Wr1r5rOk7st35YvUxslJhuT74ePMDGFp7aOc:0dPfktSaS3ylboffFpJc
                                        MD5:C770DD5A75156826DC1ADCF60027BAE2
                                        SHA1:718E61ADFAD3A2E271B8871DAD8962A6CB5F3486
                                        SHA-256:3827F2A40435C9B20D1473847834B92FADA9E9C75FAFA71FC9678B429BE62931
                                        SHA-512:24E6AA9EAE3815D306CAD9576252F567C366B05A53C6A2E9368B137486F202CCDDADD8A4BC7AB8E768494D60D7B0E55478678C8CF4E9043BA1DA19AE49DED9A3
                                        Malicious:false
                                        Preview:.B.[........%\L.r....Gx.6.M....\.R).v...l3..z..kD......!...y.E{MV.g'P.:Vu,!7.:.'..*.6oNZW....[.n.$.6...=c..l.m.g.A.......}e..c.R2..\.#*...L.....?.&.rm{a.!...s........rsm....JH.]X...f....Hx..(.?.\..~.....#,w...."..f.(y...l@w$.7e1.WPt-..*.r...1#j.........).:.......8....%.f.(.F.x<....=f.7r..P.k....F..MH1.k:Dm...k..9..I.p.....P.Cb/...Pq,...b.1..R.oU.mF.`.9...5.D.;.F....h0..I.3..\+...e.}. .ey......T.os.{.enAY.P/M..+d..:....).f.}..m.A..5..G..T.e.<.{.#N..w.:6..D..-c"..T...t|.....PR.P.o&7..\....y...eR.&.>../.H..U..h..H.....9.&.CH1.....).%.....M.w}T.=.rY#d:.39.D.Hi..#.M D..:....:..5..Kf.sv.n...l.%t.c_S.Lof...1...?..I....yk..naM...z-.*.....N2D..1(u=.O.I.{r....?.L...AT{...g.+HV.p!..U.z..........5P....?..e.T..V.M..xP.}..V..!E+...q?.:.O....C6r.....j#@.9{..F....(4.$%.(okgk.d.._...>?......!.:|.{...Fr...h...s.o....\..<.._`.u....S...c0......;.h.....LiU....2L..H.....FB2.a...0.(J...].tW.v.......$..S..#...t..(\..2.......D...m..?L......0+..c,.......Z..........<
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.856918427130306
                                        Encrypted:false
                                        SSDEEP:24:cEvIqZaFSAJ/os2ui9zhhV8GeR/YvawqsvYKxaFvvcBAmKBKdbSyhTp7aOc:1vNlbt91hHbiwcKMFvNmkiVpJc
                                        MD5:EF7F4D488295B1CF963BE15A5EB887A3
                                        SHA1:422B9B571BEB2F713625F9C2879A5B8B88477081
                                        SHA-256:10A3AA1FAF85F2F420A704074BB0F72CF7657F7C063D02FD625699384F3834E9
                                        SHA-512:69B9D21A24EB0887D6EEB06F370C102FB801D223F8AFDD255FE33848174EF2B1344A8232285B6A8C238D2D2048DEA07F1970961B1EB550F8987B5B02E592F6D3
                                        Malicious:false
                                        Preview:. aWS.D.k..W+...o..k.?......F.....Ma$I.AQ5C....&..w.T....r._j..._...P.[.S.E.V>......L..:.c.._..pp....G....{.).E...;....ux.Y.....<......L.#....oH.:....;`....S...2=R.....S6..%L..H.k....t.i.m.:`g7,+-...&..#.....xxo..u...t.3K).ns.....I..P.....e...i..i.g.".......).r.&.\K.......~x.r....^...V.<N+..n<#;...+..e.I..n..z.....R.v...l.q...FF...:..e..Z.?..9.....}...q.T.;..I.Q.*.et$I.....V.dD.&.5.pz.U~..M..h..:...y..a._w...V... ...rH[d...R..w.*C.4@w...U..e...bN,LN.}.`?.s.........%..A[..O.<Ae..x....{mE.@..i....%..<..^(.....c.....m...h......G..3=........k....^..q\.s..s...|.I.g...p.....V..V..E...qRu..T.\d.D..s..6.\\..-.H.B4.....|].9.+EB1.Tj......f[..:m.p08hv#V..W..'..c..)..?...V#.(.b..E.i.."".i/;^...e..S.0.gN.....S<....l..............;:.BW.a=...J....h..I......].pR..x...K.t...C...3~ZeIP....*......$S....m......#4i...iKP..uK..tMW.A........>i........].*.f"6...5q2.>2C.x.*dM..Mx..w......L.<...W{t"~.......Q..X.."..S=H.L....(~..C..;...9X..7........T.:....&U
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Secret Key
                                        Category:dropped
                                        Size (bytes):1271
                                        Entropy (8bit):7.862951693865457
                                        Encrypted:false
                                        SSDEEP:24:joA86tMe8aCwl8lxEWxX89WG0G/jUd31K39Kuv4TlqenqNkkEX8+p7aOc:joAVMe8aCwl8lxEYkWGjUV4gFTlbnqoO
                                        MD5:6690AADFC033AC547D38DDBE7F4D60F6
                                        SHA1:E44F8293C5A7505F36113A5378DEDBE6BABC64A3
                                        SHA-256:EF2352AAEC53CF89253CE49ADA3E28C1455AD8AD359F68D68AD45C4D7F8F4267
                                        SHA-512:79AD1AD9BA0760DD25E2F306EE8049DA711074A2CA07497DEA8A3835CFBE03443C14F7EB24814B199C5C72EDE5B2D47C5307CDBBB3919B4F9D69AF14D938A93A
                                        Malicious:false
                                        Preview:..]....vF\...).W...|J..|..7n....$..f.D..>..).,b.mBT@m8..R.S......](R..ep...)K.K....U.e....l.E\.7O....=D(I..3.k........11,;..%....3...o..{...........69..s..A.`...BZ..R..+...[.W.s....^.X ...z.l.......N@.9j.......JR......%^..-}.~..m../.iP.ANQ........;...Ps....x(.Xj@.Id...5X.K....Y...Z*D.c..M...X..(G |.([....7...V3...)Z...)X..).]n.h\.Z.d.)H8/^.(s...(:....8.>}..Y.t-a.}.`q..+.....03....d{.UN#.K-u=.V>.*...yo..s..k...)9N.0TIh.a... 1..2}....e..E..x..B.aB.Z.2k..>..l..:|.....9..^?.JuD....S..*.t.K.i\..E..@...*....R!.kL..7.f..ub#6C9OB.w..2.....;W.j......5..p....3...$...'..8".@.).#...z...@.......s.-......ew..G.l<.r.....>O<.....xc.a.....*...SnKS...y..a-...P.Rw..8..;W...A..5d.."..[.......Y.F.......W..8.i...7@.p@...Vcx..^*K..3......h..$E|.v}.E5..q.....$[.R...U).o!..`9...X'....P..Bj...N[...u!..~..b...nQ^...7....t2..T&z.1*F1.!.HU.h.kd.m.C../@..E.TC..... c..@x.K!:....q..;M=f.m......u...._.c\....q....D.,Yr@.lj..u..W..]..A$.j.y.4........,F.6..k&...l.e^.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1271
                                        Entropy (8bit):7.860287787421211
                                        Encrypted:false
                                        SSDEEP:24:P8VZu7TL6XElTPkvxiPrNJ2jOhEZhZ46Y1DdG3p7aOc:UVeL6Ul7kv+rNJ2jOWZ46SEpJc
                                        MD5:67DE8C87F5375812FC446C01F231CD44
                                        SHA1:9E3A7A9257344C5154D7EE4EE6C5211D0ACBA441
                                        SHA-256:62292EC277C10540BB98ECB7684826E8EC24D093AA97BA1B817FF8A63D97A292
                                        SHA-512:86D43FBE3D03F28DFD8F24CB1A6942E5E379D091E32186D6F40FD2697D34FEE275CFD7ABF5A416D9428FF8DFE04127D8D77DBF168DA2D8956CB47CC87B6B70EE
                                        Malicious:false
                                        Preview:..?.EC^..p....._...7[>..r..V..H.~..l.z...[....*.V.X..e.|N ..v......&..O.[...)a`.S..3.....\Z[.e.N....;2+..|..._.Wb3.....cm.O>.@.7.p.Y.a8+_.......Y........x.8.P>...9t9."R...9*..7..._'><.I~.!.u.....].R../^G.=..W..........9...A..]...r.Z..'.....uQ..p..#...PR....]S_...........,.D./...P.^...s..e.)9.i....#t$.>..|Q...C.t.~.x....V...o...X....!...o.....w.Sj....Rs.S..&.........C.+...^.45;3&.35Zd]..&.4.?.w...=a....0.x.=l.'....1.n.0(s.;.....7......$6vZ.....V<WK.8n.D< ..?.{E.!..s...]....qA}M8._..+.....\W..&.(....^ri.L\.CGT.z?w....3;{3t..q6.P..<.(th...e.A..D.F.....@z.$o......|5..I...F.~.d..i..D.^...]..q.T.$.....E.......T..v.'......v/..^w....|..j.4.;.{.y:...G..N.....l..;......S5....)..G.V......nY....=t.7.q..&........Vi.......lF 1....*.XbU.....S<..T..b....\.,r.....L{!..V..Y.$..C&.@ E..F.....w..ud..!L..K_....gn?^..SsH....8...O..-.....*...D......g.....l........M../.y.9`K....[.C...2B.N.@;{..7<w..A.HB..J.*.....}'.......... 6.iY.TT....^W.+}.cz.2d.U<...}AiK...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.87153397399252
                                        Encrypted:false
                                        SSDEEP:24:qjZj8cmZNX7FpWCbT+8OUB2v9kvV2pmwALX1TZLVlajePtOSFp7aOc:qjZj8c4B+9AUpcL1BVojidFpJc
                                        MD5:E09C21100AF93C18A5AC2679720C1D6E
                                        SHA1:7ADD21499A1242AD70D762628ED3BF569FEA96EA
                                        SHA-256:AE73912258F608E28388C871AD03C4A9E5EDC442CE060CED4D6028F1C3046884
                                        SHA-512:2E4B71D1998E99A3AB0F3F7F48EC0549856877DA6F27D98F0C64C3DD59B0A0F90717654F164A2A2761FE143569B33394525CAD791E6F46520B0109D444FFA5F5
                                        Malicious:false
                                        Preview:..t9.F.S.....!.A .....hF.b...TS..}..duI......C.......g....z.,..v.B..x^^HCn../u7. 1.N..G.G.y..|=.R..tL...g..i..b.q..W.,...^.Y.._~..P<Q..X.d..b...0H&....A,..}.....i......s...t.M. 8|U>....8.`(..(.\....A.....s....&.~H.....oR1D.o ......,..{cW....F.N.#t.... ..-.o...3E....Y_...|....(...f.#D..".y|J.a..&X....0..].m.9U..#c?.}z.....W.i.......p..}G...].{3".q7T.79....7.v..1.1&.C.W...x>..D7....BEj.J!fh..2+......s..,L......f.T...k{.....<:.p...FZ..r....~6...N.9h.4GE.qA..c..s..=...s.s.jg.J8..r..'2.D;..l..-....*.Z.<.......|.(u.......i..B..=4.HV..j.0.f u....e.u..{..<Z..2-4....z...:..S.z.._....-.i.tj..}.=n<_.......]...1.6e...H)J...l.......m..i.*2pm..@.[L.....t~....PO......$....[.L)6jz.@.u.h...'.~Z~.%...T....l[...@....*xH.5-.Gm@A.#..O..t.fn.@w..Dv._w..J..%.\#v...hE.z...7.O...W...........vv.......O...6L.,e6.|.....l"..y.e.Z.X....4..p2.........*. .......t...IpQ..FDZ..E.....U...QXsf.E.....~.. g.1}f..k.=K../..ta.[..h.:.d....a!..Q`.f.6A...^*......d.a.......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.83275592310483
                                        Encrypted:false
                                        SSDEEP:24:XWB8ZscPT3bKBLOJJpR+aBsVsNS7x9Z3/N6xaV1Gy+Fqd2JxFp7aOc:XbPretS73Bs+mZ3/NcaL/92JxFpJc
                                        MD5:A7095C128B92DA70C73D2782B1DC12AF
                                        SHA1:B0BC48B2AFEB44B690963765577BAF2E4D3CA627
                                        SHA-256:CAE84C9F91062BE97E6FE30A57C5887CECF088646D942F35D8E4B04824A7B0B2
                                        SHA-512:C2B9219E5EB7CA2246869DF87626DDDF851E5950E927E6886CCC2F7711195935ADAE4E1CDD1644AE58BEF8A2FB50AC007E276E7C7F292B7A5B491F2EC66AD15A
                                        Malicious:false
                                        Preview:c..u..t f..}..,.v>..O.-p.?.$...U."<F....>h..2.-H.5...v.^p..&+.E4Y..K.......V."..Y..i.kC.w....U.b]./%.B...,hG..W.;?A..q.r.E;.Q.$.E..p.....:.M..2C..$."....+...5....Y.\.."....W.|...A....W7...dP.}.pA...N.......YA..".s.j.<.....~.U.Lch...m)._~.c......9/4.8.6..'b.w.0.h.p.vd......H.6.{...%.h6..d...m...m..J...o.K&....u.b..e..&Fe-..M.R..l..H........*g(.%..bx>...............'=o.....)j@....f..)...<...@........../&.<.O.....!.m....#..v...*.n..;..GI.=...../..;...../..F.._.....?.L..n@h.\.8.4Z..\........w...f..yqA......b.......O.`....AF......Z..^.g.q.:......-......ZLo..]..@........B.....73.mQ*...OYe.D.,g$cl-...:K.M.L6.|....V?=.D.}..)..}$..J....Az.q...*P..}..L\.....md..%....YS.~..M.K3..T....a.zfl.0.Nl..~..P.k...t.-~....$,\..G...X.5'..E..C).....Mh1.lC.&...yf..`.F...p...8...-..?.z.T...n.......`.q3.v...>..;...........j.0{.?x...A{:...H.L...np...3.[.......e*......U.Qv1B...D2.f"l.VZA.}.....o..@-Q.. I..bN*...2K8.}r...t..e...{....b.h.......'t...Y|.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.823661660528826
                                        Encrypted:false
                                        SSDEEP:24:JkvIDbIcB86585RALABbUxzKMjtWzZwYh2WYVnTfI9UprHV3ZE938d+9oxiBi1/j:JjrBh585G8ALtkwYEV0ahCRM+uxiBO/j
                                        MD5:C757A312201E14B51887ECFAA767D684
                                        SHA1:64E31FA6A4E43FC48677AE00FCC4BC1F590CF7B4
                                        SHA-256:3AF620BB7AB8748C6A4BFFC9D3A7E08F579C22497772BA9C82031D40EA618DA8
                                        SHA-512:6BD8E13530065A7191DDA1FC5F2CD45341E31DC18D7DB02EBCE8666A6A01ED46FEB95FE740468AFF59B2B0DF161C2BA05E72972A456877C5E789F764527B259B
                                        Malicious:false
                                        Preview:r..*...R'%k...]...,.....r...JM..j.n...\.g.dc..7..*....r........N\..p.#..."....E..>Ex.2...Y.....[...;..g...1.KBZ&.x...:.*~......p|.PX\O..\..^f..S..L;..f.E[.~m.D.]m.. ...=.).A.B...^K.h^.....)2...a.dkn'.M...P..et...I.....l.....Yy...\.Cx.$.....I...a.]...}4.]1...X.........mo|..*......XC...p..&~....mw....ev?{..>k...;..:....'/K.x...*K..)....%.d.~`Q....4'C%Tx.q..{.......t@4W..m......+.....=....d...k.x...P.....[...1....'...]....n...(.......*..J.n..N...q...(0....b....E.....@.48.>.P]oi...A.IC...V[....).T'M.j...W...G..c.N3x^'N...Z.\.1G....;0..#...%...YY.... .lL......x..DZ.Cxp..O....x;....Z...bN.$o..q.e7.;K sQ....?.`X.}...{..9u....|..'....|8....,.K.i..O...i.<....L.IT.k.....6[....W5.......G....YA...|s}.),...P...<>..+5fr`.xqQ..X.6....9?...G.z.....8....9.......+Sj...)..S.....5\~.=..f.d.....RHo..zy.....K].r..qL.&..2T....A..yj.....!.~.^.sw..[)(._..#*.......n.aN........g.p?...o,r. .r...U..,.~...:d..\.......5.L.b...{ .PZ7Z..otT.pr..6UX......xc.....$.....
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.8350137707079845
                                        Encrypted:false
                                        SSDEEP:24:lQX19OHMgii14EPwrC8/H7SxZA5Je6f65paHWI/nv6Ap7aOc:ei14E4W8DFvxwpAWynSApJc
                                        MD5:6816128F12EA56E1423964815C73DEEF
                                        SHA1:879D52A178C86185F5E365ECD0964B9AB7BFDD1F
                                        SHA-256:66EC9FCC269D9EA4874DD5F57721100E51A2DFA18A3832F2C479E527728D5B48
                                        SHA-512:3454B3D2DE54493A70C663944ACE13EB483C20443153F45D1F5D9D6E4184140ECC80A4BE5396C720F47FDB4F5527587B9A84379F967AE8B1FEAC5A1AA1F13AC4
                                        Malicious:false
                                        Preview:........\..1f.`.u.@c.t......|~3.5...{..Yg[a.DzFe'Y..Q....e..&5K.....C....#p..w.X6~.bf.$.W.8..[K.....dyoS[..l. ..ph....p..k...5........H..>m@.g.jLM@.rIv}B3.jL..[).v(..>.J}.F..y.&..o..`......[..[..7a...4G.K%N..G.....e.a..O\....].+|!..C0.0d.;\>l..)u....g............9.i..!..'&.|.{j.$0..Z.-0.> <....hD.k...]=..+..W*.m(....H..g...w...g.<L^..?Og..g.nu.....:.%...9(}.(.o.....9G.... .C.iu.............}P............1.F...6w.qw<.Y..Z.157.9.L1$di..&...Ub;..X.l.....s..~.'bw..8hx......i......^P...eH..1.......?$H.Q=K.w2.0N-...TW........!&dx.._.....r.]^]..o..6..9.:.."mE+...x..*...f..$A.-.....F6.J:y-...=...D..#@...$.....)Y...S'.........)....Y76.G`.a.....8..h..I..I.h-.T..Mgna8.%..t..-.C...E..8.....0.a.....4...c...9d.i..He./....w|'Z-.V..YH../...vY.L.:.e....M5I^.+....v.S.Gd(/cs../.{$M.k..`.......(......2.+.~..S...K.s...(.......e.X......S.F...1...g....G......)c.o.....>..6.....bo9..O~U...3..c..:.....\.#:.,...;%..S..Rs....:....Y-.W....*.q...K.P..)id......4.JU.o...&..e
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.863297060778159
                                        Encrypted:false
                                        SSDEEP:24:ghCreaIZt8t8a8LXV5brOmM96ut9DVX+MOrjQikofu/d5/IMWpp7aOc:Uyt8agV53lQVuMOnQZ5qpJc
                                        MD5:AD564BA761576E6195C5AD108502480E
                                        SHA1:08AD8DA34BFBBC44455D039E932FD9C26EBAB8C7
                                        SHA-256:0A09995981795913C95A59CD7585FC4133D7AE59E42D84ECEBFC499877A7A8B0
                                        SHA-512:A126C0482AD93C47EFD3297EE7B06C14BC397EDF7D1D04989F45E57DD31A21760226E2187525F5AD468473ED0FB818E2822F50721E7E216CC18DCCAF59D33793
                                        Malicious:false
                                        Preview:;.K..u|.N.*..b.9n..|.VB.J.....7...........u....R.D;..{w..A....}......HB.]G.....<{q..c\1.tD..0.':.+.D...V........55.v.......5."2........9...O...|.....8...R....;I..V.K".X.\.{....:2...?._.......7+\.3...=....*..Z...1|nx.v....R.a.eG.[g..t.p.9..*.4...............5......).w.Xj.uPZAf...E..-F).5..-O.4H.n....|......x...F..L....d.^..A..G..h....E.\2...P.#.Y.......JS.W..!.,.)...L.e..r.....l.,.p.....v.A....s@...Evb....ufY.v.U.9u.EGf..s...[y^.hsT...[..9F..&.....76..I.z....X..2{......AuFJ.C....$}.D%fg....{..4..g...R..P....r.JN.b.\...[pPj.x........V.*...r9)V.A).P......RB...I..n.;..).\c..A..(.k.%..[Y.......<.j.....O..*e...p..:a/..rb.`a.../5q.0.Vx.%...a...'...L..Hmf..1_..n.......q.<......zU..[.s..g_.Z.yx...l4~.f.`Y.tF.7...BX..+..(...E.f....;....;.~..4...DKUw...JV.y:;.$.9.T3..#L.A.]...+]..!....Kq...x.4_..:....F....d..tw].|x.....H...Q...I..@.lK9.B2D0..f.....Q1..j.C.8.*.=O.9.3y.......e.$...5NmmF<]T...7.F....o80...2...V..H..W...1.....F-.Ea.........
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.856085436053041
                                        Encrypted:false
                                        SSDEEP:24:8ZoaRUTMJjkUy0bi1aOA1Kk8wWFH3Jg5BpZl2sqP2Irw05vuXBp7aOc:8ZoaGQJoVX6n8wWZJkMsO2IrwAvCpJc
                                        MD5:3B93E55ACF21E6539B753D17C727B8CE
                                        SHA1:BC0C4CFA8C34F6BA6CE31E15D03778D7ADCE4789
                                        SHA-256:2881209E8B6B2C28AE62A8A459C331A2EDAD383162D914625B4D0C9DBCA0CA78
                                        SHA-512:A067AAC6FCB826F14C5C2323FAC4E2CD6A3A29429E2FF68606E38DE88C78E5F498B80C64795328302ADB2E9FBEBAC14E61A16A2BB4DA6C7F2123C9B582C79443
                                        Malicious:false
                                        Preview:. wx.;^.O.i......^[...;:w@ux'...z...@ex.....gji.a....Q..:..q...g...x.ZioC....9F......x..JQ2....799. ..F=2....2.,..qW...l..-+.....|.a)k.Z7}..L.t.......p.S..&w.o........>Mrv`.C..G b.R.Y....q3..........h+w@..a......g~...Tq*.-.H....w.KIe<...C.C.Wl.3.....y.]...t%).T|....Z..*N.<..{......POd#.....]..Y....].e.i.$..p...`{.M-X.3g..........6....T..Ts.H...{1....K.\.wl.%....L.EM.;..@.u.g.Ruu.<...r..........y7mmF.Oq..F.5O..0\..Lj..i6..D.q,7...\>2./....d/..m0...^_..].C..W..:N}......].bv...Ct.H....E=e.v.B....Bh>.......M.w.L..wC.s Wb......3&.@~a....o.....E...o...*.,........p \..9.7.Ig....U.Mt...lL.C..4./5d.....I..w.C..f.n..=U.+.....lC...S<...Ik..Uw......a..>..`.|`..b..?F..i/)B!...j.5....|(...@~.b..8.5U`VE(..W..r\W.Ljl_`c....c..~v..........u.".I.{Y.....?.}..5...U......0U.....q.'..o......M....N@....r...+RX}..s'..-m...w...5..^fbH.....ZJE.l..`.J...D.g$*.ob.).....#R..{+1o.../;.C..B..S.?....G..'.s..T{..2.....C|...>.|.........{h......V...k9\..M......Hyg
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.851779396012989
                                        Encrypted:false
                                        SSDEEP:24:/qY7G2lScAedfltg90y0tVndQWBqvWBjpqDyvU0c/2b3ccjAIeR9wp7aOc:XG2lScAetg9CndFqGqDyvUSb3FjOCpJc
                                        MD5:24E83A6025CDF86121A2DE23A4A856CC
                                        SHA1:75C5D7BC8D205AF2E3E39D2B7EAE63BC04B29DB4
                                        SHA-256:90E02326F64305D8375596EC0185F26271241D93F1C72ACD82773E59705191BA
                                        SHA-512:F65F65026A747DA82A2770BB3CD94E98D17F902E7B551A10331DFBE465355F5F1676C8BF72FC619DDCB088CA11EC6FF49AEE8A9F76B7506DBBE6788668FC46C0
                                        Malicious:false
                                        Preview:y....;...Y..W.>....U....9'..,....j..r.v=>s.....y.A8..H......l7..6.....8....HK..f..Z.O....../..u..L..p.....[fB8.'.7..m.Y$v...$.rL....".Z.8.2......;=.*.r..g...v.......\.qi.]9...7..y......3on..$.....=5......q..9.&..o.j.......\..(....[...m.d.z...w..J8../.*.%../.Q..x...KU.4Z{C..B;.h_...a..q..w.3......_.V1......95.j.jwj.U<....|.........87w........^._L......w+...b...E..uA.F.&.L....F.z..>7......,..G..|(olE!.. .\,....I...y*.{....d..ZJ.O..I%.../..M.B`Y...@)....u...:.9.f..Nz.Y.....I.Z...mQ.Z.Z.(...v......s......hF.W;)..(...8|..X.ot.o...QM.....(...,..v7..*...&.j.....M<3..6.2.r..\.Z.B...#^O=.Av./...R..........mv3.7{^X..W..@`.k..3...[.O...#M.Fn....<..0BF..r.......6s.....D{.._...}Thc..qK...h.o../..`...A.M..&qpt.y.g...50Ay..p..f.#....>..rM..%a..].!.DV.eh.......4@.k.H.g.'n...-.sl............b.J..r_.(._.%.Y.L.:...^.]..}w.'...R..5..}O|.n_...tF.lGiY..O..x.>.h.....R1.~..*~.~..[wX....dp.Q...Z...w5(.4..j.C+...u.t{.C=...?..;Q.......
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.849244917423206
                                        Encrypted:false
                                        SSDEEP:24:JLl2GoFIFfSUcnnHUTZlZlx7h5z9bsvybdIiteWd/W+Wm+IMM5He+5x6p7aOc:9D8HUdhx779bsvm2i8Ww8+IM6H15x6pS
                                        MD5:C4C335032645271DCD0FBDAFE1328B46
                                        SHA1:B374FD7380A29CEB3EFFC4FA6EDEA4A86E06C8CA
                                        SHA-256:2BFB81795A7185D48115C73324C656D29702B2F842CFA0BC53BDE45ED2A6BA91
                                        SHA-512:07C013E1485E86D6E41ECFA608F26955B46746501B1F47A74F924530BC899FA8884B4A76D8C2306A22800CC180CBD0E5A479C6CD3AD40C240305FD4C503B4A40
                                        Malicious:false
                                        Preview:..5...........v4z..t._....E.b.&.I....iP..w\Z..nv.D..<.#d.....qf.I]!-......;ID....n..f&j..3.....:.S...q7.!...nD.NV#.|....g0u!.i.W..3..R..H..vc.6.L....zW...1..?:.;.6.....f....,...3p^....-w..M...u.[...M.u........%..:5.!.k..%...w......n.%%..udB`*Q..A......~pU..'........E.-.x.F....V..B.?...Nzz<...}r.|..m5oQ...=F..t.*..uS!..P.:.+.........4....[.j...C..sP.....V$..m..r.(wb(.w..~y..+u.*.......z/.......+k~.]R........jy.? .lAcU...._....n..d...Wu'.....e..Y......-..X. .m;..3.8.....`....J.>.<.>...j.8...t.....,U.0.@.g.#.=...u.p?aC.!=.E..:.R....'....E)v.g-`i...[L..|.....p...Q.[.:w.c..%..uBSoWc.6.. .c..1..../q..t.^.....).KJ..w.HN.....ZK-..cX4G...eD.' .&].Z.}=...i....<.....2.....mn...."&...}.?n..pa..h..J%+T[.*U.....o..[.P.....je..&}..\.k|>1k]..)~(d.u....D.Uz..e....8av.S../.X...;..eQ...z..L.[.~...k....`zt&*...g]:5....bD...u..n....Y..(....yPB.#...E.....h[:.T..u..)Ghx......vs.....|g.(:...H.n....L..6.;.-|F......o.+..<>.|......./S..ff....5...]...T...L...c...5..p`
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1274
                                        Entropy (8bit):7.8252110422321675
                                        Encrypted:false
                                        SSDEEP:24:96FeYYqjQcSzyWHVOmXCt07kxA6tIr3uCWe2NIOb6LAqwjhN0/KzCpnHYwLqvrIk:4eQccSzyWLYykxAsIrFWhbmAhjhNkIC2
                                        MD5:8382EEE6C1C104CA08258EADDBB216A8
                                        SHA1:5AD61DF055B97FD71DA153628254CFC491E336A1
                                        SHA-256:CC27B8C46EE9DF8BE6B0DE35ED28F6AE1DD09499B0695F88D7C66D6972640D23
                                        SHA-512:2DB8575F972E3CF8F3D3752CD31BD1C16E4EDD5916F357FEF5E60D4BB0299649B8C14D4F62E6533BD4AC6A54F5D4792A0A0B42699EC482FF0C704681496E3997
                                        Malicious:false
                                        Preview:Yu...T.....a..{.oZ,........"..$.Y-.I:TD....Q.r(RG..q/N#F..i....~e...t..B.! .|.L.d..7...=......C.c.U...`.)..|..@...v'.2LN.I..4....A)6{...np......._G.Y...vJU...xG..../...O{.A.s,...R....k$N..L..Wz...."P....$b.yV....lL.+...(g..9D..`.<p.b..G.}..N...R?5.....p..\...>....s.....9..~aK-..&g..T.<.x........R0&3kLF.Uk.b^A...;.lT.x..\....)8yU$...........D;{.T...N|&.....f.. .Fd.O&...........u..l.i.&=G..T..Duu.t."T........-....}...\.!T...k..MU{.}......3.p.A...0..2-. .f..9.DH.j.`..=.........~...q@.z.ZN.\.k..<.x..z^v...K...D2......tiT.|..3I..........."MJ.....?._.G&2.Nd.Us..,.q.)...*..v..........D.bu9!..kGTb.....k...4.h].v .t..|...).;..bzC..t...n..MM.sEY.....&./#.s.1.Hs8.".).t.../a.#...k(....1.l....8h(....%V..r....A*.....*.1[..]R..3.YcU....f.K.....=.9...T.uE.ak...i.5..c.;W5.tye..)....Y..^1.....r.1... .U..t....).l...y]5r>5..C...:{.5.p>.R.5UkFT..7.8..?..x.O.hO.P.eJy...k..V..s.{.r .2.st..C....$..^+o..K......!.*...a.J~......?..^.+.xY.|.2...3..o.<..2.cvA#.2.!}..@.>l
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.825817315677867
                                        Encrypted:false
                                        SSDEEP:24:wBLzRlSUdfwBVHTTmXiRkwe6u0CFX2qp7kzIVQIP24tgTEk9U+LEASO2WAp7aOc:wBLzrSOfwBWiRLJCpFp7kzNi2Suq+BS2
                                        MD5:464288C4F10F6131CDA1313104DC41F4
                                        SHA1:9C37B2DDC9A797AED91DEDCC59674A5907F3A5AB
                                        SHA-256:9ED7993076AFDFB7B914B023B0E826530C193CE30CE007B9DAA0E05D9DC2019C
                                        SHA-512:60EE05BD3826BD38B3687B2E94862F6AA2D204963A7E60C6D5C2C6A91B584A1A4D38EBE032FAF1988D97D33E2E068F143223B1EE2040BB3921895F324C886835
                                        Malicious:false
                                        Preview:.. ...:G..@b3.a..T.@...X...};..t..!.xB.... ..d<..2...[%....\.....p{. ..p..._atl-.M..X...Ot.A>..#&..-....y..h....c.}..W.\..F[}K...}.m.l.`."^........k.._...~.0...q...s.....#...#...w{.....c.M.c.3KD;..>..?..W...:R .N....@..zq.+E.5 .h.....<:9 .ke..$..dq.?..wqf.3...H.Tt.&.dkl........._9..._(....{R.b....w..}V..}B.cE..a....Sdg......b.]f..#.s..d.....=.R...7...Tm.U.5wl$.....]"?4!...(.~...........~e........`i.w..jKl....iJ"Qb?.9|....|j...*.I...mP.~....`.....L.-.Q9>..1.Hr.........e........Q.+n.....%D,v.......X%...V..v.50O.2x..!..{.Z.G.pPO.7_[.y..7....wV...'....ijc.r.j..s.f.C.Q..T..n......^.j..$. .( ....ul........O6i....#..#..>..d<.`...J3.+z....!..]e.&....T.f.)nS...ze..&.Cg...?9.<.y..@...'*;b......!|Q...~....[.vK..6..... q...<*Kx.*.[z..@G...'......Qi.h)o......2.p....}.....`..LI....i..v...O...Y..vK7pHJ.2....0....O....9_.&h.....-g.wV...%.f.J..x......?...Z..j.*.....{..Y..4m..r?.G\(...t..}._.rI..:.2....k....,O[.Y.....b,.M%.f..K.J..T.Z.;wj...}f.P.N..:...."/.&i9.`...~_..z..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.815056374130521
                                        Encrypted:false
                                        SSDEEP:24:XX6HBQuWlY9YsN7Nq1h9AbFYK95ecmFXMVxP+9bOp7aOc:XqHnSwYdL9ARYaxsaP9pJc
                                        MD5:AB0286B0EA01555AC329502017B19BE4
                                        SHA1:D075B54AFEC51A2947CE148E9BFF876AA28D8805
                                        SHA-256:52B53566E0C77A90163207C44121BEBD534AB5FDF3F0864BA52DB6B58EAA33C0
                                        SHA-512:59EAE9A957C99B64B3FDE2A896CDDB6D0F574DE2D9EFE6A9B2849D33878FDD93D9FCDB692AA4C11E9A08DC58E3D37E413F6DE09A25D75F56C7B858813E24FF5E
                                        Malicious:false
                                        Preview:...+WN..W_....)...sX~.2...-....<.y-..yO.. |.....d.....Sx..xp.t.X..........(."..q.%....f2.....a.a.....'...,4R.uA...C*..C...j<j.{<..u.y.u.g........nG.$............P.j..A....?.6...e..M[.7......bD.F.C....@t.2.;..Wb....;..&&.......O...O...A!*.tB.].`...hy....C...I...4.....;.D...@T..y'..&.....P.=nZ.zzX..y.@.9i..c1G.x^.L#.`50..%I(....R.c..{R4t......$..E9.....6...).V..p.\[.p..&..o....'......."k..=[.Rt.5..ERr..&.(G.....,s5.q4....u.m...$7.jr.R!......C.....Y..>..KWu.....I$..*.;$.I.........e.%4......q...7......X. ..%..n> .........#.~...e.g.;.}T..)s$.J...E.u..2.t .XQ.-...f.~.9._.......yg4..K...]z..JITdU...k7..&..}.....U&|.....N8.x...>B1.W..7]p^.....b.J.FH...e.p..8Q.Z...+.i...%..I.i..?.......9a)....2y.... K.<n...Wb.y.2r8.....~...<.l.t........-.....,O.....QL.N<..$b..,....]...R..m..MxV1Le...l...`.|.M~..T)..0....aU.&.:>.N.XZ'....8+..^....e..Gt^6........1.......x[....).,Cc..[..^,P.P....;R.2x..x.....A.."#?..m......),}q.3.BT.h<.G.-.V..E&R.T.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1268
                                        Entropy (8bit):7.8434651076768915
                                        Encrypted:false
                                        SSDEEP:24:Kkm75Vhd2pe2JHUBW7zsX70hu76avWnhfw4BRGYp7aOc:TwISSzsrGauntwSFpJc
                                        MD5:D3E24F8E27F9F3A02BD6A736C9711035
                                        SHA1:CC18A8CFA3C114F0A6B8CFE6008581B7A984FDA9
                                        SHA-256:72CEF56BC75D3A594EBA86A65CB5F6B5977D23C31AC62B1B4A32A69ED3F870E1
                                        SHA-512:9C3AEE7498C16CAF245863FCFD135096440C4EA455EDD8B109269C5EB227CE8742BB9828B22FA103A9CE53FA885AEBD97849D3E133759F92B230C0001D8CB9F5
                                        Malicious:false
                                        Preview:..~y?6.F......."....,r.vJ+G2.............^l.?.\.d..N;..p...^.X.[.+k%y?C......H....K.'....../.9....N@.........Y................*f.l..U(...Be.*g5..^I....J.5._.%q....m(d.w^N.......;.............J..Z....j^.w.}.4...h.|..../v.j.#.P.~3...8i......m.yWU].....N)OtT.j.,..b.....f=..uz.HD1.K..`".4.k?.....[.K/.2.....eh!jG.....6.7...cri`>............~..h_...3.V.z.<tW......D.k|$.OpB .8)(.7X.#..7.AF....X.d.....|....G8o..{C.-.(e\...^.'2-^ ..H!<A..l.....'.a..8...3.4.,R..o.+U.D@...S./..M..J....j.H.~........Y`.=K...I........j.../..W......M.......F)..../@..O>d...T.l?X..b|L..vy......&zZ.RYH.v-...!.z..^B}.P...O..#.>..*._]..[o6...._."...HTeP5.B..%.....R.I....4~.G4.6%.m.._Xt.%J.].pH...#........=......=..E..hG....*P.d.$........}.0.N.o.....h$..;.f........ze.Bf.........wa.W9^\..7.T.Z.Gp....~..r.91.*.MQd...5..K.6.BL]..)...t....~.....X..\5.....F..0* ........5...L.l.h...9h8.'<..G..~.c...+.......>I.>|..._.2...H.C...E_.+w;...'g.`...1fu.j....H`...x...I>...b...Q..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.866508163585782
                                        Encrypted:false
                                        SSDEEP:24:G8BPuI0tq+i3TmycnYPfewHZmoT9kCc2gbqOuvWYEvCiXSup7aOc:GqPUY+cmyoQfdBkC9hMCiiupJc
                                        MD5:7A498F61E77917332A9B1D0008B951AB
                                        SHA1:E21C2D7BBDD8ABED6F9488B2765A59038EB334B6
                                        SHA-256:39AE77F54B3E404242B7E763B3BE508640EC5F0700AA8E7F513C1A21A0F715C0
                                        SHA-512:15968F01B6D84D4CA72AD6377B4CA84F91024B2D94E6E38E2362C34960125D3DC50B7E04DBEAB54E212D80F898A2C11BAB2041584252027CB7C8AF39B1E8758C
                                        Malicious:false
                                        Preview:..?=.0.....<.....<Us...l...7.J".....ay...6.\.v[Z.Z ....u9._.y.z@J...<}......SV......th..@8..7.nr(..\.B.....H...P.#...|t2?...`...fZ.......gS..$.>-J.cm..............D1.vW..e.:..w..x.+.iI...!]...y../s...csVIZ...o..qS....<..).[1..6G.!.hR..p0.{...^..9.7V...a....pA.....L... .:.&...VW...x.W..X7-.B..0...U....a..h.....1rHm.elH.E..l..y|...fX5.tcV+...q..$...,k..3b.,../f....#..W7..F...^..........K%.....R..a..&.{...{_.... PG.....f.8u.g...kL..?...0;.dB<S.a#.to....k......~r....p.7........H.1:f9J...@...cG..'F....*>..]g....p..R...x...5.H.4)..nw=.P7...8.......#.........x.^.0....[..^...Bm*RW.....P...Dc.y......^..YO.D^..8..Q.....^.y....aA.F,BW=.'...UY.s0..R0[.a...MC..d'....NqIM..J..~.>..O"....c.m76.b+q.).?..4..}./..P.y..*.a....z..A.\3.d...F.g!..}W(....x..o|;-X.M.}.)..`$Lr..{..3p....5..r..u._.1............A5`N.*....OFk$..t.....jm.s..`..5......5b.....j..P....V.T...h.X.z..e......X...B\.XC....RvC........."r./.}E...".._.....1...z....<H.T}..&gh..3.#.L.W.h...M.W.-..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.851297886598686
                                        Encrypted:false
                                        SSDEEP:24:cRocLws4ZyCik7B1DktzxIex2eqAL2UTY8cxsvj7n5XyGa8Eb5M3iCerygC9/QpS:cecLtEN1DktqewLAqUTYVwoP/57CeHCR
                                        MD5:DAE4D2DC8913A997EF3F6D275BBED738
                                        SHA1:4444E5B778639D845566ADC6225ACEAC71D87272
                                        SHA-256:E196C392C9DC9FDA0F01AAE20B1F6CBE9DA108C39240529292061760A6E63636
                                        SHA-512:BE6FF0BCC6EF7B1C313F40BDC84D13D558F373CB22B168F8A029D6EEA6B2D8912A3AD8BA3E345DC6FA0AED3CB203EFE46A6050279D6BB32C0F881B1CE56366AA
                                        Malicious:false
                                        Preview:`{...7.T....e.`..x.]n5..V0....E..|.J..m$#.h*.@....Q.]...-.P..J].7......|?o...==.n....{.AJX.=..B......D..d..|..[.o..R..q.O.ISp...]...}.S..#.d.$..C..k..aw.<pU/......d#...@.*.Z.aP..../Q.Q..Pt......an...F......#.y...LS..(.....6".'c.2.c.''.L...{..I..-.f.xa.)..G........5z8.fg.*...w.0...KIb.....C.d.13....nz.irQ.m<.M..54L.3.\.....iY@.X$...*...j.~P..u[........D.....a~>...5u...7.L..."......X.1.2x.B..).$.^......B\2W0S.]........X.o..e.M;3.....$[..L.5[..../..:..b.j.e.u....,Q.. .c.....L.;V.jEQ..U......Q....'...DO...a}..9..N.Z.x......R..o|.z....:.z"A..9D.^.pH;ub...*...O.......o%...b.|.v...J.....t...!}..N#.UV'.[.?.8.......%.9.`..4=.V.w..j...6....'..f....G.X+.......D`X.`TK.Sw2....A..k..2................sC.\..i.2".....L....!)....-.."m...0`^R.;..'..6..B.....K6x.il..F...LM..$.2.J8....'.X.a...;7.U....5.V...*zO..9..)....&..s...gA.{.b.)....S.z*.^k*.Nb.s.7......4.-3....(..7._.......E.......h.Rv......*.......!;]..d.Kt.2.......e....v.@.....`.-cj..G..........}<.'[j
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.840552028616512
                                        Encrypted:false
                                        SSDEEP:24:owkIZyWGPLgQcaQ3LcB2NYPGNln7wKDwexgN5Qu/CWXzp7aOc:fkIZIlNB1GNx7wKDwNg0CwzpJc
                                        MD5:2126931614757EFC0AEC0523680ECD32
                                        SHA1:0744F44FB94061E310A27B8053328736C3558604
                                        SHA-256:75B76E66CEFE6162C58E13CB5AE4D0047382BB07C7B256219DFC3C1F6996A19B
                                        SHA-512:48EBDBAC2D9FB49FAC8021FADAEE3F2E7CB82449529FA809E1E79A716C2FEA916090B9A3A4430AE3F03E3EBD3E3C30F3E0BC85C83E7C2FC1CF94DA663CF148A7
                                        Malicious:false
                                        Preview:E...[.c./BO0.l....k..L.....`"._.....0.6.n...}..t....'..*S.X>..B..*.}.lZ8l...U)/..z>{.d<..W5.(...a...}J]....!.7.F.f....d!.t,..K...^Yd...[..........F.j>...V..|I....t.(..w*_.0]..j..7.SG.u`Z{.S`..,.Rj.......^. ..f..F_..$..I.4..~.~..m......l.<XhF...(.9..r...k.A.{).....g....3N6...x.Y.2...#....i.F.*7e/..'.....@+9)......8-^...0$....r...?.M"t[.G.b>8........._.....A...L.R.5....D.Q"..2.Ui...>E.SD.....'...........x..............i}N..1...'.y.SO......*.0s..:..D\..,.9..}....zQ{..h=..<.......%Ix....t......G.k1(.B.G..~DPa.B.Nz....4*6....I.U..~A./..d..k..X.7;.H.4U.a....i..BE.......|.ZU-.(7~.3...!. hZ.,...l.qx.F%B.....H.9:...1.L.B.r -)....|..v<....t..FE..s....hU..B&.Zv.`v.y."2.. >.X.B.;znUQh.qz3.H"q.?...L.G...O34S.-{..Z.......LDB.._.I%,."Z[..Gs%..L..]...................*x.#.)P.M....._..E+w..b.^...*w.mo...I.7.....-.......?..D...2..'.x.A.A...O..y.Lf....vd'....+.*]J...>.M....w'......4.L.r.........@..P-.u.;L..m..5........'c.T..X..C7x...tG.QX....x.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.858811322778889
                                        Encrypted:false
                                        SSDEEP:24:wWKT81jMIG6J5IM+qGlRG8kMKWsx2szT920Vrvtxg25XVyn9VcTgeuhM57Wp7aOc:wTT8xMNWWnqWGtr7x2szT80Vvtxh5FyQ
                                        MD5:503BACBFDFDFDC3AA2186B906EB857A8
                                        SHA1:D3C221828D678C34E5E627E387A7A808A55BD9FE
                                        SHA-256:0AA04A0F02A6A6E8DCD0D022CCDE1AD94D93820410EB6E1CB79E0AE005A75178
                                        SHA-512:AACC060A3E1D07F0DAB16D4D306F149447DD713E39C47EB0966DA3D5309880B28B188B29A6E62579944E4800FF2C57001E3FE79B64E870644DA6121F3CCEA3C8
                                        Malicious:false
                                        Preview:.w.bCe.?.........s.7....X.;...U.....V..g..?..R.....Z.X........qq..DK.A.=Br.q.WZ..G...j..`.\....Z...Q.E@.......%2....".....Zb..x.J9.,.5az4...a.O(Lc..E.~..u......b..Uh.)|.$...d.:G.z.c.Z&.g..T.X.s.Oh..x..'7S..%vs.+...V.........0IM+l........D..b.U.c....7.!...s...f..OrW+9(Y-Ka$Auv.b.r>..&.........p.S.hf.}sG..@...8#.|..a85......<r.1S....#..{..y.D...r...0..A....;E.-.c...m.F.{....|..m.h.. #S.1..~..s.'....{..._#......*-M......|..A\.....Dn...9y.J..p.d.e.~)....f3....A..<....AAE.1...`3...c...sEK........=.....n.F. ....M).....'.P.h.#S{&Z...(.....OO.<)..i.vMD_....n".....J..E....z.:.t.p...H.H.Xd..... .U(Q...#.6..h+...t.;...."F...j.|i..3.....J_..."..:....ojX%..j.zg$...Y.<....=.U0L ......9.....T4.....i..p.XX*O..N)%.j.=../.jx..E.\.......9.u..a.\Lb.....D..G....Pn6o..Fv.Z\.........u.D0...d......$T..I....V.U.!O*..68+^.:k..E..../....p.Q.^{..&h...@>..U..=T..$...q.zf...i...S_.u..R ..B.....mz......).*.\D.4...J`.^.._..;.A.....pA....g..Q.....Q.....v...._.,..R?.{u&.%
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.864684388418172
                                        Encrypted:false
                                        SSDEEP:24:15wS74z6+NvnTlLgpdVLrtpRWZt2sSRpGp7aOc:1mSke+NfyjVLtWKDRApJc
                                        MD5:5E1D1C54C78E1690A5B8C2BA6BEC1963
                                        SHA1:514C3890463196D3D22E9700BAA24121016CD61D
                                        SHA-256:09A6ED84A74BDDD7E692C1467DC7DD24FDC5685C3470395D245547C28B36F55C
                                        SHA-512:EFF1533DB29EBA70828A4FCDDD8C63109CB2C9CFFE1AB01DCA635CAE64092047968BA42CB51B2D66BBCDAB46666ED6328F9A86A405F5E2D5BAD9E1E67746265A
                                        Malicious:false
                                        Preview:...(..........OuSzN..FR....-....Tjl.....`>...0P.t.....V?<..P.k\&...%.K.+....Tf.W..6...g4....-......y.e@...0..L".[j/y6....QR...H.?T.a@...0Q...C.k7..4...n..33....vfq..@HN4*r...z....X0L..R..:t...P.Z...'~.......e.!|.kgd.}..9Y)i........C6.......Pk./.l"..s......r..9......z...1....../...O.._.X.n....d....#...I.......$.b....).Z(r^...`D....J....3..t.XW..W@..X..V1.Hb...ad...^...la9oM....SC..v.a(`..F....... ./........-.(kZ.M+........DDt...AXb.r...E..:.g7.QL.....l...}.j....#..]..?:..1~x=..{.3...\g.B.*....N....Sy0..Z....n...RF..O9.Z.`....o;;}..a...m.z.S.=.7eKb..P...d..H.+...O+&........0.O..!.....W..|V. {..F........{ng?<....@...wi..r.|s........Y...M?.;.$|..N+.Tx.>....~9@.Cg..|..p2..8A....K..Eh.....=.....2.@...%D.D.v......x:..)..t...K.....5.2...v..Ma..... ........>e....e$D....M.V.V../Il.}..oA.y..h.c._3..z.h.^L.?.F......I....e....k./7.......t.Z...I.D.%5.A....5..O.=[...P..M..J........u+....".3...J.C..m.....9V.r...#.L.a:,..s...V.,U..B.J...(v(......<#.fR.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:DOS executable (COM, 0x8C-variant)
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.856591654044859
                                        Encrypted:false
                                        SSDEEP:24:LoBMzhZoGTK1EMWNJaZXuIh1I6gxzpl7+2WbrLqhg/7k5p7aOc:xh2CKJM4bAtzpl7CHcgDk5pJc
                                        MD5:4AC66F96B6ADB80958D877CF30C66432
                                        SHA1:9030BD7EFDDB2DA92E11E28D30839A8BE9300B0A
                                        SHA-256:E6CA1C4BEC63F5AB8B80CE5A1D0DBAA6D3F181F0F68CD5C361A6AFD85F6AED55
                                        SHA-512:8E87320AED6DAB2782D487CCF20D51510CE0DBEEBF8842383860497DC3E0F65B1745D869C4ED385E3DA97829740A2CB65FA8113598572E311CEE054B0F5149ED
                                        Malicious:false
                                        Preview:..Rt........A..o.g....ZJ.....>X..sY....?../.{1.h....r..A..KD$Q.!.}.&u.Sf.&w..V..V.%..\.M.. }...c..l.v...Dr.L......D.........?m...u2..l(...<.i.&.........IH..~...z.T...Y..a 0.|..n...~.kG.5....}p..|J.X........../Mh9....`.V. .zK..5...[u.d.Q,.h'u<CuE..M.....Y..%.t.'|p?.S..?..y&O.Lu.q....E......W./..........G.q?....N..#...!.5>.U."(...5.3PFMR_`....<..O}P.)2+lh.rf...Z.#r6.^.y6[...?G.t...TC.9....&..$.......k...Z.p..s....s~@.{....:...S[(...dx.8E......q.2.E..h?.W.h..6o...J..7........(aX."........3..6......BO.....v.a............gxtm.........l.{C...g..a.*.m..W..>ZBd..p....B.dQ.a...4&..i.suo..../.fyA.....\.)m%.B.az.&....J<qy.}z...T.+....U..@A../Fy..d..,...I..a...\.:a......|#_y.O.cI.E...B....j..8. .*a(....l.8..I.5I..V.M...q.FH..F.m.xq...k.+.q%a...aez....O....,.............8Z4...<1I.V..}.*............+.3..3w..(!.q?.....N.Q.......j....f.RH.r..R..Y`..,.Gf>.F.........wO.:....).eST.....:...>...C.X.Mq...9..1rgP..!Q...-.@.7.F...R.l....Bm.f.......%(dvJ>..=.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.859824358771715
                                        Encrypted:false
                                        SSDEEP:24:VxJpJcBcRfwWi93zCWOa+8aCWFUtWG6AAfdX9yMHKRrMqjPXQQBDVg8p7aOc:nJwcRIRzCWNDZUUtLg9RHKRMqjoSDa8k
                                        MD5:435EA546AC5D36E2868AB43C1CFB29E2
                                        SHA1:8F6794B1E8FC6DEE3924B4A2FA02C55F77ED8F80
                                        SHA-256:49AB3581776522D905556586C3094C450D0467214F48E9DA153607B4838DE076
                                        SHA-512:2AC09C53C3881A555A58D875B635B5AAB59FECE3AEFA8691D9DAB22A6AE104625DD6F0182EA7C09C0C594EE544B4EAF83892EA13C8367BECC11FEA3054877DD7
                                        Malicious:false
                                        Preview:.y.m..L....c....T.0.|....D..@.......).b.kh...h.EJ..%...5.@....L..:....Z.p.[..Ig...........}.MQ.V......+.e....w'...Ww...D.a..yR|4_.]B=`g...l.W>.o ........K..X....~d.9T.f[...U..j....H..>...xFoUE<]wq.Q.....GM9.E.09.. t.p....9zwZ&^...!.@:..........Xu.:E.i..t...bEd...& %..:x..).....]...x.P..$.g.m......[.W.h.[....C..K...5.zn=........\....oR...M.w.[.=...:A..j@.V.c0D..7~.z%...-...Z..e.yY.0w.Od..m..y.O.U.<.@#.6.\h.G..3...B.U........k.{....=}......+....B`dN!$.3<.rq.J&o..{m.}..c.f.wb.g&.x.)3..~....Z)V.8M...]....&.....mt....W.W..b!.D&'|.....\..]..h...Ru..%,5?.........-.Y..'..<.oz......Q.L.c..3..A6U0g.C!e..h.+.M.. ...J.`...*....l..5.[.[vg9. ...X ..m7...`C.......\....>8;l..2.$8.i..<...........S........E...5.p...e....b...H....P..4I.Q.\i...{}p..{z..H.$g%/.:7..I..2.G.:&..X.......332..x.5....lO]V\...NW.I+R...F......69...i....4..I.j....!.P`.........[.&.xU.:.C.Wo......t.._..I!..>.}.M...."u...Z....'.....S.}.........P#...,..q.It.@i.S.....c.n..Do.M.Bp
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1271
                                        Entropy (8bit):7.87165788959964
                                        Encrypted:false
                                        SSDEEP:24:0Ng3fDfk7cMpopRXIhz5eTQtBV0el/hCmxa0COk/cdu+eRp7aOc:SYfDfk7f+YhleTQtBVfpNoCReRpJc
                                        MD5:C3B66FB72AE91A91815F7AE132084165
                                        SHA1:A40596EE77E7B0909C7C1B0E9D708CA9A5BDA046
                                        SHA-256:05D980AE2659B8FC2482DC81D4D420639362D3D5DDC7205D7A820C93A4AD3E46
                                        SHA-512:3C779A94D3DB879C010BB59F1E5C7933464398B40513AD2D66F1FE67AB800D05514FB7C1DD9907F07DF803BC0B123966954B2440540035732EB2BFF7608B1F07
                                        Malicious:false
                                        Preview:%4@.m...=G.W!g..\Hi....8.p.j.O.Q.......e.!.............@s.....#CI&n....%?.c.:tC.55y...../..".N.O.0.^nK. .....z.k.N_".,.Js.>N3...9.....#M.a..n........3...CZ..O.^3L..^..].......`....?J.).k......v.Y.. ..x....BX..~AY}.s.h.......A.`...G.u.6X.'.....7.krw.5..."..|....$.....C...!......:.?a`.;.......@.%*0..7..'j..U.6+...i...x8.vN.+.k.....{.b...\>.t..y.PV........,...`....p.d.N.N=.mP_.....oW.p..?.;jO...t......Uz..uS#....5.I..$;2............v#....w...........R%6Q.8...^.s..a.l.'_..r2...T.^_..o).6._.Q.f...G.....-.1'.....U.....K..Y/m..y.....g.)4.U......,A...R.`.1.u\...H.~'....n.EN..V...=..@4...o0z.Z=.W...$.p.&Jh.....4..__.>u.r=....0..Lq.u.q.P|../...{..I!u..$..K..t._.,.C..TW........&G..a.....e..w...$....h...c..7..y?........m.X..]../{...O....e..O......v.0.:.%...O.*...K...L.....9...Q.O....,:.v.L...h.K........s%e...w.Mv,....r..,.....~.".G.&R...0.^p....F5.wu;....h.....u.c>..t8....w..1.QI....i.8...#..Z._..Y...w..z..&..C=.k.(GP.A2m.OF......_.?.Z+...a...(.D..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1271
                                        Entropy (8bit):7.840065061064641
                                        Encrypted:false
                                        SSDEEP:24:mZwjxx8LU7XiJOeL2Oh0sazbmtb0aFlOnP9LuMGA5F2u9IAxRUDkoouU4p7aOc:muxxUUbUHL2oubmt3F0nPQfA5F2u9IAN
                                        MD5:A0C4E07DDC6AC00514B83877EF15AA68
                                        SHA1:2568E2ABFA920513177B97BDA563FC6068CADEE3
                                        SHA-256:8890AEBE3E15267A323934B6835B24A500D8713B4C83BDD22D4F5A566E19337C
                                        SHA-512:F79E88B2566AC36B8469D5D3642EF48F28F9CB569C8E41ABC366C2403B2E19EB522F53FC40E817FA921B1D98BF1570A191FAA23DE583270FCDF1FF6863E88B77
                                        Malicious:false
                                        Preview:...}! ..`.cu!.....8....z...}/%.W...R.n.......q.i/'..N..t@..f..,p....o.o.[..V......]...(.B.............=E..X...."B"J....V.Z...X....E_.8.."...#..a}....W....b^.N{j[....I...T......R.i.....`.....$JAS....N.O.D...O.8....0.|...Ex...../..2...."...8...t......h..XU.....e.+.g;Z.x..Wa....uz..N.V.....n6J...D..7jqO..#K..o.&Y.c#a..U...F..vE....bN..E.....%....PX...k\.[!...h.Y..H.:IfW."Z............].ZuODFqwN}=..w......An.........'94>ml.t.&..$^..,.....;.....U...l.&.1.m...`[.."..`...d$..h..L.'.....+..F;...6W.u...g...=.|.d.....~..Y...^..c.1...c..c......pZ...N.i.*"_J.*..y3..bq.i..5k..F8nD...L.K.5g.......T].. U.....e...|.w.HWN..b.....m0K......q&..hY...hFJ.......Wowb.c.+....4....:.z...hs.....Q....9{A..24...%.F{..ZB.....^.......}.?....K......."....k...H.{Q...ry.V....S.P..N...'!.Ur..*....@.EP5c$..k....>K..1.....NJ...._m2EK.O..g....00~4s.....za..E......f..^./.Q3......J...~......+.r.Gl....4.[..n.R;;...,g....EJ<w&...S.....u~.k..!m.C.e*?^.1...4"..n..8.. kO.2...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.807933262615748
                                        Encrypted:false
                                        SSDEEP:24:QBW2BJP8ZSuqMvFkGMxeRU3IQhUWhCo1AFCn6++XziKRWjvZh2p7aOc:QAMP8RNFxMxKHQThz56++jRWj32pJc
                                        MD5:4B04E37F23DA0DEE524D1895AF5B6432
                                        SHA1:A80E3B8D81FC111E57A693A0DCBCC6D2D870CF79
                                        SHA-256:50C73A0B67010EDE29104D7B35F4FF0D36EA6695A59B4EF1EF57548007565385
                                        SHA-512:FE53B6DFD2B72F215F9428593F327622560E50244EAA3FA1D109CEBA559A433F915FE25E562C6074321C4F90AC90AEC4B6F42B286669015342F7075CA26D3C2E
                                        Malicious:false
                                        Preview:_..t...jNx.....%_.Vb.......|..8d..>R.Q.......g.._.KGt...-...q8.o.....I.k..E^."...H..Ft....^....9..(R.........(.<.i......PD.(W.r.......0....0..=b d.{.U..g..C..n}9.....M}.8..s}cO..7.f..C.=..S1.O?.........Rsfk.wM.B....I...\....+...N.rE.)..g.:...!.."..;.P.x`.<..kT.+.^..1......,.]..j7.........p..m....;.g.o....ND........6Rq.`..].-.........o...W..0...c.Q.~4.q.Mv. ..(.g....?A/..Y...Xa`O....6....,.6T...EQ~.....P?....ic.s.Ec.......;..w.qi.j..d..f............B,......Q.0}...e..R..r.-*...a+......O.x.[..U..H...x.na.....L?....s.0.g.)d.-....>...qTtq..`~..'N.h....j6...^..o..4........F...E....C.2.$.4<.R.....d2..ac..I...`.....r&\8L.,.#w0FY.Om.....X.n.H.....XrO.......T.%B..H...J.D..v...}g<..........w.g....b.6..|V.Idd..Y.,.&....#mW.O.K.l.......+.i{..>.Q..[....B....fbkF....".d...{..........,.S..J..Z...kB...?$/...v.$..V$B6.b..../.....$..[....4b. ..0g.."q.(..<-4......)......=v...M.7.0v.3......."..)-knrw..3%....+]`.N_{q..|n........l.-\...5..\/#.....x.c~..O........7
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:SYMMETRY i386 .o not stripped version 59926373
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.8384230502795145
                                        Encrypted:false
                                        SSDEEP:24:TMrkphdD7qmToNMzVywEMC8JJ2S0AuctNbFF3c8p7aOc:TphhoNMIVXScgND3RpJc
                                        MD5:4A2D089615D6F48ADCBF9FFA122C2D0A
                                        SHA1:BF3DC22E161FD7088B57CFF8E83105C746C9F6D4
                                        SHA-256:DEE00D8D9DEF3439A5A36EF2B87FE3967C0A8D6D99CF010709F90BF2D793F3C6
                                        SHA-512:B2D01071634CAF19975FE82E199CF85AB82D5E8CE293BE01F09DD825121301475A56EC42461E4F6240B74092C6CDC30C64631884487F6EDC8B43A918AB6B3622
                                        Malicious:false
                                        Preview:....D..._'p|....$..kmL`Y.@....<.3...".[.DD.. ..\Q.."dR4{..!.{....'...#;...8.i..P.Uh..``(.&..l.XQV..x.k!}^..h..L..&..eg.../X..J.x....>...z.m...GA.XD..VIv$;....I<!O%..G...<.oc....t.j....P.D...j.c...0....y..02,...U..)...y..1SV..b.t...?fk.cT.......!.......F.......*..O^].~.A7.O..W.s.....!...(7....&....f..r.*D7........L...F."....A...?.Q....'...d.Rj..`(q.2.P.b..<yS..e'@.rs..=..T.n.h..k....T..cW .wHF...!.......e.[.7....H......~.......VZ..>.w.C.jS......4j..Xn.f.'..)..F..4#....@.x..?t,.....15..L}1)v..g...bF.k.!eG..".>./...".....W}[..^GM.P2..tD.V.(.i.....E..O.e`~UB.v..@.....,+....".M.0..t..<....i..\uAX.odtS..3'.z.qD.....x...2....5....K.....O.p1."...2{8...gDj<m....GE.Dy.....*..........$...$.7../.ZE2.t..G...4d_.>.........}~...O.|W-.{p.H.C.A_.T...O...KON..S7...q...#"1.4..#.7.TG.b....UO.RVlV...@..B,Y....YgY.+..Y`'.?...."e.6........"..W..a...Y(..>..x..O....*..n3.px8.\......w.......)`../V......C"...ae......Z. .,g..gt.cF.....q...1....#.Q......7{..A..3.`E
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.8447463039452865
                                        Encrypted:false
                                        SSDEEP:24:9g9KU6R64VVi10n7y168pdHcexMXyZU5HA8PQpe31zpIeK5sp7aOc:69KUD1h162H2iO5HvQpW1zpSapJc
                                        MD5:E1A168A564CFC52752B1864B76137BBC
                                        SHA1:B9F004A838B298289442FE08D02AB746C7569959
                                        SHA-256:A44F42D98A373356A74A7D2CDBAAF451E44643C9362BA5FB7AA76BA40CA11CF4
                                        SHA-512:17DA4D6C5EF98347EB6A52D3D2FFF00736199820B0956180C1975DA282F9666E8B46D46F0650F616B3F891A11C895B769AB7D5E608482AFFFF3EDD95AEF38BE5
                                        Malicious:false
