Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://blogue.corim.qc.ca

Overview

General Information

Sample URL:https://blogue.corim.qc.ca
Analysis ID:1455421

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Snort IDS alert for network traffic
Stores files to the Windows start menu directory

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://blogue.corim.qc.ca/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5740 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=2008,i,16529732949000549158,12455434054195987808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
Timestamp:06/11/24-20:21:11.701171
SID:2053320
Source Port:49699
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected
Timestamp:06/11/24-20:21:11.701463
SID:2053320
Source Port:56997
Destination Port:53
Protocol:UDP
Classtype:A Network Trojan was detected

Click to jump to signature section

Show All Signature Results
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49751 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49753 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49755 version: TLS 1.2

Networking

barindex
Source: TrafficSnort IDS: 2053320 ET CURRENT_EVENTS TA569 Keitaro TDS Domain in DNS Lookup (moderncssframeworks .com) 192.168.2.16:49699 -> 1.1.1.1:53
Source: TrafficSnort IDS: 2053320 ET CURRENT_EVENTS TA569 Keitaro TDS Domain in DNS Lookup (moderncssframeworks .com) 192.168.2.16:56997 -> 1.1.1.1:53
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.209.189
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: global trafficDNS traffic detected: DNS query: blogue.corim.qc.ca
Source: global trafficDNS traffic detected: DNS query: moderncssframeworks.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49751 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49753 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49754 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49755 version: TLS 1.2
Source: classification engineClassification label: mal48.win@14/35@8/127
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://blogue.corim.qc.ca/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=2008,i,16529732949000549158,12455434054195987808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=2008,i,16529732949000549158,12455434054195987808,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://blogue.corim.qc.ca0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
blogue.corim.qc.ca
141.193.213.10
truefalse
    unknown
    moderncssframeworks.com
    158.160.11.208
    truefalse
      unknown
      www.google.com
      216.58.206.36
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://blogue.corim.qc.ca/false
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          1.1.1.1
          unknownAustralia
          13335CLOUDFLARENETUStrue
          216.58.206.78
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.185.110
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.185.227
          unknownUnited States
          15169GOOGLEUSfalse
          216.58.206.36
          www.google.comUnited States
          15169GOOGLEUSfalse
          141.193.213.10
          blogue.corim.qc.caUnited States
          396845DV-PRIMARY-ASN1USfalse
          172.217.23.110
          unknownUnited States
          15169GOOGLEUSfalse
          64.233.167.84
          unknownUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          172.217.23.99
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.185.72
          unknownUnited States
          15169GOOGLEUSfalse
          142.250.186.42
          unknownUnited States
          15169GOOGLEUSfalse
          IP
          192.168.2.16
          Joe Sandbox version:40.0.0 Tourmaline
          Analysis ID:1455421
          Start date and time:2024-06-11 20:20:40 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowsinteractivecookbook.jbs
          Sample URL:https://blogue.corim.qc.ca
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:14
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          Analysis Mode:stream
          Analysis stop reason:Timeout
          Detection:MAL
          Classification:mal48.win@14/35@8/127
          • Exclude process from analysis (whitelisted): svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.185.227, 216.58.206.78, 64.233.167.84, 34.104.35.123, 142.250.185.72, 142.250.186.42, 142.250.185.106, 172.217.16.202, 142.250.185.138, 142.250.184.234, 142.250.186.74, 142.250.185.74, 172.217.18.106, 142.250.185.234, 142.250.186.170, 142.250.185.202, 216.58.212.138, 172.217.23.106, 216.58.206.42, 142.250.185.170, 142.250.181.234
          • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, www.googletagmanager.com, clientservices.googleapis.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • VT rate limit hit for: https://blogue.corim.qc.ca
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jun 11 17:21:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2673
          Entropy (8bit):3.993340957650991
          Encrypted:false
          SSDEEP:
          MD5:A4CF44E4CD0E0FF6D483888ECFEFC467
          SHA1:B7F6D14AEED1AFC59BAF1E3D737BBC4FE0A71B10
          SHA-256:417E1BE5628AE8A9D7291FB7BABA4BA6737365D357F1DA683B6755F971E3E66E
          SHA-512:357865646AF0F9CDE3CB3B25FD80FF349A8918982A45081AFC4C7D3F99FEC374AF3E6F141A5067D6AECB150FD79EFB64A0F000A8BB8A79C57D7E5205379ECAC1
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,......z",...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z8.,.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jun 11 17:21:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2675
          Entropy (8bit):4.008489619681703
          Encrypted:false
          SSDEEP:
          MD5:191D039516E6D901574A6038896980ED
          SHA1:F83BE5776829FE878E71ED9E425D6354990C28EC
          SHA-256:C115FD8A8B0CEC4EB9685C67B52B9A6E036083D40FBC9B61755C6A56A89AE9A1
          SHA-512:8863BCA7E3B2AB5ACB556DBAC5F8367CF7892579348090A5E746717FF097FD0567C3411250A52FDAF2B89AC0BA7B4C1A4B39122AF850E3E28A7291302024AD02
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,......o",...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z8.,.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2689
          Entropy (8bit):4.015364874850155
          Encrypted:false
          SSDEEP:
          MD5:69C46ED8AD3CF54BA853EEF1DD78CF4D
          SHA1:ECBECA412F206E910A1D2687F76B152C34035DCD
          SHA-256:C796079A0BEF7D09D1924EBA5C1E45D4D62B2DA79D38AA003006AC5B16E095C8
          SHA-512:82B7AEF5A550F1095BEDA62CDF9225BDDAD8DA19D677B59F0BCAE79ED0092ACA4EE1807EF89C9029FBD2B271498E3E196CE51A5B7900599A841FCEB429E24BD6
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z8.,.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jun 11 17:21:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):4.005672315611052
          Encrypted:false
          SSDEEP:
          MD5:B745D2E2B21231E1E7E2E0E686287253
          SHA1:03002AD6AE461B2B3A1A9F5CC6BC10BC52D072BE
          SHA-256:75E231E3050E716788A56E3C5B16B023E61959942DC6E183C2E65C04840F26BB
          SHA-512:011E21DB9064ED4FE0421A346EA0C939CE81A135C65B29233772E2E4F20FE824090A0DD45C2FF7B08E6BE1496EA335A99144CD9943F1016C3780190E6372CBAD
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,.....Fj",...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z8.,.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jun 11 17:21:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2677
          Entropy (8bit):3.9939169594022323
          Encrypted:false
          SSDEEP:
          MD5:B2B3AB8511E5C195B53E586ED66C8388
          SHA1:E9B796C74B5FC4D4D8D9D55EE9FA14AB53C59713
          SHA-256:A80C984BC8EAE9189DCFE784CFAB5754F6B2ED1410B73D7041C0B79E9BD136D1
          SHA-512:DB1728E77036B17EE71289F4E0371FB2FBE3CE0561C2E558BE31015179075E9E175DD2B8303472A3DA8DB08C6018C1B5E9472A80BEAC64FFF6CC9341E1EB4FB3
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,....k.u",...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z8.,.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jun 11 17:21:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
          Category:dropped
          Size (bytes):2679
          Entropy (8bit):4.0061798292871185
          Encrypted:false
          SSDEEP:
          MD5:7BCC779A52632EDDF90FCF2E57714603
