{"Username: ": "6WLmA2S8h7", "URL: ": "https://GsKwOmvIezHndSQmIcyS.com", "To: ": "armyscheme@yandex.com", "ByHost: ": "smtp.yandex.com:587", "Password: ": "UM9UHPz8BDmgDL", "From: ": "armyscheme@yandex.com"}
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe.7080.4.memstr | Malware Configuration Extractor: Agenttesla {"Username: ": "6WLmA2S8h7", "URL: ": "https://GsKwOmvIezHndSQmIcyS.com", "To: ": "armyscheme@yandex.com", "ByHost: ": "smtp.yandex.com:587", "Password: ": "UM9UHPz8BDmgDL", "From: ": "armyscheme@yandex.com"} |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Virustotal: Detection: 36% | Perma Link |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | ReversingLabs: Detection: 33% |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Joe Sandbox ML: detected |
Source: 4.2.SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe.400000.0.unpack | Avira: Label: TR/Spy.Gen8 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Static PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4x nop then mov dword ptr [ebp-18h], 00000000h | 0_2_05920BB8 |
Source: Malware configuration extractor | URLs: https://GsKwOmvIezHndSQmIcyS.com |
Source: global traffic | TCP traffic: 192.168.2.4:49764 -> 77.88.21.158:587 |
Source: Joe Sandbox View | IP Address: 77.88.21.158 77.88.21.158 |
Source: global traffic | TCP traffic: 192.168.2.4:49764 -> 77.88.21.158:587 |
Source: unknown | DNS traffic detected: queries for: smtp.yandex.com |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911990568.00000000029C1000.00000004.00000001.sdmp | String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911990568.00000000029C1000.00000004.00000001.sdmp | String found in binary or memory: http://DynDns.comDynDNS |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://crl.certum.pl/ca.crl0h |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://crl.certum.pl/ctnca.crl0k |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.915387308.0000000006370000.00000004.00000001.sdmp | String found in binary or memory: http://crl.certum.plWq |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://crls.yandex.net/certum/ycasha2.crl0- |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://repository.certum.pl/ca.cer09 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://repository.certum.pl/ctnca.cer09 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://repository.certum.pl/ycasha2.cer0 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000002.651915801.0000000002671000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://smtp.yandex.com |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://subca.ocsp-certum.com0. |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://subca.ocsp-certum.com01 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911990568.00000000029C1000.00000004.00000001.sdmp | String found in binary or memory: http://tTAnFc.com |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://www.certum.pl/CPS0 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.915387308.0000000006370000.00000004.00000001.sdmp | String found in binary or memory: http://www.certum.pl/Ciq |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://yandex.crl.certum.pl/ycasha2.crl0q |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: http://yandex.ocsp-responder.com03 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912499535.0000000002CDB000.00000004.00000001.sdmp, SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912630626.0000000002D4D000.00000004.00000001.sdmp, SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000003.856886257.0000000000BB4000.00000004.00000001.sdmp | String found in binary or memory: https://GsKwOmvIezHndSQmIcyS.com |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911990568.00000000029C1000.00000004.00000001.sdmp | String found in binary or memory: https://api.ipify.org%$ |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911990568.00000000029C1000.00000004.00000001.sdmp | String found in binary or memory: https://api.ipify.org%GETMozilla/5.0 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000002.651915801.0000000002671000.00000004.00000001.sdmp | String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.912711978.0000000002D64000.00000004.00000001.sdmp | String found in binary or memory: https://www.certum.pl/CPS0 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000002.652337158.0000000003679000.00000004.00000001.sdmp, SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.910118958.0000000000402000.00000040.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911990568.00000000029C1000.00000004.00000001.sdmp | String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, FrmStart.cs | Long String: Length: 13656 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 0_2_059213B8 | 0_2_059213B8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 0_2_024E9608 | 0_2_024E9608 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 0_2_024EC2A8 | 0_2_024EC2A8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 0_2_024EAB34 | 0_2_024EAB34 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 0_2_001BA161 | 0_2_001BA161 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 2_2_0018A161 | 2_2_0018A161 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007B0C58 | 4_2_007B0C58 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007B9858 | 