                                        Preview:.,.....w.1..(/7...)..D.......QT*5..."....._.d..`E?..q...Q...c...!.A.....cQ...|r.....e..w...q......Z..K.....w........ ...m.~.H...........}...gU....%....es.....Q.5....g.^|.....}.}k.9.%...|...dD....e./.....:5K.....C......%6.LQ_...H.nU.Jg..%...<.F.....J0.W.4..._F..yC..GCBK.....#q)Q.plT%.B(....{..,.C...U.Eh{5GO=)].#.VQ..F.1....Qp.J.I.......y....%.......?_...kI..O'.2d../..\.8.aRa|Wr5&..S1w.....&.il.2...{.t/...$y..z..5.-.q..zWM...^....t^.....d..DK...qD.>.*..\../...sR?....V..p..dN.(....)..q.T...A...'l\.&....L =wB.*vKE...j...L.....4,@,IKl."N.h>...Q......\".M..TlJ.f.Fy} .)......i...},...F%xC....%\.UQ.I.p*.z. V@......?[`..q....".N..]..-....b.;....._k...PN...L...6..Z.9..zy...C....q....^#..I......s/H..c..?"<..:..Z..!..n.I.B0.B..R....N.......f.f.h$s`.(9..Y...).t ...Sc....y.b$h."~.\P....w.,5....hW..Hj..n..q)vT.W....#..K;.5O....o... {..`....Af.......RP.k....u.....k.Qu*....:w$.:.w.cQ...t.|...0. .(....N.6...s.Q......(..5..'I}.$...r../..&V......<_.+.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.844989033865094
                                        Encrypted:false
                                        SSDEEP:24:vXrQfDEASkger5aaXFuZAlZG7kT7KnU4+h/b1Nkw/j+8Q3v8tIdPiup7aOc:PrINSkMzMZxTE29UwyX3UcpJc
                                        MD5:9073A70AE5255151895F517A15A00249
                                        SHA1:D41736FCBD9FB2724275AEC27DE5C673EBCC5041
                                        SHA-256:8C960E303560B2D1273460426E7EE2A3CF2229E5AA5D11648A69FD06D9417B1A
                                        SHA-512:C08B90FC4494E5B1230BF45A1D4A22EBB1F9348C5CD586CC4CD419C7FCB8F909EF0A0C6085BFBC9513BBB74E794343DC7E6E72F10E61DAD6285E4F6D43E3CF47
                                        Malicious:false
                                        Preview:.......?.<...+......$....].....]k9b..l..D^......E........|.@....:K...&i0...OoV{.........{m..U.....@. .BA"..._..O..%bi.N5!.......M.U..]...Q{=[j.......o..L.Q._..|.\\...A.#.TU...La.D)'>.....,"=].c.!x...@..[.....,...x. .zQ.o].....*....."Z%.q..Z.h..l.-....*..u..P.-M.K.u._p....Tl1......u.M.lKV...Q.!..a....R...h...@O....x..nC.....dy~g,..=.fP-oO/.w$.=.w.....:...pv....y4.69.M.r.XE........O..N...`4K..6[..F-K.e..(....O.ouZl:.M......B..|Sx.U<.T.H..S.8...q...C..^t.`....W..w..m....S..M....Hjw....QH.S..U...[.....aD.$...:=...I..U.@..M."c......a...4s .z...U.zR....M..\3iug....?.....3F...b.h.&.h....ZC....d..r.z+..=u.Qo..h..}*"J..5}..]...L...A...r.V.+.T.D.A..<@.....H].I.............%/\B...$p..uE..N.:.....&g..\...6.=...]..........zi.)("^!.?.\Q..s.8DL....U1gZj.o...*..*..,.t...m.../...M.....3.6C..j-.........}qg.....c.I...o...&.bY....._.9.E~a....?J.}tb.Sc...#.....>..M....T.H3'...&...%...(..zHy..|5..8.kH..Z_'.........s.;...?...Z..@.n./....`q.>..8...K.d.F..+.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1269
                                        Entropy (8bit):7.850203392087575
                                        Encrypted:false
                                        SSDEEP:24:CanJfITZOUeUzcdfjTOT0LVB/WRtJU5dEsUBCjTp7aOc:BnJwTZOZqcdLe0BBWzJkd+BepJc
                                        MD5:5FF726788755EFDED3A818CD8D26A6FA
                                        SHA1:FDFA439101EED13D1194AF5342C3DB9AF40F6E95
                                        SHA-256:D1526CBBEBDE623318B5D8D5972E163DEE90702456A293E88A290FB5D5BC6C7B
                                        SHA-512:CBE7A77B1B0D4F46F3F0A88D27685A38787F73A5C131365592D2E2954873D0D0BFF815EA62A738E50E704D127F529B17E0D82D77EC6BEF76FA9E7180A6DA321F
                                        Malicious:false
                                        Preview:.c.K..........!...n..rv*.Lv..V.....u....../m.=T(.Y.&D@.{....fc.\......0..z...1r.O..;.>R.H..L...a..%:L.8p@CJ...2......a...a.....x...V.....r.._..e..i.@........."...U.&.W.c\.~@..y..Z~.f ..Vt......@Q/}.. u.......n..-.t0Z....s..t..A...\....L=....H...S..Yz..7.E&....7B3@.$w.D...b..-......<.#...u;...YS.%_.2...."6..TV[..).E..J..G...qw.<V.v8....}.....Q.....f.l.c..G...b`.JE.#..`...t.u........m.6d..y.o....d>.......i~.K......Z....C.qJT....H;..Y....I..*.....i.B..B.Hh-#s..g'..|cw.P<...w.H..4Z..j....u.z?.....@...G..f....C..J...KJ.....B....<.!.m._...v.f=R5.k./..g.......g.....M[....JT...=..?.!\..........]..j.p,./.%&.l&!(..D..-E...v...+..z..._.k....|......4....8..v2@.~c..k..P..U8-..%..S..L...q....ds...P....... .5.!..<..f.k.b8|.M.].%.eN.w......fd+........A.r.0o".I'X..4}.t..7.....$..K.mj........^v..yiNU..l'.D(.7w..OR7Ex.v.Yoh!.;...bw.Pbk..G..6P.'!....O..%.D`3.8...1.h...z....>B`..Z@.Z.a.0..^+....6....6.[F?A......5..v..C.."...n~.D6{....5..V.]........U...F.a{...]
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.843499100268485
                                        Encrypted:false
                                        SSDEEP:24:3Afn5EhbYysbNTpB+9Z+A/56aTxuUYOuJ1PbbBp7aOc:KnahYySfjObTQL1Pb9pJc
                                        MD5:98F510E8668886829346A3778698621A
                                        SHA1:46164F6D576B85EA18462CA5626CF23D1B2BDCBF
                                        SHA-256:83D71672487F2FE8977411022BADD4215F795E487788D64BDB196DF3E69D0DC4
                                        SHA-512:9DC4FF79CC6C9A250E19351E4118FB4C69DA85D64AB34BB399121D13CF4CCED9AC6651F1B52E531ED386C818DE635DE2D540D638AD4EF99CB26402293C7AE678
                                        Malicious:false
                                        Preview:.6...q..~..k}.h3..,D........o.F..:6.!v/..+.I..5%...~a9r...Ll....|..g....%d...f..f..._;vy.n..r.J.}(.;RQ.d,ja....F.O.........~..Ho.oQ12.R.~...=1../.2.n*5.......i...+...MJ...\.N...Q.0}.>\(..............<.e....B.?8G.+>T..)hbq..B....i......:)...V.{.U...kAN..4.R.X^i.........b..O./.qF/..y.......l5.I.{[.._.......=w.L.b.F..>.;.|o......`#..&.j|..n...........$..f.-..~..O..r..P....8!"..*..%..\.n...[&Bbj.....O...(.Jg.1. .QS..*.....~...:.AU..Lm...thH.....F..|Zw....l.,#..Y.Ms.....f.....2.`.M..u.*....kPQ'H.n......no9.)t/...."[........*.";}....C(0..LO4.A..g......u.h....?...>.s..9..0n..Z.~..W.8A[}Y6s........F]H..T\.........TzF._...........0X......M.kGV.A..=F....a.1.7.!....R.*S.`pp`V...#..0.,*.YjxI...&....A|...M.M..{.E...y..l..G..U0.M.1A....Zm.../.{...q..G{...$...S.1s.uC....7.P.Z.y...MR...1......(..^$.Vs...=...4.61c/2....2.^.r.K.r)...;...D.g....8.........;>....en...L.U.om.......C...}.....OV2..U4.oZ...6...-.....WW.}.2I..[.TQ>.#.?...'..2.o.X<<C}...b.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.8302255579558775
                                        Encrypted:false
                                        SSDEEP:24:K6W094A8QetQZLrooP6nIj3RkbLvtis8mevp7aOc:K6W094VyRroobCVis8m0pJc
                                        MD5:5F404CA74EBD6B95D0B6A38C000D9187
                                        SHA1:37343E3FDC1B7C7DD51E3C7D588B4BEDFD49E451
                                        SHA-256:89C8D2F01C0ABA914BAA1675AF9C522BCE5711BA8729798681475D3D87EA77EE
                                        SHA-512:EB5B357421BC6B904E5C36F397A85D145184ED27CF8ACFC1F491AB9DBCF7D66FFD5ECC07A3FDEE602460361C1140D0352CF74D52D3A02228635021BBECEB52CC
                                        Malicious:false
                                        Preview:..C.N&..O..2.s-..1(h.q.........l...9O.+..?.e.V.V.mw..a.U.. #.=........R...j.....T.0...!.......9i.l..yF;..(L.....e......T.....3G.Mu....IJ....>...\....pG]O.{B3...D...Nb:6.\...i..m#l.WDp....d.lD9.6..ol..T6.....`T.`..bK.K)...X..hG.,h.e.Ud..v6........O...X......#.3......U.cuf..q.....:c....VkL&+p..k.u....>O9c..#0m|....]............uE.s.#...>p.$....._...4O.0....nzT.... .P........a|..T..]....Q....Lk..i...e._.]..q-c..(D...N..(....h.....<...G]......^}....X.@..c.c.:..k]cE......;..6..#! ..Z...+;........0.....=.....LmTP.=.&..V.>0F6.F...+..k.....P.o...(D`."x:.,.%==.z.(...y..."nP.-V..nc[..b..~~$#.nt.....D.R..?.%s..,.....8.......G.......e...{.}.?.4.^.h;&\.y..>F.!.*.!..t.=.......%H..^....{R$.J.^..x........R...#z.[......%.e...PIC...l.K...||:..#.....i.M3.......C..T..."..>...ZL$K.xwZL.9....nX.l..........4......F.....R...A\.....&n...Oo.nU.X...#....H.=.....I..;..CdK.D..O .. 6....`..$..sg..`..nH......zx...=^.G........Fg..*.O.W..3H)..e...%.re.\.....$-.<O.S$
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.865435101489191
                                        Encrypted:false
                                        SSDEEP:24:dm2PusdKVcPMQ1nxjAWnBHNIJD9DkXPD5koizcsaJ+zO7CoAQNi6OaArE+Ap7aOc:NPdxjAWnBHGJD9DkgcUzO7CuOaArE+Ak
                                        MD5:6DFEDAB32BDBA0CC5E6A5E4E9C1410ED
                                        SHA1:FD8D6EA6D5168F8414A377ABBFEE074D94D8DDFA
                                        SHA-256:D4E7020A5CBFEBE7626F7150EB28740C731A412810A431C2882278F4FB8D29D2
                                        SHA-512:403AFE850C639745CD414A9177BA1F2A93AAF70C44DF90A9C9C7572B703B9A31B39B10A4F354F8860A0BD23B5BAF193D64F99F7E57F5CD4F954F31DF08A2E639
                                        Malicious:false
                                        Preview:l..-..N...5Xu..7....9;tD.....9b..xW(..@y..8..S...... .Lo....5..G0)P..w.....!6.".Q.......Q...=.6....!.|@@. .j.....A...~.{N=.,#.......Pm.c.at..x.(.Q.....X.......C..]aoX...8.N&...{p;.5]k..@0.V.Z.v5]..y...e..Y.....8Si;E-.sr.L.F...........j..._.[B./..9..........@....ll.....G..J~...@P.v..4.+..)...Z..R.8.C....9f.....@...+......k{..<~&\..P!LZ......`)..V....*u.M.^B.......j.)...^K} .f.V..f.4.z.R-.L.6".$....A.)...vo.%G....I.ch...x...p./7.U5..K...i..e,.W'%>% .YE7...`|....S....,.&......S.....g..b0V.N...$.B.5.K%.......u.R7...........T5........b.T$.....`j.7I#....!D.D.2p.H.4.;GK.J7..-..1.YElI..3T...q.u}... .n.......|.G..iND..UA..|......../.[..`......\.2........*.+.....+.~x.*.:.V7.MQ(NI(...a..........g#.......`....8..Y.(U.JU.^.!.D4.|..B...}..mA....c........$z.52.."..M...l|o..#3.M..Z..H8O$.<.....%.PR.G....>p.V......UGi[....v.k.}..k.@i0.,...+.?j....vc.S...G..=.=....4m[Y.t&:8.q.i..V...6-Y..{............r8c[.X..4.o..w..b?Dc:...6.._P..U..6!.!.=...z..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1274
                                        Entropy (8bit):7.86237365605646
                                        Encrypted:false
                                        SSDEEP:24:jKu3xJ8E7m4AIJg2ecsrpIjm4o8a8U0Oq0WdI0HeVwzhbo5p7aOc:5hFq4AF3ckWPjaWXl6wts5pJc
                                        MD5:175C2F6FB3812E77BF4F1168438B5AE1
                                        SHA1:1274FC98ED287D9E65AC3CE5E02CF8C53B1CD467
                                        SHA-256:D80D4BFF9724F032EFC09A5C7726909DCA5A3DA36A1C3B9F6BB080322A19D975
                                        SHA-512:803FE1A632F948F2F1CC8D76A80FFEB15911E390336A15788A006D99D963938B72074011D7CF5099C26E9E824064EAC5FE4A44727ABA7EB6B1533716A73AA003
                                        Malicious:false
                                        Preview:.....N...Ih0_.....$..:-...gg...]...w..Rs......_.....e.F..O.*9:....D.U.3wK.2T.._..AO......../,P./...&.o....)h...N\...."}:+"..[,9..0$..|yL."}..C.ux}.....;.l.uI....u...m`...V.~..gzH}.Z..<.o.*.70(Y...#1...m.E1O.Oy.-.......=......m.......?.....>:.I..g-_..]...;{..... _f0..~..8......x..l.s.{....Y.*w.R.f..i-.;..p%V.U...`.G..*+...8S...Nz'2.......\.....)~...k..h{R..t.[...y9*g4....Gs.O....j..,.c.O=-....Y..9..#...l.U..."...!..A..8....7v..=.Ai._Yi......._..$h>".>......E.m..}..C./.i..v..$....a%.Z.n#.....Y....@.3zg.`Q3.1..Q..U}2.)....@..?.f..~.xY2........3f._rXM.......if=..F..)..gr.8'..D..b.3..7..E.....4..)>.S.'o,<FE.=M\...,e2\Z........F....6(h.Y:...........m.L.........M........c.d.9e.Swe......WI.CMI?.p...;e.... 6..NE.q.5CT...-.nn-v?...:.f...50P....7.............&`qURR.d..>.J.?H.......{.h.=....I....=..8p.5....N|\....C...~.x|G.......=.R..cmF.mZ.s...@czEhP..{.v..Y.1...MR........&B...,...C.........{fS..!....\..q.%..m..Ns....1.9+..B.:.L.......o%.2.Y.rp.G+C..q_1..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1272
                                        Entropy (8bit):7.851383964768049
                                        Encrypted:false
                                        SSDEEP:24:G0p/YDh83O+UxUuyPs3uvonhpx/7e9lrPckwRH6DT7aRLqOYdI/p7aOc:GWah8YxU7+pxze42ss6pJc
                                        MD5:CBFDFC290E7B8E6C1D379D848336D52B
                                        SHA1:6B203BE2AB51C225CAF6FF4BB62345733183BA82
                                        SHA-256:48810649030CDFD8A7A7299BDFA4699B9236E7C21CF28EA1B7F4F1F62EED7EF7
                                        SHA-512:942B965AB94540CDB1E836C4819BE99A3EF1F3D55A51707CDD90EF3267C862153547F8D3A68B03CEC24F33EF2C6A8651103515346CAEADE94DEBFE47A6BB6F30
                                        Malicious:false
                                        Preview:..y.E..1]$....F..>.A.........m..%...^..V.Y..>6.. ...-he...(.ga.2..{~.$...L.0...^..A..../.e..t....rv......b..............g.M..6.d.m..|...3....q..<..A@..E.?.=......^..K....."...z.*.V...&....'.A...D..R..^.T......m........r.~.j$...6.pTz...*.xo.(A.6...w.u....+.x..u V~....K......l...T.t...<#Z...X<...F....V."...2z..\...6...I.]9...M6........fp..i..e......)zaX..sD.Zi.>....^p...d......LZ.....%I.>.(..Je...U.Bk!../.l..I?N.mg%...h..C[.R..B..N.a..4......!.@*.@~.....4..{i...#..A...n..2Y.r...>...[....'B..A...@f[G...2.W.2.....d".e.!....UQ..l..............4.4U..;T.ec.....s.g....(...W....J...L.Wk.1gK&XOpP...\.a....(....5../&.]O.].o.{.......a . }i.Q~I.hJL...$..Q...Y...]..T.a....&..c...8..<UE.F.....g{.J..~.J.......*..8."6.....4o.8.1.zy..........t.K........L3q..5.d|.....,)F../...G*.....2.w{:.Cj.o.fY.zJ..o(.Y...d(..1.u..0.#..'.\f..n...4<.y...N.L.tJ..H.O.!.....l...?J.....Sw.pB....^(..yI...a.Y.P....J{...'.2`8g.[..]..=q...`.../....w.4..1.jn"...)jY.x..Q
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:OpenPGP Public Key
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.882020413335691
                                        Encrypted:false
                                        SSDEEP:24:Tw0jYsHe3bvwhoppjp3if5D6x+L22mGIhGgIDuKwRUjeFCBvRo+3afMDlK2hp7aV:9jNHxhofx62BvYuKwyjg5fMDxpJc
                                        MD5:A08A2241BFCCDB173D72734D8B090508
                                        SHA1:308907D8623F5F1FC96A48E0664702C77385B7CC
                                        SHA-256:214C03212DFD05141C71135F10617F591382142F127142D7335B362F212BB1C5
                                        SHA-512:A7215F6D166404ECBA74E2E871E4F958792658F170313A9BD6FDB6E5C8545D8FA1A91D35F54D9D6746B0D15542A470C74268275038548FB4BD4D7D4F7F4010D5
                                        Malicious:false
                                        Preview:..b....}1n.....d.-UM...c....|.?.D..E...S.zo.\.a.+..5...BY...Q....;.H4.H3.Uc..>.V.Z.O..FN>..R.Mj.a.\..RK.T#.("..e..6....$.x....%Q.......]0.2....B.$.[J.[7.4.G....L.<=..i`..o..np...jZ.s#...y...'..W..&.k..H0#..S..s.^.V..|@>i..8..7..[....oY"b...y.'l5=.6..ExT....CmI...S.1uU..".7}...>..X...jU.1.\.z....-..Se....`.....NA.\.^..+#.b..B.p.....&.......*.A.E.W.N..I..g[.r...y._ML.L..X...@h....g2....LIy.&..%*..(.nG...%.J......a....h.{.v..9.2....}....v^`...<.[O...L^-'....tf4.[.....3...2$.]]..Qs....u+.z..]j".[.@..#F...7%..o.....aJ.tPMl.....$.5...a..i.c.......:...y.jcXL...*....9d.7.{......,.....`.34....3...DO....FS.H.z.:..=.s."..t..'&(.....Q|1...\..X.Bb#9sk..-..C.......B...........O5Z...j....D]...b....~."..(...a..E........cM...,p].X.[Rj.B.2..dw.....b.!e..{h.........W.K.4...S..@.....LGFw...Z~v...:..;...l.A/#.. .sm.b...DR(...}...>N.QnX...Qa....|@c.h.....A...:W.....Q.do...i.|u?....3....*k....`..l$..U....B..._~...zMg.....#.+r'.$.rWA........8.C.....I.H.*}:...8...
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1273
                                        Entropy (8bit):7.828652238338235
                                        Encrypted:false
                                        SSDEEP:24:LKhbd7GrUCBP/NgnPRFSi2zOPb7iyE2XtmoXjTp7aOc:+hxilgT2qfhFQoXHpJc
                                        MD5:7B6F4F37CB2D5C66CA762CF3AC0E8DEE
                                        SHA1:52F5B9C45BB8A7A7DB4B987C4F9458B1DD26C629
                                        SHA-256:FCE16E6C826238C66597BDEC22D668FCEB0A35EF4B7E274942333D5E7BC009B8
                                        SHA-512:CF5364F59C4C385881DEA80DDEC75858F8101078DC86ACD682B5718B81624743A03B2314D97FBD9885F97092B7E206A47266B0EC10A6E69C2798531C47E29FDE
                                        Malicious:false
                                        Preview:BfmkWj..z.`h.u.21...R.Js..37.sf.9...{.N...pr..u.......z..Q.I.|+Y....KPf.i.`.....[.F%Q....D..F.-........./'........c..{.q...vPK...Q..h.....L.....S..fd.b....O....i'Oa..Kw..|J.~.z..`.N}lV.I.d...._u.Z.`.-K.<;....Fg...8.B..jI....$..Z.R.........xh.UV..\w..>.........>...x...H.x............z.M......%<.!Q...#n>O`.U.'.#A....5.w%.....=..8%a._q.".....`..gd.k..6...P.......R...q..X8td...7d........b..J...F...y=.x..yl.$..h.......*.v.....t...-C..V..v.#.uz0..k[+..9*.4...X...=..X..s....x..&. .+....K..y...x...]..\<.........N^..#....,.A...^....D.l....9..,..".B.s*......0...}^.L....1z.q.i...|.mV...cEv.y........#%.......Q.x.. .".h=.l.m...I".S.Y#.....d\)+..~.R.6oi.......4.(t.^....O...E"~?.g.5..._d.v.....6...... X......dA&^..V....S.2...rg........V..{.3.Q...P.Z../.....g.K.&..@.O.t..%\....Q...8=e.(>..3....r.9.n.}.#...7c.M..ra..].N.;.H..nt`.........2. .+wrc.$_..o..o0...Ew./ ...d....{.7....p.c.I..N^.....o.j.>..T.QFqf.AV..J...%...~.|I.S^{..C.F........Q..a..
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1268
                                        Entropy (8bit):7.853229460723567
                                        Encrypted:false
                                        SSDEEP:24:dfdrSfoy/UQFdNc2reMVRpCLbHmU5niW22f0EWg+n26wYp7aOc:dZSQy/UOd6nM7g7Z5ixDJwYpJc
                                        MD5:0712EE6CED36F6F32EE409DA6BCB6BE8
                                        SHA1:54FE01DE8C7DBFF55AF8E05D8E9E61F8CBE7DBDB
                                        SHA-256:1396FCB0A4BA68818160D1015690F71B9A8E57F9F94DA1848CACF6152E0089AD
                                        SHA-512:BB88AF97B0C978F209C71FC84563A00C4B600D7B22701BF02EC9BD1A1001E0FD5C666BBFA2FD13D9623F3E49B44F67AE61AE263CA314F048584C284E4FADB00E
                                        Malicious:false
                                        Preview:-.....X.......*.......ar>fdv..oCH..G....'......\.a>.w.`..%.p.......d.,...~......Y....#........Uf#..1}.$....N..]Z. .,J....js..=G...g.?A.:...}o:P...f|N[..>...K.... ......YR...-....W..\F.I.....DWXH.~;s.@+$..x).......c..5....JN.j.DgK.1......qy1K.N..B..y....h.$.Z..........:.@.s.M.pU.[.y.e...G..._N.......Lx2j..w...1#.Y..$..k-o....p.S.U>...,..|...ndJ...8;(7.....I..G..X..S.Pp......B..I...../H.)Rf..9...gmLnHk..]..:..+........r..2N.4.^u....L......u.'.W..o;..%m.\.../,(.?...%..eg.Z..Z.LKK...H.F.d..:..a.N)...eKD....s.r_.O.9.....!....$H7F..G..D+.6.R.h.#U..s.l..f....N-.."g.y.<R.p.O...7&n..4...#t/...E....w[s...+-...BdG....X*........y3-.hf.b@q.7.Q.fV..ZS.1....$..|.U..xJ...x.....]D'/g}..'+....Z...<.....*..;...v.<..eM..V.. .......3}B....5.4....z......v.q....E.......8.x.u.d..{.y>X;..a.(:..|..g.-<y....:.Z.!..p......o..u.@...q....E...\.y[.H*.j..VE.z....vw.ad}..(A.|{T.}{.....Q0..........6.......!Q.mx...Z.6......-./..t.7.D..U.7...y.k.....<H..1.c.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1270
                                        Entropy (8bit):7.8202736942104005
                                        Encrypted:false
                                        SSDEEP:24:VygNMQRlYOg+LyDqWXcxNGHp3M7m0q7veP2FYwysN9unTrJdp7aOc:QgNhYeLXWF3ImJ7GPtPsN9IX/pJc
                                        MD5:B4385A13AD1EE05A31C82A100E0C65B6
                                        SHA1:2F0DE23F20188CC6BB66C2FCA98A85C6AA05C2DC
                                        SHA-256:AC433FC33AD2A05DDE589E29221EB854D86B7C4EE4E3867ACA8134D829B88436
                                        SHA-512:441A65C12E23120D5904E5DF74B9FFB7EABDA286DF9E90CED74CF0B8366965684E00785B74EB0DEA1BC7FCBAEB8553156406B8CC9493D0C649FB1851C2C627C2
                                        Malicious:false
                                        Preview:.O...G.iD..Y,.-..3.W.r..O...r...'F..+Q.,..k...{.p.-..>.Sc..(,.&.9L.....6.D.[..w..Z..?..3....h.<.<.pa......(0..L..Q......E.9.t.Q.I{M.9e.......W..<R......V.y....w...2./T.v-......M.N..u..].A?.-..'.C...C...%.Ur7.z.....$..S.3.A...9f.....'.-.X..1....5.'...AD_.....2./..t.....F]yr...... ,.y..`..p....$....g ....|S.L..Nh....M...n....}....3?9*@.. ........l..d....+e+.5.%.Z.&....D?.'u......&..B8.c..p.Ju.0{.W.k%..^..\6..h).e.ab.FF...GN[..8.<W&..rE....J,...v...T..... ..+..R,W..).C..*....+..s9.^@....sq.....H....*..t...f4.kK.4..>\'.".#.}..f..s.G..Ss.:#..@.......q3M.x $...x..I,.C.4G.w..e)@<..r.]2H...u'@....*-.O%....!&.).A8c....(.>.....IMS.4 ......Yi.....`...O.,).G..q.wX..?!....)..9.%...A.L.cH.....g.mc...8...v....H...>..Q.nM.D(.2.z.......K...!....m.E.GW7.ACsW..6...S.W........].YY.Z....C...?....<z..%...!]tV.6.Vb.K.....DW.7.......C..0.N.+@..;`..^..'.I-.'......,E"....K.'......$...7...A.@...N.9VD.#]m....c.*a_......2H:.l..v<.C)..pv..\.....2...f.9.q.0.Km..%u.fIT...:...N.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1271
                                        Entropy (8bit):7.856413268767954
                                        Encrypted:false
                                        SSDEEP:24:E7hJN71ptx+e/+Y/IDmO+//r/rUXSpWrDspbh7Rp7aOc:E1PPiM+YcmfrjxWr0h9pJc
                                        MD5:C038A6E98BCAD37C8C73E3343C81FF11
                                        SHA1:0E1EE755F414E0FE3987E46C6FFF81C87D02E541
                                        SHA-256:CADBF43EE95EFFCBFDF734E970BE297719596BC8BF8209E01FC7D15E91053C45
                                        SHA-512:1033C6F1F3FE930AB6763C464422B0DF09A638F0B7C14CDF255416B093A74CF179E22AA3A03509237BC4EAB549C6D6885BEA56051BF1C2216EBEADE368F620E5
                                        Malicious:false
                                        Preview:.6B;...~PP."L_[`...Z~;q..7.D.RU..1*l...).axw....\....1.r....".4...)nhH..o..J..D.Zr..'G8.=.cM.TE.....I/..g.[.G.s.P.....X..N).PT.(....^..]._..[...I!../../...g.......b..B.Q r?.L.[b.\I:.t..L...U.4.......c.r...J.\.o..q...Z...@....|e.<...1,...<...#n...L7.x........u..).s.J..0#..j...p.X2s..`....x/.7..+B.5.Q. .....U;......l..we.iU(f=.f.qX..+..h.cSx#..A..,....o... .>.......(rR.ugr.<.4..=..wZ..;+T.}.$.}Y:..!J....]1..X~U.(...Ko...sN..0.....o/.z.X-s2?..'`B...s....*..!.L..v...2*F-V..A...@.7`.&....U.4..X5.m...2F..,5.u7..$.......C.e.s..C<..l..).CHAN+...P.$.,.@..%..|.Jfy.....V.GwK...0.+...S.$....k.......h......O/3rH`.5.ai.[...}.f.9.$5..;'...m2.i.U.=...lAu.5<..b..|.?..u..pwy..h#..o0..wp\.g...-..*.........N..-.4.w....Tp.}c.\{..<~'......2.I......qa=PV....\...<..>.?We..3.\o.~Iz..R..;p#...lu8..:.V1...m..z..>.u......:....b.........d.......Z...G.d).3v.%.rw=..t...e.*:U.Pf 1]...4H.Dn..U...o..H...r`...9)u..y;.b.W.I.zN....-.".....W....".$..gN...k....g..HL.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):350
                                        Entropy (8bit):7.367354399063354
                                        Encrypted:false
                                        SSDEEP:6:ihC4y0SY1EcNLuc9nk5qaYlkmW5kblVwnfwU2xDp78frSJVgxGnFY22w20FCnBR:ihC4zr1EcNickgasDblanfl2xDp7aE67
                                        MD5:49B440763FFDA93F1CABC442CB5F44F2
                                        SHA1:0CBDAF33FB2A1C9B4F4F8F99262412662E180160
                                        SHA-256:F551E7CAB33770C67159723221E5D459C7759ADD583363DF9A27933371073360
                                        SHA-512:D879B546F915D62D46693E376674795E63AE0EB7B2BBC209F8FD2FD122B44A9D9B3A5C4E76FF1866F8B4A603FE30367ACF5EB1E51EEB7B43207D7A15F455CF1F
                                        Malicious:false
                                        Preview:...8..d.}..cg^..'...3..zc(.M...h.o.....(....t[...=P.q5..I.i.}...[...."..ky!b.Vk.A~.5l...._i...W...A.h0e.b)......d/.tv.R.A#.5.aZy..}..b%./...L...~.....f....Dfei..9oBY.I....~..z.n...RI..6\.D>g.?xF.E.33xW.i......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):443
                                        Entropy (8bit):7.476617588489942
                                        Encrypted:false
                                        SSDEEP:12:aZw8YRSxzipR4oRkOZsrZeLBpcHmQp7aE6wKBR:aS6iomkOadCcHfp7aOc
                                        MD5:CAC11D32E1D957CBC2E9177165D4048F
                                        SHA1:934DFC603E5F8BF4A7082B443327182CB6711618
                                        SHA-256:E92DAD2A6FE7D8D8FE8B41F576B797B33FBF8CFB33E58A8FAFBAAA3CDF6CEF9E
                                        SHA-512:6C1318AE39C7377926C161C75690F0510C9536866349807A5EBC127E6CF82CF4C1F4A2103F47D4A3D5E447FF9F5CAAA1061DB6A4D8EF9778073E420A45F97A1C
                                        Malicious:false
                                        Preview:....'iBy..CQ.5d...3.k.U...nq..F.W^...U..QD._..V..I.'.S..m.........B}..*..7y.MY..G.8...8....W...$.[..!Q._Y.n...:8.>,...l*.jA*.)N.W}..l.S<Y..w..c....D.~,..j .DZ.|h.......KM.....5.F.f..E9..^.b..7Y.....f.f).......ds.mw......p.aZ+..}..b%.N4..W...^.......o......{...+`.=..*.C~e..7JE.V..!e.....z..T%g..e......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):355
                                        Entropy (8bit):7.416405373502098
                                        Encrypted:false
                                        SSDEEP:6:2val+9iS/ZphqQSCajE1VQstl3Or3lO6eAp78frSJVgxGnFY22w20FCnBR:ial+tLhqQGE1Wm3OLlO6rp7aE6wKBR
                                        MD5:10A50BA0DD9077BF5834D3102A4FAB6C
                                        SHA1:644000E39C200C20BD852061D9F7256C359BF157
                                        SHA-256:FC5472798D2884462329128233C2E610B42F33C4128AB932F53A40BDEFD0F5FE
                                        SHA-512:B4F119F66115806395373BFE567949AB156428B5C9346D250F4D5D77ACBB4CAE0AF8134D9BA9D639E8DA38E7E9A4CF514FC5DEAB21B2214C028F61AC88550CD7
                                        Malicious:false
                                        Preview:NP.Vzb..(.{.\._}..I...v.....3..t./..IM.E{.u..g.."?#R]Lk..-y..l"X.C#.n....9`.C...a..UQ..v.QZ..M.B6.....s...b.n)......J......... .a@+../..a%.,.......nC.|..[@1tu...K.N.t..Y.?k0.x..2.+...>....vS.Q^.a....7..2.Hol......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):347
                                        Entropy (8bit):7.381885539797238
                                        Encrypted:false
                                        SSDEEP:6:eMZ9ppi4+aRQKk2GgYNxUOMHVyu2J51Ap78frSJVgxGnFY22w20FCnBR:rppbRQ+GHNi34Jcp7aE6wKBR
                                        MD5:EE46781E718763E03CDF497A8102EB14
                                        SHA1:04E56400A916607BA41105ED4F51D53AB8D60A97
                                        SHA-256:1B548777ACB2EA676CFF058BB2DE59C4616F1BF0D7CEC3DDBCF302747A7D9A91
                                        SHA-512:CECC2C6727129F2D781DFC3F3A0367AE8FAD512ADF34CAB90530D1948FBD0AA6D5AF8F81ED9D19901EA1CAE47516D06D1D6F9CF03768F91EEC4740738CFF4C21
                                        Malicious:false
                                        Preview:s.P/.V4."eHQ!......(.gT./m.|\.....s..v[.......A..@.~.......;#...4..v.X..._...?..AMf....5....pJ..p.j.. c.`...D...0.......".aZ+..~..a&.,....I..I.Z..C......0}"....Hk.#a0W..a#.p..?.L.guc.*Gk,....n/.?G,f......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):344
                                        Entropy (8bit):7.316189446522499
                                        Encrypted:false
                                        SSDEEP:6:qIo+hxJ9Lo/oh8zxBtyZRY1VBG+u4kpPp78frSJVgxGnFY22w20FCnBR:qIo+h7y/oC1WZeLBG+urPp7aE6wKBR
                                        MD5:2D5BC3D390F8E066F857893A02E51165
                                        SHA1:F3432E65F894A27B0415DF63BE3B8CD33906A85F
                                        SHA-256:B782635BCB8E1277FC6EF3EA473BC34646FAB860C4DAF61049C1A9B93AF9A477
                                        SHA-512:78921FBD55A54F3CE105BD9338FDAED6AFFD99E06C54EA7AF32AB099A4EFC163C836C21E6B005BD7D60D6429136D9E5E364A3F70B8D8B4708FF01701FB248E7A
                                        Malicious:false
                                        Preview:-.{Q.........h...7+g.6ZsXm.A{"G..Ete..i..Q..+6#...).b...l.a..\.8.`.$.v.6bT...qa..V.}*zC....j.......;.45#h.f).......ds.mw......p.aZ+..}..b%...}.{....@..Ak.4+.+[.8f.}m...........y....[./..........0....:<.e......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):353
                                        Entropy (8bit):7.451194080263232
                                        Encrypted:false
                                        SSDEEP:6:oiuMUZOWmzgmE3Tl/66fO3P2B6bupugriRfw5FDp78frSJVgxGnFY22w20FCnBR:OvFWK3A6mf2B6b4ry45FDp7aE6wKBR
                                        MD5:29F7B8ABE8385E45AEF772BF8D0B77BC
                                        SHA1:C17B4DD34A9755014E48A06E8451240AA4827ABB
                                        SHA-256:BDF24D5406C01CD43F13FE2268EDF3C181ECFF093DC2532FF6F06469FE2E2EE8
                                        SHA-512:FDD6599E6038CB9905C300764DDB68458919AD6881A555D210F16295CCB1DBADA0E01D0FD62A37BE50FE8F3111E7AF666248F29F9D5CC382C608266721C2D272
                                        Malicious:false
                                        Preview:.......t.XZ8..z......F.F...1.......3\....].y..Y..K...7_jI...K8.`oX!a>.J.8&.y...7Fl.l#....4.z[..'.j....(..j.V)......dr./v.R.@... .xZ+..}..a%.,.........{Ot.L.w..E.m.....w.&.j/...r,.$..u~...JV6K{ZN...eCT..i^...k......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):349
                                        Entropy (8bit):7.338354797913851
                                        Encrypted:false
                                        SSDEEP:6:F0qIwIAs4tT2E0mYespR6slsEz7CFjZSPt1bKiCDp78frSJVgxGnFY22w20FCnBR:CwIArt90i56sCWpSbKiAp7aE6wKBR
                                        MD5:04D9F7BDE7B615C8EE3D59213DB2E565
                                        SHA1:2A67D840B736EB7F0E567297BD4EE5CFF66E767A
                                        SHA-256:5FFA8F9BDEFCB41B23E5F0281B8805127ACD1AD4BD6281903289312A71801FE1
                                        SHA-512:65B8D2180A6A0035CF1AA0346BF539F0A16A962306B673E02339F643250B350A03326650ABA2E5E9003140DBDA42337FFBD345FA8314F83F456D3C3196B51B88
                                        Malicious:false
                                        Preview:'.O{....@l...9.)...&._d.....v..C\N.$..VxP.....b.6...UG.....\)=....V..X[.Se.j..x?..Ex..J.a.$.o...\.fO].....v.j). .A...0......".a.+..}..a%.,..k....).6<Cg..z,...S....Ec..8.T..wd.Z'H.[..6[.....". .J...B.h......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):350
                                        Entropy (8bit):7.378138506237121
                                        Encrypted:false
                                        SSDEEP:6:YPeBz1tZ/G1nIl9FXKC6Ez7uSC8il8DBL/CDp78frSJVgxGnFY22w20FCnBR:Y+z1tZ/BThKC6Cw8jd/Ap7aE6wKBR
                                        MD5:3B65DD6EDF4DC3D3E820519469076D11
                                        SHA1:81388BD758C2D2F8FAF33230BDEE1174228F07B8
                                        SHA-256:3B6923E2DCB372A27E0E03CDC7AC198A4D40B452CEDD162D590EEEE63FBC2927
                                        SHA-512:CF238A6CE4B4EA4F4F2F2FC8ED60E2F5AB08F704F82F834E6123188BEBF29C9001BFD238B3AFB2792B72F7AD48828E4A9FC4F87CE3FA5018BCCA2A1E070712DD
                                        Malicious:false
                                        Preview:q/%1W*Q...&.a.........=..[A...&.........s.......@..r......f._..rU.z.3L.'.Z......-i......2.T.=.U..BYV..$...+p.x)........k...f...".a.+..}..a%.,.... ...j.r.b.k.P.f$....f..a[x....H.....=..)!.9..q..9twebRv.h......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):356
                                        Entropy (8bit):7.395410504092869
                                        Encrypted:false
                                        SSDEEP:6:T5aKzFWGQogyqGN1dwE9lU9CVQKt4yGyp78frSJVgxGnFY22w20FCnBR:6d5ggE9CgVGIp7aE6wKBR
                                        MD5:D6C134FDD4AB83C5795E9E7FDA2325E1
                                        SHA1:9A5885761DCBF3E19C9D59C6EACB0E692B77F5F1
                                        SHA-256:38CA93D22C166633B6D3D301B50334E1C237759D991BC2921B50119A270B7F17
                                        SHA-512:9B52E544FF5392D042A40BCCF70EFAB4BD97EED3184BA2CA2EBA0E097C4E7754D45ACFE90086EA2F5CEB1C3926A4196B712F8D6B3B4B38CB68EED77360F0AE9F
                                        Malicious:false
                                        Preview:b....,..)?....o........x...)...1.[S<|.. j(.|.v.....x..5z.IR.|9..w."!.....y&Y....f\.....6...O.-...Xg......s.f). .X....$.U.g.s.X..a@+../..a%.,........NI.J.4...|...;J|.....e..]....V&...0...O.....u/....e...IU..vl......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):350
                                        Entropy (8bit):7.318268167830308
                                        Encrypted:false
                                        SSDEEP:6:EC7DWvacZThO2sg+HeRRyhzBaW0/6Ez7UzMX3z/Mz5hVJIDp78frSJVgxGnFY227:87ThFsg4URQcz/6CIC2B+p7aE6wKBR
                                        MD5:8B536B4AFF322D77CB08BF54FBE4B709
                                        SHA1:A306189DECA09B3E5034BFF23DA6A820816A26BC
                                        SHA-256:31581D3E4B3AD0E69AA589EE9C1C5FDCF30B1688590BB07C3AE96FFD316A1711
                                        SHA-512:66B380FCA999DEA0036EB7AEE74967ADA9B4603ACE7D7DB1FCF9B6A12EF9B9AABE291F5AB24B660D09969B29C78D7F97CA2F8827A9AE96762A6AFAF3C8EAE834
                                        Malicious:false
                                        Preview:...H.2 ..E#r......u2.....O..._. ...s...+.<.....~x...<3.5#...s..;>.K[.a......p.........bE..a1...#..N..f]$_._.}.`)........k..U.f...".a.+..}..a%.,...-<lf..Uv..a..)....%..I}..G.;...s.6=...VN....%.#...G.C.B..-n.Bh......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):1173
                                        Entropy (8bit):7.837325403989578
                                        Encrypted:false
                                        SSDEEP:24:a2Hii24/ABh1D7D8eilweqAuKwn8pzUrDkpkFrp7aOc:aoii248h1DkwCuKwn8pzUXkpWrpJc
                                        MD5:E8C17C9D0720BD8465AE00D525811D4C
                                        SHA1:4E2ABDDE033B2A29EDBE8077030092311C4DC27D
                                        SHA-256:B190D369EE5E45EB6D4EAFFF1F9C5BF281DBB2228AAD9BF9D4F4E347E95D66C1
                                        SHA-512:F0F6DFA978CFEF019C46A4AAF230B351E0E9C4195A20814860A3BE1E4AB06705ACE5313A75477A8B5C210DECC42CB559EF39A2E8707A824CD5B7C3D1BA867DB1
                                        Malicious:false
                                        Preview:.....4..6...'k.iS......c+./.o2..$....,.../M.i<....p...R....9.v.Z.......D.a.8.7P0$X'.lS.|..?c.&.......Yo.L...>V.C.D....3u|..e....%..$..i9..QN..x.P.a.)?*7.N...y.......I.k,..2.x.@.V&....c..:.^..T...g.0..].)>:.+..:.."...`A..Y9k...o.y.....b=.........."..e..+.&D3.J.B....*/.s...H.SR...a.k9Yn........".7<126.>..`.L.X.$.xvk.?.'...'c.&.m......... ..?.)....]=M...E........e..k.,r.N..I+..N7).9{u..r..h..YR.@Ip...N.......E.v.v..*$,...V........i6....,.*N._%.A..r6?..^..z&......T...`.m;..u.Vi.....J...}..x......m.5.w#G..0.qJu...Q..Ut....I...{..MFJN+.!..b.....L.( ..b.k....>.....,.B.r.c..:.@tn....:..&..\........%.p..g.O.3..^..F..=;l....O.....-M.C.CoFt....XM.....U.....I...%9....s.Yr..D%D.....1.........*.s..[..r..Q(...*Y...%.7..We{..J...G.Y.I[e.....4..X~..K....p...Zq.4.x.1.;.......1...i.](E.K].e..!..AY...R...'{*..S.f)......J.>...O..}.(._...e.....@.#.&!....A..w.s.....>.Z.x..........._0..u,._../....._..kZ(.......;2k..N,.o..Ra"...j..W@...&..S.IB...i.
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):434
                                        Entropy (8bit):5.294462083814933
                                        Encrypted:false
                                        SSDEEP:12:bGgfZUqbl8ZTOhg+0ED0nNErJgwiLaOh7J:bG0yq6ZTOhg+2EVRiNJ
                                        MD5:AD29BD8C66E114FF57C943D16C78F72A
                                        SHA1:5AB070EE89A36F38FACAE4DFC8EC5CE3E59AF46E
                                        SHA-256:6FE668FE8BF69158D1FD08E90F3CFF60C1DF410BF752635BF152853B6112549C
                                        SHA-512:A53121E2379AA9C3BC52D073498A54F26383834F6D6636B4B3831010565C80BF0DA07511907EAB7BD92F9796E559958B1C0EBEA4C4B0F0D869E95B7DEB5DA7F1
                                        Malicious:false
                                        Preview:.....!! ALL YOUR FILES ARE ENCRYPTED !!!..........You can't restore them without our decryptor...........Don't try to use any public tools, you could damage the files and lose them forever...........To make sure our decryptor works, contact us and decrypt one file for free...........Download TOX messenger: https://tox.chat/..........Add friend in TOX, ID: 36F186C6FDCAAC0CF122E234B5D15F3F42F73568745F251C1306D71EBCA96817770F9B9AC2E6
                                        Process:C:\Users\user\Desktop\Document.doc.scr.exe
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):239
                                        Entropy (8bit):7.1126751910563035
                                        Encrypted:false
                                        SSDEEP:6:0l7OOhy3ZkI9R+7wy12Ap78frSJVgxGnFY22w20FCnBR:47ZyeyRmwmrp7aE6wKBR
                                        MD5:8D1C83CBC5C3B2D2CEAA4CADB055CA39
                                        SHA1:1F0E4FE21812612300CE3C23C827A2C7614EFCCD
                                        SHA-256:0E77EA1E17EE8E7B27AAB24DEF53FDD3CD5256F94BF719A35DA3E9E369FC4FD8
                                        SHA-512:D62ACAEC17152FA0E00C9505999DC0D47681D564CDD318C624031E81BF58D30CC1245A5BE39CB633E5D3DCF28C7744ACA05DD0D849CD3F22527FC4E42F75079B
                                        Malicious:false
                                        Preview:..v....8{.l)....8.aG.......".bZ+..}..bT.*../b.MST..-.4......aJu..4.&...d5.*#%a.....i.>..%EU.A.SS;.a......f....&%;.C.7.h...$G.e..bT.....jVY.p%..l..Z&j.^kZ..z......b.....j.<BK.?X.n....!].....k....[S..2*...".Q..S..Y.g6.g.<cX\.&.k....4
                                        Process:C:\Windows\splwow64.exe
                                        File Type:Microsoft OOXML
                                        Category:dropped
                                        Size (bytes):13754347
                                        Entropy (8bit):7.892811076564575
                                        Encrypted:false
                                        SSDEEP:196608:0CL0Wjt0qV/W8OUZdzA43goa4p/iTdP7XV:L3NZ1xATpV
                                        MD5:75E8ECEDB5EBE973ADA5FEA32FE9211B
                                        SHA1:3099094DF186B0E281E1E9A99D6E1F91B5C3A668
                                        SHA-256:D9AD89D5654723AAF1E48A87B8282716FA0EA95A40BBE403205358DDF057B878
                                        SHA-512:DEAFEE9796316AA908E4C1AE3AE193A89FEC6E3261AC7C9EEFCCF936F896FCCD8C9612F8D62973C5B5326A189DD4ECAE5DE1E4749525633E795130092D2CD8BD
                                        Malicious:false
                                        Preview:PK.........*.X................[Content_Types].xml/[0].piece.....0..W..o.x .....e.(....Ql!..<...S^.MMw....#Nr.9....p..:..J.z..`3..DM....T.n..J..-c...3....&a#......PK....X.j...q...PK.........*.X................[Content_Types].xml/[1].piece..1..0....eE$....{e.C.&..X.........H\., .....o.T..i.."...K.s..4..VW...i+.Ak.....}....\.+..O?PK..K..jb...l...PK.........*.X................_rels/.rels/[0].pieceM.A..!.E.B.w...1.....9@...C!...?,].......f..4.qp.,.._^I...y?\`.....Cc.jF". .^...#g.T.A.e.c.........3.....PK...BpJl...y...PK.........*.X................_rels/.rels/[1].piece..K..0....9@&.....nk/.....O3S...s....L/'.UN...'.......P....UO:....=X......B..gD...c]...[..[..3..9.9a.... .....N.PK..4...u.......PK.........*.X................[Content_Types].xml/[2].piece-.A.. .F....p.u.q.&....!...m..[.n_^..kA.......>|.......f....`........}..F..(v.6.t...0-.n.C|@.N-.Z...PK....[Pm...{...PK.........*.X............%...FixedDocumentSequence.fdseq/[0].pieceU.M..0.F..fo&.....H.`..2.....H.o..p
                                        Process:C:\Windows\SysWOW64\cmd.exe
                                        File Type:ASCII text, with CRLF line terminators
                                        Category:dropped
                                        Size (bytes):22
                                        Entropy (8bit):4.186704345910024
                                        Encrypted:false
                                        SSDEEP:3:otlZ1ln:otll
                                        MD5:672C68F2CF2762D09DC2AA4419C3E093
                                        SHA1:CC931B9D0700C6685574F67C9774510742C7972D
                                        SHA-256:CCCC88ED5702555D57A3DAD0FAB295676DAA224E29DD4EB74C8CA10D2F258BAA
                                        SHA-512:AD85F23C830ABB9C7327B7878F419554B6BF132DEED86070E2FAA624160AEC359AB503DE8C05746F38E880391F51102EF769B56B732595799BCDC9C0C266A594
                                        Malicious:false
                                        Preview:C:\PROGRA~3\2172.tmp..
                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Entropy (8bit):6.768600181335579
                                        TrID:
                                        • Win32 Executable (generic) a (10002005/4) 99.96%
                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                        • DOS Executable Generic (2002/1) 0.02%
                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                        File name:Document.doc.scr.exe
                                        File size:199'168 bytes
                                        MD5:50e5dec57451005668704281688ca55d
                                        SHA1:67dd4ac7eb8c193b39149b34d3a0d5bc21c3f200
                                        SHA256:062683257386c9e41a1cd1493f029d817445c37f7c65386d54122fa466419ce1
                                        SHA512:29ca4a44795c71d3e2b4e3417355ebb93765157d464d6d5a3fe6774056d934d57081c72001fb29e47982da11e5a5ccfdbcc958d05a11fb49bd8bf84e6d0c61ad
                                        SSDEEP:3072:66glyuxE4GsUPnliByocWepRGbVZqid91h2ys+tU:66gDBGpvEByocWeubV4inP9B
                                        TLSH:02145C20F245A8F3C42324F52A36E47173AA9F2D1D6C180FEAB53F4A68725D32B55D4B
                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...e..c............................o.............@..........................P......MU....@...........@....................
                                        Icon Hash:76d393391a9ba6ba
                                        Entrypoint:0x41946f
                                        Entrypoint Section:.itext
                                        Digitally signed:false
                                        Imagebase:0x400000
                                        Subsystem:windows gui
                                        Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                        DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                        Time Stamp:0x631A9665 [Fri Sep 9 01:27:01 2022 UTC]
                                        TLS Callbacks:
                                        CLR (.Net) Version:
                                        OS Version Major:5
                                        OS Version Minor:1
                                        File Version Major:5
                                        File Version Minor:1
                                        Subsystem Version Major:5
                                        Subsystem Version Minor:1
                                        Import Hash:41fb8cb2943df6de998b35a9d28668e8
                                        Instruction
                                        nop
                                        nop word ptr [eax+eax+00000000h]
                                        call 00007FBB4CCF57C7h
                                        nop dword ptr [eax+00h]
                                        call 00007FBB4CCE2B5Ah
                                        nop
                                        call 00007FBB4CCE6147h
                                        nop dword ptr [eax+00h]
                                        call 00007FBB4CCF3C06h
                                        nop word ptr [eax+eax+00h]
                                        push 00000000h
                                        call dword ptr [004255C8h]
                                        nop word ptr [eax+eax+00000000h]
                                        call 00007FBB4CCF5566h
                                        call 00007FBB4CCF5555h
                                        call 00007FBB4CCF5544h
                                        call 00007FBB4CCF5551h
                                        call 00007FBB4CCF553Ah
                                        call 00007FBB4CCF5535h
                                        call 00007FBB4CCF5536h
                                        call 00007FBB4CCF554Fh
                                        call 00007FBB4CCF5544h
                                        call 00007FBB4CCF550Fh
                                        call 00007FBB4CCF54ECh
                                        call 00007FBB4CCF54F9h
                                        call 00007FBB4CCF54E8h
                                        call 00007FBB4CCF5501h
                                        call 00007FBB4CCF5502h
                                        call 00007FBB4CCF54EBh
                                        call 00007FBB4CCF54DAh
                                        call 00007FBB4CCF54BDh
                                        call 00007FBB4CCF54B8h
                                        call 00007FBB4CCF54D7h
                                        call 00007FBB4CCF54BAh
                                        call 00007FBB4CCF54A3h
                                        call 00007FBB4CCF54AAh
                                        call 00007FBB4CCF4035h
                                        call 00007FBB4CCF403Ch
                                        call 00007FBB4CCF4019h
                                        call 00007FBB4CCF4020h
                                        NameVirtual AddressVirtual Size Is in Section
                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x1a2300x50.rdata
                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x270000xc160.rsrc
                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x340000xfd0.reloc
                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x1a1200x1c.rdata
                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_IAT0x1a0000x70.rdata
                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                        .text0x10000x17de80x17e00cfbda2c44e51b3b0b00bcbbc767c62a2False0.48375122709424084data6.634079266913224IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                        .itext0x190000x5460x6006f4cd57381bb5584c0a0755384d25180False0.251953125data2.9337361310958805IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                        .rdata0x1a0000x4920x600bd829aa493ecd52fe5bec776d207f206False0.3671875data3.5366359784052652IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .data0x1b0000xadc80xa000aced96dbfa5389a74c5f3b4aa34bf0a5False0.9826416015625SysEx File -7.986665903168469IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                        .pdata0x260000x8800xa00fd55173b0926e9241343dc4ae298653bFalse0.875390625data7.32033544143519IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                        .rsrc0x270000xc1600xc2000498258b0cc68156e1295f5d17bb63e6False0.22473018685567012data4.478609900548174IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                        .reloc0x340000xfd00x10003f87e4c23650dfad0bee7da98889ba94False0.843505859375GLS_BINARY_LSB_FIRST6.738987246879603IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                        NameRVASizeTypeLanguageCountryZLIB Complexity
                                        RT_ICON0x271f00x176dPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9296314824078706
                                        RT_ICON0x289600x4228Device independent bitmap graphic, 64 x 128 x 32, image size 00.0973665564478035
                                        RT_ICON0x2cb880x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.13340248962655601
                                        RT_ICON0x2f1300x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 00.16715976331360946
                                        RT_ICON0x30b980x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 00.20309568480300189
                                        RT_ICON0x31c400x988Device independent bitmap graphic, 24 x 48 x 32, image size 00.2721311475409836
                                        RT_ICON0x325c80x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 00.34244186046511627
                                        RT_ICON0x32c800x468Device independent bitmap graphic, 16 x 32 x 32, image size 00.41932624113475175
                                        RT_GROUP_ICON0x330e80x76data0.7457627118644068
                                        DLLImport
                                        gdi32.dllSetPixel, SetDCBrushColor, SelectPalette, GetTextColor, GetDeviceCaps, CreateSolidBrush
                                        USER32.dllDefWindowProcW, CreateMenu, EndDialog, GetDlgItem, GetKeyNameTextW, GetMessageW, GetWindowTextW, IsDlgButtonChecked, LoadImageW, LoadMenuW, DialogBoxParamW
                                        KERNEL32.dllSetLastError, LoadLibraryW, GetTickCount, GetLastError, GetCommandLineW, GetCommandLineA, FreeLibrary
                                        No network behavior found