          SHA1:CDA44811F246E9C1C52A5CB037AFA503619DD2DC
          SHA-256:7DA64BC5F1318D951E13DA57A3B31CE1CB5FBC1810C86DD1776A33A0FED0A586
          SHA-512:1D30D6A90E6F9582A4E85E7060486BEAC781276D96AC593D1766E49551A5CE4BF5CBBC6D9B6AECDB43CF026135018B2ADADA7BEC5DDFB79ACD72F3BC095B863E
          Malicious:false
          Reputation:unknown
          Preview:L..................F.@.. ...$+.,......`",...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X......B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X......L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X......M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................."&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X.............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........Z8.,.....C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:HTML document, Unicode text, UTF-8 text, with very long lines (6409)
          Category:downloaded
          Size (bytes):126903
          Entropy (8bit):5.597052918174226
          Encrypted:false
          SSDEEP:
          MD5:56BD85F349FFF462537CA79D7B683515
          SHA1:D1CD6FE5204D73F86E7CC8B54C7947AB64B95C98
          SHA-256:FC1B5C6C942DE7A669D65840D05B8F894E2DEF46F796D0EFCAABF4CAE045AC9F
          SHA-512:12F2408D136EC91FE48E9FA9E526D04C9C955C4DB75025CB665C5A176274541ED3646F4493430990D3159311B19F31B91CA35DA941BE7F4A7F1F02B14BBAC773
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/
          Preview:<!doctype html><html lang="fr-CA"><head><meta charset="UTF-8"><link data-optimized="2" rel="stylesheet" href="https://blogue.corim.qc.ca/wp-content/litespeed/css/8b5214d810e9c3f179de19ecce2e8544.css?ver=d0a3e" /><meta name="viewport" content="width=device-width, initial-scale=1"><link rel="profile" href="https://gmpg.org/xfn/11"><meta name='robots' content='index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1' /> <script data-cfasync="false" data-pagespeed-no-defer>var gtm4wp_datalayer_name = "dataLayer";..var dataLayer = dataLayer || [];</script> <title>Blogue CORIM | Espace de r.flexion sur les affaires internationales</title><meta name="description" content="Espace de r.flexion sur les affaires internationales" /><link rel="canonical" href="https://blogue.corim.qc.ca/" /><link rel="next" href="https://blogue.corim.qc.ca/page/2/" /><meta property="og:locale" content="fr_CA" /><meta property="og:type" content="website" /><meta property="og:title" content="Blo
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (5945)
          Category:downloaded
          Size (bytes):319577
          Entropy (8bit):5.596800454275675
          Encrypted:false
          SSDEEP:
          MD5:0942526C4B9B7534A9DE547DF1DCE600
          SHA1:FB86990F37F00F656FBED98348BFAA1AB544432E
          SHA-256:4B53454B1D536CF095D4B2239BA4DC3AE148AEFAA7FCD45F03EA31E7AB2D91FD
          SHA-512:4757149323FF26057C3875BDEBE3844915EAE1F3101FF58AC59425DACE34B238B8BD530FA1EDDDA4E0C67E970E9ED6E77080539BC6C2EAC66F27BAF2467D5134
          Malicious:false
          Reputation:unknown
          URL:https://www.googletagmanager.com/gtag/js?id=G-83MSRRMVZP&l=dataLayer&cx=c
          Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"},{"vtp_signal":0,"function":"__c","vtp_value":0},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0},{"vtp_signal":0,"function":"__c","vtp_value":0},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_1p_data_v2","priority":15,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECTOR","vtp_email
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:GIF image data, version 89a, 339 x 218
          Category:dropped
          Size (bytes):49966
          Entropy (8bit):7.88346118907404
          Encrypted:false
          SSDEEP:
          MD5:3807D407B08049330AB0AD3E86078613
          SHA1:BE1DEC361C8D4CB782E0A3DC1724B3A9E15A08B6
          SHA-256:04BC077C031C7B117D537AE18A9AF1012835DDAA6A054F8CB4EBB1E0B37E0395
          SHA-512:ED91C8A1DC2CEAD8E0997623CED99217E7CC268AEADE4AC3F6EF0E04534EFF66CCEC4C934E0804AAE05E56C6C45DF7C65EB0F0835D1A8998E68A172898CB867B
          Malicious:false
          Reputation:unknown
          Preview:GIF89aS......57H..s..g.uU..)......BFW..%..NE)....gF4O...z.vs.6$.#.......9BR...UD3$...........x......h5-....I../...........oniow......y.\2..%&3hVD........g..xgT.....H2!...#!'w..P7DU4#......xv.....uVF..EeIF.XVwgI.{x..P.hfXEC.......ge&..IReicH.dY...GJ`X745...y`........VU6&#.XU.... &!...QE'!....k}...WZsfYp.62...RUiG61328+0lwf3{tT.tg...C@H...FBwEDvWU.cX.hXhUU.!}3..,..$.'62%........~.E.........Yf.tmjiP.3C7"...v..VTX.GDev..TH...g'...$..h....wv.SKTD.jN..vhT&.y.....fe.Oe...`cu.sI3'7...XS=...)1<.......$4..x...iw.jdf.....jDIRZ.iuTIQ_h.JV......~..[`...zz..dwIS....?yvC..Wn.t.)..%....H...!.C.GS...s...h}eISL....u.{X..G@1..GU.}Cpk.E(4.......5GZ'/...)*"j..........PRt.j:..RksZ.!.)#.<3._]0.' ZcD9V....9..@Hp .a#..@C.............RJc.......[............!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.1-c002 79.f354efc70, 2023/11/09-12:05:53 "> <rdf:RDF xmlns:rdf="http://www.w3.org/
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:JPEG image data, progressive, precision 8, 339x218, components 3
          Category:downloaded
          Size (bytes):53122
          Entropy (8bit):7.987975056830059
          Encrypted:false
          SSDEEP:
          MD5:A2ABF9E4FC61BCA2E9D2D4F84E5D945E
          SHA1:1462A0CC155D27B7EEBF8B212C96C3419A65C2A7
          SHA-256:C9AAC8646AE121AD6086CA582F32880546040FF6452C0FB5C9973AEF4E94F744
          SHA-512:1438043000C5B433A40F6FB9743E8351E558250128D93C445AAA503513BC43BBF92EB98407CECFE2C853012B8AAAD5B6F87D9CBBD7F60602FB14501C1E1DEBF3
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/05/Thumbnail_article_Barry-1jpg.jpg
          Preview:........................................................................................................................................................S.............9...........................................................................:U.Gy$\...l,..#..o.l.'.j.kB..f...-W.l..f.V.f......4.|../.z.D.|D2..T..@.$,..bX.5..h.'s# .#.]..|..t...'#.#.GNk..t.s/..8......"....y...w\............../.n..yQ..../."lk%....y.+f....H....x..:.Xs..... .8...Q..9.t<........,5.......V{K.br...(K>E1.b.........l.Z....H.)5.u..-v........M N.......4;.DJX.'*..>....j.fp..sW.5...+u3..9KS...&...L..ko..R.B4.(.].|.&C.%..;.).7.QG..oC....^N.1..'c.3O..$..E....$eiU..,.I.....t.-.......e+#.;o.z7Q%.?........sn.<g!1.G....i>;....|.2.d.['.....*~xJ.?..6D...m..}..K''.."wO'$~tQ...(v..s.E .q#..1..."5..h..X....].d.Lu...R}.v.mp.....|.{.e.u.?W......-.Y..a.s.-U....7..P..W.q...x.$.e.F6Y..4.=.p.U.lycc..SQ..$xn.?:.y.v...*.ab....../.y....(Z.a(X..MZ..`48.h.M.e.|r-.;&..p._..w..f2..y+......%Q..X....
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:Web Open Font Format (Version 2), TrueType, length 76764, version 331.-31261
          Category:downloaded
          Size (bytes):76764
          Entropy (8bit):7.996848906523996
          Encrypted:true
          SSDEEP:
          MD5:F7307680C7FE85959F3ECF122493EA7D
          SHA1:FCE0DA592A3E536D6D5DF5B50CB513398D8C5161
          SHA-256:43C072C16C9EE6D67ACDFA6C6D6685FF1E74EB4237B7CC3C1348AB1C108B26AF
          SHA-512:D115A6F0DF1F766FC83A77ADEFF79DA5B0A463C01C13532CF48F29ED53A0C4EF1D87DB38B8E492FBC3F97A0D192A9A6F636B837E65FCBEAC03BB6F36336CA69E
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2
          Preview:wOF2......+...........+..K......................?FFTM....`..r.....d....6.$..0..... .....k[.qEa..*v...m.pG......"..9z...8...>....5.B.v....1..........6....G_RA...P.8.a.2r.g....X.u.d..4;.LN..<.. GV..q"."."..........t..!._..!...4...=j.=b?q.lhg.u...I.E...[d8.KY.h......7N.../.?Y...9........l...A..L.$C.%..D.:dJ...ZZgiv7..nLrA...o.k[.E..2S.l..Vp...g..3=...y.e._....% ........k.....w:...P..h......OoH.#&......D...!....s..}......aB...4..(.q....I..z.F(....^;.$.C..L...../.N...G./....O..wQScM..K.fP.....FP..s...`..ZX. ...%.Hj.....X.!V....Q..}..o...b[N4.;`".o.\^.S........D5IM.Bk.}...v...........v.9......j..... %.C'.C;.0...C......*X5k.WDnM...H.AB@Q..1...+...+]f.vJ......p..b..r.:m..b..o)..\.'Mn.dQ-9N2h.3. .X....=....A...4......g...pZ.6W#.7.|...93...u.B^,'.!..Z..P......1...rZu....d.8..+.T.d..h...w.....9..p.Gd...0igw'l.V..].*!.V..A..UDB.IH.lI... ..-.....o.v...cgl..!b...8.;.=~..h@.-.....4a.....G...`...........~..8..L..4I.1.4N|....=\..t}`..X"0|..P......9.EF......
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):43318
          Entropy (8bit):7.983476369664151
          Encrypted:false
          SSDEEP:
          MD5:B013302F38FC335F9D9767FB6FF1E283
          SHA1:13C82F9B7549D3BD0D530308F5EA9A83011C7DB9
          SHA-256:374909752C48179342C3E560F8FA4A3E1390E4D135C2CA8CAB75D63016C6C7E2
          SHA-512:4EB58F8176920727869FD06BA6595E871E708588902E5D73404AAEA869F9BCDA6815EA4930595F9918307BB3A2CA92B77E9A78BE4A80EA4AA4059FBE4418BA2E
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/04/Thumbnail_article_Jegen-1.gif
          Preview:RIFF....WEBPVP8L".../RA6.....4.e.jf.q..W.^.3;...d[{.......i.F=.O..aw.3.V.-.!....QR.9.O..=w.1..(..?..."...x.,.....4.....J.....2.% @.hS...BP.e.mK.Y..:F61V.......L..."q.Y.D.....3..WC....2)..f..6.s&.P=."..X$.(;...(.......L..&H#.U.z..#T.9T..Z.[....p0....T~M.....Q...<._=.OC.%.Y.+.%.f.E3...p..++..(Cf...."..#..=I...'.3&E.4.c..v.ho...A.$Y.).....6..6..n<V....00.`.._S..)...a\...o..D.^..V..R.b@.!....L.)...nNt..@=I..FH...X..r..3...ZL....Th*~.uH.EcD=.+a@@..".HB..Q..1. A...T......}.jD{.a%.q.j..n.e...6..A.4...6.>.H.%...|..:...Y.....I.&.......r.sQ].....?.6L.....U........v........y......&d..S..N.....j.vO^n?8GA.F.]......ADD.3.......j...s.r..j..._{....{O......m.m.m{... ". ....t.!?..$`7.!...*.0......o.$Y.$....M...O.d...6.._....g...f.j.....M.Iv.I. ..^...jBM..1......d..l6P..&....R5.Y.nN?..0........g....L..8.$iU.e.h..YLO.a..3.'..5O.Z.. .E.......m$m..Gw..d.oOw....f.p..%.?...p].0.".?..l...H...LrC..6A...$...t..E.@..^s.fD.'..m.[i...e-;.P..ef..f*.U.f(........u
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:JPEG image data, progressive, precision 8, 339x218, components 3
          Category:downloaded
          Size (bytes):44112
          Entropy (8bit):7.99011253407492
          Encrypted:true
          SSDEEP:
          MD5:E05C03B4C98ED97A85D0F4F1B10AC18F
          SHA1:6A779B0FCC964FDE39C4A91E88970F8B14C67B8D
          SHA-256:527AD5A5EA50E681AAC2A024B972AB2DBC1F5031A3A1E77AC7570C772441CDF0
          SHA-512:4A9BC853478C8C0F2396DB716680979D32FA94BA55B17FAF2DDB4490CE991C55AA75D241C5C9855910150DB36DD8756E27EA7619D4BA915EC1DCEBC36C506529
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/05/Thumbnail_article_Hardy-Chartrand-2.jpg
          Preview:........................................................................................................................................................S.............9.......................................................................P.2..4*v..VXQ...-.T-E_\....U.<.3..t%.hvi..._.qa..=..}..Z...u$.a...7er[.#....G;BT.^s.g.x.K<.at.%...2.):....g6.kK?@.}.V+ 7.m.*J..M...].R*...Ysp.+.R...M[k....v..Sy.......C.1MB<..U}.bh....)G...c.h.t....*..\czoV1.29^.A..mJMZV......).u....2I.c.g/g.Wzr*.. ...n......f...,..e.i.G#.....z.jB...`).._..C.P.......8f.9...L....1+.......*L.....K.ak.kd..nG.Ma.yn...b..j.../"(/..s... ....8+QX..K0S. a...F......Q8..B.7b..r..{.52:89.)..Dr~tE+Z..Z4.j..`..}.,h...t..u..<d....S.KR....\....Vn.......X.|.....u.:...KD.*.....].Zs.D..'.a..o....U....u...,".!D...E..j.q.r.y.n....M.6\.k$..B}..x*....h.V.....ad.k..h...'us>....P.....]-.vF.......V.g../.E+......'\.U.-<...e.4z0/....n...Z...d.7A.:.*.S..e...S.,A[pu...r...y...uN}.).n.yIT.r..08..6
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (65447)
          Category:downloaded
          Size (bytes):87553
          Entropy (8bit):5.262620498676155
          Encrypted:false
          SSDEEP:
          MD5:826EB77E86B02AB7724FE3D0141FF87C
          SHA1:79CD3587D565AFE290076A8D36C31C305A573D18
          SHA-256:CB6F2D32C49D1C2B25E9FFC9AAAFA3F83075346C01BCD4AE6EB187392A4292CF
          SHA-512:FC79FDB76763025DC39FAC045A215FF155EF2F492A0E9640079D6F089FA6218AF2B3AB7C6EAF636827DEE9294E6939A95AB24554E870C976679C25567AD6374C
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
          Preview:/*! jQuery v3.7.1 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(ie,e){"use strict";var oe=[],r=Object.getPrototypeOf,ae=oe.slice,g=oe.flat?function(e){return oe.flat.call(e)}:function(e){return oe.concat.apply([],e)},s=oe.push,se=oe.indexOf,n={},i=n.toString,ue=n.hasOwnProperty,o=ue.toString,a=o.call(Object),le={},v=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},y=function(e){return null!=e&&e===e.window},C=ie.document,u={type:!0,src:!0,nonce:!0,noModule:!0};function m(e,t,n){var r,i,o=(n=n||C).createElement("script");if(o.text=e,t)for(r in u)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.remove
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):37240
          Entropy (8bit):7.992479260259733
          Encrypted:true
          SSDEEP:
          MD5:B827560CC08F8AD9E78F1BBDBADF7C05
          SHA1:8AEAD1D31008169289529CCE5307AA43A4D8548E
          SHA-256:DF19A5CFF0F91910A328208E63BB3C254379B3C47911939258DA5E6CEB189308
          SHA-512:28459ED8A9B0CEC795011A29AB042C911A1601D19E519189F42C667B6157C9C59F2A6E75EB79D67D655F26A66B8B0952B3A9888001F11BD956E2558786629AD0
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/05/Thumbnail_article_Caron-1.gif
          Preview:RIFFp...WEBPVP8Lc.../RA6......4.g..0.,...-l....fFy.V..k.N..'.2.\..M...t8EL.... .. .m....Y?6j.D..>;..z......X..Z.h..Z.L-..! ...Ed.DX!..Oh.)M'.D..duK..5s.q...1.Ow.*........$.V&..O.o^.;)R.......3C..Fi[.B....v.(.\L.b4.%..2c.BT..8......T.k...H.M/."l....r.].5.......m.T.!..HP..a.M...u.J......k.lB../...(..R.*..`.X.........A...c.<.9....H...)L%...B.........<.0...@..<.0X.L.........I._5.L...v...^.@...........?........?k.0L$Q.ns.&.5.V.........Tr.-Y.$....0.R....P..9 ..... ...j~`...bD.IXgR. W.3.r.Qn......:...v..X....l.F,..[.v..`..|...y..s...6.R...vA.S.j.#....x)..N~..-NO.~.[...y=7o-[d..._.....7....LN.:w.|SbC.m..}.M.......B..... 9.v/H|c.N].)....m#I.v....|.""Jr,9).3.Ij................%...M.Z.".).....V..].s...2..x.|...U.\.sQ.&.?..y...a.."..A......T...-..x...q.j..h.(.g4b.f.B1>..%.....5#.k...:H..I..y.s.]lb...9J.B9z{z.. ....<q.......<X.5>...Z+...m[.*....ZY.....m..,.6RF...W....Z....^..........D0...f...H..8....?.Ir.6K.'.*.....p......ng_B.g.9$Xt.Pe....\..=A.....3.>
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:GIF image data, version 89a, 339 x 218
          Category:dropped
          Size (bytes):61717
          Entropy (8bit):7.774413304861477
          Encrypted:false