                                        Click to jump to process

                                        Click to jump to process

                                        Click to dive into process behavior distribution

                                        Click to jump to process

                                        Target ID:0
                                        Start time:05:13:52
                                        Start date:25/04/2024
                                        Path:C:\Users\user\Desktop\Document.doc.scr.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Users\user\Desktop\Document.doc.scr.exe"
                                        Imagebase:0x930000
                                        File size:199'168 bytes
                                        MD5 hash:50E5DEC57451005668704281688CA55D
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Yara matches:
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: Windows_Ransomware_Lockbit_369e1e94, Description: unknown, Source: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Author: unknown
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000002.2466936126.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000003.2457027491.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000003.2463997094.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000000.2003658828.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Author: Joe Security
                                        • Rule: Windows_Ransomware_Lockbit_369e1e94, Description: unknown, Source: 00000000.00000000.2003658828.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Author: unknown
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000002.2465988864.0000000000FEE000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000003.2463644830.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        • Rule: JoeSecurity_LockBit_ransomware, Description: Yara detected LockBit ransomware, Source: 00000000.00000003.2457278883.000000000107B000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                        Reputation:low
                                        Has exited:true

                                        Target ID:4
                                        Start time:05:14:29
                                        Start date:25/04/2024
                                        Path:C:\Windows\splwow64.exe
                                        Wow64 process (32bit):false
                                        Commandline:C:\Windows\splwow64.exe 12288
                                        Imagebase:0x7ff725a30000
                                        File size:163'840 bytes
                                        MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:moderate
                                        Has exited:true

                                        Target ID:7
                                        Start time:05:14:38
                                        Start date:25/04/2024
                                        Path:C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
                                        Wow64 process (32bit):true
                                        Commandline:/insertdoc "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\{EA82EC72-B970-44A4-8C1B-42CD300B85FB}.xps" 133584884697420000
                                        Imagebase:0x210000
                                        File size:2'191'768 bytes
                                        MD5 hash:0061760D72416BCF5F2D9FA6564F0BEA
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:moderate
                                        Has exited:false

                                        Target ID:8
                                        Start time:05:14:38
                                        Start date:25/04/2024
                                        Path:C:\ProgramData\2172.tmp
                                        Wow64 process (32bit):true
                                        Commandline:"C:\ProgramData\2172.tmp"
                                        Imagebase:0x400000
                                        File size:14'336 bytes
                                        MD5 hash:294E9F64CB1642DD89229FFF0592856B
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:moderate
                                        Has exited:true

                                        Target ID:9
                                        Start time:05:14:39
                                        Start date:25/04/2024
                                        Path:C:\Windows\SysWOW64\cmd.exe
                                        Wow64 process (32bit):true
                                        Commandline:"C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\2172.tmp >> NUL
                                        Imagebase:0x790000
                                        File size:236'544 bytes
                                        MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Target ID:10
                                        Start time:05:14:39
                                        Start date:25/04/2024
                                        Path:C:\Windows\System32\conhost.exe
                                        Wow64 process (32bit):false
                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                        Imagebase:0x7ff6d64d0000
                                        File size:862'208 bytes
                                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                        Has elevated privileges:true
                                        Has administrator privileges:true
                                        Programmed in:C, C++ or other language
                                        Reputation:high
                                        Has exited:true

                                        Reset < >

                                          Execution Graph

                                          Execution Coverage:22%
                                          Dynamic/Decrypted Code Coverage:0%
                                          Signature Coverage:16%
                                          Total number of Nodes:1984
                                          Total number of Limit Nodes:12
                                          execution_graph 11389 939811 11390 939813 11389->11390 11391 9397f9 NtQuerySystemInformation 11390->11391 11392 93982c 11390->11392 11393 936894 RtlReAllocateHeap 11390->11393 11391->11390 11395 93980f 11391->11395 11394 93686c RtlFreeHeap 11392->11394 11393->11390 11394->11395 11396 93686c RtlFreeHeap 11395->11396 11397 939872 11396->11397 11622 947556 11632 94752b 11622->11632 11623 947624 11625 94205c 16 API calls 11623->11625 11624 947631 11626 947646 11624->11626 11627 947637 11624->11627 11630 94762c 11625->11630 11628 947656 11626->11628 11629 94764c 11626->11629 11631 939bb0 14 API calls 11627->11631 11634 947675 11628->11634 11635 94765c 11628->11635 11633 9473ac 27 API calls 11629->11633 11636 94763c 11631->11636 11632->11623 11632->11624 11633->11630 11638 947685 11634->11638 11639 94767b 11634->11639 11637 946fa0 5 API calls 11635->11637 11640 941ef4 138 API calls 11636->11640 11643 947661 11637->11643 11641 9476d8 11638->11641 11642 94768b 11638->11642 11644 94390c 5 API calls 11639->11644 11640->11630 11646 9476e7 11641->11646 11647 9476de 11641->11647 11645 9476ba 11642->11645 11651 946da8 2 API calls 11642->11651 11648 946bbc 2 API calls 11643->11648 11644->11630 11645->11630 11652 9404b4 13 API calls 11645->11652 11650 93a338 2 API calls 11646->11650 11649 946bbc 2 API calls 11647->11649 11648->11630 11649->11630 11653 9476f8 11650->11653 11651->11645 11652->11630 11654 94771c 11653->11654 11655 93a338 2 API calls 11653->11655 11656 942428 12 API calls 11654->11656 11657 94770b 11655->11657 11656->11630 11657->11654 11658 947710 11657->11658 11659 939bb0 14 API calls 11658->11659 11660 947715 11659->11660 11661 947034 138 API calls 11660->11661 11661->11630 11478 93df94 11484 93de8f 11478->11484 11479 93def1 ReadFile 11479->11484 11480 93e0aa WriteFile 11480->11484 11481 93e150 NtClose 11481->11484 11482 93686c RtlFreeHeap 11482->11484 11483 93e031 WriteFile 11483->11484 11484->11479 11484->11480 11484->11481 11484->11482 11484->11483 11485 93dee2 11484->11485 11347 93fedb 11360 93fd52 11347->11360 11348 93686c RtlFreeHeap 11348->11360 11349 9369e0 RtlAllocateHeap 11349->11360 11350 93f59c NtSetInformationThread NtClose 11350->11360 11351 93ff71 11352 93ffdb 11351->11352 11353 93686c RtlFreeHeap 11351->11353 11354 93ffe9 11352->11354 11355 93686c RtlFreeHeap 11352->11355 11353->11352 11356 93fff7 11354->11356 11357 93686c RtlFreeHeap 11354->11357 11355->11354 11357->11356 11358 93f6d8 NtSetInformationThread NtClose 11358->11360 11359 93b3c0 2 API calls 11359->11360 11360->11348 11360->11349 11360->11350 11360->11351 11360->11358 11360->11359 11196 93d88a 11197 93d88c 11196->11197 11216 93cd04 11197->11216 11200 93cedc RtlAllocateHeap 11205 93d8cb 11200->11205 11201 93d9cc 11203 93d9da 11201->11203 11206 93686c RtlFreeHeap 11201->11206 11202 93686c RtlFreeHeap 11202->11201 11204 93d9e8 11203->11204 11207 93686c RtlFreeHeap 11203->11207 11208 93d9f6 11204->11208 11209 93686c RtlFreeHeap 11204->11209 11210 936de8 RtlAllocateHeap 11205->11210 11211 93d8c1 11205->11211 11206->11203 11207->11204 11209->11208 11212 93d921 11210->11212 11211->11201 11211->11202 11212->11211 11213 936844 RtlAllocateHeap 11212->11213 11214 93d974 11213->11214 11214->11211 11215 93cfcc 2 API calls 11214->11215 11215->11211 11217 936de8 RtlAllocateHeap 11216->11217 11218 93cd56 11217->11218 11250 93cd5f 11218->11250 11251 93c658 11218->11251 11220 93ce70 11223 93ce7e 11220->11223 11226 93686c RtlFreeHeap 11220->11226 11222 93686c RtlFreeHeap 11222->11220 11227 93ce8c 11223->11227 11229 93686c RtlFreeHeap 11223->11229 11226->11223 11230 93ce9a 11227->11230 11233 93686c RtlFreeHeap 11227->11233 11228 93c8c4 2 API calls 11232 93cd79 11228->11232 11229->11227 11231 93cea8 11230->11231 11234 93686c RtlFreeHeap 11230->11234 11236 93ceb6 11231->11236 11238 93686c RtlFreeHeap 11231->11238 11286 93c928 11232->11286 11233->11230 11234->11231 11239 93cec4 11236->11239 11240 93686c RtlFreeHeap 11236->11240 11237 93cd81 11291 93cb20 11237->11291 11238->11236 11241 93ced2 11239->11241 11242 93686c RtlFreeHeap 11239->11242 11240->11239 11241->11200 11241->11211 11242->11241 11246 93cd99 11247 936844 RtlAllocateHeap 11246->11247 11248 93ce19 11247->11248 11249 936894 RtlReAllocateHeap 11248->11249 11248->11250 11249->11250 11250->11220 11250->11222 11252 93a488 6 API calls 11251->11252 11253 93c68c 11252->11253 11254 93c692 11253->11254 11255 936844 RtlAllocateHeap 11253->11255 11256 93c832 11254->11256 11258 93686c RtlFreeHeap 11254->11258 11257 93c6a4 11255->11257 11259 93c840 11256->11259 11260 93686c RtlFreeHeap 11256->11260 11257->11254 11262 93a488 6 API calls 11257->11262 11258->11256 11261 93c84e 11259->11261 11263 93686c RtlFreeHeap 11259->11263 11260->11259 11277 93c858 11261->11277 11264 93c6c1 11262->11264 11263->11261 11264->11254 11265 936de8 RtlAllocateHeap 11264->11265 11266 93c6d6 11265->11266 11266->11254 11267 936de8 RtlAllocateHeap 11266->11267 11268 93c6ee 11267->11268 11268->11254 11269 936844 RtlAllocateHeap 11268->11269 11270 93c71f 11269->11270 11270->11254 11271 936844 RtlAllocateHeap 11270->11271 11275 93c748 11271->11275 11272 93a1c0 6 API calls 11272->11275 11274 93c7ff 11276 936894 RtlReAllocateHeap 11274->11276 11275->11254 11275->11272 11275->11274 11298 93a54c 11275->11298 11276->11254 11302 93a108 11277->11302 11280 936844 RtlAllocateHeap 11281 93c88d 11280->11281 11282 93c8b4 11281->11282 11283 93a108 2 API calls 11281->11283 11282->11228 11284 93c8a8 11283->11284 11284->11282 11285 93686c RtlFreeHeap 11284->11285 11285->11282 11287 936c98 2 API calls 11286->11287 11288 93c951 11287->11288 11289 936844 RtlAllocateHeap 11288->11289 11290 93c955 11288->11290 11289->11290 11290->11237 11292 93cbdb 11291->11292 11293 936844 RtlAllocateHeap 11292->11293 11294 93cc88 11292->11294 11293->11294 11295 93ccb4 11294->11295 11296 936844 RtlAllocateHeap 11295->11296 11297 93ccc6 11296->11297 11297->11246 11299 93a58f 11298->11299 11300 93b3c0 2 API calls 11299->11300 11301 93a5a9 11299->11301 11300->11301 11301->11275 11303 93a13f 11302->11303 11304 93b3c0 2 API calls 11303->11304 11305 93a159 11303->11305 11304->11305 11305->11280 11306 937e8a 11312 937e60 11306->11312 11307 937e72 NtQuerySystemInformation 11307->11312 11308 936894 RtlReAllocateHeap 11308->11312 11309 93686c RtlFreeHeap 11309->11312 11310 93686c RtlFreeHeap 11311 937f40 Sleep 11310->11311 11311->11312 11312->11307 11312->11308 11312->11309 11312->11310 11313 936844 RtlAllocateHeap 11312->11313 11313->11312 11590 93ddca 11592 93dd81 11590->11592 11591 93ddf0 11593 93de3d 11591->11593 11596 93686c RtlFreeHeap 11591->11596 11594 93dd9d 11592->11594 11595 936894 RtlReAllocateHeap 11592->11595 11594->11591 11597 93db90 NtTerminateProcess 11594->11597 11598 93dc60 NtTerminateProcess 11594->11598 11595->11592 11596->11593 11597->11594 11598->11594 11369 93b6c8 11370 93b715 11369->11370 11371 93b71a 11370->11371 11372 93b71c RtlAdjustPrivilege 11370->11372 11372->11370 11372->11371 11373 9396cd 11374 9396af 11373->11374 11375 939735 11374->11375 11376 93686c RtlFreeHeap 11374->11376 11376->11375 11314 93d88c 11315 93cd04 14 API calls 11314->11315 11316 93d8b8 11315->11316 11317 93d8c1 11316->11317 11318 93cedc RtlAllocateHeap 11316->11318 11319 93d9cc 11317->11319 11320 93686c RtlFreeHeap 11317->11320 11325 93d8cb 11318->11325 11321 93d9da 11319->11321 11323 93686c RtlFreeHeap 11319->11323 11320->11319 11322 93d9e8 11321->11322 11324 93686c RtlFreeHeap 11321->11324 11326 93d9f6 11322->11326 11327 93686c RtlFreeHeap 11322->11327 11323->11321 11324->11322 11325->11317 11328 936de8 RtlAllocateHeap 11325->11328 11327->11326 11329 93d921 11328->11329 11329->11317 11330 936844 RtlAllocateHeap 11329->11330 11331 93d974 11330->11331 11331->11317 11332 93cfcc 2 API calls 11331->11332 11332->11317 11398 93f032 11401 93effb 11398->11401 11399 93efe7 MoveFileExW 11399->11401 11413 93eff9 11399->11413 11400 93f034 11402 93686c RtlFreeHeap 11400->11402 11401->11399 11401->11400 11404 93686c RtlFreeHeap 11401->11404 11410 93ece4 RtlAllocateHeap 11401->11410 11401->11413 11402->11413 11403 93f051 CreateFileW 11405 93f075 11403->11405 11406 93f07a 11403->11406 11404->11401 11407 93f14d 11405->11407 11408 93686c RtlFreeHeap 11405->11408 11412 93ed30 2 API calls 11406->11412 11409 93686c RtlFreeHeap 11407->11409 11408->11407 11411 93f155 11409->11411 11410->11401 11414 93f08f 11412->11414 11413->11403 11413->11405 11414->11405 11415 93f0a3 CreateIoCompletionPort 11414->11415 11416 93f0ba 11415->11416 11418 93f0dc 11415->11418 11417 93686c RtlFreeHeap 11416->11417 11417->11405 11418->11405 11419 93686c RtlFreeHeap 11418->11419 11419->11405 11599 93ddf2 11601 93ddde 11599->11601 11600 93ddf0 11602 93de3d 11600->11602 11604 93686c RtlFreeHeap 11600->11604 11601->11600 11603 93db90 NtTerminateProcess 11601->11603 11605 93dc60 NtTerminateProcess 11601->11605 11603->11601 11604->11602 11605->11601 11377 93f8f0 11379 93f8d2 11377->11379 11378 936844 RtlAllocateHeap 11378->11379 11379->11378 11381 93f8ee 11379->11381 11380 93fa12 11381->11380 11382 936844 RtlAllocateHeap 11381->11382 11382->11381 11420 93e430 11421 93e3f3 11420->11421 11422 93e3c5 SetFileAttributesW CreateFileW 11421->11422 11423 93de48 5 API calls 11421->11423 11424 93e40b 11421->11424 11422->11421 11422->11424 11423->11421 11458 944070 11464 9440b4 11458->11464 11459 9444e2 11462 9444f0 11459->11462 11463 93686c RtlFreeHeap 11459->11463 11460 9440d2 11460->11459 11461 93686c RtlFreeHeap 11460->11461 11461->11459 11465 9444fe 11462->11465 11466 93686c RtlFreeHeap 11462->11466 11463->11462 11464->11460 11467 936de8 RtlAllocateHeap 11464->11467 11466->11465 11468 944186 11467->11468 11468->11460 11469 936844 RtlAllocateHeap 11468->11469 11469->11460 11341 938ea2 11346 938e63 11341->11346 11342 938eb3 11344 938ec2 11342->11344 11345 938eb9 CloseServiceHandle 11342->11345 11343 938eaa CloseServiceHandle 11343->11342 11345->11344 11346->11342 11346->11343 11425 93aa20 11426 93aa43 11425->11426 11427 93ab2f 11426->11427 11428 936844 RtlAllocateHeap 11426->11428 11429 93ab03 11428->11429 11429->11427 11430 93686c RtlFreeHeap 11429->11430 11430->11427 11431 940220 11443 94011d 11431->11443 11432 94028d 11433 93686c RtlFreeHeap 11432->11433 11435 94029b 11432->11435 11433->11435 11434 9369e0 RtlAllocateHeap 11434->11443 11436 940313 11435->11436 11438 93686c RtlFreeHeap 11435->11438 11437 940321 11436->11437 11439 93686c RtlFreeHeap 11436->11439 11440 94032f 11437->11440 11442 93686c RtlFreeHeap 11437->11442 11438->11436 11439->11437 11441 93f6d8 NtSetInformationThread NtClose 11441->11443 11442->11440 11443->11432 11443->11434 11443->11441 11444 93686c RtlFreeHeap 11443->11444 11445 93b3c0 2 API calls 11443->11445 11444->11443 11445->11443 11662 938f66 11663 938f68 RtlAdjustPrivilege 11662->11663 11664 9397d8 4 API calls 11663->11664 11665 938fa0 11664->11665 11666 939010 11665->11666 11667 939880 NtClose 11665->11667 11669 939035 11666->11669 11671 938ecc 4 API calls 11666->11671 11668 938fae 11667->11668 11668->11666 11670 938fb7 NtSetInformationThread 11668->11670 11670->11666 11672 938fcb 11670->11672 11671->11669 11673 938da8 7 API calls 11672->11673 11674 938fe0 11673->11674 11674->11666 11675 939880 NtClose 11674->11675 11676 938fee 11675->11676 11676->11666 11677 938be0 2 API calls 11676->11677 11677->11666 11446 93782a 11447 93782c CoInitialize 11446->11447 11448 937861 11447->11448 9285 94946f 9286 94947e 9285->9286 9293 93639c 9286->9293 9290 94948e 9389 947458 9290->9389 9434 935aec 9293->9434 9296 9363b6 RtlCreateHeap 9297 93654d 9296->9297 9298 9363d1 9296->9298 9344 939990 9297->9344 9299 935aec 3 API calls 9298->9299 9300 9363ed 9299->9300 9300->9297 9442 935da0 9300->9442 9303 935da0 8 API calls 9304 936419 9303->9304 9305 935da0 8 API calls 9304->9305 9306 93642a 9305->9306 9307 935da0 8 API calls 9306->9307 9308 93643b 9307->9308 9309 935da0 8 API calls 9308->9309 9310 93644c 9309->9310 9311 935da0 8 API calls 9310->9311 9312 93645d 9311->9312 9313 935da0 8 API calls 9312->9313 9314 93646e 9313->9314 9315 935da0 8 API calls 9314->9315 9316 93647f 9315->9316 9317 935da0 8 API calls 9316->9317 9318 936490 9317->9318 9319 935da0 8 API calls 9318->9319 9320 9364a1 9319->9320 9321 935da0 8 API calls 9320->9321 9322 9364b2 9321->9322 9323 935da0 8 API calls 9322->9323 9324 9364c3 9323->9324 9325 935da0 8 API calls 9324->9325 9326 9364d4 9325->9326 9327 935da0 8 API calls 9326->9327 9328 9364e5 9327->9328 9329 935da0 8 API calls 9328->9329 9330 9364f6 9329->9330 9331 935da0 8 API calls 9330->9331 9332 936507 9331->9332 9333 935da0 8 API calls 9332->9333 9334 936518 9333->9334 9335 935da0 8 API calls 9334->9335 9336 936529 9335->9336 9337 935da0 8 API calls 9336->9337 9338 93653a 9337->9338 9448 93b444 9338->9448 9340 936541 9451 947738 9340->9451 9345 939995 9344->9345 9498 936f48 9345->9498 9347 93999a 9531 93b4dc CheckTokenMembership 9347->9531 9349 9399d7 9532 936d40 9349->9532 9351 9399e6 9352 9399f4 9351->9352 9535 93bb70 9351->9535 9352->9290 9353 9399b9 9353->9349 9593 93b4fc 9353->9593 9357 939a00 9538 93b708 9357->9538 9366 939a13 9367 939a9f 9366->9367 9551 93b1ac 9366->9551 9369 939ade 9367->9369 9373 93b674 NtQueryInformationToken 9367->9373 9565 93c3f8 9369->9565 9370 939a3c 9370->9366 9606 93ae74 9370->9606 9382 939acc 9373->9382 9381 939a7a 9381->9367 9384 93686c RtlFreeHeap 9381->9384 9382->9369 9630 9431e8 9382->9630 9385 939a89 9384->9385 9386 93686c RtlFreeHeap 9385->9386 9387 939a94 9386->9387 9388 93686c RtlFreeHeap 9387->9388 9388->9367 9390 947482 9389->9390 9391 9474a3 9390->9391 9400 9474b2 9390->9400 9424 947498 31 API calls 9390->9424 9693 939bb0 9391->9693 9395 947624 9762 94205c 9395->9762 9396 947631 9398 947646 9396->9398 9399 947637 9396->9399 9401 947656 9398->9401 9402 94764c 9398->9402 9403 939bb0 14 API calls 9399->9403 9400->9395 9400->9396 9405 947675 9401->9405 9406 94765c 9401->9406 9846 9473ac 9402->9846 9407 94763c 9403->9407 9409 947685 9405->9409 9410 94767b 9405->9410 9857 946fa0 9406->9857 9813 941ef4 9407->9813 9412 9476d8 9409->9412 9413 94768b 9409->9413 9884 94390c 9410->9884 9417 9476e7 9412->9417 9418 9476de 9412->9418 9416 9476ba 9413->9416 9891 946da8 9413->9891 9416->9424 9905 9404b4 9416->9905 9936 93a338 9417->9936 9420 946bbc 2 API calls 9418->9420 9420->9424 9426 94771c 9940 942428 9426->9940 9427 93a338 2 API calls 9429 94770b 9427->9429 9429->9426 9430 947710 9429->9430 9431 939bb0 14 API calls 9430->9431 9432 947715 9431->9432 9433 947034 138 API calls 9432->9433 9433->9424 9435 935afe 9434->9435 9436 935b18 9434->9436 9437 935aec 3 API calls 9435->9437 9438 935aec 3 API calls 9436->9438 9440 935b40 9436->9440 9437->9436 9438->9440 9439 935c0a 9439->9296 9439->9297 9440->9439 9462 935a84 9440->9462 9477 935c24 9442->9477 9444 935dcb 9444->9303 9445 935aec 3 API calls 9446 935ddb RtlAllocateHeap 9445->9446 9447 935db5 9446->9447 9447->9444 9447->9445 9449 93b458 NtSetInformationThread 9448->9449 9449->9340 9452 947754 9451->9452 9492 936844 9452->9492 9454 936548 9457 93b470 9454->9457 9456 947764 9456->9454 9495 93686c 9456->9495 9458 935aec 3 API calls 9457->9458 9459 93b495 9458->9459 9460 93b4bb 9459->9460 9461 93b49e NtProtectVirtualMemory 9459->9461 9460->9297 9461->9460 9463 935ae2 9462->9463 9464 935ab0 9462->9464 9463->9440 9464->9463 9469 935a20 9464->9469 9466 935ac4 9466->9463 9467 935ad8 9466->9467 9472 9359d4 9467->9472 9470 935a37 9469->9470 9471 935a65 LdrLoadDll 9470->9471 9471->9466 9473 9359e3 9472->9473 9474 935a04 LdrGetProcedureAddress 9472->9474 9476 9359ef LdrGetProcedureAddress 9473->9476 9475 935a16 9474->9475 9475->9463 9476->9475 9478 935c37 9477->9478 9480 935c51 9477->9480 9479 935aec 3 API calls 9478->9479 9479->9480 9481 935aec 3 API calls 9480->9481 9483 935c79 9480->9483 9481->9483 9482 935aec 3 API calls 9490 935ca1 9482->9490 9483->9482 9483->9490 9484 935ce9 FindFirstFileW 9484->9490 9485 935d5a 9485->9447 9486 935d37 FindNextFileW 9489 935d4b FindClose 9486->9489 9486->9490 9487 935d19 FindClose 9488 935a20 LdrLoadDll 9487->9488 9491 935d30 9488->9491 9489->9490 9490->9484 9490->9485 9490->9486 9490->9487 9491->9447 9493 93684c 9492->9493 9494 93685a RtlAllocateHeap 9493->9494 9494->9456 9496 936874 9495->9496 9497 936882 RtlFreeHeap 9496->9497 9497->9454 9634 936de8 9498->9634 9500 936f60 9501 937237 9500->9501 9502 936844 RtlAllocateHeap 9500->9502 9501->9347 9507 936f7d 9502->9507 9503 93722f 9504 93686c RtlFreeHeap 9503->9504 9504->9501 9505 937221 9506 93686c RtlFreeHeap 9505->9506 9506->9503 9507->9503 9507->9505 9508 937000 9507->9508 9509 936844 RtlAllocateHeap 9507->9509 9510 936844 RtlAllocateHeap 9508->9510 9511 937033 9508->9511 9509->9508 9510->9511 9512 937066 9511->9512 9513 936844 RtlAllocateHeap 9511->9513 9514 936844 RtlAllocateHeap 9512->9514 9516 937099 9512->9516 9513->9512 9514->9516 9515 937132 9522 936844 RtlAllocateHeap 9515->9522 9523 937169 9515->9523 9517 9370cc 9516->9517 9518 936844 RtlAllocateHeap 9516->9518 9519 936844 RtlAllocateHeap 9517->9519 9520 9370ff 9517->9520 9518->9517 9519->9520 9520->9515 9521 936844 RtlAllocateHeap 9520->9521 9521->9515 9522->9523 9523->9505 9524 936844 RtlAllocateHeap 9523->9524 9525 9371a4 9524->9525 9525->9505 9637 936ee4 9525->9637 9527 9371cc 9528 936844 RtlAllocateHeap 9527->9528 9529 9371eb 9528->9529 9529->9505 9530 93686c RtlFreeHeap 9529->9530 9530->9505 9531->9353 9533 936844 RtlAllocateHeap 9532->9533 9534 936d55 9533->9534 9534->9351 9536 936844 RtlAllocateHeap 9535->9536 9537 93bb81 9536->9537 9537->9357 9539 93b715 9538->9539 9540 939a0a 9539->9540 9541 93b71c RtlAdjustPrivilege 9539->9541 9542 93b674 9540->9542 9541->9539 9541->9540 9543 93b68b 9542->9543 9544 939a0f 9543->9544 9545 93b68f NtQueryInformationToken 9543->9545 9544->9366 9546 93b388 9544->9546 9545->9544 9646 9397d8 9546->9646 9548 93b3a5 9550 939a29 9548->9550 9656 939880 9548->9656 9550->9366 9605 93b4dc CheckTokenMembership 9550->9605 9552 93b1ca 9551->9552 9553 936844 RtlAllocateHeap 9552->9553 9555 93b1d5 9553->9555 9554 939a58 9554->9367 9623 93b5b8 9554->9623 9555->9554 9556 93686c RtlFreeHeap 9555->9556 9559 93b1f6 9556->9559 9557 93b350 9558 93686c RtlFreeHeap 9557->9558 9558->9554 9559->9557 9663 936e18 9559->9663 9561 93b306 9562 936e18 RtlAllocateHeap 9561->9562 9563 93b32b 9562->9563 9564 936e18 RtlAllocateHeap 9563->9564 9564->9557 9566 939af3 9565->9566 9567 93c418 9565->9567 9587 93e2b8 9566->9587 9568 936de8 RtlAllocateHeap 9567->9568 9569 93c429 9568->9569 9569->9566 9570 936844 RtlAllocateHeap 9569->9570 9574 93c445 9570->9574 9571 93c645 9572 93686c RtlFreeHeap 9571->9572 9572->9566 9573 93686c RtlFreeHeap 9573->9571 9574->9571 9575 93c499 CreateFileW 9574->9575 9577 93c636 9574->9577 9576 93c4ed WriteFile 9575->9576 9575->9577 9576->9577 9578 93c508 RegCreateKeyExW 9576->9578 9577->9573 9578->9577 9579 93c531 RegSetValueExW 9578->9579 9581 93c563 RegCreateKeyExW 9579->9581 9582 93c62d NtClose 9579->9582 9581->9582 9584 93c5de RegSetValueExW 9581->9584 9582->9577 9584->9582 9586 93c612 SHChangeNotify 9584->9586 9586->9582 9588 93e2d4 9587->9588 9666 93e350 9588->9666 9590 93e32a 9591 939af8 9590->9591 9592 93686c RtlFreeHeap 9590->9592 9591->9290 9592->9591 9595 93b511 9593->9595 9594 9399ce 9594->9349 9599 93babc 9594->9599 9595->9594 9596 936844 RtlAllocateHeap 9595->9596 9597 93b54a 9596->9597 9597->9594 9598 93686c RtlFreeHeap 9597->9598 9598->9594 9601 93bad1 9599->9601 9600 93bb66 9600->9349 9601->9600 9670 939740 9601->9670 9604 93686c RtlFreeHeap 9604->9600 9605->9370 9607 93aebf 9606->9607 9618 93b074 9607->9618 9674 93ac28 9607->9674 9609 93aecd 9610 93afbb 9609->9610 9611 93b0cf 9609->9611 9609->9618 9612 936de8 RtlAllocateHeap 9610->9612 9610->9618 9613 936de8 RtlAllocateHeap 9611->9613 9611->9618 9615 93afee 9612->9615 9614 93b0fe 9613->9614 9616 93686c RtlFreeHeap 9614->9616 9614->9618 9617 93686c RtlFreeHeap 9615->9617 9615->9618 9616->9618 9619 93b010 9617->9619 9618->9366 9619->9618 9620 936de8 RtlAllocateHeap 9619->9620 9621 93b056 9620->9621 9621->9618 9622 93686c RtlFreeHeap 9621->9622 9622->9618 9624 93b5cd 9623->9624 9625 936844 RtlAllocateHeap 9624->9625 9626 939a71 9624->9626 9628 93b606 9625->9628 9626->9367 9629 93b4dc CheckTokenMembership 9626->9629 9627 93686c RtlFreeHeap 9627->9626 9628->9626 9628->9627 9629->9381 9631 9431f8 9630->9631 9633 943256 9631->9633 9683 942f58 9631->9683 9633->9369 9635 936844 RtlAllocateHeap 9634->9635 9636 936df9 9635->9636 9636->9500 9638 936f0b 9637->9638 9643 936e8c 9638->9643 9640 936f2b 9641 93686c RtlFreeHeap 9640->9641 9642 936f3f 9641->9642 9642->9527 9644 936844 RtlAllocateHeap 9643->9644 9645 936eaf 9644->9645 9645->9640 9647 936844 RtlAllocateHeap 9646->9647 9649 9397f6 9647->9649 9648 9397f9 NtQuerySystemInformation 9648->9649 9653 93980f 9648->9653 9649->9648 9650 93982c 9649->9650 9660 936894 9649->9660 9652 93686c RtlFreeHeap 9650->9652 9652->9653 9653->9548 9654 93686c RtlFreeHeap 9653->9654 9655 939872 9654->9655 9655->9548 9657 9398a5 9656->9657 9658 939977 9657->9658 9659 93996e NtClose 9657->9659 9658->9550 9659->9658 9661 93689c 9660->9661 9662 9368aa RtlReAllocateHeap 9661->9662 9662->9649 9664 936844 RtlAllocateHeap 9663->9664 9665 936e2a 9664->9665 9665->9561 9667 93e35c 9666->9667 9669 93e369 9666->9669 9668 936844 RtlAllocateHeap 9667->9668 9667->9669 9668->9669 9669->9590 9671 939752 9670->9671 9673 93977a 9670->9673 9672 936844 RtlAllocateHeap 9671->9672 9672->9673 9673->9604 9675 936844 RtlAllocateHeap 9674->9675 9676 93ac4d 9675->9676 9677 93ac83 9676->9677 9678 936894 RtlReAllocateHeap 9676->9678 9682 93ac66 9676->9682 9679 93686c RtlFreeHeap 9677->9679 9678->9676 9679->9682 9680 93686c RtlFreeHeap 9681 93adb0 9680->9681 9681->9609 9682->9609 9682->9680 9684 942f69 9683->9684 9686 9430f7 9684->9686 9687 93b3c0 9684->9687 9686->9633 9688 93b3d2 9687->9688 9689 93b3cf 9687->9689 9688->9689 9690 93b419 NtSetInformationThread 9688->9690 9689->9686 9691 93b42f NtClose 9690->9691 9692 93b42e 9690->9692 9691->9689 9692->9691 9694 939bc3 9693->9694 9695 939c5e 9693->9695 9977 937fbc 9694->9977 9702 947034 9695->9702 9698 939c11 9700 939c31 CreateMutexW 9698->9700 9699 9404b4 13 API calls 9699->9698 9981 9368ec 9700->9981 9715 947051 9702->9715 9703 9470ff 9704 947145 CreateThread CreateThread 9703->9704 9705 94711a CreateThread 9703->9705 9707 947183 9704->9707 9708 94717e 9704->9708 10477 937468 GetLogicalDriveStringsW 9704->10477 10482 93782c CoInitialize 9704->10482 9705->9704 9706 947135 9705->9706 10462 938f68 RtlAdjustPrivilege 9705->10462 9706->9704 9711 9471a4 9707->9711 9712 94718c CreateThread 9707->9712 9987 937ca4 OpenSCManagerW 9708->9987 9709 9470bc 9709->9703 9714 939c64 3 API calls 9709->9714 9720 947221 9711->9720 9995 93b734 9711->9995 9712->9711 10513 937e58 9712->10513 9714->9703 9715->9703 9715->9709 10125 939c64 9715->10125 9717 94727f 9722 9472a3 9717->9722 9723 947288 CreateThread 9717->9723 9718 94726b NtTerminateThread 9718->9717 9720->9717 9720->9718 9726 947392 9722->9726 9727 9472c3 9722->9727 9723->9722 10457 939628 9723->10457 9725 947201 9734 93e2b8 2 API calls 9725->9734 9738 947214 9725->9738 10150 941934 9726->10150 9730 9472cc CreateThread 9727->9730 9753 9472e7 9727->9753 9730->9753 10484 93c064 9730->10484 9733 947339 9736 93b674 NtQueryInformationToken 9733->9736 9735 94720f 9734->9735 10049 93fc88 9735->10049 9741 94733e 9736->9741 9743 93e2b8 2 API calls 9738->9743 9739 93e2b8 2 API calls 9744 9471f2 9739->9744 9745 947342 9741->9745 9746 947349 9741->9746 9743->9720 10018 940a38 9744->10018 10146 938960 9745->10146 10086 938230 9746->10086 9750 947390 9750->9424 9752 9471f7 9754 93e2b8 2 API calls 9752->9754 9753->9733 10071 93da00 9753->10071 9755 9471fc 9754->9755 10025 940be4 9755->10025 9757 947347 9757->9750 10119 939640 9757->10119 9761 9404b4 13 API calls 9761->9750 9763 936934 RtlAllocateHeap 9762->9763 9764 942074 9763->9764 9765 9420a5 9764->9765 9766 942096 9764->9766 9804 94210d 9764->9804 10684 937428 9765->10684 10658 940000 9766->10658 9770 942105 9771 93686c RtlFreeHeap 9770->9771 9771->9804 9772 936844 RtlAllocateHeap 9784 9420ea 9772->9784 9773 942122 9774 93686c RtlFreeHeap 9773->9774 9774->9804 9775 942196 9778 93686c RtlFreeHeap 9775->9778 9776 93a338 2 API calls 9776->9784 9777 93a280 NtSetInformationThread NtClose 9777->9784 9778->9804 9779 94236f 9780 93686c RtlFreeHeap 9779->9780 9780->9804 9781 94228e 9782 93686c RtlFreeHeap 9781->9782 9782->9804 9783 9422a1 10696 93a3dc 9783->10696 9784->9770 9784->9772 9784->9773 9784->9775 9784->9776 9784->9777 9784->9779 9784->9781 9784->9783 9785 942271 9784->9785 9786 9423a1 9784->9786 9788 942382 9784->9788 9801 9422c5 9784->9801 9784->9804 9808 93ab68 NtSetInformationThread NtClose 9784->9808 9811 93686c RtlFreeHeap 9784->9811 10690 93a958 9784->10690 9787 93686c RtlFreeHeap 9785->9787 9789 936984 RtlAllocateHeap 9786->9789 9787->9804 9788->9786 9793 942397 9788->9793 9794 9423fa 9789->9794 9791 942323 9797 936984 RtlAllocateHeap 9791->9797 9792 94232d 10700 936a74 9792->10700 9799 93686c RtlFreeHeap 9793->9799 9800 93686c RtlFreeHeap 9794->9800 9803 94232b 9797->9803 9799->9804 9805 942403 9800->9805 9801->9791 9801->9792 9802 9422b8 9806 93686c RtlFreeHeap 9802->9806 9807 93686c RtlFreeHeap 9803->9807 9804->9424 9805->9804 9809 94096c 11 API calls 9805->9809 9806->9804 9810 94233e 9807->9810 9808->9784 9809->9804 9810->9804 10704 94096c 9810->10704 9811->9784 9814 941d28 2 API calls 9813->9814 9815 941f02 9814->9815 9816 941f06 9815->9816 9817 941f27 9815->9817 9818 941f22 9816->9818 9820 9404b4 13 API calls 9816->9820 9819 939640 2 API calls 9817->9819 9818->9424 9821 941f2c 9819->9821 9820->9818 9822 941f30 9821->9822 9823 941f3a 9821->9823 9824 947034 138 API calls 9822->9824 10713 93b4dc CheckTokenMembership 9823->10713 9826 941f35 9824->9826 9826->9424 9827 942056 9827->9424 9828 941fb5 9829 941ffe 9828->9829 9834 939c64 3 API calls 9828->9834 10714 940e30 9829->10714 9831 939c64 3 API calls 9831->9828 9832 941f3f 9832->9827 9832->9828 9832->9831 9834->9829 9839 940e98 3 API calls 9840 942043 9839->9840 10762 941170 9840->10762 9843 938230 14 API calls 9844 94204f 9843->9844 9845 9416ac 2 API calls 9844->9845 9845->9827 10801 941be8 9846->10801 9849 938230 14 API calls 9850 9473bf 9849->9850 9851 93b674 NtQueryInformationToken 9850->9851 9854 9473d8 9851->9854 9852 947450 9852->9424 9853 939640 2 API calls 9855 947430 9853->9855 9854->9852 9854->9853 9856 9404b4 13 API calls 9855->9856 9856->9852 9858 943954 RtlAllocateHeap 9857->9858 9862 946fb2 9858->9862 9859 947021 9860 94702f 9859->9860 9861 93686c RtlFreeHeap 9859->9861 9872 946bbc 9860->9872 9861->9860 9862->9859 9863 946ff6 9862->9863 10814 946490 9862->10814 10832 943ea0 9863->10832 9869 947017 9870 943ea0 2 API calls 9869->9870 9870->9859 9873 946bd0 9872->9873 9874 946d9f 9872->9874 9875 943954 RtlAllocateHeap 9873->9875 9874->9424 9880 946be0 9875->9880 9876 946d91 9876->9874 9878 93686c RtlFreeHeap 9876->9878 9877 93686c RtlFreeHeap 9877->9876 9878->9874 9879 946c86 9879->9876 9879->9877 9880->9879 9881 936844 RtlAllocateHeap 9880->9881 9882 946ca8 9881->9882 9882->9879 11140 946688 9882->11140 9885 943954 RtlAllocateHeap 9884->9885 9889 94391e 9885->9889 9886 943942 9887 943950 9886->9887 9888 93686c RtlFreeHeap 9886->9888 9887->9424 9888->9887 9889->9886 11150 943784 9889->11150 9892 946dc4 9891->9892 9893 936de8 RtlAllocateHeap 9892->9893 9894 946ed5 9893->9894 9895 936de8 RtlAllocateHeap 9894->9895 9904 946ede 9894->9904 9896 946eef 9895->9896 9902 936de8 RtlAllocateHeap 9896->9902 9896->9904 9897 946f7b 9899 946f89 9897->9899 9900 93686c RtlFreeHeap 9897->9900 9898 93686c RtlFreeHeap 9898->9897 9901 946f97 9899->9901 9903 93686c RtlFreeHeap 9899->9903 9900->9899 9901->9416 9902->9904 9903->9901 9904->9897 9904->9898 9906 9404e9 9905->9906 9907 936de8 RtlAllocateHeap 9906->9907 9908 940562 9907->9908 9909 936844 RtlAllocateHeap 9908->9909 9910 94056b 9908->9910 9913 940582 9909->9913 9911 940930 9910->9911 9914 93686c RtlFreeHeap 9910->9914 9912 94093e 9911->9912 9915 93686c RtlFreeHeap 9911->9915 9916 94094c 9912->9916 9918 93686c RtlFreeHeap 9912->9918 9913->9910 11168 940338 9913->11168 9914->9911 9915->9912 9919 94095a 9916->9919 9921 93686c RtlFreeHeap 9916->9921 9918->9916 9919->9424 9920 9405b3 9920->9910 9922 9405d4 GetTempFileNameW CreateFileW 9920->9922 9921->9919 9922->9910 9923 940619 WriteFile 9922->9923 9923->9910 9924 940635 CreateProcessW 9923->9924 9924->9910 9926 94069f NtQueryInformationProcess 9924->9926 9926->9910 9927 9406c3 NtReadVirtualMemory 9926->9927 9927->9910 9928 9406ea 9927->9928 9929 936de8 RtlAllocateHeap 9928->9929 9930 9406f4 9929->9930 9930->9910 9931 940758 NtProtectVirtualMemory 9930->9931 9931->9910 9932 940784 NtWriteVirtualMemory 9931->9932 9932->9910 9933 94079e 9932->9933 9933->9910 9934 940829 CreateNamedPipeW 9933->9934 9934->9910 9935 940895 ResumeThread ConnectNamedPipe 9934->9935 9935->9910 9937 93a35b 9936->9937 9938 93b3c0 2 API calls 9937->9938 9939 93a375 9937->9939 9938->9939 9939->9426 9939->9427 9941 936934 RtlAllocateHeap 9940->9941 9971 942440 9941->9971 9942 93a338 2 API calls 9942->9971 9943 93a280 NtSetInformationThread NtClose 9943->9971 9944 9425bc 9945 93686c RtlFreeHeap 9944->9945 9976 9424c6 9945->9976 9946 9424db 9948 93686c RtlFreeHeap 9946->9948 9947 9424ee 9952 93a3dc 2 API calls 9947->9952 9948->9976 9949 9424be 9953 93686c RtlFreeHeap 9949->9953 9950 9425ee 9951 936984 RtlAllocateHeap 9950->9951 9956 942647 9951->9956 9957 942501 9952->9957 9953->9976 9954 942512 9958 942570 9954->9958 9959 94257a 9954->9959 9955 9425cf 9955->9950 9960 9425e4 9955->9960 9962 93686c RtlFreeHeap 9956->9962 9957->9954 9963 942505 9957->9963 9964 936984 RtlAllocateHeap 9958->9964 9965 936a74 RtlAllocateHeap 9959->9965 9961 93686c RtlFreeHeap 9960->9961 9961->9976 9966 942650 9962->9966 9967 93686c RtlFreeHeap 9963->9967 9968 942578 9964->9968 9965->9968 9972 94096c 11 API calls 9966->9972 9966->9976 9967->9976 9970 93686c RtlFreeHeap 9968->9970 9969 93ab68 NtSetInformationThread NtClose 9969->9971 9974 94258b 9970->9974 9971->9942 9971->9943 9971->9944 9971->9946 9971->9947 9971->9949 9971->9950 9971->9954 9971->9955 9971->9969 9973 93686c RtlFreeHeap 9971->9973 9971->9976 9972->9976 9973->9971 9975 94096c 11 API calls 9974->9975 9974->9976 9975->9976 9976->9424 9979 937fd5 9977->9979 9978 93808e 9978->9698 9978->9699 9979->9978 9984 9368c0 9979->9984 9982 93686c RtlFreeHeap 9981->9982 9983 9368fb 9982->9983 9983->9695 9985 936844 RtlAllocateHeap 9984->9985 9986 9368d6 9985->9986 9986->9978 9988 937cd2 9987->9988 9989 937dda 9987->9989 9991 936844 RtlAllocateHeap 9988->9991 9990 937df7 9989->9990 9992 93686c RtlFreeHeap 9989->9992 9990->9707 9993 937d01 9991->9993 9992->9990 9993->9989 10179 93dc60 9993->10179 9996 9368c0 RtlAllocateHeap 9995->9996 9997 93b73c 9996->9997 9998 93b742 NtSetInformationProcess NtSetInformationProcess NtSetInformationProcess 9997->9998 9999 93b784 9997->9999 10000 9368ec RtlFreeHeap 9998->10000 10001 93e1e8 9999->10001 10000->9999 10003 93e1f5 10001->10003 10002 93e22a CreateThread 10002->10003 10183 93de78 SetThreadPriority 10002->10183 10003->10002 10004 93b444 NtSetInformationThread 10003->10004 10005 93e25a 10003->10005 10006 93e24b NtClose 10004->10006 10005->9720 10005->9725 10007 93a68c 10005->10007 10006->10003 10008 93a6b3 GetVolumeNameForVolumeMountPointW 10007->10008 10010 93a6f6 FindFirstVolumeW 10008->10010 10011 93a947 10010->10011 10016 93a712 10010->10016 10011->9739 10012 93a72b GetVolumePathNamesForVolumeNameW 10012->10016 10013 93a75c GetDriveTypeW 10013->10016 10014 93a7fd CreateFileW 10015 93a823 DeviceIoControl 10014->10015 10014->10016 10015->10016 10016->10011 10016->10012 10016->10013 10016->10014 10017 93a600 6 API calls 10016->10017 10017->10016 10019 940a92 10018->10019 10022 940b08 10019->10022 10024 940b63 10019->10024 10191 93b4dc CheckTokenMembership 10019->10191 10021 940b0c 10021->9752 10022->10021 10192 936984 10022->10192 10024->9752 10026 940bf9 10025->10026 10196 93a488 CreateThread 10026->10196 10028 940c0b 10029 936844 RtlAllocateHeap 10028->10029 10048 940c11 10028->10048 10031 940c23 10029->10031 10030 940e0a 10033 940e18 10030->10033 10035 93686c RtlFreeHeap 10030->10035 10034 93a488 6 API calls 10031->10034 10031->10048 10032 93686c RtlFreeHeap 10032->10030 10036 940e26 10033->10036 10038 93686c RtlFreeHeap 10033->10038 10037 940c40 10034->10037 10035->10033 10036->9725 10039 936844 RtlAllocateHeap 10037->10039 10037->10048 10038->10036 10040 940c5b 10039->10040 10041 936844 RtlAllocateHeap 10040->10041 10040->10048 10047 940c76 10041->10047 10043 936984 RtlAllocateHeap 10044 940cd2 CreateThread 10043->10044 10044->10047 10214 93f308 GetFileAttributesW 10044->10214 10045 936984 RtlAllocateHeap 10045->10047 10046 93b3c0 2 API calls 10046->10047 10047->10043 10047->10045 10047->10046 10047->10048 10204 93a1c0 CreateThread 10047->10204 10048->10030 10048->10032 10050 93fcb4 10049->10050 10051 936844 RtlAllocateHeap 10050->10051 10052 93fcc1 10051->10052 10053 93fcca 10052->10053 10376 93f82c CoInitialize 10052->10376 10055 93ffdb 10053->10055 10057 93686c RtlFreeHeap 10053->10057 10058 93ffe9 10055->10058 10060 93686c RtlFreeHeap 10055->10060 10057->10055 10061 93fff7 10058->10061 10063 93686c RtlFreeHeap 10058->10063 10059 936844 RtlAllocateHeap 10062 93fcf7 10059->10062 10060->10058 10061->9738 10062->10053 10064 936844 RtlAllocateHeap 10062->10064 10063->10061 10070 93fd12 10064->10070 10065 93f59c NtSetInformationThread NtClose 10065->10070 10067 93686c RtlFreeHeap 10067->10070 10068 93f6d8 NtSetInformationThread NtClose 10068->10070 10069 93b3c0 2 API calls 10069->10070 10070->10053 10070->10065 10070->10067 10070->10068 10070->10069 10382 9369e0 10070->10382 10386 93cedc 10071->10386 10073 93da42 10074 93db6a 10073->10074 10075 93686c RtlFreeHeap 10073->10075 10076 93db78 10074->10076 10077 93686c RtlFreeHeap 10074->10077 10075->10074 10078 93db86 10076->10078 10080 93686c RtlFreeHeap 10076->10080 10077->10076 10078->9733 10079 93da39 10079->10073 10081 936de8 RtlAllocateHeap 10079->10081 10080->10078 10082 93da8f 10081->10082 10082->10073 10083 936844 RtlAllocateHeap 10082->10083 10084 93dac5 10083->10084 10084->10073 10390 93cfcc 10084->10390 10087 93828b 10086->10087 10091 938290 10086->10091 10088 938909 10087->10088 10089 93686c RtlFreeHeap 10087->10089 10090 93686c RtlFreeHeap 10088->10090 10092 938917 10088->10092 10089->10088 10090->10092 10091->10087 10429 940e98 10091->10429 10092->9757 10094 9382ed 10094->10087 10095 936844 RtlAllocateHeap 10094->10095 10096 9383cf 10095->10096 10096->10087 10097 938401 10096->10097 10098 9383e7 10096->10098 10100 936de8 RtlAllocateHeap 10097->10100 10099 936de8 RtlAllocateHeap 10098->10099 10101 9383f1 10099->10101 10100->10101 10101->10087 10102 938434 10101->10102 10104 938448 10101->10104 10103 93686c RtlFreeHeap 10102->10103 10103->10087 10104->10087 10105 9384fb DrawTextW 10104->10105 10105->10087 10106 938523 10105->10106 10106->10087 10107 93865d CreateFileW 10106->10107 10107->10087 10108 938686 WriteFile 10107->10108 10108->10087 10109 9386a7 WriteFile 10108->10109 10109->10087 10110 9386c5 WriteFile 10109->10110 10110->10087 10111 9386e3 10110->10111 10436 936c98 10111->10436 10113 938705 10113->10087 10114 938788 RegCreateKeyExW 10113->10114 10114->10087 10115 9387b9 10114->10115 10116 9387f2 RegSetValueExW 10115->10116 10116->10087 10117 93881f 10116->10117 10118 93887e RegSetValueExW 10117->10118 