          SSDEEP:
          MD5:302A1DD50E1384DA5D1D06D6B07F4840
          SHA1:CDD563268C5A57CCF86DBADB51DCEA48FBB0CD4B
          SHA-256:4824CED2D56D4357D678D2372043165B0072A2A1C7E0CCCFF2E207055AB242F6
          SHA-512:E3F9CBC5569E887A15A561E41FDEE91A420660EB27A3B290F4DDE4FE3A7AA81F926E3B03A21B35B58656DDABAB874549E244D85920B1523397A098F10A30F353
          Malicious:false
          Reputation:unknown
          Preview:GIF89aS..........DE.30.m.fE1U..Q.......I..Fd0OW.eIs..l'.3E.L"3op)I-%'%qE*Hsr.\...L....G..wEh.f0..*....j.jO."...o..2.Tw......$......1.TF..p..(3n.M....vOj..)QK.jQ..LM'-.H....LlMoKN'../D.....o...m...qtLK.L(.o........KLLi...rq.3L.K.o..mnv.)'.....rK...)...0n,,..molK.ta.*'&)NKPq.LI.. .l1.G......'.....+'...L..O...of+..n.p..2&rH..2.M...I....rm..I<2~..N..1...F.&.....#N.L......m.i.Mg2.$......".%k..ING.t...Tr..r.Df.hI....i...v....k.3..f.bw.kf...o.)...........q.Uh....*2K..KW%.I ft.U3.fD.f3.wV.U3D...DA...U!........U..."".f7.35.wC...""......wU.wA..V..."4......UU........DU.UV.U.......V.......w5...3..D"U.....f"D....."6....fW......fD.w".UA...f".3.............D:.U8.A<...w6....w!.DU.D.C..33.f\.D<..........D.......m3.....U......U.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.1-c002 79.f354efc70, 2023/11/09-12:05:53 "> <rdf:RDF xmlns:rdf="http://www.w3.org/
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:JPEG image data, progressive, precision 8, 339x218, components 3
          Category:downloaded
          Size (bytes):40422
          Entropy (8bit):7.986147326516818
          Encrypted:false
          SSDEEP:
          MD5:F1AE9F979657637F672BA3D5A8B79D2F
          SHA1:F8289C8739211210FF94F0688F75AB498A36E48B
          SHA-256:51342136719494F0DAA07365B4DED9325FF6A43351810D047DAA19D694E2C0B3
          SHA-512:E45809BCB2496052947275C8DF14C02370E8A510BFB937BCF53DBD0B1211B1F8EBD7E1D5A68FCD4404CE7522F99E00D71933F30AF4FD52E9337CD0DAA5523C5B
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/05/Thumbnail_article_Manulak.jpg
          Preview:........................................................................................................................................................S.............9.....................................................................$u..1....Z..6.M.Q>.7*.J..7a`.H.K.."(>;KJ;..ZD..r..vr.a....[5.e:.z...Q...Mx.F.(V.fu...u...u./...i-..l..hn...\.J...r.........o8.w.?.....S....D.:..mJ.)].Z...%....8.6..q......zd.;..q...s<L..K..i..G.7...{Y%..Cp}Ja....W;..n.....9q..t<$=...........WB..f.D..5....2^...-s.v..tj...`....<..n=...z.....y+.../G.k"v...F......=.I.$.U.180.*..FDF3..5Wg...nk....<..?e.....;.F|HFu:....R..,.T.z.wH7. ....Z.T.3y.:..i-9G...`...7v....2......R.._.......i.O6.s.!/.`.mJ.PD.,............>V.'=.Dq:S.$.....mL....O...i.F..aq...`.B.`....]...].B...E....].z..&.....]..6.9.Vg}.VPr.3@.Y7...c.....MH..i,....2....d.b.~...lX.5..&k.H?..\X).^..@D.#t.{c...l%..... )}..r..l[S.G8...7Nb...k-...Oi....%r.<..V.......=...i..O]....u...t.6..9..I...;Q........[_.waV1d.....i
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):43852
          Entropy (8bit):7.992818846371328
          Encrypted:true
          SSDEEP:
          MD5:854EBE7B095404D21D3C1C11A57EB987
          SHA1:620814FD328AA9FE47830212BD3A54BC79A8B4C2
          SHA-256:2317A8D6DFE8DFD72C8581491355BAA8C65B09F4C0FE609AE7839CEC784AD584
          SHA-512:508DAAAE040E19C01E9508A9E069447504E39F2B0220D31FF721EE9D061CBF7D32013852D0EC6D90DCD3EB5527B7325B70476FA5EA753E537EA7FE3AE0DD430D
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/04/Thumbnail_article_Normandin-1.gif
          Preview:RIFFD...WEBPVP8L7.../RA6.....m..7.n.w..p..B.!...{O..d.V...^..'.....y...'.o..m..}.E..b...i`z..m.1z....L..`........R(.).@....)...d.H.`..7.{.......b(..!.^9..I.A.._BU+..i......L.N.S.x..q......&f.~.,.... ..`...qRl....!%Hwy.0..m..xP.H.R..#v..W._7....2...1./F...x..B.6~.F..].._a.....|j.c..a./.1.p.....|..0.8_.Z.....0..}.MV...]..H.^.<x...t..^...a.. .....3..... P...(..)......)..w'J{.,.i_......YK.....s.u...x.k._.6...w....33.U.e..H<..?......"e.n-.E8$k........1.]..!...?&.~....%.KRf.....W|.B....`7..!m..D{......%...-cNo.yR(.P.\.r.5kB...\.%...[..]..F....`..N...HY)....k...N.L-.:....W.>......Ew..6u..t.^x......1.....Sky..K......=....V.-)GA.F......1D.......D...QG.fX..-kn.....\...m..H........UES.V..\].[.Al5.CVj.E..=[.D..c..>.K.t....v.A8#...k.lHE...........}.....$.$.8...D...j........H....psPy.aj...s.;..I....'.!cpW...0.o.p........-Vm.r........Z[.....'.BD.e.....tA..5.&@I.OG.m..3._...Nx...x.8......n.:R.......E..C...G...7... In...%v/.UP @...g....(..9b....n.....K..
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:Web Open Font Format, TrueType, length 26628, version 1.0
          Category:downloaded
          Size (bytes):26628
          Entropy (8bit):7.981218762912301
          Encrypted:false
          SSDEEP:
          MD5:6A6E62FC2F2A5D18A6FBE52AD664EA46
          SHA1:9B024EBA9F5C0410A78C30D76BD7EB183DD883F5
          SHA-256:4A1F3FF5F953D4C1A1B4516830C34C1AEB1F176ECA593AD01C4A6F04B9597731
          SHA-512:B285AD1BC6B6302DE5044B81E4DAD3EBFE5CC966F2AB6EF604F427A776B101925691D4BBBA20F6106BEEEBF8F5518701634821A5B3CA4CC64B35C287DCDBBFE3
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2023/07/proximanova-regular-webfont-1.woff
          Preview:wOFF......h.................................FFTM............[...GDEF.......-...2....GPOS..............."GSUB...x........L.uMOS/2.......Z...`}..)cmap.............D.cvt ...d...B...B....fpgm...........eS./.gasp...\............glyf...d..L.........head.._X...2...6...hhhea.._.... ...$....hmtx.._....T.....jCfloca..b...........:$maxp..c.... ... ....name..c........._...post..el........9L8.prep..gX...........xwebf..g.........o.S..........=........4....... %x.c`d``..b-..`b`a`d...Z.z .........X.$...^......x..ol.G.....?.....}..>..I...8..7.P.F.....`...........B.S.(..@.&.+B...e*+JQ.H...|.K.....EVA.....`U..y.l..;............>.X...KF..../..k...wD).._..7.=..7.gGj..`..5.].'1...3.1s.%....uW..qu...jH.R.U;..T...jF.G..&U..i.'...S{.0...Au../..q<....)......p..r.......m.........kkE..uK.....5..y5'......;...3x.15S...z./].n.\..Tw..'....[..?....U....\U...RS....u.W....XU.p...e...0G>.s..0[.... ?..U.#..9xn.T..'.......M<X....8..V....0..../l...)..Y..V%...<...>X.|.....Vy....a5r.../..r.V+=.:.:,..