10118->10087 10123 939669 10119->10123 10120 939698 10121 939735 10120->10121 10122 93686c RtlFreeHeap 10120->10122 10121->9761 10122->10121 10123->10120 10442 93c8c4 10123->10442 10127 939c96 10125->10127 10126 939c9a 10126->9709 10127->10126 10448 943954 10127->10448 10129 939e11 10138 93b674 NtQueryInformationToken 10129->10138 10145 939e20 10129->10145 10130 93a04a 10132 93a05e 10130->10132 10133 93686c RtlFreeHeap 10130->10133 10131 93686c RtlFreeHeap 10131->10130 10134 93a072 10132->10134 10135 93686c RtlFreeHeap 10132->10135 10133->10132 10136 93a086 10134->10136 10137 93686c RtlFreeHeap 10134->10137 10135->10134 10136->9709 10137->10136 10139 939ee2 10138->10139 10140 936de8 RtlAllocateHeap 10139->10140 10139->10145 10141 939f25 10140->10141 10142 936de8 RtlAllocateHeap 10141->10142 10141->10145 10143 939f45 10142->10143 10144 936de8 RtlAllocateHeap 10143->10144 10143->10145 10144->10145 10145->10130 10145->10131 10147 938971 10146->10147 10148 93b3c0 2 API calls 10147->10148 10149 938b6c 10147->10149 10148->10149 10149->9757 10151 936de8 RtlAllocateHeap 10150->10151 10152 941967 10151->10152 10164 941970 10152->10164 10451 9418b8 10152->10451 10153 941aa8 10155 941ab6 10153->10155 10158 93686c RtlFreeHeap 10153->10158 10154 93686c RtlFreeHeap 10154->10153 10156 941ac4 10155->10156 10159 93686c RtlFreeHeap 10155->10159 10167 941d28 10156->10167 10158->10155 10159->10156 10160 9419a4 10161 936934 RtlAllocateHeap 10160->10161 10160->10164 10162 9419bf 10161->10162 10163 936de8 RtlAllocateHeap 10162->10163 10162->10164 10165 941a25 10163->10165 10164->10153 10164->10154 10166 93686c RtlFreeHeap 10165->10166 10166->10164 10168 941e2c 10167->10168 10170 941e5a 10168->10170 10454 941c34 10168->10454 10171 941eeb 10170->10171 10172 93686c RtlFreeHeap 10170->10172 10173 9416ac 10171->10173 10172->10171 10174 9416c4 10173->10174 10175 936de8 RtlAllocateHeap 10174->10175 10177 9416fe 10175->10177 10176 941707 10176->9750 10177->10176 10178 93686c RtlFreeHeap 10177->10178 10178->10176 10180 93dcba 10179->10180 10181 93dcd2 10180->10181 10182 93dcbe NtTerminateProcess 10180->10182 10181->9993 10182->10181 10187 93de8f 10183->10187 10184 93dee2 10185 93def1 ReadFile 10185->10187 10186 93e0aa WriteFile 10186->10187 10187->10184 10187->10185 10187->10186 10188 93e150 NtClose 10187->10188 10189 93686c RtlFreeHeap 10187->10189 10190 93e031 WriteFile 10187->10190 10188->10187 10189->10187 10190->10187 10191->10022 10194 93699c 10192->10194 10193 9369b2 10193->10024 10194->10193 10195 936844 RtlAllocateHeap 10194->10195 10195->10193 10197 93a524 10196->10197 10198 93a4c8 10196->10198 10212 93a470 GetLogicalDriveStringsW 10196->10212 10197->10028 10199 93a4fa ResumeThread 10198->10199 10200 93b3c0 2 API calls 10198->10200 10201 93a50e GetExitCodeThread 10199->10201 10202 93a4d9 10200->10202 10201->10197 10202->10199 10203 93a4dd 10202->10203 10203->10028 10205 93a1f3 10204->10205 10206 93a24f 10204->10206 10213 93a1b0 GetDriveTypeW 10204->10213 10207 93a225 ResumeThread 10205->10207 10208 93b3c0 2 API calls 10205->10208 10206->10047 10209 93a239 GetExitCodeThread 10207->10209 10210 93a204 10208->10210 10209->10206 10210->10207 10211 93a208 10210->10211 10211->10047 10215 93f37f SetThreadPriority 10214->10215 10217 93f321 10214->10217 10220 93f38e 10215->10220 10216 93f371 10218 93686c RtlFreeHeap 10216->10218 10217->10216 10296 93a094 FindFirstFileExW 10217->10296 10221 93f379 10218->10221 10223 936844 RtlAllocateHeap 10220->10223 10228 93f3ad 10223->10228 10224 93f34b 10225 93c19c 10 API calls 10224->10225 10227 93f355 10225->10227 10231 93ef6c 14 API calls 10227->10231 10230 93686c RtlFreeHeap 10228->10230 10234 93686c RtlFreeHeap 10228->10234 10235 93f54c 10228->10235 10237 93f514 FindNextFileW 10228->10237 10240 93f1c8 RtlAllocateHeap 10228->10240 10242 93c19c 10228->10242 10261 93f164 10228->10261 10265 93ef6c 10228->10265 10232 93f3dd FindFirstFileExW 10230->10232 10233 93f36b 10231->10233 10232->10228 10234->10228 10236 93686c RtlFreeHeap 10235->10236 10238 93f56f 10236->10238 10237->10228 10239 93f52c FindClose 10237->10239 10239->10228 10240->10228 10243 93c1b8 10242->10243 10259 93c1b3 10242->10259 10299 936934 10243->10299 10246 93c1d0 GetFileAttributesW 10247 93c1e0 10246->10247 10248 93c225 10247->10248 10249 93c23e 10247->10249 10250 93c28c 5 API calls 10248->10250 10251 93c246 10249->10251 10252 93c255 GetFileAttributesW 10249->10252 10253 93c22d 10250->10253 10303 93c28c CreateFileW 10251->10303 10255 93c262 10252->10255 10256 93c26e CopyFileW 10252->10256 10258 93686c RtlFreeHeap 10253->10258 10260 93686c RtlFreeHeap 10255->10260 10257 93686c RtlFreeHeap 10256->10257 10257->10259 10258->10259 10259->10228 10260->10251 10262 93f17c 10261->10262 10263 93f192 10262->10263 10264 936844 RtlAllocateHeap 10262->10264 10263->10228 10264->10263 10266 93f155 10265->10266 10267 93ef8d 10265->10267 10266->10228 10314 93e3ac 10267->10314 10270 93f14d 10271 93686c RtlFreeHeap 10270->10271 10271->10266 10273 93efa5 10273->10270 10274 93efb9 10273->10274 10275 93efcc 10273->10275 10347 93ec00 10274->10347 10351 93ece4 10275->10351 10278 93efe7 MoveFileExW 10279 93eff9 10278->10279 10285 93efc7 10278->10285 10282 93f051 CreateFileW 10279->10282 10293 93f075 10279->10293 10280 93f034 10281 93686c RtlFreeHeap 10280->10281 10281->10279 10284 93f07a 10282->10284 10282->10293 10283 93686c RtlFreeHeap 10283->10285 10327 93ed30 10284->10327 10285->10270 10285->10278 10285->10279 10285->10280 10285->10283 10287 93ece4 RtlAllocateHeap 10285->10287 10286 93686c RtlFreeHeap 10286->10270 10287->10285 10290 93f0a3 CreateIoCompletionPort 10291 93f0ba 10290->10291 10294 93f0dc 10290->10294 10292 93686c RtlFreeHeap 10291->10292 10292->10293 10293->10270 10293->10286 10294->10293 10295 93686c RtlFreeHeap 10294->10295 10295->10293 10297 93a0e5 10296->10297 10298 93a0c5 FindClose 10296->10298 10297->10216 10297->10224 10298->10297 10300 93694a 10299->10300 10301 936961 10300->10301 10302 936844 RtlAllocateHeap 10300->10302 10301->10246 10301->10259 10302->10301 10304 93c3ed 10303->10304 10305 93c2bd 10303->10305 10304->10259 10306 93c2f5 WriteFile 10305->10306 10307 93c31a 10306->10307 10308 93c32c WriteFile 10306->10308 10307->10259 10309 93c353 10308->10309 10310 93c365 WriteFile 10308->10310 10309->10259 10311 93c38a 10310->10311 10312 93c39c WriteFile 10310->10312 10311->10259 10312->10305 10313 93c3c3 10312->10313 10313->10259 10315 93e3c5 SetFileAttributesW CreateFileW 10314->10315 10316 93e3f3 10315->10316 10318 93e40b 10315->10318 10316->10315 10316->10318 10355 93de48 10316->10355 10318->10270 10319 93e45c SetFileAttributesW CreateFileW 10318->10319 10320 93e508 10319->10320 10321 93e49c SetFilePointerEx 10319->10321 10320->10273 10321->10320 10322 93e4bb ReadFile 10321->10322 10322->10320 10323 93e4da 10322->10323 10324 93e350 RtlAllocateHeap 10323->10324 10325 93e4eb 10324->10325 10325->10320 10326 93686c RtlFreeHeap 10325->10326 10326->10320 10329 93ed60 10327->10329 10328 93ed91 10331 936844 RtlAllocateHeap 10328->10331 10329->10328 10330 93e2b8 2 API calls 10329->10330 10330->10328 10332 93ed9d 10331->10332 10339 936844 RtlAllocateHeap 10332->10339 10346 93eee4 10332->10346 10333 93ef39 10335 93ef47 10333->10335 10336 93686c RtlFreeHeap 10333->10336 10334 93686c RtlFreeHeap 10334->10333 10337 93686c RtlFreeHeap 10335->10337 10338 93ef55 10335->10338 10336->10335 10337->10338 10338->10290 10338->10293 10340 93edfa 10339->10340 10341 936844 RtlAllocateHeap 10340->10341 10340->10346 10342 93ee29 10341->10342 10343 936844 RtlAllocateHeap 10342->10343 10342->10346 10344 93eedb 10343->10344 10345 93686c RtlFreeHeap 10344->10345 10344->10346 10345->10346 10346->10333 10346->10334 10348 93ec0d 10347->10348 10349 936934 RtlAllocateHeap 10348->10349 10350 93ec19 10349->10350 10350->10285 10352 93ecf2 10351->10352 10353 936934 RtlAllocateHeap 10352->10353 10354 93ed01 10353->10354 10354->10285 10356 93de53 10355->10356 10357 93de60 10356->10357 10361 93dce4 10356->10361 10358 93de71 10357->10358 10359 93de66 Sleep 10357->10359 10358->10316 10359->10358 10364 93dd1b 10361->10364 10362 93ddf0 10363 93de3d 10362->10363 10365 93686c RtlFreeHeap 10362->10365 10363->10357 10364->10362 10366 936844 RtlAllocateHeap 10364->10366 10365->10363 10367 93dd74 10366->10367 10367->10362 10368 936894 RtlReAllocateHeap 10367->10368 10369 93dd9d 10367->10369 10368->10367 10369->10362 10371 93dc60 NtTerminateProcess 10369->10371 10372 93db90 10369->10372 10371->10369 10373 93dbb0 10372->10373 10374 93dc2d 10373->10374 10375 93dc60 NtTerminateProcess 10373->10375 10374->10369 10375->10374 10377 93fa12 10376->10377 10379 93f869 10376->10379 10377->10053 10377->10059 10378 93f8ee 10378->10377 10381 936844 RtlAllocateHeap 10378->10381 10379->10378 10380 936844 RtlAllocateHeap 10379->10380 10380->10379 10381->10378 10383 9369f9 10382->10383 10384 936844 RtlAllocateHeap 10383->10384 10385 936a19 10384->10385 10385->10070 10388 93cef8 10386->10388 10387 93cf7d 10387->10079 10388->10387 10389 936844 RtlAllocateHeap 10388->10389 10389->10387 10391 93d01f 10390->10391 10392 93d024 10390->10392 10394 93d45e 10391->10394 10395 93686c RtlFreeHeap 10391->10395 10392->10391 10393 936844 RtlAllocateHeap 10392->10393 10401 93d065 10393->10401 10396 93d46c 10394->10396 10397 93686c RtlFreeHeap 10394->10397 10395->10394 10398 93d47a 10396->10398 10399 93686c RtlFreeHeap 10396->10399 10397->10396 10400 93d488 10398->10400 10402 93686c RtlFreeHeap 10398->10402 10399->10398 10403 93d496 10400->10403 10405 93686c RtlFreeHeap 10400->10405 10401->10391 10417 93d67c 10401->10417 10402->10400 10406 93d4a4 10403->10406 10408 93686c RtlFreeHeap 10403->10408 10405->10403 10406->10073 10407 93d08e 10407->10391 10421 93d4b0 10407->10421 10408->10406 10410 93d0a1 10410->10391 10425 93d638 10410->10425 10413 936de8 RtlAllocateHeap 10414 93d0cc 10413->10414 10414->10391 10415 936844 RtlAllocateHeap 10414->10415 10416 93686c RtlFreeHeap 10414->10416 10415->10414 10416->10414 10418 93d6a7 10417->10418 10419 936844 RtlAllocateHeap 10418->10419 10420 93d7a4 10419->10420 10420->10407 10422 93d540 10421->10422 10423 936844 RtlAllocateHeap 10422->10423 10424 93d57e 10423->10424 10424->10410 10426 93d657 10425->10426 10427 936de8 RtlAllocateHeap 10426->10427 10428 93d0b4 10427->10428 10428->10391 10428->10413 10430 940edf 10429->10430 10431 940fee RegCreateKeyExW 10430->10431 10435 940f2c 10430->10435 10432 94101b RegQueryValueExW 10431->10432 10431->10435 10433 94104a 10432->10433 10434 941096 RegDeleteKeyExW 10433->10434 10433->10435 10434->10435 10435->10094 10437 936cd2 NtQueryInformationToken 10436->10437 10438 936cbb 10436->10438 10439 936ccd 10437->10439 10438->10437 10438->10439 10440 936d24 10439->10440 10441 93686c RtlFreeHeap 10439->10441 10440->10113 10441->10440 10443 93c8e5 10442->10443 10444 936844 RtlAllocateHeap 10443->10444 10445 93c8f5 10444->10445 10446 93686c RtlFreeHeap 10445->10446 10447 93c917 10445->10447 10446->10447 10447->10120 10449 936844 RtlAllocateHeap 10448->10449 10450 94396b 10449->10450 10450->10129 10452 936844 RtlAllocateHeap 10451->10452 10453 9418ce 10452->10453 10453->10160 10455 936844 RtlAllocateHeap 10454->10455 10456 941c4e 10455->10456 10456->10170 10521 9391c8 10457->10521 10459 93962d 10460 93963c 10459->10460 10538 9390bc 10459->10538 10463 9397d8 4 API calls 10462->10463 10464 938fa0 10463->10464 10465 939010 10464->10465 10466 939880 NtClose 10464->10466 10468 939035 10465->10468 10565 938ecc 10465->10565 10467 938fae 10466->10467 10467->10465 10469 938fb7 NtSetInformationThread 10467->10469 10469->10465 10471 938fcb 10469->10471 10550 938da8 10471->10550 10474 939880 NtClose 10475 938fee 10474->10475 10475->10465 10559 938be0 10475->10559 10478 9374b3 10477->10478 10479 93748b 10477->10479 10479->10478 10480 937494 GetDriveTypeW 10479->10480 10568 9374bc 10479->10568 10480->10479 10483 937861 10482->10483 10485 936de8 RtlAllocateHeap 10484->10485 10486 93c080 10485->10486 10487 93c16b 10486->10487 10489 936844 RtlAllocateHeap 10486->10489 10488 93c179 10487->10488 10490 93686c RtlFreeHeap 10487->10490 10491 93c187 10488->10491 10492 93686c RtlFreeHeap 10488->10492 10495 93c097 10489->10495 10490->10488 10493 93c195 10491->10493 10494 93686c RtlFreeHeap 10491->10494 10492->10491 10494->10493 10495->10487 10496 93686c RtlFreeHeap 10495->10496 10497 93c0c5 10496->10497 10498 936844 RtlAllocateHeap 10497->10498 10499 93c0d5 10498->10499 10499->10487 10500 936ee4 2 API calls 10499->10500 10501 93c0eb 10500->10501 10502 93686c RtlFreeHeap 10501->10502 10503 93c108 10502->10503 10628 93bf94 10503->10628 10506 93c14a 10508 93bf94 9 API calls 10506->10508 10507 93b3c0 2 API calls 10507->10506 10509 93c155 10508->10509 10510 93bf94 9 API calls 10509->10510 10511 93c160 10510->10511 10512 93bf94 9 API calls 10511->10512 10512->10487 10519 937e60 10513->10519 10514 936844 RtlAllocateHeap 10514->10519 10515 937e72 NtQuerySystemInformation 10515->10519 10516 936894 RtlReAllocateHeap 10516->10519 10517 93686c RtlFreeHeap 10517->10519 10518 93686c RtlFreeHeap 10520 937f40 Sleep 10518->10520 10519->10514 10519->10515 10519->10516 10519->10517 10519->10518 10520->10519 10522 9392a9 10521->10522 10523 93946d RegCreateKeyExW 10522->10523 10524 9394a1 RegEnumKeyW 10523->10524 10525 9394c7 RegCreateKeyExW 10523->10525 10524->10525 10529 9394cc RegCreateKeyExW 10524->10529 10528 9395e2 10525->10528 10534 9395bc RegEnumKeyW 10525->10534 10528->10459 10529->10524 10531 9394fa RegSetValueExW 10529->10531 10531->10524 10533 93951c RegSetValueExW 10531->10533 10532 9395e4 OpenEventLogW 10532->10534 10535 9395fc ClearEventLogW 10532->10535 10533->10524 10536 93953a OpenEventLogW 10533->10536 10534->10528 10534->10532 10535->10534 10536->10524 10537 939552 ClearEventLogW 10536->10537 10537->10524 10545 93903c RtlAdjustPrivilege 10538->10545 10540 939194 10541 9391b5 10540->10541 10542 9391ac CloseServiceHandle 10540->10542 10541->10460 10542->10541 10543 9390d5 10543->10540 10544 93dc60 NtTerminateProcess 10543->10544 10544->10540 10546 9397d8 4 API calls 10545->10546 10547 939074 10546->10547 10548 939880 NtClose 10547->10548 10549 939082 10547->10549 10548->10549 10549->10543 10551 9397d8 4 API calls 10550->10551 10552 938dd3 10551->10552 10553 938ec2 10552->10553 10554 938de0 OpenSCManagerW 10552->10554 10553->10465 10553->10474 10557 938df9 10554->10557 10555 938eb3 10555->10553 10558 938eb9 CloseServiceHandle 10555->10558 10556 938eaa CloseServiceHandle 10556->10555 10557->10555 10557->10556 10557->10557 10558->10553 10560 938c11 10559->10560 10561 938c4d 10560->10561 10563 936844 RtlAllocateHeap 10560->10563 10562 938d9c 10561->10562 10564 93686c RtlFreeHeap 10561->10564 10562->10465 10563->10561 10564->10562 10566 9397d8 4 API calls 10565->10566 10567 938ee5 10566->10567 10567->10468 10576 937590 10568->10576 10570 9374d4 10571 937506 FindFirstFileExW 10570->10571 10573 937580 10570->10573 10571->10573 10574 93752e 10571->10574 10572 93756c FindNextFileW 10572->10573 10572->10574 10573->10479 10574->10572 10582 93766c 10574->10582 10577 9375b0 FindFirstFileExW 10576->10577 10579 937662 10577->10579 10581 93760e FindClose 10577->10581 10579->10570 10581->10579 10583 93768e 10582->10583 10584 937822 10583->10584 10585 936844 RtlAllocateHeap 10583->10585 10584->10572 10590 9376a6 10585->10590 10586 9377fd 10587 937814 10586->10587 10588 93686c RtlFreeHeap 10586->10588 10587->10584 10589 93686c RtlFreeHeap 10587->10589 10588->10587 10589->10584 10590->10586 10591 9376de FindFirstFileExW 10590->10591 10591->10586 10597 937706 10591->10597 10592 9377e5 FindNextFileW 10592->10586 10592->10597 10593 936844 RtlAllocateHeap 10593->10597 10594 937780 GetFileAttributesW 10594->10597 10596 93686c RtlFreeHeap 10596->10597 10597->10592 10597->10593 10597->10594 10597->10596 10598 93766c 12 API calls 10597->10598 10599 936668 10597->10599 10598->10597 10600 93667e 10599->10600 10600->10600 10601 93a094 2 API calls 10600->10601 10602 936695 10601->10602 10603 9366a5 CreateFileW 10602->10603 10604 9367a5 10602->10604 10603->10604 10609 9366cd 10603->10609 10606 9367d4 NtFreeVirtualMemory 10604->10606 10608 9367f9 10604->10608 10605 9366d2 NtAllocateVirtualMemory 10607 936703 10605->10607 10605->10609 10606->10604 10607->10604 10614 936763 WriteFile 10607->10614 10610 936808 10608->10610 10611 9367ff NtClose 10608->10611 10609->10605 10609->10607 10619 936550 10610->10619 10611->10610 10614->10607 10616 93677d SetFilePointerEx 10614->10616 10615 936821 10617 936836 10615->10617 10618 93686c RtlFreeHeap 10615->10618 10616->10607 10616->10614 10617->10597 10618->10617 10620 936934 RtlAllocateHeap 10619->10620 10621 93656a 10620->10621 10622 936573 10621->10622 10623 936934 RtlAllocateHeap 10621->10623 10624 93661e DeleteFileW 10622->10624 10625 93686c RtlFreeHeap 10622->10625 10626 936582 10623->10626 10624->10615 10625->10624 10626->10622 10627 9365df MoveFileExW 10626->10627 10627->10622 10627->10626 10629 93bfb9 10628->10629 10630 936844 RtlAllocateHeap 10629->10630 10631 93c04f 10629->10631 10634 93bfcb 10630->10634 10632 93c05d 10631->10632 10633 93686c RtlFreeHeap 10631->10633 10632->10506 10632->10507 10633->10632 10634->10631 10637 93bed0 10634->10637 10642 93bc38 10634->10642 10638 936934 RtlAllocateHeap 10637->10638 10641 93beec 10638->10641 10639 93bf8a 10639->10634 10640 93686c RtlFreeHeap 10640->10639 10641->10639 10641->10640 10643 93bc60 10642->10643 10645 936844 RtlAllocateHeap 10643->10645 10655 93bc64 10643->10655 10644 93bea1 DeleteDC 10646 93beaa 10644->10646 10649 93bc8d 10645->10649 10647 93beb8 10646->10647 10648 93686c RtlFreeHeap 10646->10648 10647->10634 10648->10647 10650 93bce0 CreateDCW 10649->10650 10649->10655 10651 93bcfd 10650->10651 10650->10655 10652 93bd9e StartDocW 10651->10652 10652->10655 10656 93bdce 10652->10656 10653 93bdec 10654 93be6c EndDoc 10653->10654 10654->10655 10655->10644 10655->10646 10656->10653 10657 93be18 DrawTextA DrawTextA EndPage 10656->10657 10657->10654 10657->10656 10709 93f59c 10658->10709 10661 93f59c 2 API calls 10662 940080 10661->10662 10665 9400a8 10662->10665 10668 93f59c 2 API calls 10662->10668 10663 940313 10664 940321 10663->10664 10667 93686c RtlFreeHeap 10663->10667 10669 94032f 10664->10669 10671 93686c RtlFreeHeap 10664->10671 10670 936844 RtlAllocateHeap 10665->10670 10680 9400d1 10665->10680 10666 93686c RtlFreeHeap 10666->10663 10667->10664 10668->10665 10669->9424 10672 9400c8 10670->10672 10671->10669 10673 936844 RtlAllocateHeap 10672->10673 10672->10680 10674 9400e3 10673->10674 10675 93e1e8 9 API calls 10674->10675 10674->10680 10683 9400f6 10675->10683 10676 9369e0 RtlAllocateHeap 10676->10683 10677 94028d 10678 93686c RtlFreeHeap 10677->10678 10677->10680 10678->10680 10679 93f6d8 NtSetInformationThread NtClose 10679->10683 10680->10663 10680->10666 10681 93b3c0 2 API calls 10681->10683 10682 93686c RtlFreeHeap 10682->10683 10683->10676 10683->10677 10683->10679 10683->10681 10683->10682 10685 937433 10684->10685 10686 936934 RtlAllocateHeap 10685->10686 10687 937441 10686->10687 10688 937464 10687->10688 10689 93686c RtlFreeHeap 10687->10689 10688->9784 10689->10688 10691 93a983 10690->10691 10692 93a488 6 API calls 10691->10692 10694 93a99a 10692->10694 10693 93a9c9 10693->9784 10694->10693 10695 936844 RtlAllocateHeap 10694->10695 10695->10693 10697 93a3ff 10696->10697 10698 93a419 10697->10698 10699 93b3c0 2 API calls 10697->10699 10698->9801 10698->9802 10699->10698 10701 936a8d 10700->10701 10702 936844 RtlAllocateHeap 10701->10702 10703 936aa3 10701->10703 10702->10703 10703->9803 10705 93e1e8 9 API calls 10704->10705 10706 940977 10705->10706 10707 93b3c0 2 API calls 10706->10707 10708 9409c8 10706->10708 10707->10708 10708->9804 10711 93f5f6 10709->10711 10710 93f610 10710->10661 10710->10665 10711->10710 10712 93b3c0 2 API calls 10711->10712 10712->10710 10713->9832 10715 940e8d 10714->10715 10716 940e48 10714->10716 10715->9827 10720 941400 10715->10720 10717 93c8c4 2 API calls 10716->10717 10718 940e4d 10717->10718 10718->10715 10719 93686c RtlFreeHeap 10718->10719 10719->10715 10772 941240 10720->10772 10722 941441 10723 936de8 RtlAllocateHeap 10722->10723 10748 941445 10722->10748 10731 941454 10723->10731 10724 9415e0 10726 9415ee 10724->10726 10727 93686c RtlFreeHeap 10724->10727 10725 93686c RtlFreeHeap 10725->10724 10728 9415fc 10726->10728 10729 93686c RtlFreeHeap 10726->10729 10727->10726 10730 94160a 10728->10730 10732 93686c RtlFreeHeap 10728->10732 10729->10728 10730->9827 10749 941760 10730->10749 10731->10748 10794 941611 10731->10794 10732->10730 10735 936de8 RtlAllocateHeap 10736 94149b 10735->10736 10737 941611 RtlFreeHeap 10736->10737 10736->10748 10738 9414d4 10737->10738 10739 936de8 RtlAllocateHeap 10738->10739 10740 9414de 10739->10740 10741 941611 RtlFreeHeap 10740->10741 10740->10748 10742 941521 10741->10742 10743 936de8 RtlAllocateHeap 10742->10743 10744 94152b 10743->10744 10745 941611 RtlFreeHeap 10744->10745 10744->10748 10746 94156b 10745->10746 10747 936de8 RtlAllocateHeap 10746->10747 10747->10748 10748->10724 10748->10725 10750 936de8 RtlAllocateHeap 10749->10750 10754 941791 10750->10754 10751 941890 10753 94189e 10751->10753 10755 93686c RtlFreeHeap 10751->10755 10752 93686c RtlFreeHeap 10752->10751 10753->9827 10753->9839 10756 9418b8 RtlAllocateHeap 10754->10756 10758 94179a 10754->10758 10755->10753 10757 9417ce 10756->10757 10757->10758 10759 936de8 RtlAllocateHeap 10757->10759 10758->10751 10758->10752 10760 941809 10759->10760 10761 93686c RtlFreeHeap 10760->10761 10761->10758 10763 941190 10762->10763 10764 936de8 RtlAllocateHeap 10763->10764 10771 941195 10763->10771 10769 9411a1 10764->10769 10765 941219 10767 941227 10765->10767 10768 93686c RtlFreeHeap 10765->10768 10766 93686c RtlFreeHeap 10766->10765 10767->9843 10768->10767 10770 936de8 RtlAllocateHeap 10769->10770 10769->10771 10770->10771 10771->10765 10771->10766 10773 94126f 10772->10773 10775 941282 10772->10775 10774 936de8 RtlAllocateHeap 10773->10774 10773->10775 10776 94128d 10774->10776 10786 94130f 10775->10786 10798 9410cc 10775->10798 10776->10775 10777 936de8 RtlAllocateHeap 10776->10777 10778 9412a5 10777->10778 10778->10775 10780 9412b4 10778->10780 10783 936de8 RtlAllocateHeap 10780->10783 10781 941336 10782 936934 RtlAllocateHeap 10781->10782 10784 941345 10782->10784 10785 9412bd 10783->10785 10784->10786 10787 936934 RtlAllocateHeap 10784->10787 10785->10722 10786->10722 10788 941377 10787->10788 10788->10786 10789 9413bd 10788->10789 10790 93686c RtlFreeHeap 10788->10790 10791 9413cb 10789->10791 10792 93686c RtlFreeHeap 10789->10792 10790->10789 10791->10786 10793 93686c RtlFreeHeap 10791->10793 10792->10791 10793->10786 10795 941491 10794->10795 10796 941617 10794->10796 10795->10735 10797 93686c RtlFreeHeap 10796->10797 10797->10795 10799 936844 RtlAllocateHeap 10798->10799 10800 9410e2 10799->10800 10800->10781 10802 941bef 10801->10802 10805 941b50 10802->10805 10804 941c07 10804->9849 10806 936844 RtlAllocateHeap 10805->10806 10807 941b67 10806->10807 10808 941b9d 10807->10808 10809 936894 RtlReAllocateHeap 10807->10809 10811 941b80 10807->10811 10810 93686c RtlFreeHeap 10808->10810 10809->10807 10810->10811 10811->10804 10812 93686c RtlFreeHeap 10811->10812 10813 941be0 10812->10813 10813->10804 10817 9464b6 10814->10817 10815 9465f0 10815->9863 10816 93686c RtlFreeHeap 10816->10815 10831 9464ce 10817->10831 10866 946124 10817->10866 10831->10815 10831->10816 10833 943fa4 10832->10833 10835 943fd5 10833->10835 11127 943d98 10833->11127 10836 944066 10835->10836 10837 93686c RtlFreeHeap 10835->10837 10836->9859 10838 944508 10836->10838 10837->10836 10839 94452e 10838->10839 10857 944532 10839->10857 11130 942af8 10839->11130 10841 944684 10844 944692 10841->10844 10846 93686c RtlFreeHeap 10841->10846 10843 93686c RtlFreeHeap 10843->10841 10847 9446a0 10844->10847 10849 93686c RtlFreeHeap 10844->10849 10845 936844 RtlAllocateHeap 10848 944553 10845->10848 10846->10844 10847->9869 10858 9446a8 10847->10858 10850 939640 2 API calls 10848->10850 10848->10857 10849->10847 10851 944566 10850->10851 10852 93f82c 2 API calls 10851->10852 10853 94457f 10852->10853 10854 936844 RtlAllocateHeap 10853->10854 10853->10857 10855 94459d 10854->10855 10856 936844 RtlAllocateHeap 10855->10856 10855->10857 10856->10857 10857->10841 10857->10843 10859 9446b9 10858->10859 10860 9448ba 10859->10860 10861 939640 2 API calls 10859->10861 10860->9869 10862 9446c7 10861->10862 10862->10860 10863 936de8 RtlAllocateHeap 10862->10863 10864 9446e1 10863->10864 10864->10860 10865 93686c RtlFreeHeap 10864->10865 10865->10860 11098 9460a8 10866->11098 10868 94616c 10869 946450 10868->10869 10870 93686c RtlFreeHeap 10868->10870 10871 94645e 10869->10871 10873 93686c RtlFreeHeap 10869->10873 10870->10869 10874 94646c 10871->10874 10876 93686c RtlFreeHeap 10871->10876 10873->10871 10875 94647a 10874->10875 10877 93686c RtlFreeHeap 10874->10877 10878 946488 10875->10878 10880 93686c RtlFreeHeap 10875->10880 10876->10874 10877->10875 10878->10831 10889 945d28 10878->10889 10879 936844 RtlAllocateHeap 10881 9461a8 10879->10881 10880->10878 10881->10868 10882 936844 RtlAllocateHeap 10881->10882 10883 946249 10882->10883 10883->10868 10884 936844 RtlAllocateHeap 10883->10884 10885 946299 10884->10885 10885->10868 10886 936844 RtlAllocateHeap 10885->10886 10887 946344 10886->10887 10887->10868 10888 93686c RtlFreeHeap 10887->10888 10888->10868 10890 945d8f 10889->10890 10891 936de8 RtlAllocateHeap 10890->10891 10892 945da4 10890->10892 10897 945e1b 10891->10897 10893 94608f 10892->10893 10894 93686c RtlFreeHeap 10892->10894 10895 94609d 10893->10895 10896 93686c RtlFreeHeap 10893->10896 10894->10893 10895->10831 10899 944c60 10895->10899 10896->10895 10897->10892 10898 936de8 RtlAllocateHeap 10897->10898 10898->10892 10900 936844 RtlAllocateHeap 10899->10900 10902 944c93 10900->10902 10901 944e1b 10904 944e29 10901->10904 10906 93686c RtlFreeHeap 10901->10906 10905 936844 RtlAllocateHeap 10902->10905 10911 944c9c 10902->10911 10903 93686c RtlFreeHeap 10903->10901 10907 944e37 10904->10907 10908 93686c RtlFreeHeap 10904->10908 10909 944cc6 10905->10909 10906->10904 10907->10831 10912 945a84 10907->10912 10908->10907 10910 936844 RtlAllocateHeap 10909->10910 10909->10911 10910->10911 10911->10901 10911->10903 10913 936844 RtlAllocateHeap 10912->10913 10915 945add 10913->10915 10914 945caa 10917 945cb8 10914->10917 10919 93686c RtlFreeHeap 10914->10919 10949 945ae6 10915->10949 11104 94497c 10915->11104 10916 93686c RtlFreeHeap 10916->10914 10920 945cc6 10917->10920 10921 93686c RtlFreeHeap 10917->10921 10919->10917 10922 945cd4 10920->10922 10923 93686c RtlFreeHeap 10920->10923 10921->10920 10924 945ce2 10922->10924 10925 93686c RtlFreeHeap 10922->10925 10923->10922 10926 945cf0 10924->10926 10927 93686c RtlFreeHeap 10924->10927 10925->10924 10928 945cfe 10926->10928 10929 93686c RtlFreeHeap 10926->10929 10927->10926 10930 945d0c 10928->10930 10932 93686c RtlFreeHeap 10928->10932 10929->10928 10930->10831 10951 9457b4 10930->10951 10931 945b0e 10931->10949 11107 944a30 10931->11107 10932->10930 10934 945b3a 10935 93686c RtlFreeHeap 10934->10935 10934->10949 10936 945b5c 10935->10936 10937 944a30 RtlAllocateHeap 10936->10937 10938 945b75 10937->10938 10938->10949 11110 944aa8 10938->11110 10940 945bbd 10940->10949 11113 944c08 10940->11113 10943 936844 RtlAllocateHeap 10944 945bf2 10943->10944 10945 936de8 RtlAllocateHeap 10944->10945 10944->10949 10946 945c0a 10945->10946 10947 936844 RtlAllocateHeap 10946->10947 10946->10949 10948 945c33 10947->10948 10948->10949 10950 93686c RtlFreeHeap 10948->10950 10949->10914 10949->10916 10950->10948 10952 936844 RtlAllocateHeap 10951->10952 10953 9457fc 10952->10953 10954 936844 RtlAllocateHeap 10953->10954 10975 945805 10953->10975 10965 945814 10954->10965 10955 945a22 10957 945a30 10955->10957 10958 93686c RtlFreeHeap 10955->10958 10956 93686c RtlFreeHeap 10956->10955 10959 945a3e 10957->10959 10960 93686c RtlFreeHeap 10957->10960 10958->10957 10961 945a4c 10959->10961 10962 93686c RtlFreeHeap 10959->10962 10960->10959 10963 945a5a 10961->10963 10964 93686c RtlFreeHeap 10961->10964 10962->10961 10963->10831 10976 944e50 10963->10976 10964->10963 10966 936844 RtlAllocateHeap 10965->10966 10965->10975 10967 945943 10966->10967 10968 936de8 RtlAllocateHeap 10967->10968 10967->10975 10969 94595b 10968->10969 10970 93686c RtlFreeHeap 10969->10970 10969->10975 10971 9459a4 10970->10971 10972 936844 RtlAllocateHeap 10971->10972 10973 9459bd 10972->10973 10974 936de8 RtlAllocateHeap 10973->10974 10973->10975 10974->10975 10975->10955 10975->10956 10977 936844 RtlAllocateHeap 10976->10977 10979 944e98 10977->10979 10978 945065 10981 945073 10978->10981 10983 93686c RtlFreeHeap 10978->10983 10982 94497c RtlAllocateHeap 10979->10982 11012 944ea1 10979->11012 10980 93686c RtlFreeHeap 10980->10978 10984 945081 10981->10984 10985 93686c RtlFreeHeap 10981->10985 10995 944ec9 10982->10995 10983->10981 10986 94508f 10984->10986 10988 93686c RtlFreeHeap 10984->10988 10985->10984 10987 94509d 10986->10987 10989 93686c RtlFreeHeap 10986->10989 10990 9450ab 10987->10990 10991 93686c RtlFreeHeap 10987->10991 10988->10986 10989->10987 10992 9450b9 10990->10992 10993 93686c RtlFreeHeap 10990->10993 10991->10990 10994 9450c7 10992->10994 10996 93686c RtlFreeHeap 10992->10996 10993->10992 10994->10831 11015 9450e0 10994->11015 10995->11012 11118 944920 10995->11118 10996->10994 10998 944ef5 10999 93686c RtlFreeHeap 10998->10999 10998->11012 11000 944f17 10999->11000 11001 944920 RtlAllocateHeap 11000->11001 11002 944f30 11001->11002 11003 944aa8 RtlAllocateHeap 11002->11003 11002->11012 11004 944f78 11003->11004 11005 944c08 RtlAllocateHeap 11004->11005 11004->11012 11006 944f8d 11005->11006 11007 936844 RtlAllocateHeap 11006->11007 11006->11012 11008 944fad 11007->11008 11009 936de8 RtlAllocateHeap 11008->11009 11008->11012 11010 944fc5 11009->11010 11011 936844 RtlAllocateHeap 11010->11011 11010->11012 11013 944fee 11011->11013 11012->10978 11012->10980 11013->11012 11014 93686c RtlFreeHeap 11013->11014 11014->11013 11016 936844 RtlAllocateHeap 11015->11016 11025 945143 11016->11025 11017 94571b 11019 945729 11017->11019 11020 93686c RtlFreeHeap 11017->11020 11018 93686c RtlFreeHeap 11018->11017 11021 945737 11019->11021 11022 93686c RtlFreeHeap 11019->11022 11020->11019 11023 945745 11021->11023 11026 93686c RtlFreeHeap 11021->11026 11022->11021 11024 945753 11023->11024 11027 93686c RtlFreeHeap 11023->11027 11028 945761 11024->11028 11029 93686c RtlFreeHeap 11024->11029 11038 936844 RtlAllocateHeap 11025->11038 11054 94514c 11025->11054 11026->11023 11027->11024 11030 94576f 11028->11030 11031 93686c RtlFreeHeap 11028->11031 11029->11028 11032 94577d 11030->11032 11033 93686c RtlFreeHeap 11030->11033 11031->11030 11034 94578b 11032->11034 11035 93686c RtlFreeHeap 11032->11035 11033->11032 11036 945799 11034->11036 11037 93686c RtlFreeHeap 11034->11037 11035->11034 11036->10831 11037->11036 11039 9451ff 11038->11039 11040 94497c RtlAllocateHeap 11039->11040 11039->11054 11041 945230 11040->11041 11041->11054 11121 9448c4 11041->11121 11043 94525c 11044 93686c RtlFreeHeap 11043->11044 11043->11054 11045 94527e 11044->11045 11046 9448c4 RtlAllocateHeap 11045->11046 11047 945297 11046->11047 11048 944aa8 RtlAllocateHeap 11047->11048 11047->11054 11049 9452df 11048->11049 11050 944c08 RtlAllocateHeap 11049->11050 11049->11054 11051 9452f4 11050->11051 11052 936844 RtlAllocateHeap 11051->11052 11051->11054 11053 94533d 11052->11053 11053->11054 11055 936de8 RtlAllocateHeap 11053->11055 11054->11017 11054->11018 11056 945355 11055->11056 11056->11054 11057 936844 RtlAllocateHeap 11056->11057 11058 945381 11057->11058 11058->11054 11059 93686c RtlFreeHeap 11058->11059 11060 945427 11059->11060 11061 945435 11060->11061 11062 93686c RtlFreeHeap 11060->11062 11063 94544a 11061->11063 11064 93686c RtlFreeHeap 11061->11064 11062->11061 11065 94545f 11063->11065 11066 93686c RtlFreeHeap 11063->11066 11064->11063 11067 945474 11065->11067 11068 93686c RtlFreeHeap 11065->11068 11066->11065 11069 945489 11067->11069 11070 93686c RtlFreeHeap 11067->11070 11068->11067 11071 94549e 11069->11071 11072 93686c RtlFreeHeap 11069->11072 11070->11069 11073 9454b3 11071->11073 11074 93686c RtlFreeHeap 11071->11074 11072->11071 11075 9454c8 11073->11075 11076 93686c RtlFreeHeap 11073->11076 11074->11073 11077 936844 RtlAllocateHeap 11075->11077 11076->11075 11078 9454ef 11077->11078 11078->11054 11079 94497c RtlAllocateHeap 11078->11079 11080 945520 11079->11080 11080->11054 11124 9449c0 11080->11124 11082 94554c 11082->11054 11083 93686c RtlFreeHeap 11082->11083 11084 945579 11083->11084 11085 9449c0 RtlAllocateHeap 11084->11085 11086 945587 11085->11086 11086->11054 11087 944aa8 RtlAllocateHeap 11086->11087 11088 9455cf 11087->11088 11088->11054 11089 944c08 RtlAllocateHeap 11088->11089 11090 9455e4 11089->11090 11090->11054 11091 936844 RtlAllocateHeap 11090->11091 11092 94565b 11091->11092 11092->11054 11093 936de8 RtlAllocateHeap 11092->11093 11094 945673 11093->11094 11094->11054 11095 936844 RtlAllocateHeap 11094->11095 11096 94569c 11095->11096 11096->11054 11097 93686c RtlFreeHeap 11096->11097 11097->11054 11099 9460c8 11098->11099 11100 946108 11099->11100 11101 936934 RtlAllocateHeap 11099->11101 11100->10868 11100->10879 11102 9460f1 11101->11102 11102->11100 11103 936934 RtlAllocateHeap 11102->11103 11103->11100 11105 936844 RtlAllocateHeap 11104->11105 11106 944985 11105->11106 11106->10931 11108 936844 RtlAllocateHeap 11107->11108 11109 944a3c 11108->11109 11109->10934 11111 936844 RtlAllocateHeap 11110->11111 11112 944ab8 11111->11112 11112->10940 11114 936844 RtlAllocateHeap 11113->11114 11116 944c27 11114->11116 11115 936844 RtlAllocateHeap 11115->11116 11116->11115 11117 944c54 11116->11117 11117->10943 11117->10949 11119 936844 RtlAllocateHeap 11118->11119 11120 94492c 11119->11120 11120->10998 11122 936844 RtlAllocateHeap 11121->11122 11123 9448d0 11122->11123 11123->11043 11125 936844 RtlAllocateHeap 11124->11125 11126 9449cc 11125->11126 11126->11082 11128 936844 RtlAllocateHeap 11127->11128 11129 943db2 11128->11129 11129->10835 11133 942b21 11130->11133 11131 942b25 11131->10845 11133->11131 11134 942954 11133->11134 11135 94297b 11134->11135 11136 9397d8 4 API calls 11135->11136 11137 94298b 11136->11137 11138 9397d8 4 API calls 11137->11138 11139 94299f 11137->11139 11138->11139 11139->11131 11142 9466b6 11140->11142 11141 946714 11143 946ba4 11141->11143 11144 93686c RtlFreeHeap 11141->11144 11142->11141 11147 936de8 RtlAllocateHeap 11142->11147 11145 946bb2 11143->11145 11146 93686c RtlFreeHeap 11143->11146 11144->11143 11145->9879 11146->11145 11148 9467ec 11147->11148 11148->11141 11149 936844 RtlAllocateHeap 11148->11149 11149->11141 11151 9437a7 11150->11151 11152 942af8 4 API calls 11151->11152 11167 9437ab 11151->11167 11153 9437c2 11152->11153 11155 936844 RtlAllocateHeap 11153->11155 11154 9438e9 11157 9438f7 11154->11157 11159 93686c RtlFreeHeap 11154->11159 11158 9437cc 11155->11158 11156 93686c RtlFreeHeap 11156->11154 11160 943905 11157->11160 11161 93686c RtlFreeHeap 11157->11161 11162 93f82c 2 API calls 11158->11162 11158->11167 11159->11157 11160->9886 11161->11160 11163 9437e4 11162->11163 11164 936844 RtlAllocateHeap 11163->11164 11163->11167 11165 943802 11164->11165 11166 936844 RtlAllocateHeap 11165->11166 11165->11167 11166->11167 11167->11154 11167->11156 11169 940350 11168->11169 11170 936844 RtlAllocateHeap 11169->11170 11171 940371 11170->11171 11171->9920 11470 93ac68 11471 93ac50 11470->11471 11472 93ac83 11471->11472 11473 936894 RtlReAllocateHeap 11471->11473 11475 93ac66 11471->11475 11474 93686c RtlFreeHeap 11472->11474 11473->11471 11474->11475 11476 93686c RtlFreeHeap 11475->11476 11477 93adb0 11476->11477 11678 943168 11680 94317f 11678->11680 11679 9431ce 11680->11679 11681 942af8 4 API calls 11680->11681 11681->11679

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 9 9404b4-940569 call 93164c call 936de8 18 940570-940589 call 936844 9->18 19 94056b 9->19 27 940590-9405a3 call 948c34 18->27 28 94058b 18->28 20 9408e9-9408f0 19->20 22 9408f2 20->22 23 9408fe-940905 20->23 22->23 25 940907 23->25 26 940913-940917 23->26 25->26 30 940922-940926 26->30 31 940919 26->31 37 9405a5 27->37 38 9405aa-9405ba call 940338 27->38 28->20 33 940930-940934 30->33 34 940928-94092b call 93686c 30->34 31->30 35 940936-940939 call 93686c 33->35 36 94093e-940942 33->36 34->33 35->36 41 940944-940947 call 93686c 36->41 42 94094c-940950 36->42 37->20 49 9405c1-940612 GetTempFileNameW CreateFileW 38->49 50 9405bc 38->50 41->42 45 940952-940955 call 93686c 42->45 46 94095a-940960 42->46 45->46 52 940614 49->52 53 940619-94062e WriteFile 49->53 50->20 52->20 54 940635-94064e 53->54 55 940630 53->55 57 940650-940655 54->57 55->20 58 940657-940698 CreateProcessW 57->58 59 940659-94065b 57->59 61 94069f-9406bc NtQueryInformationProcess 58->61 62 94069a 58->62 59->57 63 9406c3-9406e3 NtReadVirtualMemory 61->63 64 9406be 61->64 62->20 65 9406e5 63->65 66 9406ea-9406fb call 936de8 63->66 64->20 65->20 69 940702-94077d call 9492f4 call 949348 call 94941c NtProtectVirtualMemory 66->69 70 9406fd 66->70 77 940784-940797 NtWriteVirtualMemory 69->77 78 94077f 69->78 70->20 79 94079e-9407fa 77->79 80 940799 77->80 78->20 82 940801-940822 79->82 83 9407fc 79->83 80->20 85 940824 82->85 86 940829-940891 CreateNamedPipeW 82->86 83->20 85->20 87 940895-9408ae ResumeThread ConnectNamedPipe 86->87 88 940893 86->88 89 9408b0-9408bb 87->89 90 9408bf-9408dc 87->90 88->20 89->90 91 9408bd 89->91 93 9408e0 90->93 94 9408de 90->94 91->20 93->20 94->20
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID: D
                                          • API String ID: 0-2746444292
                                          • Opcode ID: 95a0d12d71aa5f9bfc828e95036746133d15b20fd385be4cee82b104e609a4b1
                                          • Instruction ID: cddb3176ce8e3e602fcc6783aeaadccd98f58be2535b1379ad0f42fc75264ebf
                                          • Opcode Fuzzy Hash: 95a0d12d71aa5f9bfc828e95036746133d15b20fd385be4cee82b104e609a4b1
                                          • Instruction Fuzzy Hash: 9DE12871900318EFEF209F91DC49FEEBBB9FB48305F1040A5E209A61A1D7769A85DF91
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 233 9391c8-93949b call 931240 * 5 RegCreateKeyExW 244 9394a1 233->244 245 93957d-939581 233->245 246 9394a8-9394c5 RegEnumKeyW 244->246 247 939583 245->247 248 93958c-9395ba RegCreateKeyExW 245->248 251 9394c7 246->251 252 9394cc-9394f8 RegCreateKeyExW 246->252 247->248 249 939615-939619 248->249 250 9395bc 248->250 256 939624-939627 249->256 257 93961b 249->257 253 9395c3-9395e0 RegEnumKeyW 250->253 251->245 254 939575-939578 252->254 255 9394fa-93951a RegSetValueExW 252->255 258 9395e2 253->258 259 9395e4-9395fa OpenEventLogW 253->259 254->246 260 939566-93956a 255->260 261 93951c-939538 RegSetValueExW 255->261 257->256 258->249 262 939610-939613 259->262 263 9395fc-939607 ClearEventLogW 259->263 260->254 265 93956c 260->265 261->260 264 93953a-939550 OpenEventLogW 261->264 262->253 263->262 264->260 266 939552-93955d ClearEventLogW 264->266 265->254 266->260
                                          APIs
                                          • RegCreateKeyExW.KERNELBASE(80000002,?,00000000,00000000,00000000,0002011F,00000000,00000000,00000000,?,00000007,?,00000004,?,00000019,?), ref: 00939493
                                          • RegEnumKeyW.ADVAPI32(00000000,00000000,?,00000104), ref: 009394BA
                                          • RegCreateKeyExW.KERNELBASE(00000000,?,00000000,00000000,00000000,0002011F,00000000,00000000,00000000), ref: 009394F0
                                          • RegSetValueExW.KERNELBASE(00000000,?,00000000,00000004,00000000,00000004), ref: 00939512
                                          • RegSetValueExW.KERNELBASE(00000000,?,00000000,00000001,?,00000064), ref: 00939530
                                          • OpenEventLogW.ADVAPI32(00000000,?), ref: 00939543
                                          • ClearEventLogW.ADVAPI32(00000000,00000000), ref: 00939557
                                          • RegCreateKeyExW.KERNELBASE(80000002,?,00000000,00000000,00000000,0002011F,00000000,00000000,00000000), ref: 009395B2
                                          • RegEnumKeyW.ADVAPI32(00000000,00000000,?,00000104), ref: 009395D5
                                          • OpenEventLogW.ADVAPI32(00000000,?), ref: 009395ED
                                          • ClearEventLogW.ADVAPI32(00000000,00000000), ref: 00939601
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Event$Create$ClearEnumOpenValue
                                          • String ID:
                                          • API String ID: 1260815474-0
                                          • Opcode ID: ff4a5d3af619dc98fe3c102c82b8881469e62eec3676985c4bb90923dc996d8c
                                          • Instruction ID: 0e9e4ef8a911a0adc3113d7aa9e3a3d3f4a5e64e33f13e23e5dca9efbe436ff8
                                          • Opcode Fuzzy Hash: ff4a5d3af619dc98fe3c102c82b8881469e62eec3676985c4bb90923dc996d8c
                                          • Instruction Fuzzy Hash: 71C105B8851306EFDB208F51D845B997B78FF04744F528088E6145F2B2D7BA9A84CF56
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 267 93a68c-93a70c GetVolumeNameForVolumeMountPointW FindFirstVolumeW 271 93a712-93a718 267->271 272 93a950-93a955 267->272 273 93a91f-93a941 271->273 274 93a71e-93a725 271->274 273->271 283 93a947 273->283 274->273 275 93a72b-93a742 GetVolumePathNamesForVolumeNameW 274->275 275->273 276 93a748-93a74c 275->276 276->273 278 93a752-93a756 276->278 278->273 279 93a75c-93a766 GetDriveTypeW 278->279 281 93a771-93a779 call 931564 279->281 282 93a768-93a76b 279->282 286 93a7f7-93a81d call 9316f0 CreateFileW 281->286 287 93a77b-93a7c3 281->287 282->273 282->281 283->272 291 93a823-93a849 DeviceIoControl 286->291 292 93a916 286->292 297 93a7e3-93a7e7 287->297 298 93a7c5-93a7de call 93a600 287->298 291->292 293 93a84f-93a856 291->293 292->273 295 93a858-93a864 293->295 296 93a8bc-93a8c3 293->296 302 93a883-93a889 295->302 303 93a866-93a86d 295->303 296->292 301 93a8c5-93a8cc 296->301 299 93a7f2 297->299 300 93a7e9 297->300 298->297 299->273 300->299 301->292 307 93a8ce-93a8d5 301->307 305 93a88b-93a892 302->305 306 93a8a8-93a8b5 call 9316c0 call 93a600 302->306 303->302 308 93a86f-93a876 303->308 305->306 310 93a894-93a89b 305->310 318 93a8ba 306->318 307->292 312 93a8d7-93a8f1 call 9316c0 307->312 308->302 313 93a878-93a87f 308->313 310->306 314 93a89d-93a8a4 310->314 323 93a8f3-93a8fa 312->323 324 93a90a-93a911 call 93a600 312->324 313->302 317 93a881 313->317 314->306 319 93a8a6 314->319 317->318 318->292 319->318 325 93a908 323->325 326 93a8fc-93a903 call 93a600 323->326 324->292 325->292 326->325
                                          APIs
                                          • GetVolumeNameForVolumeMountPointW.KERNELBASE(?,?,00000104), ref: 0093A6D6
                                          • FindFirstVolumeW.KERNELBASE(?,00000104), ref: 0093A6FF
                                          • GetVolumePathNamesForVolumeNameW.KERNELBASE(?,?,00000040,00000000), ref: 0093A73A
                                          • GetDriveTypeW.KERNELBASE(?), ref: 0093A75D
                                          • CreateFileW.KERNELBASE(?,80000000,00000003,00000000,00000003,00000080,00000000,?), ref: 0093A810
                                          • DeviceIoControl.KERNELBASE(000000FF,00070048,00000000,00000000,?,00000090,00000001,00000000), ref: 0093A841
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Volume$Name$ControlCreateDeviceDriveFileFindFirstMountNamesPathPointType
                                          • String ID: '
                                          • API String ID: 754975672-1997036262
                                          • Opcode ID: f6310f7aa9a7ceb72e9124f9bf6a76113100b1c5ac328a9df277ce27a91c724b
                                          • Instruction ID: 3da5e4a155914855fd6eac4fedd98bc01bbb313630b1bdde84e7815f38c63dd6
                                          • Opcode Fuzzy Hash: f6310f7aa9a7ceb72e9124f9bf6a76113100b1c5ac328a9df277ce27a91c724b
                                          • Instruction Fuzzy Hash: 8A71AC30804B18EFDB319F51DC09B9A7BBCEF01326F168095F285B60A2D7745A85DF66
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 329 93c3f8-93c412 330 93c64b-93c654 329->330 331 93c418-93c42d call 936de8 329->331 331->330 334 93c433-93c449 call 936844 331->334 337 93c645-93c646 call 93686c 334->337 338 93c44f-93c460 call 948c34 334->338 337->330 342 93c466-93c4e7 call 9316c0 CreateFileW 338->342 343 93c63f-93c640 call 93686c 338->343 342->343 349 93c4ed-93c502 WriteFile 342->349 343->337 350 93c636 349->350 351 93c508-93c52b RegCreateKeyExW 349->351 350->343 351->350 352 93c531-93c55d RegSetValueExW 351->352 354 93c563-93c5dc RegCreateKeyExW 352->354 355 93c62d-93c630 NtClose 352->355 354->355 358 93c5de-93c610 RegSetValueExW 354->358 355->350 358->355 360 93c612-93c626 SHChangeNotify 358->360 360->355
                                          APIs
                                            • Part of subcall function 00936844: RtlAllocateHeap.NTDLL(?,00000008,00000000,?,00947764,?,00000000,00000000), ref: 00936860
                                          • CreateFileW.KERNELBASE(?,40000000,00000000,00000000,00000002,00000080,00000000), ref: 0093C4DA
                                          • WriteFile.KERNELBASE(000000FF,00000000,000000FF,?,00000000), ref: 0093C4FA
                                          • RegCreateKeyExW.KERNELBASE(80000000,?,00000000,00000000,00000000,00020106,00000000,?,00000000), ref: 0093C523
                                          • RegSetValueExW.KERNELBASE(?,00000000,00000000,00000001,?,00000000), ref: 0093C555
                                          • RegCreateKeyExW.KERNELBASE(80000000,?,00000000,00000000,00000000,00020106,00000000,?,00000000), ref: 0093C5D4
                                          • RegSetValueExW.KERNELBASE(?,00000000,00000000,00000001,?,00000000), ref: 0093C608
                                          • SHChangeNotify.SHELL32(08000000,00001000,00000000,00000000), ref: 0093C620
                                          • NtClose.NTDLL(?), ref: 0093C630
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Create$FileValue$AllocateChangeCloseHeapNotifyWrite
                                          • String ID:
                                          • API String ID: 1108940941-0
                                          • Opcode ID: 5581b570d4ef1ca400e4fb90c0c358d8633a03e824eb52d079bdd29d9318ce30
                                          • Instruction ID: 5cee44131a80313586fe71c0711c5208f4a7a35a7719c2d9c0b0de804a123406
                                          • Opcode Fuzzy Hash: 5581b570d4ef1ca400e4fb90c0c358d8633a03e824eb52d079bdd29d9318ce30
                                          • Instruction Fuzzy Hash: D05180B1A14709BBEB209FA1DC4AFAE7BBCFB04705F504114F604AA0E1D7B1AA54DF94
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 361 947034-947053 363 947111-947118 361->363 364 947059-947060 361->364 367 947145-94717c CreateThread * 2 363->367 368 94711a-947133 CreateThread 363->368 365 947062-947088 call 936ae8 364->365 366 94708b-947092 364->366 365->366 372 947094-94709b 366->372 373 9470ce-9470d5 366->373 370 947183-94718a 367->370 371 94717e call 937ca4 367->371 368->367 369 947135-94713e 368->369 369->367 377 9471a4-9471ab 370->377 378 94718c-9471a1 CreateThread 370->378 371->370 372->373 374 94709d-9470c7 call 939c64 372->374 373->363 376 9470d7-9470de 373->376 374->373 376->363 382 9470e0-94710a call 939c64 376->382 383 9471b6-9471dd call 93b734 call 93e1e8 377->383 384 9471ad-9471b4 377->384 378->377 382->363 410 947221-947225 383->410 411 9471df-9471e6 383->411 384->383 387 94722e-947232 384->387 389 947234-94723f 387->389 390 947248-94724c 387->390 389->390 396 947262-947269 390->396 397 94724e-947259 390->397 399 94727f-947286 396->399 400 94726b-947276 NtTerminateThread 396->400 397->396 406 9472b3-9472bd 399->406 407 947288-9472a1 CreateThread 399->407 400->399 416 947392-9473a0 call 941934 call 941d28 call 9416ac 406->416 417 9472c3-9472ca 406->417 407->406 409 9472a3-9472ac 407->409 409->406 410->387 413 947201-947208 411->413 414 9471e8-9471fc call 93a68c call 93e2b8 call 940a38 call 93e2b8 call 940be4 411->414 420 947214-94721c call 93e270 call 93e2b8 413->420 421 94720a-94720f call 93e2b8 call 93fc88 413->421 414->413 451 9473a5-9473a9 416->451 422 9472f7-9472fe 417->422 423 9472cc-9472e5 CreateThread 417->423 420->410 421->420 428 947300-947304 422->428 429 947339-947340 call 93b674 422->429 423->422 424 9472e7-9472f0 423->424 424->422 436 947306-947311 428->436 437 94731a-947334 call 936ae8 call 93da00 428->437 444 947342-947347 call 938960 429->444 445 947349-94734b call 938230 429->445 436->437 437->429 456 947350-947357 444->456 445->456 459 947359-947360 456->459 460 94736b-94738b call 939640 call 9404b4 456->460 459->460 463 947362-947369 459->463 466 947390 460->466 463->460 463->466 466->451
                                          APIs
                                          • CreateThread.KERNELBASE(00000000,00000000,00938F68,00000000,00000000,00000000), ref: 00947129
                                          • CreateThread.KERNELBASE(00000000,00000000,00937468,00000000,00000000,00000000), ref: 00947154
                                          • CreateThread.KERNELBASE(00000000,00000000,0093782C,00000000,00000000,00000000), ref: 0094716C
                                          • CreateThread.KERNELBASE(00000000,00000000,00937E58,00000000,00000000,00000000), ref: 0094719B
                                          • NtTerminateThread.NTDLL(?,00000000), ref: 00947270
                                          • CreateThread.KERNELBASE(00000000,00000000,00939628,00000000,00000000,00000000), ref: 00947297
                                          • CreateThread.KERNELBASE(00000000,00000000,0093C064,00000000,00000000,00000000), ref: 009472DB
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Thread$Create$Terminate
                                          • String ID:
                                          • API String ID: 1922322686-0
                                          • Opcode ID: 7ea8be913d222d06953c4d9e5e9995af67156e6d7cb85cf3c1403aa6aa4d2074
                                          • Instruction ID: 348b558d67c26e56a0726c4ded7e5d14f1ee55fac1ae62abeb9de15d4576cd07
                                          • Opcode Fuzzy Hash: 7ea8be913d222d06953c4d9e5e9995af67156e6d7cb85cf3c1403aa6aa4d2074
                                          • Instruction Fuzzy Hash: DF91A27056CB04BEEB216BF2AC2EF6D7EA9AB48707F150114F651A40F3DBB45940EB14
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 519 936668-93667b 520 93667e-936683 519->520 520->520 521 936685-936699 call 93a094 520->521 524 9366a5-9366c7 CreateFileW 521->524 525 93669b-93669f 521->525 526 9367ca-9367cc 524->526 527 9366cd-9366cf 524->527 525->524 525->526 528 9367cf-9367d2 526->528 529 9366d2-9366fb NtAllocateVirtualMemory 527->529 530 9367f3-9367f7 528->530 531 9367d4-9367ed NtFreeVirtualMemory 528->531 532 936703 529->532 533 9366fd-936708 529->533 530->528 534 9367f9-9367fd 530->534 531->530 536 936733-936738 532->536 540 93671b-93671e 533->540 541 93670a-936719 533->541 538 936808-93681f call 936550 DeleteFileW 534->538 539 9367ff-936802 NtClose 534->539 537 93673b-936746 536->537 544 936754 537->544 545 936748-936752 537->545 551 936821 538->551 552 936828-93682c 538->552 539->538 542 93672d-936731 540->542 543 936720-936728 call 936628 540->543 541->542 542->529 542->536 543->542 548 936759-936760 544->548 545->548 550 936763-936779 WriteFile 548->550 553 93677b 550->553 554 93677d-93679a SetFilePointerEx 550->554 551->552 555 936836-93683f 552->555 556 93682e-936831 call 93686c 552->556 557 93679c-9367a3 553->557 554->550 554->557 556->555 559 9367a7-9367c5 557->559 560 9367a5 557->560 559->537 560->526
                                          APIs
                                          • CreateFileW.KERNELBASE(009377D6,40000000,00000003,00000000,00000003,80000000,00000000,009377D6,?,?,00000000,?), ref: 009366BA
                                          • NtAllocateVirtualMemory.NTDLL(000000FF,00000000,00000000,00010000,00001000,00000004,?,00000000,?), ref: 009366F3
                                          • WriteFile.KERNELBASE(000000FF,00000000,00010000,00010000,00000000,?,00000000,?), ref: 00936771
                                          • SetFilePointerEx.KERNELBASE(000000FF,00010000,?,00000000,00000001,?,00000000,?), ref: 0093678D
                                          • NtFreeVirtualMemory.NTDLL(000000FF,?,00010000,00008000,?,00000000,?), ref: 009367ED
                                          • NtClose.NTDLL(000000FF,?,00000000,?), ref: 00936802
                                          • DeleteFileW.KERNELBASE(?,000000FF,?,?,00000000,?), ref: 00936817
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$MemoryVirtual$AllocateCloseCreateDeleteFreePointerWrite
                                          • String ID:
                                          • API String ID: 3569053182-0
                                          • Opcode ID: 6ab9ff00427ad0b06bf90aac5289bf099746732aa3a4fd5c3a309d3b70b72c06
                                          • Instruction ID: 8732be2bcf9c1c3db55a8850c84e421dadd1539a406557c123f71038d47ac820
                                          • Opcode Fuzzy Hash: 6ab9ff00427ad0b06bf90aac5289bf099746732aa3a4fd5c3a309d3b70b72c06
                                          • Instruction Fuzzy Hash: D7512A71900209BFDF11CFA4CC45BEEBBB9EB08769F208225F612B6090D3B55A85DF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 562 93de78-93de89 SetThreadPriority 563 93de8f-93deae 562->563 565 93deb0-93deb8 563->565 566 93dede-93dee0 563->566 565->566 567 93deba 565->567 568 93dee2-93dee5 566->568 569 93dee6-93deeb 566->569 572 93dec1-93ded6 567->572 570 93def1-93df23 ReadFile 569->570 571 93dfa0-93dfa3 569->571 573 93df96 570->573 574 93df25-93df30 570->574 575 93e0a1-93e0a4 571->575 576 93dfa9-93dfee call 9320ac 571->576 588 93deda 572->588 589 93ded8-93dedc 572->589 577 93e180-93e19f 573->577 574->573 578 93df32-93df3a 574->578 579 93e131-93e134 575->579 580 93e0aa-93e0e9 WriteFile 575->580 617 93dff0-93e005 576->617 618 93e007-93e00f 576->618 596 93e1a3-93e1ab 577->596 597 93e1a1 577->597 582 93df58-93df7f 578->582 583 93df3c-93df56 578->583 579->577 585 93e136-93e13a 579->585 586 93e0eb-93e0f6 580->586 587 93e12d 580->587 619 93df92 582->619 620 93df81-93df8c 582->620 583->573 592 93e150-93e16e NtClose call 931074 call 93686c 585->592 593 93e13c-93e142 585->593 586->587 594 93e0f8-93e116 586->594 587->577 588->572 589->563 621 93e173-93e17e 592->621 600 93e146-93e14e 593->600 601 93e144 593->601 623 93e129 594->623 624 93e118-93e123 594->624 604 93e1d1 596->604 605 93e1ad 596->605 606 93e1d3-93e1d5 597->606 600->593 601->592 604->577 604->606 609 93e1b4-93e1c9 605->609 610 93e1d7-93e1da 606->610 611 93e1db 606->611 630 93e1cb-93e1cf 609->630 631 93e1cd 609->631 611->569 625 93e031-93e04d WriteFile 617->625 626 93e011-93e013 618->626 627 93e01e-93e02a 618->627 619->573 628 93df90 620->628 629 93df8e 620->629 621->577 638 93e1e0 621->638 623->587 632 93e127 624->632 633 93e125 624->633 635 93e097 625->635 636 93e04f-93e05a 625->636 626->627 634 93e015-93e01c 626->634 627->625 628->582 629->573 630->577 631->609 632->594 633->587 634->625 635->577 636->635 640 93e05c-93e080 636->640 638->563 643 93e093 640->643 644 93e082-93e08d 640->644 643->635 645 93e091 644->645 646 93e08f 644->646 645->640 646->635
                                          APIs
                                          • SetThreadPriority.KERNELBASE(000000FE,00000002), ref: 0093DE89
                                          • ReadFile.KERNELBASE(?,?,?,?,?), ref: 0093DF1B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: FilePriorityReadThread
                                          • String ID:
                                          • API String ID: 3643687941-0
                                          • Opcode ID: 80091347dcd8de93eca9a44ac0b0bd59fefa55ddef4caccc164b3580276c7bff
                                          • Instruction ID: d0910d371898cf53f5c27a2c3c3d4975538e356f53550ac27be91fb21d9f85ee
                                          • Opcode Fuzzy Hash: 80091347dcd8de93eca9a44ac0b0bd59fefa55ddef4caccc164b3580276c7bff
                                          • Instruction Fuzzy Hash: 20A18CB1518608EFDF218F90DCC4BAA3BBDFB08705F204662E906891E6E774DA44DF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 647 93f308-93f31f GetFileAttributesW 648 93f321-93f32d call 93bbf4 647->648 649 93f37f-93f391 SetThreadPriority call 931564 647->649 654 93f371-93f37c call 93686c 648->654 655 93f32f-93f33d call 93a094 648->655 656 93f393-93f39a 649->656 657 93f39c 649->657 655->654 664 93f33f-93f343 655->664 660 93f3a3-93f3b6 call 936844 656->660 657->660 668 93f3bd-93f3fd call 93c19c call 93f164 call 93686c FindFirstFileExW 660->668 666 93f345-93f349 664->666 667 93f34b-93f36e call 93c19c call 937290 call 93ef6c 664->667 666->654 666->667 681 93f403-93f411 668->681 682 93f535-93f54a call 93686c 668->682 688 93f416-93f41f 681->688 686 93f54e-93f562 682->686 687 93f54c-93f56a call 93686c 682->687 686->668 695 93f56f-93f572 687->695 690 93f421-93f427 688->690 691 93f429 688->691 690->691 693 93f42e-93f438 690->693 694 93f514-93f526 FindNextFileW 691->694 696 93f43a 693->696 697 93f43f-93f446 693->697 694->688 698 93f52c-93f52f FindClose 694->698 696->694 699 93f453-93f457 697->699 700 93f448-93f44c 697->700 698->682 702 93f481-93f489 call 93f21c 699->702 703 93f459-93f461 call 93f2b4 699->703 700->699 701 93f44e 700->701 701->694 710 93f490-93f497 702->710 711 93f48b 702->711 708 93f463-93f47a call 93f1c8 703->708 709 93f47c 703->709 708->709 709->694 713 93f4a4-93f4ae call 93bbf4 710->713 714 93f499-93f4a0 710->714 711->694 719 93f4b2-93f4d0 call 93f1c8 call 937290 call 93ef6c 713->719 720 93f4b0 713->720 714->713 716 93f4a2 714->716 716->694 726 93f4d5-93f4dc 719->726 720->694 726->694 727 93f4de-93f4e0 726->727 728 93f4e2-93f507 727->728 729 93f509 727->729 728->694 729->694
                                          APIs
                                          • GetFileAttributesW.KERNELBASE(?), ref: 0093F314
                                          • SetThreadPriority.KERNELBASE(000000FE,00000002), ref: 0093F383
                                          • FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000,?,?,?,00955180,003D0900), ref: 0093F3F0
                                          • FindNextFileW.KERNELBASE(000000FF,?), ref: 0093F51E
                                          • FindClose.KERNELBASE(000000FF), ref: 0093F52F
                                            • Part of subcall function 0093A094: FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 0093A0B6
                                            • Part of subcall function 0093A094: FindClose.KERNELBASE(000000FF), ref: 0093A0DC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Find$File$CloseFirst$AttributesNextPriorityThread
                                          • String ID:
                                          • API String ID: 3755735135-0
                                          • Opcode ID: 382dc47adb2866b1118858b9376fa9c5c431dde4c7199a4d66f92e68ce7ee96a
                                          • Instruction ID: 9b534f3e8a1a11c3a416c20536573b3d9e51e6b923d333daa25bc89d943d4b19
                                          • Opcode Fuzzy Hash: 382dc47adb2866b1118858b9376fa9c5c431dde4c7199a4d66f92e68ce7ee96a
                                          • Instruction Fuzzy Hash: 65619630C04209EBDF21AFA1DC69BBEBB79EF45306F104071F914A61A2D7359A91EF91
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 751 93766c-937693 753 937822-937827 751->753 754 937699-9376ad call 936844 751->754 757 9376b3-937700 call 9316c0 FindFirstFileExW 754->757 758 937806-93780a 754->758 757->758 768 937706-93770f 757->768 759 937814-937818 758->759 760 93780c-93780f call 93686c 758->760 759->753 762 93781a-93781d call 93686c 759->762 760->759 762->753 769 9377e5-9377f7 FindNextFileW 768->769 770 937715-93771b 768->770 769->768 772 9377fd 769->772 770->769 771 937721-93774f call 936844 770->771 771->769 777 937755-937791 GetFileAttributesW 771->777 772->758 781 937793-93779e 777->781 782 9377ce-9377d1 call 936668 777->782 786 9377a2-9377ad 781->786 787 9377a0 781->787 785 9377d6-9377de call 93686c 782->785 785->769 790 9377b9 786->790 791 9377af-9377bb call 93766c 786->791 789 9377bd-9377cc call 93686c 787->789 789->769 790->789 791->781
                                          APIs
                                            • Part of subcall function 00936844: RtlAllocateHeap.NTDLL(?,00000008,00000000,?,00947764,?,00000000,00000000), ref: 00936860
                                          • FindFirstFileExW.KERNELBASE(00000000,00000000,?,00000000,00000000,00000000), ref: 009376F3
                                          • GetFileAttributesW.KERNELBASE(00000000), ref: 00937786
                                          • FindNextFileW.KERNELBASE(000000FF,?), ref: 009377EF
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$Find$AllocateAttributesFirstHeapNext
                                          • String ID: *
                                          • API String ID: 2400493143-163128923
                                          • Opcode ID: 0718c8db93703387318d71328558d692800ae674c1fe24f0a30bc244d681fed0
                                          • Instruction ID: 5fa3ce787401276f345edd27d8628e1664e253cceffc6c370d2c6d73b738a831
                                          • Opcode Fuzzy Hash: 0718c8db93703387318d71328558d692800ae674c1fe24f0a30bc244d681fed0
                                          • Instruction Fuzzy Hash: 6B414AB0C18218EBDF21AFA1DC4DBAEBB79FF04306F104460E412A50B1E7765A64EF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 798 935c24-935c35 799 935c37-935c51 call 935aec 798->799 800 935c56-935c5d 798->800 799->800 802 935c5f-935c79 call 935aec 800->802 803 935c7e-935c85 800->803 802->803 804 935c87-935ca1 call 935aec 803->804 805 935ca6-935cad call 931658 803->805 804->805 812 935cb2-935cb6 805->812 813 935cb8-935ce2 call 931240 812->813 814 935cdd-935ce0 812->814 818 935ce9-935d04 FindFirstFileW 813->818 814->812 819 935d06-935d17 call 9311c4 818->819 820 935d54-935d58 818->820 828 935d37-935d49 FindNextFileW 819->828 829 935d19-935d2b FindClose call 935a20 819->829 821 935d5a-935d9c 820->821 822 935d5c-935d66 820->822 825 935d8b-935d8e 822->825 826 935d68-935d6d 822->826 825->818 830 935d86-935d89 826->830 831 935d6f-935d84 call 931240 826->831 828->819 833 935d4b-935d4e FindClose 828->833 835 935d30-935d34 829->835 830->826 831->825 833->820
                                          APIs
                                          • FindFirstFileW.KERNELBASE(?,?,?,00000004,?), ref: 00935CF7
                                          • FindClose.KERNELBASE(000000FF,?,00000000), ref: 00935D1C
                                          • FindNextFileW.KERNELBASE(000000FF,?,?,00000000), ref: 00935D41
                                          • FindClose.KERNELBASE(000000FF), ref: 00935D4E
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Find$CloseFile$FirstNext
                                          • String ID:
                                          • API String ID: 1164774033-0
                                          • Opcode ID: ce541b01dac68bb8083b6d339bd827f04b3e9c16ebd4428a229858fb60aa776b
                                          • Instruction ID: 27e3d7c8fc055b648b920eb037488bed980b0eaddc252185fcf4000a3b503864
                                          • Opcode Fuzzy Hash: ce541b01dac68bb8083b6d339bd827f04b3e9c16ebd4428a229858fb60aa776b
                                          • Instruction Fuzzy Hash: 1A41A070814B08DFCB20AFA1DD997A97B78FB08307F6285A1E4159E1B2E73849C5EF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtSetInformationProcess.NTDLL(000000FF,00000021,00000000,00000004,00000004,00000000,009471D1), ref: 0093B751
                                          • NtSetInformationProcess.NTDLL(000000FF,00000012,00000000,00000002), ref: 0093B763
                                          • NtSetInformationProcess.NTDLL(000000FF,0000000C,00000000,00000004), ref: 0093B778
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationProcess
                                          • String ID:
                                          • API String ID: 1801817001-0
                                          • Opcode ID: fae62883296e5a708dcfea6b3f4ed70b08011d7f73334a3321068ad2209b2e60
                                          • Instruction ID: 7cc12fa2ca7bc6aa78598df4b82d1dc9d5a7882d32e0d243794e727e65322b5b
                                          • Opcode Fuzzy Hash: fae62883296e5a708dcfea6b3f4ed70b08011d7f73334a3321068ad2209b2e60
                                          • Instruction Fuzzy Hash: DEF01CB1244710BFEB21AB94DCC6F1137AC9B0A762F100360B331DD0E6D7B084449B52
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtProtectVirtualMemory.NTDLL(000000FF,00000000,00000020,00000040,?,9870B143), ref: 0093B4B1
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: MemoryProtectVirtual
                                          • String ID:
                                          • API String ID: 2706961497-3916222277
                                          • Opcode ID: 9ba5aec8a051fec4a46e1fe175dc9cd753bdba524bf752834cb33a129f2173bc
                                          • Instruction ID: 5c5c3c75cc0ae1fb563a74368f947e760ae0b0fe7b6b53632e189b5f2d8d7453
                                          • Opcode Fuzzy Hash: 9ba5aec8a051fec4a46e1fe175dc9cd753bdba524bf752834cb33a129f2173bc
                                          • Instruction Fuzzy Hash: 28F0BE70900308FBDB10CFA4CC88B9EB7BCEB04325F608294A628E71E2E7755B009B64
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 00936844: RtlAllocateHeap.NTDLL(?,00000008,00000000,?,00947764,?,00000000,00000000), ref: 00936860
                                          • NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00937E7E
                                          • Sleep.KERNELBASE(000007D0,?), ref: 00937F45
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeapInformationQuerySleepSystem
                                          • String ID:
                                          • API String ID: 3184523392-0
                                          • Opcode ID: daeaa540b03866076b2b9ab677d7e14b4d143e7ff5fe96faad477ffddb59eaa0
                                          • Instruction ID: 6be9d9c1884125e581cc643924331aba0349e9b761a36c494177b13804784965
                                          • Opcode Fuzzy Hash: daeaa540b03866076b2b9ab677d7e14b4d143e7ff5fe96faad477ffddb59eaa0
                                          • Instruction Fuzzy Hash: A8212AB1908208BFDF219FE1DC84BDEBBB8FF04305F208095E914AA161D7769A45DFA0
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAdjustPrivilege.NTDLL(00000014,00000001,00000000,00000000), ref: 00938F8A
                                            • Part of subcall function 009397D8: NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                            • Part of subcall function 00939880: NtClose.NTDLL(00000000), ref: 00939971
                                          • NtSetInformationThread.NTDLL(000000FE,00000005,00000000,00000004,00000000,00000002,00000002,D1F935A5), ref: 00938FC1
                                            • Part of subcall function 00938DA8: OpenSCManagerW.SECHOST(00000000,00000000,00000001,7DDDCD9C), ref: 00938DE6
                                            • Part of subcall function 00938DA8: CloseServiceHandle.SECHOST(00000000), ref: 00938EAD
                                            • Part of subcall function 00938DA8: CloseServiceHandle.ADVAPI32(00000000), ref: 00938EBC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close$HandleInformationService$AdjustManagerOpenPrivilegeQuerySystemThread
                                          • String ID:
                                          • API String ID: 4089816224-0
                                          • Opcode ID: 7ba5d5f8710ddf934f8731fffef8bf5ecc6fceffefb3126e5c9930dc19e4eaa0
                                          • Instruction ID: 566d958261c1ff6a5bbaad510ef1f235c12af033c389b1eaf675fa574f330058
                                          • Opcode Fuzzy Hash: 7ba5d5f8710ddf934f8731fffef8bf5ecc6fceffefb3126e5c9930dc19e4eaa0
                                          • Instruction Fuzzy Hash: 93218170904309BAEB24AFA0CC4EB9E7A7CAF45706F104054F501A61E5EBB08A80DF61
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAdjustPrivilege.NTDLL(00000014,00000001,00000000,00000000), ref: 00938F8A
                                            • Part of subcall function 009397D8: NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                            • Part of subcall function 00939880: NtClose.NTDLL(00000000), ref: 00939971
                                          • NtSetInformationThread.NTDLL(000000FE,00000005,00000000,00000004,00000000,00000002,00000002,D1F935A5), ref: 00938FC1
                                            • Part of subcall function 00938DA8: OpenSCManagerW.SECHOST(00000000,00000000,00000001,7DDDCD9C), ref: 00938DE6
                                            • Part of subcall function 00938DA8: CloseServiceHandle.SECHOST(00000000), ref: 00938EAD
                                            • Part of subcall function 00938DA8: CloseServiceHandle.ADVAPI32(00000000), ref: 00938EBC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close$HandleInformationService$AdjustManagerOpenPrivilegeQuerySystemThread
                                          • String ID:
                                          • API String ID: 4089816224-0
                                          • Opcode ID: 7f9cf4219037ff06242e5e751fedadca311370cda92d2e09babc970224411bf1
                                          • Instruction ID: 4244ab6e86cd11818eb9c7eea3f224442d15c1ab9022ad5c49bfbf1413b561e4
                                          • Opcode Fuzzy Hash: 7f9cf4219037ff06242e5e751fedadca311370cda92d2e09babc970224411bf1
                                          • Instruction Fuzzy Hash: 79219370904309BAEF24AFA0CC4EBDE7A7CAF45706F104054F501A61E5EBF08A80DF61
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 00937590: FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 009375FF
                                            • Part of subcall function 00937590: FindClose.KERNELBASE(000000FF), ref: 0093765C
                                          • FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 0093751F
                                          • FindNextFileW.KERNELBASE(000000FF,?), ref: 00937576
                                            • Part of subcall function 0093766C: FindFirstFileExW.KERNELBASE(00000000,00000000,?,00000000,00000000,00000000), ref: 009376F3
                                            • Part of subcall function 0093766C: GetFileAttributesW.KERNELBASE(00000000), ref: 00937786
                                            • Part of subcall function 0093766C: FindNextFileW.KERNELBASE(000000FF,?), ref: 009377EF
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: FileFind$First$Next$AttributesClose
                                          • String ID:
                                          • API String ID: 95010735-0
                                          • Opcode ID: 0b1af467977d9bbd096a11bb3480b359adeb310a2d12bb0df3b762dc1495ff08
                                          • Instruction ID: a388c6dc7199e27eb3cc1ef731fe5ed26385f6de6258a46a80faa7440202a77b
                                          • Opcode Fuzzy Hash: 0b1af467977d9bbd096a11bb3480b359adeb310a2d12bb0df3b762dc1495ff08
                                          • Instruction Fuzzy Hash: BE212EB194420DABDB20EFA0DD4DFD9B7BCAB14302F4004A1B608D61A1E731AB54DF62
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 009375FF
                                          • FindClose.KERNELBASE(000000FF), ref: 0093765C
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Find$CloseFileFirst
                                          • String ID:
                                          • API String ID: 2295610775-0
                                          • Opcode ID: 71be75cc1df9c569f5c034f0b7de70c2da0f078b818fbaf2db5729b4fdd6ec99
                                          • Instruction ID: a0b911fdc4be1e876c4b60ddd6f37e84788d7118e83ac7e4959ef4bd30c90abc
                                          • Opcode Fuzzy Hash: 71be75cc1df9c569f5c034f0b7de70c2da0f078b818fbaf2db5729b4fdd6ec99
                                          • Instruction Fuzzy Hash: 9E216FB0804208EFDB10DF94DC1DB9CBBBDFF0430AF0041A0E908AA162E7759A99DF55
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00937E7E
                                          • Sleep.KERNELBASE(000007D0,?), ref: 00937F45
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationQuerySleepSystem
                                          • String ID:
                                          • API String ID: 3518162127-0
                                          • Opcode ID: 2e2b59960c2e2ffbdcc3fbf9b71613a5e6e8407e8c6626e6833e8574d9c5d8cf
                                          • Instruction ID: a72b0b8097aab74e80ac7a7d06b527cadef68f9b37151c54f7c5a4cb30392cdc
                                          • Opcode Fuzzy Hash: 2e2b59960c2e2ffbdcc3fbf9b71613a5e6e8407e8c6626e6833e8574d9c5d8cf
                                          • Instruction Fuzzy Hash: C6212EB1908208EFDF21DFD0CD44B9DBBB8FF04305F208095E501AA161D7769A45DFA0
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00937E7E
                                          • Sleep.KERNELBASE(000007D0,?), ref: 00937F45
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationQuerySleepSystem
                                          • String ID:
                                          • API String ID: 3518162127-0
                                          • Opcode ID: 73ed73407dbac577ae035c8c60a77c043bfcda9c6a0c8b113e3bca83eeb6f47c
                                          • Instruction ID: a72b0b8097aab74e80ac7a7d06b527cadef68f9b37151c54f7c5a4cb30392cdc
                                          • Opcode Fuzzy Hash: 73ed73407dbac577ae035c8c60a77c043bfcda9c6a0c8b113e3bca83eeb6f47c
                                          • Instruction Fuzzy Hash: C6212EB1908208EFDF21DFD0CD44B9DBBB8FF04305F208095E501AA161D7769A45DFA0
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CreateThread.KERNELBASE(00000000,00000000,0093DE78,00000000,00000000,00000000,?,00000000), ref: 0093E239
                                            • Part of subcall function 0093B444: NtSetInformationThread.NTDLL(00000000,?,00000000,00000000,?,00936541,00000000,0095586C,00936390,00000000,00000000,00955858,00936378,00000000,00000000,0095584C), ref: 0093B465
                                          • NtClose.NTDLL(00000000,00000000,?,00000000), ref: 0093E24C
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Thread$CloseCreateInformation
                                          • String ID:
                                          • API String ID: 3895992022-0
                                          • Opcode ID: a332a25956ae04320c4511d81148ef14961f6d2477e8f85f0bb4b4e160b3d26a
                                          • Instruction ID: 656ba41b22629b88db2f6956e0d702a088feee36fd1221347936b506bdf31390
                                          • Opcode Fuzzy Hash: a332a25956ae04320c4511d81148ef14961f6d2477e8f85f0bb4b4e160b3d26a
                                          • Instruction Fuzzy Hash: 37014970344B04EBE3206B55AC9AB9E736CEB04717F210210FB11A22E2EBB06E049B54
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtSetInformationThread.NTDLL(000000FE,00000005,00000008,00000004), ref: 0093B424
                                          • NtClose.NTDLL(00000008), ref: 0093B432
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseInformationThread
                                          • String ID:
                                          • API String ID: 3167811113-0
                                          • Opcode ID: 217432d14617271235c0a821e4005c6eadbc497bd2f47a61329268cb68441d5b
                                          • Instruction ID: a6485c2600a2784b0e83b999937a2b31e2378dbe3b2fd5eb3ae719734f2912ca
                                          • Opcode Fuzzy Hash: 217432d14617271235c0a821e4005c6eadbc497bd2f47a61329268cb68441d5b
                                          • Instruction Fuzzy Hash: C8017C70504208AFE700CF50CC89FAABBACFB00305F518164EA049B1B2E3B58A58EFA0
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 0093A0B6
                                          • FindClose.KERNELBASE(000000FF), ref: 0093A0DC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Find$CloseFileFirst
                                          • String ID:
                                          • API String ID: 2295610775-0
                                          • Opcode ID: 44a0a00ae4a38c0e5eb78748c5708dcc599ef305234f4f5d09a83d2f1f570848
                                          • Instruction ID: 93283a1c48e02401d360e6aecb9e25a94a635b6dd47cddef583784b1134231eb
                                          • Opcode Fuzzy Hash: 44a0a00ae4a38c0e5eb78748c5708dcc599ef305234f4f5d09a83d2f1f570848
                                          • Instruction Fuzzy Hash: A3F03A74901308EFDB20DF94CC49B9CBBB4EB45311F208295E818AB2A0E7716F92DF44
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Close
                                          • String ID:
                                          • API String ID: 3535843008-0
                                          • Opcode ID: 765440a128d5c490da27c7a507b15ede1c69735291a9f80ce21641ef95f79615
                                          • Instruction ID: 00391f9c63afd1a56155ebcbc235020602094b7ca97e66745b48b07cedb6b934
                                          • Opcode Fuzzy Hash: 765440a128d5c490da27c7a507b15ede1c69735291a9f80ce21641ef95f79615
                                          • Instruction Fuzzy Hash: B931B87081020CEFEB00CF95D858BEEBBB9FB04319F608159E415BA291D7B69A49DF91
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 00936844: RtlAllocateHeap.NTDLL(?,00000008,00000000,?,00947764,?,00000000,00000000), ref: 00936860
                                          • NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeapInformationQuerySystem
                                          • String ID:
                                          • API String ID: 3114120137-0
                                          • Opcode ID: c5f3f0594b47f104c3e47b9310833272058e6f552ae51d782ad3662d21dd3514
                                          • Instruction ID: c3fe07185948796a155af770f9c5c0e2cd35f0c937db801b8e7f927d9e9a2e32
                                          • Opcode Fuzzy Hash: c5f3f0594b47f104c3e47b9310833272058e6f552ae51d782ad3662d21dd3514
                                          • Instruction Fuzzy Hash: 73113672D00108FBDF11DF95D880BDDBBB9EF4A310F2081A2EA10AA161D7B25A50AF90
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtQueryInformationToken.NTDLL(00000000,00000001,?,00000028,?,00000000), ref: 00936CDF
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationQueryToken
                                          • String ID:
                                          • API String ID: 4239771691-0
                                          • Opcode ID: 14b5e5b2e1b8e21ee561718be4733f328c23b69c80ab9f90d2f4df601aa1afce
                                          • Instruction ID: 787ae8a5350f8aa28848afcddd76dc387f40a82d48a0374a44108ed276c4f342
                                          • Opcode Fuzzy Hash: 14b5e5b2e1b8e21ee561718be4733f328c23b69c80ab9f90d2f4df601aa1afce
                                          • Instruction Fuzzy Hash: 03115830A04209FBDF109F81DC88BAEBBB8FB04306F508125E924A61E1D7719A98DF11
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • LdrLoadDll.NTDLL(00000000,00000000,00000000,?), ref: 00935A71
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Load
                                          • String ID:
                                          • API String ID: 2234796835-0
                                          • Opcode ID: a1881dcad14e7380e440b7b6708c926c868580be1291e9bf4f73243935dcd6e2
                                          • Instruction ID: dda8797ccf1989be82df5bb5c7c7ebd0f3e1f26b5e380f22e832b414d7f4c555
                                          • Opcode Fuzzy Hash: a1881dcad14e7380e440b7b6708c926c868580be1291e9bf4f73243935dcd6e2
                                          • Instruction Fuzzy Hash: 0CF03C7690060DFACF10EE95D849FDEB7BCEB08315F4141A2A919E7040D234AB489FA0
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtTerminateProcess.NTDLL(00937DB8,00000000), ref: 0093DCC3
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: ProcessTerminate
                                          • String ID:
                                          • API String ID: 560597551-0
                                          • Opcode ID: f30a1bf1604b2b8ec6d9a5b9675ade7a6d442bfefd7daa94ad660a8516451ce7
                                          • Instruction ID: 626e249c608adeb47dbae420581034918a97dc7a2b706161d4a734076399c188
                                          • Opcode Fuzzy Hash: f30a1bf1604b2b8ec6d9a5b9675ade7a6d442bfefd7daa94ad660a8516451ce7
                                          • Instruction Fuzzy Hash: 7601E8B0910308EFDB00CF90D858BDEBBB8FB04319F608198E504AB291D7B79646DF91
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtQueryInformationToken.NTDLL(?,00000001,?,0000002C,?), ref: 0093B69E
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationQueryToken
                                          • String ID:
                                          • API String ID: 4239771691-0
                                          • Opcode ID: 59de00644282aa70c71fd0cbab5d9607d46d652921dc6cf3b4bb24f9e8a84918
                                          • Instruction ID: 9a6ea5f5ac5cc50019834ca852eefc5561cbc232b6b9ec643ff37db11106a164
                                          • Opcode Fuzzy Hash: 59de00644282aa70c71fd0cbab5d9607d46d652921dc6cf3b4bb24f9e8a84918
                                          • Instruction Fuzzy Hash: E3F05431605608AFEB10DF95DC86EADB7BDFB04326FA00165FA14D31A1E761AE549B40
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationQuerySystem
                                          • String ID:
                                          • API String ID: 3562636166-0
                                          • Opcode ID: ec292c72cb193a2c35b020928f19e170b2366f376bbcda5c7005294aae60c44f
                                          • Instruction ID: 0c1eba2606da9a16b51b268bb283704a9068a23cbd1442abb883f5b6007791c1
                                          • Opcode Fuzzy Hash: ec292c72cb193a2c35b020928f19e170b2366f376bbcda5c7005294aae60c44f
                                          • Instruction Fuzzy Hash: 92F0DA35A04108EBDF11DFC5D8C0BADBB78EF56301F204492EA01AA151D3B59A50EF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationQuerySystem
                                          • String ID:
                                          • API String ID: 3562636166-0
                                          • Opcode ID: 0d80675b02fa97038adc5404357b6434e0a5f53bf635ade0f975e96eb84cd687
                                          • Instruction ID: 0c1eba2606da9a16b51b268bb283704a9068a23cbd1442abb883f5b6007791c1
                                          • Opcode Fuzzy Hash: 0d80675b02fa97038adc5404357b6434e0a5f53bf635ade0f975e96eb84cd687
                                          • Instruction Fuzzy Hash: 92F0DA35A04108EBDF11DFC5D8C0BADBB78EF56301F204492EA01AA151D3B59A50EF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtSetInformationThread.NTDLL(00000000,?,00000000,00000000,?,00936541,00000000,0095586C,00936390,00000000,00000000,00955858,00936378,00000000,00000000,0095584C), ref: 0093B465
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: InformationThread
                                          • String ID:
                                          • API String ID: 4046476035-0
                                          • Opcode ID: 581bf64dd7814d3074c272093994d42b053f5fb26638620ae4fef97f40d54180
                                          • Instruction ID: fe8c65cc0b2732bd1594555c4ad08d2a0967a800788ef84d0ca9e54058c0a577
                                          • Opcode Fuzzy Hash: 581bf64dd7814d3074c272093994d42b053f5fb26638620ae4fef97f40d54180
                                          • Instruction Fuzzy Hash: 3CD0A7325A030CAED7009F54DC19FF6336CD311302F108525B307C60E2D7B4A490DA68
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • GetLogicalDriveStringsW.KERNELBASE(?,?), ref: 0093A47B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: DriveLogicalStrings
                                          • String ID:
                                          • API String ID: 2022863570-0
                                          • Opcode ID: 782212c969c5c28ef81e2c1dbcba4e08385df22ba93e8639a96a4b68a37abc31
                                          • Instruction ID: 7d3dc73f438624f677ecff6474c805064fa5c5260618dc3c04ecaeba1d80a3f9
                                          • Opcode Fuzzy Hash: 782212c969c5c28ef81e2c1dbcba4e08385df22ba93e8639a96a4b68a37abc31
                                          • Instruction Fuzzy Hash: E2C09236014308EF8B029F89ED48C85BFEAEB187017058061F6094B132DB32E821EB95
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: LibraryTextWindow$CreateDialogFreeLoad$BrushColorCommandErrorLastLineMenuPixelProc$ButtonCapsCheckedCountDeviceExitHeapImageItemMessageNamePaletteParamProcessSelectSolidTick
                                          • String ID:
                                          • API String ID: 2067994032-0
                                          • Opcode ID: 408cd0254a0d524634f681b650ece81a3e0362f2b2a1a46e0555efdee5121436
                                          • Instruction ID: 2c5c7cb83e299b52a412da4623726ac2f20ecf04089b501caf7d89bee70c85fc
                                          • Opcode Fuzzy Hash: 408cd0254a0d524634f681b650ece81a3e0362f2b2a1a46e0555efdee5121436
                                          • Instruction Fuzzy Hash: A301F814C6B509A9C1413BF09C0BF6FBAADBFF2314F2919A8F1182A0E39F204401C533
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 95 938230-938289 96 938290-93829f 95->96 97 93828b 95->97 104 9382a1 96->104 105 9382a6-9382b6 96->105 98 9388b9-9388bd 97->98 99 9388c8-9388cc 98->99 100 9388bf 98->100 102 9388ce-9388d2 99->102 103 9388dd-9388e1 99->103 100->99 102->103 106 9388d4 102->106 107 9388e3 103->107 108 9388ec-9388f0 103->108 104->98 112 9382b8 105->112 113 9382bd-9382cd 105->113 106->103 107->108 110 9388f2 108->110 111 9388fb-9388ff 108->111 110->111 114 938901-938904 call 93686c 111->114 115 938909-93890d 111->115 112->98 123 9382d4-9382ef call 940e98 113->123 124 9382cf 113->124 114->115 117 938917-93891b 115->117 118 93890f-938912 call 93686c 115->118 121 938926-93892a 117->121 122 93891d 117->122 118->117 125 938935-938939 121->125 126 93892c 121->126 122->121 133 9382f1-938316 123->133 134 938319-9383a9 call 931240 123->134 124->98 127 938944-938948 125->127 128 93893b 125->128 126->125 130 938955-93895b 127->130 131 93894a-93894d 127->131 128->127 131->130 133->134 141 9383b0-9383be 134->141 142 9383ab 134->142 144 9383c0 141->144 145 9383c5-9383d6 call 936844 141->145 142->98 144->98 148 9383d8 145->148 149 9383dd-9383e5 call 931564 145->149 148->98 152 938401-938412 call 936de8 149->152 153 9383e7-9383f8 call 936de8 149->153 160 938414 152->160 161 938419-938432 152->161 158 9383fa 153->158 159 9383ff 153->159 158->98 159->161 160->98 163 938434-938443 call 93686c 161->163 164 938448-93845b 161->164 163->98 168 938462-938478 164->168 169 93845d 164->169 171 93847a 168->171 172 93847f-93848d 168->172 169->98 171->98 174 938494-9384e7 call 931564 172->174 175 93848f 172->175 181 9384e9-9384f6 174->181 182 9384f8 174->182 175->98 183 9384fb-93851c DrawTextW 181->183 182->183 184 938523-9385cb 183->184 185 93851e 183->185 189 9385d2-9385ff 184->189 190 9385cd 184->190 185->98 193 938601 189->193 194 938606-93867f call 9316c0 call 931240 CreateFileW 189->194 190->98 193->98 202 938681 194->202 203 938686-9386a0 WriteFile 194->203 202->98 204 9386a2 203->204 205 9386a7-9386be WriteFile 203->205 204->98 206 9386c0 205->206 207 9386c5-9386dc WriteFile 205->207 206->98 208 9386e3-938707 call 936c98 207->208 209 9386de 207->209 213 938709 208->213 214 93870e-9387b2 call 9316c0 call 931240 RegCreateKeyExW 208->214 209->98 213->98 220 9387b4 214->220 221 9387b9-938818 call 931240 RegSetValueExW 214->221 220->98 225 93881a 221->225 226 93881f-9388a0 call 931240 RegSetValueExW 221->226 225->98 230 9388a2 226->230 231 9388a4-9388a8 226->231 230->98 231->98 232 9388aa-9388b1 231->232 232->98
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID: ($BM
                                          • API String ID: 0-2980357723
                                          • Opcode ID: bbb1f0359cba2e9424e47cfcdf336b33d8c0487c4aa926aa8f4df3a32e319cfc
                                          • Instruction ID: 488e0d781aa57bf5f738a1d7797483cdd3ed18b7b8c1de1a4099e6eb824aedf3
                                          • Opcode Fuzzy Hash: bbb1f0359cba2e9424e47cfcdf336b33d8c0487c4aa926aa8f4df3a32e319cfc
                                          • Instruction Fuzzy Hash: F3224870900309EFEB219FA0DC49BAEBBB8FF08305F514065F611BA1A1DB799A44DF65
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 469 93bc38-93bc62 471 93bc64 469->471 472 93bc69-93bc80 469->472 473 93be8c-93be90 471->473 477 93bc82 472->477 478 93bc87-93bc94 call 936844 472->478 475 93be92 473->475 476 93be9b-93be9f 473->476 475->476 479 93bea1-93bea4 DeleteDC 476->479 480 93beaa-93beae 476->480 477->473 488 93bc96 478->488 489 93bc9b-93bcf6 call 931240 CreateDCW 478->489 479->480 482 93beb0-93beb3 call 93686c 480->482 483 93beb8-93bebc 480->483 482->483 484 93bec7-93becc 483->484 485 93bebe 483->485 485->484 488->473 493 93bcf8 489->493 494 93bcfd-93bdc7 call 931240 StartDocW 489->494 493->473 505 93bdc9 494->505 506 93bdce-93bdd9 call 931720 494->506 505->473 509 93bdde-93bdea 506->509 511 93bdee-93be66 DrawTextA * 2 EndPage 509->511 512 93bdec 509->512 511->509 513 93be6c-93be7b EndDoc call 931720 511->513 512->513 516 93be80-93be83 513->516 516->473
                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Delete
                                          • String ID:
                                          • API String ID: 1035893169-0
                                          • Opcode ID: 695ac528d02701bac39c9a32899e2e6e3aaf74845f591a3318ce57fbf14f7324
                                          • Instruction ID: b707343f9bbad4e1b1376a4cc55e5b48f9aff8cd4594165925143848db515b4e
                                          • Opcode Fuzzy Hash: 695ac528d02701bac39c9a32899e2e6e3aaf74845f591a3318ce57fbf14f7324
                                          • Instruction Fuzzy Hash: 37810271900709EFDF119FA1DC19BAEBBB9FF08302F204468F605AA1A2D7765A50EF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 731 93c28c-93c2b7 CreateFileW 732 93c3ed-93c3f3 731->732 733 93c2bd-93c2d6 731->733 734 93c2dc-93c2ee call 9317ac 733->734 737 93c2f5-93c318 WriteFile 734->737 738 93c31a-93c329 737->738 739 93c32c-93c351 WriteFile 737->739 740 93c353-93c362 739->740 741 93c365-93c388 WriteFile 739->741 743 93c38a-93c399 741->743 744 93c39c-93c3c1 WriteFile 741->744 745 93c3c3-93c3d2 744->745 746 93c3d5-93c3e2 744->746 746->737 749 93c3e8 746->749 749->734
                                          APIs
                                          • CreateFileW.KERNELBASE(00000000,40000000,00000000,00000000,00000002,00000080,00000000,?,?,00000000), ref: 0093C2AA
                                          • WriteFile.KERNELBASE(000000FF,?,00000001,00000000,00000000,Function_00026000,?,?,?,00000000), ref: 0093C30B
                                          • WriteFile.KERNELBASE(000000FF,?,00000001,00000000,00000000,?,?,00000000), ref: 0093C344
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$Write$Create
                                          • String ID:
                                          • API String ID: 1602526932-0
                                          • Opcode ID: dc7008c3c4885593d3d2dcc1b1e53db4d538a8fe50b1c566adaece6ca74f3851
                                          • Instruction ID: eb8abae263bacb24e74eac23395c23dfa1eaeb5b24b6d779877d2e8bfbaf9af4
                                          • Opcode Fuzzy Hash: dc7008c3c4885593d3d2dcc1b1e53db4d538a8fe50b1c566adaece6ca74f3851
                                          • Instruction Fuzzy Hash: 9B414D71A0460CFFDB00DB95EC45BEEFB7AEB44322F5081A6E604B21A2E3715A54DB91
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 837 93e45c-93e49a SetFileAttributesW CreateFileW 838 93e511-93e518 837->838 839 93e49c-93e4b9 SetFilePointerEx 837->839 840 93e4bb-93e4d8 ReadFile 839->840 841 93e508 839->841 840->841 842 93e4da-93e4ef call 93e350 840->842 841->838 842->841 845 93e4f1-93e4f9 842->845 846 93e502-93e503 call 93686c 845->846 847 93e4fb 845->847 846->841 847->846
                                          APIs
                                          • SetFileAttributesW.KERNELBASE(00000000,00000080,?), ref: 0093E475
                                          • CreateFileW.KERNELBASE(00000000,80000000,00000000,00000000,00000003,00000000,00000000), ref: 0093E48D
                                          • SetFilePointerEx.KERNELBASE(000000FF,-00000084,00000000,00000000,00000002), ref: 0093E4B1
                                          • ReadFile.KERNELBASE(000000FF,?,00000084,?,00000000), ref: 0093E4D0
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$AttributesCreatePointerRead
                                          • String ID:
                                          • API String ID: 4170910816-0
                                          • Opcode ID: ae0882483769dc0efd5ac212521d6ad46e43b0bf323f48bfc4926b282b126d32
                                          • Instruction ID: 792c5e5bbf767b7e90737a1f1a312e7ee7ed9c1ef92718cdc3b3edfd605ac198
                                          • Opcode Fuzzy Hash: ae0882483769dc0efd5ac212521d6ad46e43b0bf323f48bfc4926b282b126d32
                                          • Instruction Fuzzy Hash: F0114C70A50308FBEF209FA1DC49FAD7BBDBB04701F5080A4B604A60E1EB71AE559F14
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RegCreateKeyExW.KERNELBASE(80000002,?,00000000,00000000,00000000,00020119,00000000,?,00000000), ref: 0094100D
                                          • RegQueryValueExW.KERNELBASE(?,?,00000000,00000004,00000004,00000004), ref: 00941040
                                          • RegDeleteKeyExW.KERNELBASE(80000002,?,00000100,00000000,000000FF,00000000), ref: 009410A9
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateDeleteQueryValue
                                          • String ID:
                                          • API String ID: 1796729037-0
                                          • Opcode ID: b27ec9b71247ef9308a64cdf12444ff2c8609473f34f6ef3bbe0fb1160ab3602
                                          • Instruction ID: ef0dee293823882adf91ba6bbfc769f2e5f31247c8e06eaf498bb678471e3ec9
                                          • Opcode Fuzzy Hash: b27ec9b71247ef9308a64cdf12444ff2c8609473f34f6ef3bbe0fb1160ab3602
                                          • Instruction Fuzzy Hash: 6E5137B0920209AFEB20CF90CC49FEEBBBCFB04705F404095BA14EA1A1D7749A94DF65
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 0093E3AC: SetFileAttributesW.KERNELBASE(00000000,00000080,?,00000000,?,?,?), ref: 0093E3CD
                                            • Part of subcall function 0093E3AC: CreateFileW.KERNELBASE(00000000,40000000,00000000,00000000,00000003,00000000,00000000,?,00000000,?,?,?), ref: 0093E3E5
                                            • Part of subcall function 0093E45C: SetFileAttributesW.KERNELBASE(00000000,00000080,?), ref: 0093E475
                                            • Part of subcall function 0093E45C: CreateFileW.KERNELBASE(00000000,80000000,00000000,00000000,00000003,00000000,00000000), ref: 0093E48D
                                            • Part of subcall function 0093E45C: SetFilePointerEx.KERNELBASE(000000FF,-00000084,00000000,00000000,00000002), ref: 0093E4B1
                                            • Part of subcall function 0093E45C: ReadFile.KERNELBASE(000000FF,?,00000084,?,00000000), ref: 0093E4D0
                                          • MoveFileExW.KERNELBASE(00000000,00000000,00000008,00000000,00000000,00000000,00000000,?,00000000,?), ref: 0093EFEF
                                          • CreateIoCompletionPort.KERNELBASE(000000FF,00000000,00000000,00000000,00000000,?,?,00000000,?), ref: 0093F0B0
                                          • CreateFileW.KERNELBASE(00000000,C0000000,00000000,00000000,00000003,40000000,00000000,00000000,?,00000000,?), ref: 0093F066
                                            • Part of subcall function 0093686C: RtlFreeHeap.NTDLL(?,00000000,00000000,?,009477F4,00000000), ref: 00936888
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$Create$Attributes$CompletionFreeHeapMovePointerPortRead
                                          • String ID:
                                          • API String ID: 97630321-0
                                          • Opcode ID: cd7f4dcb5ff4b3633eeafe88d872a6bac932b08ca894588ae135b12b6c384524
                                          • Instruction ID: cd41bbe2d3476e3ff319ec999d7e45b06042dc9f7854c7c24e6ecda5bbed90ab
                                          • Opcode Fuzzy Hash: cd7f4dcb5ff4b3633eeafe88d872a6bac932b08ca894588ae135b12b6c384524
                                          • Instruction Fuzzy Hash: 18516830908608FBDF116FA6EC19B9D7F79BF44306F118061F605A50B2D77A8A95EF00
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 009397D8: NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                          • OpenSCManagerW.SECHOST(00000000,00000000,00000001,7DDDCD9C), ref: 00938DE6
                                          • CloseServiceHandle.SECHOST(00000000), ref: 00938EAD
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00938EBC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleService$InformationManagerOpenQuerySystem
                                          • String ID:
                                          • API String ID: 1894214006-0
                                          • Opcode ID: ec15b638219452c452165cea5a0333491a7a1ef5bfcb19a0772b8ea002c5724f
                                          • Instruction ID: 04ccc420937575c69a2933221fd383656ef87cb4d094371201e46f2833b16a94
                                          • Opcode Fuzzy Hash: ec15b638219452c452165cea5a0333491a7a1ef5bfcb19a0772b8ea002c5724f
                                          • Instruction Fuzzy Hash: D8312C70911308EFDB20DF90C949BAEBBB8EF04705F558494F502AB2A1DBB98E44DF51
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 3b5893f31a9cee45e2d642998f17b3dd32982c2738532b4c976c0cca887e1d5a
                                          • Instruction ID: 1226d4c08b65e70f9a55a6b27be6c5cb8d0d8cf57c18f4ed27df2f7694e83ed6
                                          • Opcode Fuzzy Hash: 3b5893f31a9cee45e2d642998f17b3dd32982c2738532b4c976c0cca887e1d5a
                                          • Instruction Fuzzy Hash: 6921D470808A08FFDF12AFA5DD4AB5D7BB6AB05316F2041A0F52575172C7768E60BF05
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CreateThread.KERNELBASE(00000000,00000000,0093A470,?,00000004,00000000), ref: 0093A4B9
                                          • ResumeThread.KERNELBASE(00000000), ref: 0093A4FD
                                          • GetExitCodeThread.KERNELBASE(00000000,00000000), ref: 0093A515
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Thread$CodeCreateExitResume
                                          • String ID:
                                          • API String ID: 4070214711-0
                                          • Opcode ID: e37e3326d991ef42927f8d64665e852df61c267d117a4b143beaa2b91b52ddfb
                                          • Instruction ID: 67fd140988fe7d469f3f0c695d7ed9af8a4da9ed9e258003a43a005ea55082db
                                          • Opcode Fuzzy Hash: e37e3326d991ef42927f8d64665e852df61c267d117a4b143beaa2b91b52ddfb
                                          • Instruction Fuzzy Hash: 1E11E070904208FFDB11DF94DD0ABADBBB5FB08316F2081A5F915A62B1E7716A90EF41
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CreateThread.KERNELBASE(00000000,00000000,0093A1B0,?,00000004,00000000), ref: 0093A1E4
                                          • ResumeThread.KERNELBASE(00000000), ref: 0093A228
                                          • GetExitCodeThread.KERNELBASE(00000000,00000000), ref: 0093A240
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Thread$CodeCreateExitResume
                                          • String ID:
                                          • API String ID: 4070214711-0
                                          • Opcode ID: 44699192d53efd40e7ecbeab334afbe0d7cdeb2a6a7027b9557c41ab8e8212ae
                                          • Instruction ID: 87d431b027493cbc1b6b3d7489602da633de7b3284b8159b4574d0dcbc6ff98c
                                          • Opcode Fuzzy Hash: 44699192d53efd40e7ecbeab334afbe0d7cdeb2a6a7027b9557c41ab8e8212ae
                                          • Instruction Fuzzy Hash: BE11F331918208FFDF119F90ED0AB9DBB75EB04316F204194FA54A61B0E7725B60EF41
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CoInitialize.OLE32(00000000), ref: 00937853
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Initialize
                                          • String ID: @
                                          • API String ID: 2538663250-2766056989
                                          • Opcode ID: 0dedc1d719f7613578a7d88b9a943accd10faaa4b2cd225fafaa73a9fe9e36b1
                                          • Instruction ID: 5a98b2055ec7eb2e80bc74ab9ebfc8d3e30bb75a00381faa67e87765c2c18365
                                          • Opcode Fuzzy Hash: 0dedc1d719f7613578a7d88b9a943accd10faaa4b2cd225fafaa73a9fe9e36b1
                                          • Instruction Fuzzy Hash: 1BD107B490430AEFDB20DF90D888F9ABB79BF04700F158195E514AF2A2D779DA84CF65
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • SetFileAttributesW.KERNELBASE(00000000,00000080,?,00000000,?,?,?), ref: 0093E3CD
                                          • CreateFileW.KERNELBASE(00000000,40000000,00000000,00000000,00000003,00000000,00000000,?,00000000,?,?,?), ref: 0093E3E5
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$AttributesCreate
                                          • String ID:
                                          • API String ID: 415043291-0
                                          • Opcode ID: f9f70be2dea0b5d0f7ddaa0cd56d3ca79f644c5b97c66e15a69a7631cdb00a14
                                          • Instruction ID: 0112075998749da9b1d311b8d3356eca31ace2814d03f6ed067f8f21875b5270
                                          • Opcode Fuzzy Hash: f9f70be2dea0b5d0f7ddaa0cd56d3ca79f644c5b97c66e15a69a7631cdb00a14
                                          • Instruction Fuzzy Hash: 7A119E30908208FBEB218B50EC0DBBDBB78EB48722F208226F521650F0D3756A91EE45
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • MoveFileExW.KERNELBASE(00000000,00000000,00000008,00000000,00000000,00000000,00000000,?,00000000,?), ref: 0093EFEF
                                          • CreateFileW.KERNELBASE(00000000,C0000000,00000000,00000000,00000003,40000000,00000000,00000000,?,00000000,?), ref: 0093F066
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$CreateMove
                                          • String ID:
                                          • API String ID: 3198096935-0
                                          • Opcode ID: c24d54f8cc32ade8baff8ff89289af47bbb52f35d11eac606feba674c5c69fb2
                                          • Instruction ID: 00382e1ba01d345a77531475e563ae309d2dc0c12a56dc53d2e2f0a563636912
                                          • Opcode Fuzzy Hash: c24d54f8cc32ade8baff8ff89289af47bbb52f35d11eac606feba674c5c69fb2
                                          • Instruction Fuzzy Hash: E1F09A30E04208FADF215B99EC15FADBB71EB44322F2081B2F611B40E1C7761A91EF04
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • GetLogicalDriveStringsW.KERNELBASE(00000104,?), ref: 0093747F
                                          • GetDriveTypeW.KERNELBASE(?), ref: 00937495
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Drive$LogicalStringsType
                                          • String ID:
                                          • API String ID: 1630765265-0
                                          • Opcode ID: e731216a2ce08f7340c6fa73e2751455fd4a1bbc040a6c6d516fd99d8e77e8dd
                                          • Instruction ID: 6973706bab8f4c9c8968c185ec5bd47cf82415691e9e93755145b2b191e7bf8c
                                          • Opcode Fuzzy Hash: e731216a2ce08f7340c6fa73e2751455fd4a1bbc040a6c6d516fd99d8e77e8dd
                                          • Instruction Fuzzy Hash: 0DE02BB25087195BDB30A6D5ACCD9EBF7AECB05301F000150EE44D2021DB54BD86CEE2
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CloseServiceHandle.SECHOST(00000000), ref: 00938EAD
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 00938EBC
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CloseHandleService
                                          • String ID:
                                          • API String ID: 1725840886-0
                                          • Opcode ID: ffca8dac9d2363e82f3176f438170e696359b75f9b01c5be1650c181675238e4
                                          • Instruction ID: 7aa15a1e1df79112776e7b623869a7f8ee8cac9cab007a8984ba6cc21f3f8910
                                          • Opcode Fuzzy Hash: ffca8dac9d2363e82f3176f438170e696359b75f9b01c5be1650c181675238e4
                                          • Instruction Fuzzy Hash: D6F01570905308EBEB21EB90DD48BAEBBB8EF00306F600095F801A10A0CB750E84EF12
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • SetFileAttributesW.KERNELBASE(00000000,00000080,?,00000000,?,?,?), ref: 0093E3CD
                                          • CreateFileW.KERNELBASE(00000000,40000000,00000000,00000000,00000003,00000000,00000000,?,00000000,?,?,?), ref: 0093E3E5
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: File$AttributesCreate
                                          • String ID:
                                          • API String ID: 415043291-0
                                          • Opcode ID: cede53f70fd64852a2410ac2f27ff1e3c81a14dac6b7b735e4f8766e4061979b
                                          • Instruction ID: 872a80d2fe46adefc086b466541b7e619f0e99652833079799cf4bbb5e75806a
                                          • Opcode Fuzzy Hash: cede53f70fd64852a2410ac2f27ff1e3c81a14dac6b7b735e4f8766e4061979b
                                          • Instruction Fuzzy Hash: 32E04F30685704FAEF325B20EC19F683A25AB08B61F604521FA11A80F0D7B4AE51EF09
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateThread
                                          • String ID:
                                          • API String ID: 2422867632-0
                                          • Opcode ID: 57cf685265a1f3d4249e1060d31f6c254b8764efe1c646dba8362cfc9f12d8d5
                                          • Instruction ID: 5ca08055696551a0fd595dedec50f0750766e380b19b8e66461fffd94a7dd6b0
                                          • Opcode Fuzzy Hash: 57cf685265a1f3d4249e1060d31f6c254b8764efe1c646dba8362cfc9f12d8d5
                                          • Instruction Fuzzy Hash: 3A617730D1470AEFDF109FE1DC85FAEBB78EB84306F204125E601662A1E7756A55EF90
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlCreateHeap.NTDLL(00041002,00000000,00000000,00000000,00000000,00000000,E80C4717,?,?,00949487), ref: 009363C5
                                            • Part of subcall function 0093B444: NtSetInformationThread.NTDLL(00000000,?,00000000,00000000,?,00936541,00000000,0095586C,00936390,00000000,00000000,00955858,00936378,00000000,00000000,0095584C), ref: 0093B465
                                            • Part of subcall function 0093B470: NtProtectVirtualMemory.NTDLL(000000FF,00000000,00000020,00000040,?,9870B143), ref: 0093B4B1
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateHeapInformationMemoryProtectThreadVirtual
                                          • String ID:
                                          • API String ID: 2986011945-0
                                          • Opcode ID: 4dc3bd9a81435dbae81cd187c275b9ea8222a278e009e452d8812d2fca1347d5
                                          • Instruction ID: 178eb337aed080d6c73963927824efb135fd568c944a386d461c1dae2f321856
                                          • Opcode Fuzzy Hash: 4dc3bd9a81435dbae81cd187c275b9ea8222a278e009e452d8812d2fca1347d5
                                          • Instruction Fuzzy Hash: 67318621386FB078407172A76C1FF8F1C6C8DDAF6AFD38114B928A51D789906404CEBA
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • OpenSCManagerW.ADVAPI32(00000000,00000000,00000004), ref: 00937CBF
                                            • Part of subcall function 00936844: RtlAllocateHeap.NTDLL(?,00000008,00000000,?,00947764,?,00000000,00000000), ref: 00936860
                                            • Part of subcall function 0093DC60: NtTerminateProcess.NTDLL(00937DB8,00000000), ref: 0093DCC3
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeapManagerOpenProcessTerminate
                                          • String ID:
                                          • API String ID: 3645570960-0
                                          • Opcode ID: c13f81cb653cfc4a80f60ddf4c35fc5005424d3811c632506efcdc0456f5f93a
                                          • Instruction ID: c815e1d0d774bacb65a10b6af728f9dcc19b4730f21a4e7399b1eb8d5f4857a0
                                          • Opcode Fuzzy Hash: c13f81cb653cfc4a80f60ddf4c35fc5005424d3811c632506efcdc0456f5f93a
                                          • Instruction Fuzzy Hash: 62411270955208FBEB219BD1DC4ABEDBBB9EF08702F504064F610BA0E1D7B15A90EF50
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 00935C24: FindFirstFileW.KERNELBASE(?,?,?,00000004,?), ref: 00935CF7
                                            • Part of subcall function 00935C24: FindClose.KERNELBASE(000000FF,?,00000000), ref: 00935D1C
                                          • RtlAllocateHeap.NTDLL(?,00000000,00000010,00000000,00000000,00000000,00000000,?,?,00936408,0095540C,00935EE8,00000000,00000000,7E631824), ref: 00935DE4
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Find$AllocateCloseFileFirstHeap
                                          • String ID:
                                          • API String ID: 1673784098-0
                                          • Opcode ID: 6aa6ab6f3a8d40e69fdb75059b62d8e3266041796467851bdc4e4ca92ca89f1e
                                          • Instruction ID: ad0720956b76ca047e3c92a28d2d9a6c80139c92deb1e53117f7745ff5eba03b
                                          • Opcode Fuzzy Hash: 6aa6ab6f3a8d40e69fdb75059b62d8e3266041796467851bdc4e4ca92ca89f1e
                                          • Instruction Fuzzy Hash: 253109356087029ED720CF688880755FA94BF49311F19C7A9E109CF2A3EAB1C4C0CF97
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                            • Part of subcall function 0093903C: RtlAdjustPrivilege.NTDLL(00000014,00000001,00000000,00000000), ref: 0093905E
                                          • CloseServiceHandle.ADVAPI32(00000000), ref: 009391AF
                                            • Part of subcall function 0093DC60: NtTerminateProcess.NTDLL(00937DB8,00000000), ref: 0093DCC3
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AdjustCloseHandlePrivilegeProcessServiceTerminate
                                          • String ID:
                                          • API String ID: 3176663195-0
                                          • Opcode ID: 85947803332816aa0ba2f466141fe30b9a4bda26aa2505381f991e68bb7c2747
                                          • Instruction ID: cd10eab83990fcdd9ec291209ff1781aad408b2eea66b8eedab0f44e865305a6
                                          • Opcode Fuzzy Hash: 85947803332816aa0ba2f466141fe30b9a4bda26aa2505381f991e68bb7c2747
                                          • Instruction Fuzzy Hash: 51317670914308EFEB109FA1DC4DBCDBBB9AF04706F4140A4E600BA1E1D7B59A84EF10
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: fff89d4659a1a4661fadeb582b8fdf79cebf5141ae187900de1526951d513a75
                                          • Instruction ID: 24d54fe78e9ac0c177b5a426246ff490a37d41430672cfdedd3a022a75b96856
                                          • Opcode Fuzzy Hash: fff89d4659a1a4661fadeb582b8fdf79cebf5141ae187900de1526951d513a75
                                          • Instruction Fuzzy Hash: 85213630955208FFDF109F94DC46BADBBB4FF15306F2190B8E904AA2A2E7314A90EF44
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CoInitialize.OLE32(00000000,?,?,?,?,00000000), ref: 0093F85B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Initialize
                                          • String ID:
                                          • API String ID: 2538663250-0
                                          • Opcode ID: 08873ed78a7d5e9efe7c8c0a06055be82484ae0afef2efb9a7b0f341d7925f07
                                          • Instruction ID: 9b54b5415507b6f02401533844ed4456b8b075a0082249d16ea7e7f6e8bf634c
                                          • Opcode Fuzzy Hash: 08873ed78a7d5e9efe7c8c0a06055be82484ae0afef2efb9a7b0f341d7925f07
                                          • Instruction Fuzzy Hash: 98C114B494030AEFDB10DFA0D958B9ABBBCEF04701F1180A5E505AF2A2D739DA44DF65
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CreateMutexW.KERNELBASE(0000000C,00000001,00000000), ref: 00939C4B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CreateMutex
                                          • String ID:
                                          • API String ID: 1964310414-0
                                          • Opcode ID: eecba4bed4c91c47b9a20c7f58e6eb118b303bc08a5461a93236232f533100c2
                                          • Instruction ID: 96b748383721d76005bf097c5e5691354ab1348bedaa25214a6c5bf099d8ad8f
                                          • Opcode Fuzzy Hash: eecba4bed4c91c47b9a20c7f58e6eb118b303bc08a5461a93236232f533100c2
                                          • Instruction Fuzzy Hash: F5118E7081CB04EFEB11ABA2EC19B697FB5AB08306F100055F544991F2E3B59940FF48
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAdjustPrivilege.NTDLL(00000014,00000001,00000000,00000000), ref: 0093905E
                                            • Part of subcall function 009397D8: NtQuerySystemInformation.NTDLL(00000005,?,00000400,00000400,00000400), ref: 00939805
                                            • Part of subcall function 00939880: NtClose.NTDLL(00000000), ref: 00939971
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AdjustCloseInformationPrivilegeQuerySystem
                                          • String ID:
                                          • API String ID: 327775174-0
                                          • Opcode ID: f085b6511753999fca33a0d2313426a6c6e7b8c0542b4c53651a211c00d8e15f
                                          • Instruction ID: 1190db8dbc2883b982dacf171e61c9d4b762d1e5849627b446e20c3652e089a3
                                          • Opcode Fuzzy Hash: f085b6511753999fca33a0d2313426a6c6e7b8c0542b4c53651a211c00d8e15f
                                          • Instruction Fuzzy Hash: 98016770914308BFEF20AFA5CC4DFDD7AB89B40716F104194B505A61E1E7F54A84DB91
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAdjustPrivilege.NTDLL(00000000,00000001,00000000,?), ref: 0093B727
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AdjustPrivilege
                                          • String ID:
                                          • API String ID: 3260937286-0
                                          • Opcode ID: f24c4c67561a6030883d1f84f5b575fd809178973b55be3ad962caa1b5a268f3
                                          • Instruction ID: d994b519757de6888fa9120fed7ccf5b507fa707b75e5722ce65dfdfff2f2527
                                          • Opcode Fuzzy Hash: f24c4c67561a6030883d1f84f5b575fd809178973b55be3ad962caa1b5a268f3
                                          • Instruction Fuzzy Hash: 6AD02B3111820566C73016546C42BF6335DC780321F100311EF03DB5D0FB5659444AE1
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlReAllocateHeap.NTDLL(?,00000008,?,00000400,?,00939825,?,00000400), ref: 009368B3
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeap
                                          • String ID:
                                          • API String ID: 1279760036-0
                                          • Opcode ID: 038a3d4ca44fea0efa475d996e72b873770cc02deba23649a2b60ce993ba68ac
                                          • Instruction ID: 9b88d0dca59d50f7e4ec5a6174e0067da695d25f9087382510a4ad362d7969c2
                                          • Opcode Fuzzy Hash: 038a3d4ca44fea0efa475d996e72b873770cc02deba23649a2b60ce993ba68ac
                                          • Instruction Fuzzy Hash: EBD0C935144708AFCB55AF98EC09FCA7B69BB54701F41C051FA848A072CB76D9A4EF90
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAllocateHeap.NTDLL(?,00000008,00000000,?,00947764,?,00000000,00000000), ref: 00936860
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: AllocateHeap
                                          • String ID:
                                          • API String ID: 1279760036-0
                                          • Opcode ID: 47496959f2a7d3dca7285aa06e32ee6057c2a08f3c914a1deb16351b018d7cf7
                                          • Instruction ID: fd9fb016d956dc5bd5c41f9a8cfb5ee2f319148d6bb2d4d8de29a185fe550ede
                                          • Opcode Fuzzy Hash: 47496959f2a7d3dca7285aa06e32ee6057c2a08f3c914a1deb16351b018d7cf7
                                          • Instruction Fuzzy Hash: 45D01231154704AFC7549F59A945FD6376CAB14702F458015B7488B072CB75D8D0EF94
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlFreeHeap.NTDLL(?,00000000,00000000,?,009477F4,00000000), ref: 00936888
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: FreeHeap
                                          • String ID:
                                          • API String ID: 3298025750-0
                                          • Opcode ID: ef7bd304056f91b375fa4f5cca3214399a097ad8c2e48081640526c15f246c65
                                          • Instruction ID: f093450cce21ca6eaa0197d5535d49c3798c68144795d5dc26f3259455995570
                                          • Opcode Fuzzy Hash: ef7bd304056f91b375fa4f5cca3214399a097ad8c2e48081640526c15f246c65
                                          • Instruction Fuzzy Hash: 24D01231144704AFC7149F58E805FD6376CAB18705F854011B7494B0B2C775EC90EF98
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CheckTokenMembership.KERNELBASE(00000000,0093B4CC,?), ref: 0093B4ED
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: CheckMembershipToken
                                          • String ID:
                                          • API String ID: 1351025785-0
                                          • Opcode ID: 19750757d1681648216ce788af9a21f82b0de6f14c6770dca3af850ddd64eccc
                                          • Instruction ID: 87bf8a20d358752a7853445f561bd3f08c9f1a5e4fd02f619063d2b4dee538ae
                                          • Opcode Fuzzy Hash: 19750757d1681648216ce788af9a21f82b0de6f14c6770dca3af850ddd64eccc
                                          • Instruction Fuzzy Hash: 97C0123455520CA7D600D694EC46A59B36C9704A25F500390AD18922D2E7616F1056D5
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • GetDriveTypeW.KERNELBASE(?), ref: 0093A1B6
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: DriveType
                                          • String ID:
                                          • API String ID: 338552980-0
                                          • Opcode ID: dc0cc56e8d42b72319196ec1c78c05b3773a7f0e8ee40e6f9a9acaf17feaeb3e
                                          • Instruction ID: 2e5935e2cfe5fb52fb1092997ecca564e64b51d7d4401021f9655916671679e0
                                          • Opcode Fuzzy Hash: dc0cc56e8d42b72319196ec1c78c05b3773a7f0e8ee40e6f9a9acaf17feaeb3e
                                          • Instruction Fuzzy Hash: 5DB0123100420CA786005B42FC048857F5DD7102627004021F5040002197325462E694
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • CoInitialize.OLE32(00000000), ref: 00937853
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Initialize
                                          • String ID:
                                          • API String ID: 2538663250-0
                                          • Opcode ID: 429e448d15aa09c8d13d79e2ce3c459868ad36fbf0dd54da376b9c9b47291e50
                                          • Instruction ID: d316283a42d3ab681e8038a7b59da0463e5431163f2c4408ca8edb85ee30728e
                                          • Opcode Fuzzy Hash: 429e448d15aa09c8d13d79e2ce3c459868ad36fbf0dd54da376b9c9b47291e50
                                          • Instruction Fuzzy Hash: 498104B8810306DFC720DF90D988F8ABB78BF05354F56819895185F366C77ADA84CF66
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • Sleep.KERNELBASE(000000C8,?,?,0093E405,00000000,?,00000000,?,?,?), ref: 0093DE6B
                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID: Sleep
                                          • String ID:
                                          • API String ID: 3472027048-0
                                          • Opcode ID: 97f4304446c80a1fd38aff7cb51a718ceee8c7446c712768673f3c0594a407f3
                                          • Instruction ID: f0e71ee55b1357c711968a683121148d4ff5850a6de31725b852b128b6ec91f9
                                          • Opcode Fuzzy Hash: 97f4304446c80a1fd38aff7cb51a718ceee8c7446c712768673f3c0594a407f3
                                          • Instruction Fuzzy Hash: 7DD0A77120A30417DB207FF57CE190EFA0D6B50301F009133F60045112C9A1C8148A50
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 260e1e126d5493dd3c4f0ae73eaaabb7d2b01d6e051fade57e719fa2acfa8af1
                                          • Instruction ID: 46ae94e895ce9bfa84733ac11db8005f2f9439fe9cb3a3ca19a211e810f17a42
                                          • Opcode Fuzzy Hash: 260e1e126d5493dd3c4f0ae73eaaabb7d2b01d6e051fade57e719fa2acfa8af1
                                          • Instruction Fuzzy Hash: 74E12E7AA64E438BD728CF19E8C0625B3A2FB89341F19C538C65587B65C739F960DF80
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 5ae1b344ce7eabeca7d5a0e2004a9b7e15b356c338447e056007cc76e97bc746
                                          • Instruction ID: 2584949a11067ca9438b0adcedd27fecbf22ba0ba3d1efbf9d6826605f203ecc
                                          • Opcode Fuzzy Hash: 5ae1b344ce7eabeca7d5a0e2004a9b7e15b356c338447e056007cc76e97bc746
                                          • Instruction Fuzzy Hash: 7ED1E4719083818FC790CF29C58065AF7E5FFD8348F149A1EE9D9D3211E770EA998B82
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: da9637861bc93c1cbca62e619c1da33061a902a2b0a0a9ff19c2db053550d342
                                          • Instruction ID: e1c3d069cfd48592422ad11b02c4da70481b257bcbcdeb8b4290cbd9cfe0bc55
                                          • Opcode Fuzzy Hash: da9637861bc93c1cbca62e619c1da33061a902a2b0a0a9ff19c2db053550d342
                                          • Instruction Fuzzy Hash: 5ED12F7AE7494A8BDB14CF58ECD0A7AB372FB88341F098938C71197756C638AA11DF50
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: e9672ebb6c7f9dd1e6ddbae16509ddfb519d365b1a5490e6b8e8019c9705245a
                                          • Instruction ID: 4472f5f69a98398ad5b7cc125d051dc167155650b1f6d34401071f958fea1d44
                                          • Opcode Fuzzy Hash: e9672ebb6c7f9dd1e6ddbae16509ddfb519d365b1a5490e6b8e8019c9705245a
                                          • Instruction Fuzzy Hash: C0311826BCEB064AFF75E0D086417F7A21CE7107E0DED1953F96A136424C180D839F52
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: bae66bee8be32ffaddf11d54820448efa52005ec1867aae87598e9ba484a53fa
                                          • Instruction ID: 881b1f3d055f05ad6b9c971a9017a2b27b896079cd95da9978448d066e93b88f
                                          • Opcode Fuzzy Hash: bae66bee8be32ffaddf11d54820448efa52005ec1867aae87598e9ba484a53fa
                                          • Instruction Fuzzy Hash: 20311876A21A069BC328CF1AD884925F7B2FF9D311B15CA29C96987B91C734F950CF90
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Memory Dump Source
                                          • Source File: 00000000.00000002.2464445713.0000000000931000.00000020.00000001.01000000.00000003.sdmp, Offset: 00930000, based on PE: true
                                          • Associated: 00000000.00000002.2464380342.0000000000930000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464520430.000000000094A000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464580554.000000000094B000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464641356.0000000000954000.00000004.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464695239.0000000000956000.00000008.00000001.01000000.00000003.sdmpDownload File
                                          • Associated: 00000000.00000002.2464799347.0000000000957000.00000002.00000001.01000000.00000003.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_0_2_930000_Document.jbxd
                                          Yara matches
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 6e9e9d037a559c25274071be2e09c2d3cf2f15b9f66fb5d997d9d64617e40bf4
                                          • Instruction ID: c81cc427747d8c8861cf5bab7d3bacbbaeb610a6bb722fcc776f3a7b92173036
                                          • Opcode Fuzzy Hash: 6e9e9d037a559c25274071be2e09c2d3cf2f15b9f66fb5d997d9d64617e40bf4
                                          • Instruction Fuzzy Hash: 0BE04FBB20D3425FF92C951174533A7838BC380675E25849EE446DF1C0EF1BE8A52445
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Execution Graph