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
          Category:dropped
          Size (bytes):1097
          Entropy (8bit):7.795338313137207
          Encrypted:false
          SSDEEP:
          MD5:7A6AD40B1A5500D191240ADC1988983B
          SHA1:1A2F6A6F96354ECB160E0D4560439EE17BC084CC
          SHA-256:80D9136BC24EC372339F8C47964C3AA58FB9A7CF03626D63FC0964B0D4926F06
          SHA-512:1588FA117A137CBA7FCE47A7938BE88AA25B9A95BD21AC24EA0FD5BE0C76C1FC16E14AEC7F3FC8AEBAA3330D583FE4A73CFC0CAC8952815A8D3A81700E634231
          Malicious:false
          Reputation:unknown
          Preview:.PNG........IHDR... ... .....szz.....IDATx....H.u....v..f.Jl.-.&""Qj......rN.....Z...'.@...f7...3ua....Q!..1.1.\rLs..e.1D...@.}....~..|.......{_..<6.P.{..!.h$".m....%..H....%(..8.EH.......X...`.E0.Qx|....s..O~......c?^}....G..p._in{......l..%.s..y.{7.o..].~o../.9M.}.:!k..m...J.7....]....o....x..c.;]?._.5..V4....'4..X...r.f..!.CB.y.b....FB.t@0.5.T...H.....Z...`[.y_W.....jU......c.....R"..^~.48|.|pCu..Z.A...+...{J>.z.L...c....0'*......p#...A.''....CS.2h.88...a.u=.E.X:.F."..!<......yf.......5..nT..vC.5..; x*...r..$.k].4..{....R.7_.N...y.mJ..L.'..2...k.=.Q.<A......c$].....:C}.....f.U..3."..../`.<Q~&M....p............5.^...O.......MnIQtr.7.*~..i-]+P...s+.h.)....a.'.P.Y.Zt.9 H.....(./.qC..eo...B(`. 7.T..u.....a....=-B.|.....{(..6..H,b.a... h..1...e.....q..=..*.p........7|..p.I.......:..{i....*.5.....V[E.CPyK.<.B...C...f2"=.p7VQ7iJS..C............~.....>Dd.<...G...+..Hu....K...'Km..y..B......1..co}.......=...~.....U.u.W2..s.?^.8.@z.+9..
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):1084
          Entropy (8bit):7.680231107266565
          Encrypted:false
          SSDEEP:
          MD5:A313C4291199C9120DDE4F8B1621CB3F
          SHA1:9E0077762EC390F7EA2E9353B2525B25E3DFF340
          SHA-256:E91A76C6731DAAB1F18742C2D0EE3A1A4C2AF5F7755E5A9169A248512C81A5B0
          SHA-512:4CCB08B17EDB03ABFDC8F9B9DE3079C1CB7A4DCD15D39190E3513D5B7993515E41F7DE797DB39DE4922FF83A208ABB647860DF1FE2BE24D49A7E3F1DE30DB700
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2023/08/cropped-favicon-corim-32x32.png
          Preview:RIFF4...WEBPVP8L(.../.....I.......i................s...........!.C..:.v.2'.:3i2v.*...me.C............o8|..<.....c..e._.~.og......]ph.6.qGl.m'.Q.m....m....(l...H:.P.Q.2......u......b...,.+...`...<. .......,..x....!.-~...bs.....<4...s..y.......9.;.C.'.].,m..,..j(..~.....6..1t.u...pu.....[....-.....?[.h}...!........+..8..+...t..X\h.Wnqr.Q.V--..L.O.\ar.8q...<..T....zA%I..X....87@.'.5M.D..%X.L'..I. ......(.$YLe.j....F.-.Zo.0...q.'q.1..|..]...Ei.,`1[Y...Wh$Z.)-+E...q........o._..iaI.,....WRE.....c~.X.W....(^....t...U.*o\.<\.#Z.).L.\.L\.....~^.+..E?........i.yW........W.h......%...JM..-.\9..u....{[.....?..I\.....i...,.~.-.KL.....6..3..`.rey.l......Gk8t.%6.+.WO.%..C..._m....h)...C..'...":.........b1j..,......W.\.s]c.Vu..............c1I..U9.KZ8...+..-..../.1.L....%.......h5....q..........E........Qeb.b..%B+(...a..qe<.#Ik^...#....$....o..Y.[...VfJ....O.%.O......? .@%.b...j.Z..9...tQl....XW^....t..........._.;qY8.~.?.a7s..Z...../+..i.g..nq..5.....
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with no line terminators
          Category:downloaded
          Size (bytes):16
          Entropy (8bit):3.75
          Encrypted:false
          SSDEEP:
          MD5:FA9C17CE126A76733ACA269345EB7D47
          SHA1:F1D8AA71F281509D55041F671B1A7BD94524AAD8
          SHA-256:15F88A501BBE49A103551BA087FE6FC7E101894E71C3A74A42E8EFC07DCEC0D8
          SHA-512:DD2E08D8D294E24330DDACFCC602D5AB9C9BD65346E0C6540F599725AB711E1F1621D3939318BFC069E67CEF889B80E781DA3E935D61C26E2086DAC79428818C
          Malicious:false
          Reputation:unknown
          URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAkkXKMOr5TsxhIFDRM0Cs4=?alt=proto
          Preview:CgkKBw0TNArOGgA=
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:Web Open Font Format, TrueType, length 26832, version 1.0
          Category:downloaded
          Size (bytes):26832
          Entropy (8bit):7.981825769183232
          Encrypted:false
          SSDEEP:
          MD5:D721839F6D3B5F89C6C822EB3F91D781
          SHA1:9A386C36C6DE4FCF31B53D3C0BAC71D69C83D002
          SHA-256:0DBE1A634FBAD89495C79DC4C49A6871BE9D4E8348D295B0213A76145DB00E5C
          SHA-512:21464F292759959ABB41B40E6895A46608D9E9A60824CD4917DD649425C72A18C0D4642033D976DA30B78C37FF746860A6F066BA4C083DC366129EA522BADCC3
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2023/07/proximanova-bold-webfont.woff
          Preview:wOFF......h................................FFTM............[...GDEF.......-...2....GPOS.......t.....T..GSUB...h........L.uMOS/2...p...Z...`~..Ccmap.............D.cvt ...T...F...F.X..fpgm...........eS./.gasp...P............glyf...X..M........head..`0...1...6....hhea..`d... ...$....hmtx..`....M...../3.loca..b...........5.maxp..d.... ... ...:name..d....k...tT.{Qpost..f,........9L8.prep..h........-....webf..h.........o.S..........=........5....... $x.c`d``..b-..`b`a`d...Z.z .........X.$...^......x..]l.W..........Z...N..5.M]H....TX.P..BTP.>B.U.bA..DV...P...E.......e..~..>.H.-.~@.%,Y<........3^..k..1.......{..{~..f.......1...o.C....QJ./.W..-}L.o...-)..|).8.pZL..<gN......jX.y.'.....>.O.^l{UA.Qk..mAM../u.m.....j..Q...cC...--..`o.BK...>s./....Z.W...Y.{.R_;._.z..;....Z../.U.q...p..zd._.]...;.]j..Twj.....]-.p..3....x.(..QP.q.;..jQ.U.c.....y..0[..l.....|2..e\~...0[~..q.1...h'.m...8.S..N...)....`6.;.5...q.)'a.<..K., O..QX.|.V'.`...XR>.K....|.V/ga...e..\.W...