                                          Execution Coverage:32.4%
                                          Dynamic/Decrypted Code Coverage:0%
                                          Signature Coverage:1.3%
                                          Total number of Nodes:160
                                          Total number of Limit Nodes:1
                                          execution_graph 890 403983 893 40389c 890->893 902 402a78 893->902 897 403903 932 4022dc 897->932 938 4028ba 902->938 904 402a9e 904->897 907 4026c0 904->907 905 402af0 CreateMutexW 905->904 952 4024f8 907->952 909 402729 909->897 913 402f18 909->913 910 4026e7 CreateFileW 910->909 911 40270b ReadFile 910->911 911->909 914 402f2e 913->914 914->914 956 40227c FindFirstFileExW 914->956 915 402f67 CreateFileW 917 402f57 915->917 920 402faf 915->920 916 402faa 919 4030c5 NtFreeVirtualMemory 916->919 921 4030ed 916->921 917->915 917->916 918 402fb4 NtAllocateVirtualMemory 918->920 927 402fe8 918->927 919->916 920->918 920->927 922 4030f3 NtClose 921->922 923 4030ff 921->923 922->923 958 402e10 923->958 925 40311f 925->897 926 40304b WriteFile 926->927 928 403068 SetFilePointerEx 926->928 927->916 927->926 929 403095 SetFilePointerEx 927->929 928->926 928->927 929->927 933 402303 932->933 934 402335 GetShortPathNameW 933->934 935 402330 27 API calls 933->935 934->935 936 40235e 934->936 936->935 937 40246d ShellExecuteW 936->937 937->935 939 4028dd 938->939 942 402760 CreateFileW 939->942 943 4027da 942->943 944 402797 942->944 945 402802 943->945 946 4027f6 NtClose 943->946 944->943 950 4020bc 944->950 945->904 945->905 946->945 947 4027b7 947->943 948 4027c0 ReadFile 947->948 948->943 951 4020c8 RtlAllocateHeap 950->951 951->947 953 402512 952->953 955 402760 4 API calls 953->955 954 402522 954->909 954->910 955->954 957 4022af 956->957 957->917 960 402e2e 958->960 959 402e37 DeleteFileW 959->925 960->959 960->960 961 402e7c MoveFileExW 960->961 961->959 961->960 962 403956 963 403963 962->963 964 403976 962->964 971 4019d4 963->971 1009 4016b4 971->1009 974 4016b4 9 API calls 975 4019f4 974->975 976 4016b4 9 API calls 975->976 977 401a05 976->977 978 4016b4 9 API calls 977->978 979 401a16 978->979 980 4016b4 9 API calls 979->980 981 401a27 980->981 982 4016b4 9 API calls 981->982 983 401a38 982->983 984 401b70 RtlCreateHeap 983->984 985 401ba6 RtlCreateHeap 984->985 995 401ba1 984->995 986 401bcb 985->986 985->995 986->995 1057 401a40 986->1057 988 401c03 989 401a40 RtlAllocateHeap 988->989 988->995 990 401c59 989->990 991 401a40 RtlAllocateHeap 990->991 990->995 992 401caf 991->992 993 401a40 RtlAllocateHeap 992->993 992->995 994 401d05 993->994 994->995 996 401a40 RtlAllocateHeap 994->996 1001 402812 995->1001 1005 402836 995->1005 997 401d55 996->997 997->995 1062 401d94 997->1062 998 401d7a 1065 401dc2 998->1065 1002 402836 1001->1002 1003 402850 RtlAdjustPrivilege 1002->1003 1004 40284e 1002->1004 1003->1002 1003->1004 1004->964 1006 402849 1005->1006 1007 402850 RtlAdjustPrivilege 1006->1007 1008 40284e 1006->1008 1007->1006 1007->1008 1008->964 1010 40176f 1009->1010 1011 4016cf 1009->1011 1010->974 1012 4016f5 NtAllocateVirtualMemory 1011->1012 1035 401000 1011->1035 1012->1010 1014 40172f NtAllocateVirtualMemory 1012->1014 1014->1010 1016 401752 1014->1016 1020 40152c 1016->1020 1018 40175f 1018->1010 1019 401000 3 API calls 1018->1019 1019->1018 1021 401540 1020->1021 1022 401558 1020->1022 1023 401000 3 API calls 1021->1023 1024 401000 3 API calls 1022->1024 1025 40157e 1022->1025 1023->1022 1024->1025 1026 401000 3 API calls 1025->1026 1029 4015a4 1025->1029 1026->1029 1027 4015ed FindFirstFileExW 1027->1029 1028 40166c 1028->1018 1029->1027 1029->1028 1030 401649 FindNextFileW 1029->1030 1031 40162a FindClose 1029->1031 1030->1029 1033 40165d FindClose 1030->1033 1043 401474 1031->1043 1033->1029 1034 401641 1034->1018 1036 401012 1035->1036 1037 40102a 1035->1037 1038 401000 3 API calls 1036->1038 1039 401000 3 API calls 1037->1039 1040 401050 1037->1040 1038->1037 1039->1040 1041 4010fb 1040->1041 1046 401394 1040->1046 1041->1012 1044 40148a 1043->1044 1045 4014b8 LdrLoadDll 1044->1045 1045->1034 1047 4013ee 1046->1047 1048 4013be 1046->1048 1047->1041 1048->1047 1049 401474 LdrLoadDll 1048->1049 1050 4013d2 1049->1050 1050->1047 1050->1050 1052 4014d8 1050->1052 1053 4014ee 1052->1053 1054 40150f LdrGetProcedureAddress 1052->1054 1056 4014fa LdrGetProcedureAddress 1053->1056 1055 401521 1054->1055 1055->1047 1056->1055 1058 401a5d RtlAllocateHeap 1057->1058 1059 401a79 1058->1059 1060 401a85 1058->1060 1059->988 1060->1058 1061 401b5b 1060->1061 1061->988 1063 401da8 NtSetInformationThread 1062->1063 1063->998 1066 401de9 1065->1066 1067 401e12 1066->1067 1068 401df2 NtProtectVirtualMemory 1066->1068 1067->995 1068->1067 1083 402126 1084 402141 1083->1084 1085 4020bc RtlAllocateHeap 1084->1085 1086 402158 1084->1086 1085->1086 1069 4019b7 1070 4019e0 1069->1070 1071 4016b4 9 API calls 1069->1071 1072 4016b4 9 API calls 1070->1072 1071->1070 1073 4019f4 1072->1073 1074 4016b4 9 API calls 1073->1074 1075 401a05 1074->1075 1076 4016b4 9 API calls 1075->1076 1077 401a16 1076->1077 1078 4016b4 9 API calls 1077->1078 1079 401a27 1078->1079 1080 4016b4 9 API calls 1079->1080 1081 401a38 1080->1081 1082 40286c NtSetInformationProcess NtSetInformationProcess NtSetInformationProcess