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:Web Open Font Format (Version 2), TrueType, length 78196, version 331.-31261
          Category:downloaded
          Size (bytes):78196
          Entropy (8bit):7.997039463361104
          Encrypted:true
          SSDEEP:
          MD5:E8A427E15CC502BEF99CFD722B37EA98
          SHA1:A9922842A120A7F1EACED667480C5E185A106D69
          SHA-256:D0B4256ABED72481585662971262EABEE345C19F837AF00D7CE24239D3B40EEF
          SHA-512:113775748A4166C07E58C26CF6DB7FED473732DC6124B8EE0F0DCC0D6439EB2AB2C5D9E01C67324FDF9DE4105349CF30CC5796A0B0E0CE9A08F337B9D4E10B7B
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2
          Preview:wOF2......1t..........1..K......................?FFTM....`..N.....h..B.6.$..0..4.. ..+...[.u..p.(..U.d..{-.n.Pn...._=V2.e..vp.~........U..1...=..B..b....mvS....w.C.+.$...(..MMI.iH}..O...4.7.s...Y.).*.*....}..^...{^...R.z....f..h4dD7.:1*...Cj..l.8M..T...]}.]?Z..v....g.yV...^..\.?.wM|......Ws..yf%..PL.....~.z.w.S.uQw..........EY.!.........j.O.....c...>T|....W...Zk*...9.......XJ...../I`x.R....c.h..w...?tm..l...LQ......hMg...x...1.F...cU.b|.3....v.Kr.f.H ..9 @....... ......'..j...Vq.:.Q..+....._..(...J.....~../..Y<."......GB..:..P.B...7q...K.{...F"..3....6?.C,..B..P.V.......C.C*..\....+....a...X.z..Tzdn.P.M....li...l2);.!..wX..xh.o.u!.........O.......Ew.$b7X..8d..H...s...z#d..&...J.G...Q.M.....rV?.....&....#...t]........+...*.*..........v...$X.P............ h.z.{...../F.-Y..!.a.1...&.;.^^.U.U.E....!O......./+~......*...Q.|.n@.W..P.tc.l.--....]6..........u..[.SN....i....4-......"...fC...`........@.......l=..g...-..C8...B.X.........g.~..p.1%..x.A.X..
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:GIF image data, version 89a, 339 x 218
          Category:dropped
          Size (bytes):48952
          Entropy (8bit):7.8989418912874525
          Encrypted:false
          SSDEEP:
          MD5:96BE4896D85427FB7E1C41E90577C198
          SHA1:79DE0B84AF554CF14842628D9423BE2DDC50E41F
          SHA-256:DA955775954FA07F7B1075A2B4B6352979DFA8CC98C135D3F87C1E7C8E971111
          SHA-512:6EB44C3693925361F1C5F730CBA5612735259587055791697B3F2696B55FF0D5EF1CEAED425829DB64B1482DF9F6E3574023AAF7C4EECB0E1CA0C46F053811B1
          Malicious:false
          Reputation:unknown
          Preview:GIF89aS.......y.!..pI..."'..................CF...v.g....s....ujVj..WnE/.................UI.%...n.T2....&ps......13..89....9B....zO.....Epmp...........3.rk.#"..&.K6.5..y..t..T.fS....!UJIJC.....KN.l.f:.....(H..pGOr.{-...nu.............V,....1&tNF.."....((..4o5*...'&.*0N..!9BeM/+.NI...............d../.k.......M..K........o......)2Q.'.)1niM...6C.N".D8@.1(.......%...29.8;.....".b.;'5j...h+..o>.$..~.(...b........]....L..a.# Zap.]a.............9$.."...%..{bX`.../......&.n.!..FUb<......................9%.'9.}..:..{....\a.#6z~{........^_.._.D...........;2._4..gX..a....j..)*.......)!....)!.......))....))............................!!................................................................... -....!).!..................!...0.T._...!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.1-c002 79.dba3da3b5, 2023/12/15-10:42:37 "> <rdf:RDF xmlns:rdf="http://www.w3.org/
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:JPEG image data, progressive, precision 8, 1220x400, components 3
          Category:downloaded
          Size (bytes):268837
          Entropy (8bit):7.991188265587526
          Encrypted:true
          SSDEEP:
          MD5:8C9E524B7EC2213C0B44F53C3871E4B8
          SHA1:198BFE95C587859E6838F12E0F48DAC55063FBE0
          SHA-256:FAFF73844BF6C18FBF6FA156BC5C0C3A9E34F654265A0D5505A3EDC599FFEDFD
          SHA-512:9E270DDAFA0D75F84C5BC34AEC7FA54F2995DC5F6BC33BF5C68F5633943BC6F5B07D304561872A32D651C851153F82413ACFB8C9CCC00F4E919547FECB83D8B8
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/06/Banner_article_Cliche-2.jpg
          Preview:......................................................................................................................................................................9......................................................................t..D.2..2w..RK..".y9.#..d.....Jk..Ct\.J=g<S.P...r'.... .&..(.H..c.... ..").Q;.....N...EH.qR.3F2..s..<@....#...(l.....Y.9..*.T.%QWg5g_.(,.1...7H..0.d...f.'IH.u....o..i\G.&l.Dt..:l...~..+e..#...P....X!.:.-1s.#.$.....pFO...)..H....F.%.X..b.&.y..EQ.....fL....$>....>\..&s.T...1..i..(..G`.%...q.../.l.b...}C.T.....K.w..5.)n.O..Y&...d.+...R=MH..R.")..s.a.!Ek? .HCD.bB.B(.)x..J.\.I.'...+.\.,@.'..d....I.ldK..ui!3.d.:..{9.K.<l6....%t..-.k..,.s.6.k..`...F."..7....E..E2GL.\......c...).mx.w>3..)E....aH\x..W...<......N.).yY.6zRw.....\..~....=..4..9%.D...h..M.Q.:.......%..I...m[...y.Bv.{TM;.....EWVq....D.....G!q.........bRu$P....k..Cr2...C....m.qS....IpJ...8..S]..t{.QH'1.k.........2.W...."....2J.10e/c....U=.g$....m-s.K..g....0.y...
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):38428
          Entropy (8bit):7.992419143156628
          Encrypted:true
          SSDEEP:
          MD5:A375534BA7DC35E92BE17AA108802FD8
          SHA1:5673A5F4A2EE6206246B88B1836A778A9A0395C4
          SHA-256:EF881902B54C045D64F4A95A3F545F51C13B6D9A3274F71A8A35257CA8148DBB
          SHA-512:5BBF6E13AD1429411817E68D821C0AA623811562080CC2E491479FE89CFDDC68A4029BE6140934DA98DEB995499CDE58541C37DE76BF3C204C6B47D33A249E8D
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/04/Thumbnail_article_Audet-1.gif
          Preview:RIFF....WEBPVP8L..../RA6.....m...]..p... .hzp.......$.M;..).m..~..iEJN..z~...l.5......M....x..u..?..(3U.._."g.....`..#i....&e2c^.c..PO..pV...Hd.p..q.H.P..`I.q.P.... ....9..Ep..8....$$`...TXXU2(.......@.5..... ..~U2#..&..%....;I..........2O.-s.}...-#F."..;.a..#..:.P[..ME...@.......06.;%..DTE.....r..c..\.@...-..=...O..$.y.....y.V*Z..h.5$..(^.G.mP..d[d4E.......d....2.&0R...#X...yNV.R....2.......E..L7...4A..7i....QF5..cD.......q*OJ..V...oAK..K.5P_.....y.....^e,.L.Q..R.C...j.(.5..E..(....t....M..@eLv...O.h.2........H2.9..u.._..X...K.I.G.....lK....)..5W>v..U\..c+....id...R..j,.W.....H..V....q...&..3..W~%.Vb.h;...?.s.;....A.5..>f"/..p...#.n6...o.Q.mc;Q....7D....gl........(.f.}.Y.m.y...h...B].,.aB..Ku.+..`.d.7U.%=*...wI....yAb...nD.%J...... ..z.Y....m..H.P.Bh...D..@....BH$2.....%DR.".,7.Y.R.A....j.@...7l.na........D]..}oD.!J..U..fa.7.F./..j.#.M...Ym(.........=...d...d......^#lOW.0K..q[..o.....k....{#.......*/.d..*I..m[.?.q#33_A..g....0.y.)..-
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:GIF image data, version 89a, 339 x 218
          Category:dropped
          Size (bytes):49147
          Entropy (8bit):7.884550900048312
          Encrypted:false
          SSDEEP:
          MD5:DCD5D2879D7E0E06F3354EBBACF2E95C
          SHA1:4F7C29AC2FC81D7982293BD34D6B42529E74946D
          SHA-256:135C2D83D45E241403DA1A5F7B013A570FE9E1D93ECD7A1405B1B27B619C9ECB
          SHA-512:51709F2DF6CCB64176682C040895055EE45EC4460E9F5492858922FAE170175650A6B31DE0EB367AC473B767D7F7B9830604F115A4C47414E7219AACD2D75EA6
          Malicious:false
          Reputation:unknown
          Preview:GIF89aS.......la.G..1.....&O.........2j(-Lv..%d.POk...4i....$#,lhr..t.c...Fq...d{..X.#Y.&c.Fs.X(....Dk.MFR.......U.-Gq...*P........V.z..y..2d.Mg.y{.Hs.uu....Y...d.'c....C5P...Mt....Cu(4l.....K.t.S{..Y.m..,g.)Y.....Y.....dc....U.FV.."8...&V..O.cXjnOL...........#......u.....H.Fj..N5hA2Ucy..................x.....$3AUfi.....f.....hs....,.......4.'K.....g....X.lr..E.8s.W........H.....E.0c..3...l...%.'.1...%w..ew.....7W.........8g...............gy....n.....cS....8s......CX....Sj..f.Uk.._.....R...........7|aV.......E.uj........W.....{..=.....0.....x.r8t.i..h..ah.".F...q...I.0<<Y..]..C..E.fS.CZ.&w....'g....'t...=^...:;.6w.......>:2\`]....a.\.......#...<]y..a..9Rs.Z{.9k.m..P{.c..1c./k.9k.,k.c..\s.l..1c.<c.k..Z{.:c.k..Rs.O{.Zs.c..^...o.?.....z...JG...!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.1-c002 79.f354efc70, 2023/11/09-12:05:53 "> <rdf:RDF xmlns:rdf="http://www.w3.org/
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:SVG Scalable Vector Graphics image
          Category:dropped
          Size (bytes):706600
          Entropy (8bit):5.8459339228303495
          Encrypted:false
          SSDEEP:
          MD5:63875735738304D1786E20B84CA6A5CA
          SHA1:294C0FA4F870D680AE7774EE5F9C803DC7145A89
          SHA-256:F2154C5F1A87C5C7FE79C1A54B483C66F1B8D7FFA41D251C45F4F0C565B25898
          SHA-512:CE36C1F0BFE87C2DD1600DB77FD6197ED690E8775DE5745F24E6F35C2986DDE835F526C31D96AFDDBD853A81A50C50F16031CBC4E8215D0C1AC9C58D509FFCC4
          Malicious:false
          Reputation:unknown
          Preview:<svg xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" width="202" height="55" viewBox="0 0 202 55" fill="none"><rect width="201.898" height="55" fill="url(#pattern0)"></rect><defs><pattern id="pattern0" patternContentUnits="objectBoundingBox" width="1" height="1"><use xlink:href="#image0_20_21" transform="scale(0.000381534 0.00140056)"></use></pattern><image id="image0_20_21" width="2621" height="714" xlink:href="data:image/jpeg;base64,/9j/4RJ6RXhpZgAATU0AKgAAAAgABwESAAMAAAABAAEAAAEaAAUAAAABAAAAYgEbAAUAAAABAAAAagEoAAMAAAABAAIAAAExAAIAAAAeAAAAcgEyAAIAAAAUAAAAkIdpAAQAAAABAAAApAAAANAALcbAAAAnEAAtxsAAACcQQWRvYmUgUGhvdG9zaG9wIENTNiAoV2luZG93cykAMjAxNTowMzozMSAxNjoxNToxMwAAA6ABAAMAAAABAAEAAKACAAQAAAABAAAKPaADAAQAAAABAAACygAAAAAAAAAGAQMAAwAAAAEABgAAARoABQAAAAEAAAEeARsABQAAAAEAAAEmASgAAwAAAAEAAgAAAgEABAAAAAEAAAEuAgIABAAAAAEAABFEAAAAAAAAAEgAAAABAAAASAAAAAH/2P/tAAxBZG9iZV9DTQAB/+4ADkFkb2JlAGSAAAAAAf/bAIQADAgICAkIDAkJDBELCgsRFQ8MDA8VGBMTFRMTGBEMDAwMDAwRDAwMDAwMDAwMDAw
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):51194
          Entropy (8bit):7.990438272881801
          Encrypted:true
          SSDEEP:
          MD5:9BB133F76363ACDCC3679AD7DC17A3C6
          SHA1:FE93069C6909DD91A21E45999ED58B3395BB50C5
          SHA-256:EAD3354E1A44941EB639BBAE145B811B627454D8CE8B02BFF6301EE841C7C302
          SHA-512:7DBD9C957F215429AF74965F2F35B467C0F9391680B29CCF157CBA0FE46A23AF6708ED4C93554682414C5A3B5970EBAED3B2E973D55D6B0234A2509815E38376
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/05/Thumbnail_article_Merand-1.gif
          Preview:RIFF....WEBPVP8L..../RA6......QV......D?......i@.m+................[.je.s.....c.Jr2.......PZ..1..ihtF!.C.....2...p.....:..../.?.6.d'RL......."$.-"9x.. ...P.2.T..8....l.B9Z.,.U..+.6.2...`U.5...C..W.m...6{.s_..#....*...,..?:.../....J\.%.CH%...L...I.....~).pe_..L...).R&$..8 g...!(.#.....|$.!.g.#(.Q@......(!..J..S...U.TS.......+.b().4..%...e.rdm..5u-....5......G..("...E...S.|bq.Tl".r...v..{.....k....[..Z..>..Rq.....nV.....Y.c..c.b....J...O|Q........&..+(....7b.*..w.&F.s..,...(.F%.4UW}.N..t\....9%z..7._xsr..*.4....`t+._X.U..4M..>..l...ig.\l...G....ws.R.^.^..........hN.*.;.....l_.8...M..N)...z.#.(l.....I..... w.bW.3.z.......p.$u..'.$..4...3....R.Z)EV.....:I(...".I.B.j.b.,.2e*A-....@!`...*3.3a.wS...,.R..#.q..m.......q?~.?......+.$Q..L.}..H.....;.9p.hqD.....Y.0h05(.....K.d7l.R.@.d...^.~.....m%{{s.vk.x."y5...e.ejdv.").....J.D........4.8..+.$. D]eG....."y.G.C...e&....>._...._...IR.fIa.&F.jE>`M.?.m.....L.D..O.{....RY"..Y.:......5..=..}...T.....D8
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:GIF image data, version 89a, 339 x 218
          Category:dropped
          Size (bytes):52235
          Entropy (8bit):7.897874769527196
          Encrypted:false
          SSDEEP:
          MD5:EFC1DC30E155B073B4C65316656005A5
          SHA1:8C42AE51C954F526B49AF8B1977D7EC4403D271D
          SHA-256:55DCE54B49CC6C6F77046374F29B3E5B79317DB89E42FA17AB0BD37428B652DB
          SHA-512:815D3EC517FF41C0C347D8B32FF4172C89282F017A2701F6808461440C76DA7990BB76CF6CE7C9577CC65A6EDA17EA93715DD0FFC3D5D180FA96AA3D5591B08B
          Malicious:false
          Reputation:unknown
          Preview:GIF89aS......efl....{s'3T......|.....dju...ESfCHY8Gd...ry.mt.iS6:CY.$L...............'2.466.....|6:C...."K19WxhO5E&........F.Uy.#.Ui.\bk[du...IR\.....#%):BH...pZ?.........jp{wrk... *.4:#.uQCFJ.RI.....(7 DLc...VXW%*3....q...m......,3Drrp...+19..}..{7D8ZYbEF(....!T.tkS[iH9.PSa.......(N..{ytGD5RYdGVp..s.!%.."............!+R}uo.!...5olkta;"*K..<.(!YR5..V-:.1>`w.....]VE,A%...1B.T\sSK4....~}y......82]U+...Y]iTK(...dw........E<`^e....0)am.A>>...}m.bZ....0...-..f.......1R.n=...........)..bKUGMQ6v}...U..}inl8N'...,>XNKFqy.pt}.$1.m]..}...HS'LNZ.....n._KeP.1H}.2H. ....a_RPaw...F?.*.....K]d#(..........+*#...<Na///vuvVUa....YqMSk....]y.....5.,Nl~..Vq.........;M1...C"#..oL_..+W........C......1?M.1....*5.............................."..u...-0./>0wyy......]kmr/.=.......YQi...!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.1-c002 79.f354efc70, 2023/11/09-12:05:53 "> <rdf:RDF xmlns:rdf="http://www.w3.org/