                                          Callgraph

                                          • Executed
                                          • Not Executed
                                          • Opacity -> Relevance
                                          • Disassembly available
                                          callgraph 0 Function_004026C0 38 Function_004024F8 0->38 1 Function_00401A40 39 Function_00401E78 1->39 2 Function_00401DC2 3 Function_004024C2 4 Function_00402B44 5 Function_00403144 6 Function_00401FC8 7 Function_00401F4C 8 Function_0040204C 9 Function_00402B50 10 Function_00401350 71 Function_00401130 10->71 11 Function_00402ED0 12 Function_004024D4 13 Function_004019D4 76 Function_004016B4 13->76 14 Function_00403956 14->13 33 Function_00401B70 14->33 54 Function_00402812 14->54 78 Function_00402836 14->78 15 Function_00403258 16 Function_004014D8 81 Function_00401438 16->81 17 Function_00401FDB 18 Function_004022DC 19 Function_0040205C 20 Function_00401F5C 21 Function_004020DE 22 Function_00402760 83 Function_004020BC 22->83 23 Function_004031E0 24 Function_00402264 25 Function_00401EE4 26 Function_004032E4 27 Function_004032E8 28 Function_00401868 29 Function_0040286C 30 Function_00401F6C 31 Function_00401B6E 32 Function_00401FEF 33->1 33->2 55 Function_00401D94 33->55 34 Function_00401472 35 Function_00401474 41 Function_004013F8 35->41 36 Function_004013F6 37 Function_00402A78 82 Function_004028BA 37->82 38->22 62 Function_00401E28 39->62 40 Function_00403478 42 Function_0040227C 43 Function_0040217C 44 Function_00402BFC 45 Function_00401000 45->7 45->10 45->25 45->45 56 Function_00401394 45->56 73 Function_00401EB0 45->73 46 Function_00402D80 47 Function_00403983 60 Function_0040389C 47->60 48 Function_00402003 49 Function_00402104 50 Function_00402C88 51 Function_00402E10 52 Function_00401190 52->71 53 Function_00401911 56->16 56->35 57 Function_00402017 58 Function_00402F18 58->42 58->51 59 Function_00401F9A 60->0 60->18 60->37 60->58 61 Function_00402126 61->83 63 Function_00402DA8 64 Function_0040152A 65 Function_0040202A 66 Function_0040152C 66->19 66->25 66->35 66->45 67 Function_00401F2C 66->67 68 Function_004018AD 69 Function_0040362E 70 Function_00401EAE 72 Function_00403230 74 Function_00401FB1 75 Function_004016B2 76->39 76->45 76->66 77 Function_00402234 79 Function_00401436 80 Function_004019B7 80->76 82->22 84 Function_00401A3E

                                          Control-flow Graph

                                          APIs
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: Text$Color$CreateWindow$Proc$CommandFontFreeHandleLibraryLineLoadMenuModule$AddressBitmapCharsetErrorExitInfoLastLocaleObjectProcessSelect
                                          • String ID:
                                          • API String ID: 3548022523-0
                                          • Opcode ID: 75a7f395dfd15dd6a7f12e7587c497a330da91454d241e242464d6c2316bf13f
                                          • Instruction ID: 44f13d8dc4ada08d969f55db554330e9d88bd117b0c18836a0928b418f5903af
                                          • Opcode Fuzzy Hash: 75a7f395dfd15dd6a7f12e7587c497a330da91454d241e242464d6c2316bf13f
                                          • Instruction Fuzzy Hash: 89F0B724B651416AC500BFFB9947A0D6E2C6E8472BB50657EB0C1344E74D3C87009EAF
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 3 402f18-402f2b 4 402f2e-402f33 3->4 4->4 5 402f35-402f5b call 40227c 4->5 7 402f67-402f8c CreateFileW 5->7 8 402f5d-402f61 5->8 9 402f8e-402f96 7->9 10 402faf-402fb1 7->10 8->7 11 4030bb-4030bd 8->11 12 402f98-402fa6 9->12 13 402faa 9->13 14 402fb4-402fe0 NtAllocateVirtualMemory 10->14 15 4030c0-4030c3 11->15 12->13 27 402fa8 12->27 13->11 16 402fe2-402fed 14->16 17 402fe8 14->17 18 4030c5-4030e4 NtFreeVirtualMemory 15->18 19 4030e7-4030eb 15->19 28 403000-403003 16->28 29 402fef-402ffe 16->29 22 40301b-403020 17->22 18->19 19->15 23 4030ed-4030f1 19->23 26 403023-40302e 22->26 24 4030f3-4030fc NtClose 23->24 25 4030ff-40311d call 402e10 DeleteFileW 23->25 24->25 36 403126-40312a 25->36 37 40311f 25->37 30 403030-40303a 26->30 31 40303c 26->31 27->7 32 403015-403019 28->32 33 403005-403010 28->33 29->32 35 403041-403048 30->35 31->35 32->14 32->22 33->32 38 40304b-403064 WriteFile 35->38 39 403138-403141 36->39 40 40312c-403132 36->40 37->36 41 403066 38->41 42 403068-403088 SetFilePointerEx 38->42 40->39 43 40308a-403091 41->43 42->38 42->43 44 403093 43->44 45 403095-4030b6 SetFilePointerEx 43->45 44->11 45->26
                                          APIs
                                          • CreateFileW.KERNELBASE(?,40000000,00000003,00000000,00000003,80000000,00000000), ref: 00402F82
                                          • NtAllocateVirtualMemory.NTDLL(000000FF,00000000,00000000,00010000,00001000,00000004), ref: 00402FDB
                                          • WriteFile.KERNELBASE(000000FF,00000000,00010000,00010000,00000000), ref: 0040305F
                                          • SetFilePointerEx.KERNELBASE(000000FF,00010000,?,00000000,00000001), ref: 0040307E
                                          • SetFilePointerEx.KERNELBASE(000000FF,00010000,00000000,00000000,00000000,?,00000000,00000001), ref: 004030B3
                                          • NtFreeVirtualMemory.NTDLL(000000FF,00000000,00010000,00008000,?,00000000,00000001), ref: 004030E4
                                          • NtClose.NTDLL(000000FF,?,00000000,00000001), ref: 004030FC
                                          • DeleteFileW.KERNELBASE(?,?,00000000,00000001), ref: 00403118
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: File$MemoryPointerVirtual$AllocateCloseCreateDeleteFreeWrite
                                          • String ID:
                                          • API String ID: 590822095-0
                                          • Opcode ID: 52122dafd602033dbf0aaa267e6343e8fb4df09450a7f36494692c9b8865e816
                                          • Instruction ID: 1b8bdb635f3090c090aca30f1047892238d11e79f8ef36d2dcee79009cce4089
                                          • Opcode Fuzzy Hash: 52122dafd602033dbf0aaa267e6343e8fb4df09450a7f36494692c9b8865e816
                                          • Instruction Fuzzy Hash: ED714871901209AFDB11CF90DD48BEEBB79FB08311F204266E511B62D4D3759E85CF99
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          APIs
                                          • FindFirstFileExW.KERNELBASE(C:\Windows\System32\*.dll,00000000,?,00000000,00000000,00000000), ref: 00401601
                                          • FindClose.KERNELBASE(000000FF,?,00000000), ref: 0040162D
                                          • FindNextFileW.KERNELBASE(000000FF,?,?,00000000), ref: 00401653
                                          • FindClose.KERNEL32(000000FF), ref: 00401660
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: Find$CloseFile$FirstNext
                                          • String ID: C:\Windows\System32\*.dll
                                          • API String ID: 1164774033-1305136377
                                          • Opcode ID: bdb8730289e2ca857be386bc3c3ab385330ed8d95a663a52d2d02b9110bb0279
                                          • Instruction ID: b8f602421e8d3e3309feb9384621a56ef9d54da146c7d7394d3b11ea37959a12
                                          • Opcode Fuzzy Hash: bdb8730289e2ca857be386bc3c3ab385330ed8d95a663a52d2d02b9110bb0279
                                          • Instruction Fuzzy Hash: 30418C71900608EFDB20AFA4DD48BAA77B4FB44325F608276E521BE1F0D7794A85DF48
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 82 402760-402795 CreateFileW 83 4027f0-4027f4 82->83 84 402797-4027a9 82->84 85 402802-40280b 83->85 86 4027f6-4027ff NtClose 83->86 84->83 88 4027ab-4027be call 4020bc 84->88 86->85 88->83 90 4027c0-4027d8 ReadFile 88->90 91 4027e4-4027ea 90->91 92 4027da-4027e2 90->92 91->83 92->83
                                          APIs
                                          • CreateFileW.KERNELBASE(?,80000000,00000001,00000000,00000003,00000080,00000000), ref: 0040278B
                                          • ReadFile.KERNELBASE(000000FF,00000000,00000000,00000000,00000000), ref: 004027D3
                                          • NtClose.NTDLL(000000FF), ref: 004027FF
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: File$CloseCreateRead
                                          • String ID:
                                          • API String ID: 1419693385-0
                                          • Opcode ID: da89fd3cbdd23a7ddbe5d8b9f381f279ea58f3e72d3b71a90626c9ff8252170d
                                          • Instruction ID: da411bd40fb0d6d878d2d447c4e829303a7e8bd202b0d35ae7576ead56d2946b
                                          • Opcode Fuzzy Hash: da89fd3cbdd23a7ddbe5d8b9f381f279ea58f3e72d3b71a90626c9ff8252170d
                                          • Instruction Fuzzy Hash: CA211A35601209EBDB10CF94DD89B9EBB75FF08310F2082A5A510AB2E1D7719E51DF94
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 94 40286c-4028b9 NtSetInformationProcess * 3
                                          APIs
                                          • NtSetInformationProcess.NTDLL(000000FF,00000021,?,00000004), ref: 00402888
                                          • NtSetInformationProcess.NTDLL(000000FF,00000012,00000000,00000002,?,00000004), ref: 0040289D
                                          • NtSetInformationProcess.NTDLL(000000FF,0000000C,00000000,00000004,?,00000004), ref: 004028B5
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: InformationProcess
                                          • String ID:
                                          • API String ID: 1801817001-0
                                          • Opcode ID: b71ac733508e6e437ba76d930e61bde730921b23b00966883a2217b3d9eaec84
                                          • Instruction ID: 48adbd17ca007e7691ff2066b81a5959555298f4bd9a539b6f325b5cfe831ef7
                                          • Opcode Fuzzy Hash: b71ac733508e6e437ba76d930e61bde730921b23b00966883a2217b3d9eaec84
                                          • Instruction Fuzzy Hash: 2BF0F871141610EBEB15DB84DDC9F9637A8FB09720F2403A1F2319E1E6D3B0A484CF96
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 95 401dc2-401df0 97 401e21-401e27 95->97 98 401df2-401e10 NtProtectVirtualMemory 95->98 98->97 99 401e12-401e1f 98->99 99->97
                                          APIs
                                          • NtProtectVirtualMemory.NTDLL(000000FF,00000000,00000020,00000040,?), ref: 00401E0B
                                          Strings
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: MemoryProtectVirtual
                                          • String ID:
                                          • API String ID: 2706961497-3916222277
                                          • Opcode ID: 743ccc95185ac25335bad8a24ea2ffb6d91b2a6f6c30658889cc31c7cdbad58c
                                          • Instruction ID: 836d3446d31acb3b31e0b6cd8f4ee088cd02c28435d2c0c4ff934eaabbb3754d
                                          • Opcode Fuzzy Hash: 743ccc95185ac25335bad8a24ea2ffb6d91b2a6f6c30658889cc31c7cdbad58c
                                          • Instruction Fuzzy Hash: 72F03176500109ABDB00CF95D988BDFB7BCEB44324F2042A9EA14A72D1D7355E458B94
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 180 4016b4-4016c9 181 401859-401862 180->181 182 4016cf-4016d6 180->182 183 4016f5-401729 NtAllocateVirtualMemory 182->183 184 4016d8-4016f0 call 401000 182->184 183->181 186 40172f-40174c NtAllocateVirtualMemory 183->186 184->183 186->181 188 401752-40175a call 40152c 186->188 190 40175f-401761 188->190 190->181 191 401767-40176d 190->191 192 401774-401781 call 401000 191->192 193 40176f 191->193 196 401851-401854 192->196 197 401787-401798 call 401e78 192->197 193->181 196->191 200 4017c9-4017cc 197->200 201 40179a-4017c4 call 401e78 197->201 203 4017fa-4017fd 200->203 204 4017ce-4017f8 call 401e78 200->204 201->196 205 401815-401818 203->205 206 4017ff-401813 203->206 204->196 210 401830-401833 205->210 211 40181a-40182e 205->211 206->196 210->196 212 401835-40184b 210->212 211->196 212->196
                                          APIs
                                          • NtAllocateVirtualMemory.NTDLL(000000FF,00000000,00000000,?,00103000,00000040), ref: 0040171F
                                          • NtAllocateVirtualMemory.NTDLL(000000FF,00000000,00000000,00000000,00103000,00000004), ref: 00401742
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: AllocateMemoryVirtual
                                          • String ID:
                                          • API String ID: 2167126740-0
                                          • Opcode ID: 4a0fb159cb167e270aa132b3f88ebad20637f68d71e3a3db65f788631af4fc76
                                          • Instruction ID: ad4b5e7ce53ce887a57ee0cc443bca07838dd3003dcb7b2c4dfa2ad75add82e8
                                          • Opcode Fuzzy Hash: 4a0fb159cb167e270aa132b3f88ebad20637f68d71e3a3db65f788631af4fc76
                                          • Instruction Fuzzy Hash: E3416031904204DADF10EF58C884B9AB7A4FF05314F14C1BAE919EF2E6D7788A41CB6A
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 288 40227c-4022ad FindFirstFileExW 289 4022d2-4022d8 288->289 290 4022af-4022cf 288->290 290->289
                                          APIs
                                          • FindFirstFileExW.KERNELBASE(?,00000000,?,00000000,00000000,00000000), ref: 004022A4
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: FileFindFirst
                                          • String ID:
                                          • API String ID: 1974802433-0
                                          • Opcode ID: cdec62c82a5867c9461e13d27f073131a42764883e1863d73d8ab6d37f0e38bf
                                          • Instruction ID: 55f0629c3eadcc188d8749e42e063c0b49bca1bc4f8f265f590f61ae6da82bee
                                          • Opcode Fuzzy Hash: cdec62c82a5867c9461e13d27f073131a42764883e1863d73d8ab6d37f0e38bf
                                          • Instruction Fuzzy Hash: BBF0C974902608EFDB10DF94CD49B9DFBB4EB48310F2082A5A918AB2A0D7715E91CF84
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • NtSetInformationThread.NTDLL(00000000,?,00000000,00000000), ref: 00401DBB
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: InformationThread
                                          • String ID:
                                          • API String ID: 4046476035-0
                                          • Opcode ID: 2ec57d8305034ae4dcd04f6f280aec29aa5e37325b0f502564d07dd60a6e8475
                                          • Instruction ID: 482b214da63c1bafeb7c1bb62a0bbbc62c262419b9af6fea3894fce228737229
                                          • Opcode Fuzzy Hash: 2ec57d8305034ae4dcd04f6f280aec29aa5e37325b0f502564d07dd60a6e8475
                                          • Instruction Fuzzy Hash: FEE05E329A020DAFD710DB50DC45FBB376DEB55311F508236B5029A1E0D6B8F891DA98
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 100 401b70-401b9f RtlCreateHeap 101 401ba1 100->101 102 401ba6-401bc4 RtlCreateHeap 100->102 103 401d8a-401d90 101->103 104 401bc6 102->104 105 401bcb-401be7 102->105 104->103 107 401be9 105->107 108 401bee-401c05 call 401a40 105->108 107->103 111 401c07 108->111 112 401c0c-401c3d 108->112 111->103 115 401c44-401c5b call 401a40 112->115 116 401c3f 112->116 119 401c62-401c93 115->119 120 401c5d 115->120 116->103 123 401c95 119->123 124 401c9a-401cb1 call 401a40 119->124 120->103 123->103 127 401cb3 124->127 128 401cb8-401ce9 124->128 127->103 131 401cf0-401d07 call 401a40 128->131 132 401ceb 128->132 135 401d09 131->135 136 401d0b-401d3c 131->136 132->103 135->103 139 401d40-401d57 call 401a40 136->139 140 401d3e 136->140 143 401d59 139->143 144 401d5b-401d80 call 401d94 call 401dc2 139->144 140->103 143->103 147 401d83 144->147 147->103
                                          APIs
                                          • RtlCreateHeap.NTDLL(00001002,00000000,00000000,00000000,00000000,00000000), ref: 00401B96
                                          • RtlCreateHeap.NTDLL(00041002,00000000,00000000,00000000,00000000,00000000), ref: 00401BBB
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: CreateHeap
                                          • String ID:
                                          • API String ID: 10892065-0
                                          • Opcode ID: 453bda9d08a0096fe53e6a5bcc4a475ef93f8d776735eeddf63228c397926240
                                          • Instruction ID: eac1ce902914894448f3c06d12ced00cbe17960004271ddceb971b2a38276b5e
                                          • Opcode Fuzzy Hash: 453bda9d08a0096fe53e6a5bcc4a475ef93f8d776735eeddf63228c397926240
                                          • Instruction Fuzzy Hash: 34513034A80A04FBD7109B60ED09B5B7770FF18701F2086BAE6117A2F1D775A5859F8D
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 150 4022dc-40232e 154 402330 150->154 155 402335-402347 GetShortPathNameW 150->155 156 402483-402487 154->156 157 402349-402359 155->157 158 40235e-402380 155->158 159 402495-402499 156->159 160 402489-40248f 156->160 157->156 168 402382 158->168 169 402387-402425 158->169 163 4024a7-4024ab 159->163 164 40249b-4024a1 159->164 160->159 165 4024b9-4024bf 163->165 166 4024ad-4024b3 163->166 164->163 166->165 168->156 175 402427 169->175 176 402429-402481 ShellExecuteW 169->176 175->156 176->156
                                          APIs
                                          • GetShortPathNameW.KERNELBASE(00000000,00000000,?), ref: 00402340
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: NamePathShort
                                          • String ID:
                                          • API String ID: 1295925010-0
                                          • Opcode ID: a0a4f684a9d9108a63d91a30c19249ae39ae68594d14297edb71c581cb82e24b
                                          • Instruction ID: 5bcac900e59d09c9622bdf940851d370624af246baed8abb1bc217228d1f7e1b
                                          • Opcode Fuzzy Hash: a0a4f684a9d9108a63d91a30c19249ae39ae68594d14297edb71c581cb82e24b
                                          • Instruction Fuzzy Hash: B6514E75900606EFDB00DF90E948B9EFB71FF48301F2082A9E6156B2A1C375AA91DFC5
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 213 4026c0-4026e5 call 4024f8 215 402730-402734 213->215 216 4026e7-402709 CreateFileW 213->216 218 402742-402746 215->218 219 402736-40273c 215->219 216->215 217 40270b-402727 ReadFile 216->217 217->215 220 402729 217->220 221 402754-40275a 218->221 222 402748-40274e 218->222 219->218 220->215 222->221
                                          APIs
                                          • CreateFileW.KERNELBASE(00000000,80000000,00000001,00000000,00000003,00000000,00000000), ref: 004026FF
                                          • ReadFile.KERNELBASE(000000FF,000000FF,0000021C,?,00000000), ref: 00402722
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: File$CreateRead
                                          • String ID:
                                          • API String ID: 3388366904-0
                                          • Opcode ID: 64d441af2ae5f8cd80c02da2bb5cacaba4a8c0a7bb8fd120945ed4e9a720f5dc
                                          • Instruction ID: dec784d2d3492f4c007a4c80bb83cd8b4abde05e7af7cfb80cb91198c32a9eba
                                          • Opcode Fuzzy Hash: 64d441af2ae5f8cd80c02da2bb5cacaba4a8c0a7bb8fd120945ed4e9a720f5dc
                                          • Instruction Fuzzy Hash: 7511D774910209EFDB10DF94DD48B9FBBB5FB08311F2046A9A524B62E1D7B15A91CF84
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 224 401a40-401a5a 225 401a5d-401a77 RtlAllocateHeap 224->225 226 401a85-401a94 call 401e78 225->226 227 401a79-401a82 225->227 230 401ac5-401ac8 226->230 231 401a96-401ac0 call 401e78 226->231 233 401af6-401af9 230->233 234 401aca-401af4 call 401e78 230->234 239 401b4d-401b55 231->239 237 401b11-401b14 233->237 238 401afb-401b0f 233->238 234->239 241 401b16-401b2a 237->241 242 401b2c-401b2f 237->242 238->239 239->225 243 401b5b-401b6b 239->243 241->239 242->239 244 401b31-401b47 242->244 244->239
                                          APIs
                                          • RtlAllocateHeap.NTDLL(00000000,00000008,00000010), ref: 00401A6D
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: AllocateHeap
                                          • String ID:
                                          • API String ID: 1279760036-0
                                          • Opcode ID: 3090814481001f51fad53404be7bb9f089635e5ecf5702693e45b6397da5dce2
                                          • Instruction ID: 68c0462a3af62cc3e50a8e225ecc1fff045641083c52707b2e4de1a33f1d8fac
                                          • Opcode Fuzzy Hash: 3090814481001f51fad53404be7bb9f089635e5ecf5702693e45b6397da5dce2
                                          • Instruction Fuzzy Hash: 9F316935A14308DFDB10CF99C488E99F7F1BF24320F15D0AAD508AB2B2D7B59950DB4A
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 245 402e10-402e35 247 402e37 245->247 248 402e39-402e4e 245->248 249 402eab-402eb7 247->249 253 402e50 248->253 254 402e52-402e57 248->254 250 402ec5-402eca 249->250 251 402eb9-402ebf 249->251 251->250 253->249 255 402e5c-402e6d 254->255 257 402e70-402e7a 255->257 257->257 258 402e7c-402e8f MoveFileExW 257->258 259 402e91 258->259 260 402e93-402ea9 258->260 259->249 260->249 260->255
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 2ec2b1c2d5d64686e5e6a52de2e159d7ebe58570cf782c44f0051c3652f2bf9a
                                          • Instruction ID: 64be472d3da9365df722bb42b6a14b0a0006b9682bbf08d732ce7ada7e71b141
                                          • Opcode Fuzzy Hash: 2ec2b1c2d5d64686e5e6a52de2e159d7ebe58570cf782c44f0051c3652f2bf9a
                                          • Instruction Fuzzy Hash: 8A214C71940208EFDB109F90DE49B9ABB71FF18301F2081BAE505AA2E1D3759E91DF89
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 262 402a78-402a9c call 4028ba 264 402aa3-402ac2 262->264 265 402a9e 262->265 270 402ac4-402ad3 264->270 271 402ad5-402ae0 264->271 266 402b28-402b2c 265->266 267 402b3a-402b40 266->267 268 402b2e-402b34 266->268 268->267 270->266 274 402ae2-402ae8 271->274 275 402aea 271->275 276 402af0-402b1f CreateMutexW 274->276 275->276 276->266 277 402b21 276->277 277->266
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID:
                                          • String ID:
                                          • API String ID:
                                          • Opcode ID: 76ac4189c2e983f292498be2e35779ead737e5081f8c929ef40d6d428a78efce
                                          • Instruction ID: 5f31ce468cef0475a522e9655e813cee8f96e501922e94d34a843d9ecc1c4f5f
                                          • Opcode Fuzzy Hash: 76ac4189c2e983f292498be2e35779ead737e5081f8c929ef40d6d428a78efce
                                          • Instruction Fuzzy Hash: A921F974901608EFDB00CF90EA8C79EBB71FF08301F6045A9E5017A2A0D7B95A85DF89
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          Control-flow Graph

                                          • Executed
                                          • Not Executed
                                          control_flow_graph 279 401474-401488 280 40148a-40148d 279->280 281 4014ac-4014b3 call 4013f8 279->281 282 401493-401498 280->282 285 4014b8-4014d2 LdrLoadDll 281->285 282->282 284 40149a-4014aa call 4013f8 282->284 284->285
                                          APIs
                                          • LdrLoadDll.NTDLL(00000000,00000000,00000000,?), ref: 004014C4
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: Load
                                          • String ID:
                                          • API String ID: 2234796835-0
                                          • Opcode ID: cc821bb6490c49b643c0aee4c8a66cc2fb92e167f5171f05bab2522af16bb81c
                                          • Instruction ID: 140de97a3c31e0856ca0b204e221eb1e366fb0b1d4fd9a07ba92ba20ce5f8dd4
                                          • Opcode Fuzzy Hash: cc821bb6490c49b643c0aee4c8a66cc2fb92e167f5171f05bab2522af16bb81c
                                          • Instruction Fuzzy Hash: F7F03C3690020DFADF10EAA4D848FDE77BCEB14314F0041A6E904B7190D238AA099BA5
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAdjustPrivilege.NTDLL(?,00000001,00000000,00000000), ref: 00402861
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: AdjustPrivilege
                                          • String ID:
                                          • API String ID: 3260937286-0
                                          • Opcode ID: b838e4be5c385c0dc624d50355c604d381d153ee0a89857c9e86ae645bc67477
                                          • Instruction ID: 70193a9dbc7aa9cd3770003b3bb97339f6e2972f30e24310785a39762e1cef45
                                          • Opcode Fuzzy Hash: b838e4be5c385c0dc624d50355c604d381d153ee0a89857c9e86ae645bc67477
                                          • Instruction Fuzzy Hash: B9E0263251821AABCB20A2189E0CBA7739DD744314F1043B6A805F71D1EAF69A0A87DA
                                          Uniqueness

                                          Uniqueness Score: -1.00%

                                          APIs
                                          • RtlAllocateHeap.NTDLL(?,00000008,?), ref: 004020D7
                                          Memory Dump Source
                                          • Source File: 00000008.00000002.2471485013.0000000000401000.00000040.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                          • Associated: 00000008.00000002.2471427837.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471555999.0000000000404000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471615085.0000000000405000.00000004.00000001.01000000.00000008.sdmpDownload File
                                          • Associated: 00000008.00000002.2471673552.0000000000406000.00000002.00000001.01000000.00000008.sdmpDownload File
                                          Joe Sandbox IDA Plugin
                                          • Snapshot File: hcaresult_8_2_400000_2172.jbxd
                                          Similarity
                                          • API ID: AllocateHeap
                                          • String ID:
                                          • API String ID: 1279760036-0
                                          • Opcode ID: 37c2d1e8b064bb17fe79b9677c4ca25dfdae977e826a45f6764b5f2e7935cd48
                                          • Instruction ID: 701e22a529f931561d5ec47da2ef603e250127bb9ab3ab4db12cbc5835053477
                                          • Opcode Fuzzy Hash: 37c2d1e8b064bb17fe79b9677c4ca25dfdae977e826a45f6764b5f2e7935cd48
                                          • Instruction Fuzzy Hash: 05D0C97A140609ABC6009F94E949D87F769FF58711B00C6A1BA045B222C630E890CFD4
                                          Uniqueness

                                          Uniqueness Score: -1.00%