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:Unicode text, UTF-8 text, with very long lines (38540)
          Category:downloaded
          Size (bytes):432661
          Entropy (8bit):4.859953918285568
          Encrypted:false
          SSDEEP:
          MD5:8B5214D810E9C3F179DE19ECCE2E8544
          SHA1:1B08FE98588450C5884AA878148C3FE3F8DB0331
          SHA-256:BC1A188001592589C2BAB7E9FD6B4B6F4C2EA2C0D12180DF57557A46CB2F1360
          SHA-512:336727D1F6A8FB9787792A48FFDF18B3444BE3DB702FA77AB7E3553EF0CE74DCA15FD14AFDDC6D02A0E91311CCC3F72921BBF40713FCE52F678984E3A510FD58
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/litespeed/css/8b5214d810e9c3f179de19ecce2e8544.css?ver=d0a3e
          Preview:/*! This file is auto-generated */..wp-block-button__link{color:#fff;background-color:#32373c;border-radius:9999px;box-shadow:none;text-decoration:none;padding:calc(.667em + 2px) calc(1.333em + 2px);font-size:1.125em}.wp-block-file__button{background:#32373c;color:#fff;text-decoration:none}body{--wp--preset--color--black:#000;--wp--preset--color--cyan-bluish-gray:#abb8c3;--wp--preset--color--white:#fff;--wp--preset--color--pale-pink:#f78da7;--wp--preset--color--vivid-red:#cf2e2e;--wp--preset--color--luminous-vivid-orange:#ff6900;--wp--preset--color--luminous-vivid-amber:#fcb900;--wp--preset--color--light-green-cyan:#7bdcb5;--wp--preset--color--vivid-green-cyan:#00d084;--wp--preset--color--pale-cyan-blue:#8ed1fc;--wp--preset--color--vivid-cyan-blue:#0693e3;--wp--preset--color--vivid-purple:#9b51e0;--wp--preset--gradient--vivid-cyan-blue-to-vivid-purple:linear-gradient(135deg,rgba(6,147,227,1) 0%,#9b51e0 100%);--wp--preset--gradient--light-green-cyan-to-vivid-green-cyan:linear-gradient(1
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:ASCII text, with very long lines (2202)
          Category:downloaded
          Size (bytes):194058
          Entropy (8bit):5.526042447086102
          Encrypted:false
          SSDEEP:
          MD5:4B71A80108620245C1608EBDAA5A8EBE
          SHA1:173B6117CB8AF679DCF4E777EEC4C442FCFC38A1
          SHA-256:F4F6F43D755908E5E9BA48112DC08AC024EC1F46CAA3D210B83DD07CF15D9D2F
          SHA-512:0E1EB8F6F393FA6D153980C44CD1467F12A43072699646EE4785B947709DE07C873DD730C18D34F74E110D1DD7FC3F0AB21E04800AFBDA44A3171CA6F3AD7FAF
          Malicious:false
          Reputation:unknown
          URL:https://www.googletagmanager.com/gtm.js?id=GTM-MMBMFRX
          Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":"G-83MSRRMVZP"},{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"HOST","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__f","vtp_component":"URL"},{"function":"__e"}],. "tags":[{"function":"__googtag","metadata":["map"],"once_per_event":true,"vtp_tagId":["macro",1],"tag_id":4}],. "predicates":[{"function":"_eq","arg0":["macro",0],"arg1":"gtm.js"}],. "rules":[[["if",0],["add",0]]].},."runtime":[ [50,"__c",[46,"a"],[36,[17,[15,"a"],"value"]]]. ,[50,"__e",[46,"a"],[36,[13,[41,"$0"],[3,"$0",["require","internal.getEventData"]],["$0","event"]]]]. ,[50,"__googtag",[4
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:GIF image data, version 89a, 339 x 218
          Category:dropped
          Size (bytes):63054
          Entropy (8bit):7.805463284948215
          Encrypted:false
          SSDEEP:
          MD5:CB0BD11E539ECD52B4AB1AA97F025F35
          SHA1:6828B7308BA8308E7D6E100AD8FD995873EC1C02
          SHA-256:CB56DFE1DFC91BA109D0B089078F8DFA69CD3E98D13A0A1BE501A933243D2357
          SHA-512:9958C0900EA3CE3E19B104BFDA371A880B54E7EB1ADAF621F87F7C35D979D302982437AEDE85954DB025BCFDBA4513B9A8BC8C0A1E7514A07E436BB2F26A0371
          Malicious:false
          Reputation:unknown
          Preview:GIF89aS......iz.fuw...,8C...5BGIj....w.....3W.Th.7D .....'*.gkh7HR..UZX...HZe...feWwzxWku.....EHG&17...x..v.w."(6c.4En..o...376..x...h.....&R.........$H..1.Yuz...VeM...2e.x..w..$&&.........45 .G.F7%....'X.......EF&...BJT2Z...w...IcfUf-FU%..Y.yfERvFZ.3R...r...BD7j...)3SZdTSI...Gt...tsm.....ekvgT2.."J....ith...cYN.r...cw....o....%7mGRI8RZ.B.hl8VU4......UG4..#...%A.......BO.Ift..q......!..-uTF&...IU3z.............'1&...TV'#.......,H...............BJh..XNZy..s0J.tkc..Y..SWsi......y..)BG4(....;R....SJF..............V'AV1J............A_....g..8fm>Jwk...Gq......KysW..6RI........Nd.Hsi..W.......L...{}{.?fW...-Z..9...K..........BR\MRRRcmJZZKR\.....BRRRcc]caZkk.........Qkk[cl............AZ[................JZQPkcZk`)R.AZQ............sks1)1bF.JJR........;9@!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 9.1-c002 79.f354efc70, 2023/11/09-12:05:53 "> <rdf:RDF xmlns:rdf="http://www.w3.org/
          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
          File Type:RIFF (little-endian) data, Web/P image
          Category:downloaded
          Size (bytes):36788
          Entropy (8bit):7.991972273004307
          Encrypted:true
          SSDEEP:
          MD5:475C1DAE93F75D0E6AB80DD55FC983CF
          SHA1:4E93F048AAAA906EEEE9A3A3243F3346F357BA4F
          SHA-256:E83D56D06DDEF6751C76FF716EAAA049AD06FE48103C9089DFEDE6B1E61A2AD6
          SHA-512:D42877AF6EEDE6FDA003C5761B5D80C1E9FA2A3123FAFB8F1CFE022DEFC64A4BC5F4B8E3AC5E2A6A14295A770C18D0DD66D65465C3A14571F1D2F412C8F9CEA8
          Malicious:false
          Reputation:unknown
          URL:https://blogue.corim.qc.ca/wp-content/uploads/2024/04/Thumbnail_article_Dufour-Leblond-1.gif
          Preview:RIFF....WEBPVP8L..../RA6......}Ofv.L3.<:....0Jv,G..4 ......n..,0..z.M.&.8.m.m..$.....M.I`gf.....?..2R...#.H.. .*....h.RB....A......).2..cT(9..J....x.......R.c.-....j.(..A..e.?\..-.YG..0D..!.3.N.l..8..Z...i.#U.@..P...G...S_{'....^[...X....QM.H"..@J%fO.h......S..tf]...O...=.V...'O...P...B...tjCT)d3...Z*.0.:....G.k.q*D.J.@C........%.v.Pcl..$.=...K..sh#.....~.)+.'.`r-.'=Y.....q.Sk|k.o.G.........+4...H.D.%......T.;)...._..../...^..rq..X#.\....xS..h......b...S/A......T5FL.f....{./...b..%..v..+.%..A..R._L..Mu.}MS.6.s.....C..L...=....3._9i.q...$.....SK.:.-.O.Uk..dL...I.........7.l,..jj...S...-vl.._]......../.^.9?y.k.[......uO9..6rn..)....1...;..U...>.,.)... .Z.....4..... 7ir.1...0.pF':..V...Bp&.3y..Q..~...*k\E..<'.k.(35.E.LPT.*........_./D._.$.q..w..C%.x %.c...q.9.*.....,..n.....R..&...G-....8.~.W9.}...A..8AG$....lwp.P.w.q...>.........E.J.J7.......h...lm.$....`D`.....9.Q...`$$&%..N.ES .A........#2..D....XhLx.)....x..[...V|.....x...4.V..$!
          No static file info