4_2_007B9858 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007BC560 | 4_2_007BC560 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007B5950 | 4_2_007B5950 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007BE708 | 4_2_007BE708 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007BF411 | 4_2_007BF411 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007BC750 | 4_2_007BC750 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007DB44C | 4_2_007DB44C |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007DDEA6 | 4_2_007DDEA6 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007DAB70 | 4_2_007DAB70 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007D2768 | 4_2_007D2768 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_007D1FF0 | 4_2_007D1FF0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_00E346A0 | 4_2_00E346A0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_00E34690 | 4_2_00E34690 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_01060160 | 4_2_01060160 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_01061818 | 4_2_01061818 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_0106B320 | 4_2_0106B320 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_01065E48 | 4_2_01065E48 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_0106E5A8 | 4_2_0106E5A8 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_0106A9B0 | 4_2_0106A9B0 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_01066C40 | 4_2_01066C40 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_01066B48 | 4_2_01066B48 |
Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Code function: 4_2_0057A161 | 4_2_0057A161 |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Binary or memory string: OriginalFilename vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000000.642508017.00000000002BC000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenamec.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000002.652337158.0000000003679000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameLegacyPathHandling.dllN vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000002.652337158.0000000003679000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameVUjAHBxYPFxCVjXHCpyuGgBIgZxcGuTQWnqk.exe4 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000000.00000002.651915801.0000000002671000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameAsyncState.dllF vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000002.00000000.648671150.000000000028C000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenamec.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.910424435.00000000007C0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamewshom.ocx.mui vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.910296987.000000000067C000.00000002.00020000.sdmp | Binary or memory string: OriginalFilenamec.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.911469585.0000000000FD0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamemscorrc.dllT vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.910537732.0000000000AF8000.00000004.00000001.sdmp | Binary or memory string: OriginalFilenameUNKNOWN_FILET vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.910118958.0000000000402000.00000040.00000001.sdmp | Binary or memory string: OriginalFilenameVUjAHBxYPFxCVjXHCpyuGgBIgZxcGuTQWnqk.exe4 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, 00000004.00000002.910376100.00000000007A0000.00000002.00000001.sdmp | Binary or memory string: OriginalFilenamewshom.ocx vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Binary or memory string: OriginalFilenamec.exe8 vs SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe | Static PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE |
Source: SecuriteInfo.com.Trojan.GenericKDZ.73120.3552.exe, FrmStart.cs | Base64 encoded string: 'GIdDNNZNNNNRNNNN//8NNYtNNNNNNNNNDNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNtNNNNN4sht4NgNaAVotOGZ0uITucplOjpz9apzSgVTAuoz5iqPOvMFOlqJ4tnJ4tER9GVT1iMTHhQD0XWNNNNNNNNNODEDNNGNRQNViu868NNNNNNNNNNBNNNvRYNINNNPNNNNNTNNNNNNNNlw8NNNNtNNNNDNNNNNNNRDNtNNNNNtNNONNNNNNNNNNRNNNNNNNNNNPNNNNNNtNNNNNNNNZNDVHNNONNNONNNNNNRNNNRNNNNNNNNONNNNNNNNNNNNNNNUt/NNOCNNNNNRNNNBDQNNNNNNNNNNNNNNNNNNNNNNNNNTNNNNjNNNOpCjNNUNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNVNNNPNNNNNNNNNNNNNNNPPNNNRtNNNNNNNNNNNNNNP50MKu0NNNN0O8NNNNtNNNNVNNNNNVNNNNNNNNNNNNNNNNNNPNNNTNhpaAlLjNNNBDQNNNNDNNNNNDNNNNvNNNNNNNNNNNNNNNNNNONNNONYaWyoT9wNNNZNNNNNTNNNNNPNNNNWtNNNNNNNNNNNNNNNNNNDNNNDtNNNNNNNNNNNNNNNNNNNNPfCjNNNNNNNRtNNNNPNNHNhPHNNBjLNNNQNNNNNNNNNXD+NNP4NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNO4PXOLNNNbdWtNPXOpNNNbNXdMmTNNNPbNONNNRpkxNNNdNNtNNOUZnNNNXtNZNNNEmTjNNPbNRNNNRXuZjNDNDNNNNNDNNRDO+NDNNOT8pNNNXPvfNOvbGZNRNRNNNNNVNNORNstVNNNEiUDNNPtbeNNLdRmNONONNNNNQNNNENU4QNNNRok4NNNbXXjNTXuZjNDNDNNNNONNNRDO+ONNNOT8sNNNXPvfNOvbGZNVNCNNNNNHNNORNstHNNNDHXPNNNNbYOljuptRNNUQDODNNNvtuNNNXolVNNNcmVjNNPtjVtNHNNNDNNU4SNNNRPvfNOvbGZNRNPjNNNNLNNORNstLNNNDXXjNTXvVNNbNTNNNRXyMmQNNNOvtxNNNXqNLNNNXNOjNNOPbrNvtyNNNXXtNNRmNONNfNNNNUNNNENU4UNNNRPvfNOvbNRmNONNfNNNNUNNNENPtANNNTPvfNOvc+pwfNNUPNPNNNOUV7NNOjtNxNNNElBjNNpVNXNNNRXxbNNvtzNNNXNNZROFtENNNTNPbNNOZjONO0NNNNPNNNRDOmWjNNPtbTVYvPNDNtXWbONT8bNNNXXPxNNNbNNvtINNNTOPtHNNNTPjpbRjNNOtZbSDNNOvtFNNNTQNtbXtNNPt0WolfNNNbqzuZRRDEiYNNNPuhnRjHEOKV9NNOjTOvAStNNNFtgNNNXWuLbYtNNPtNdRmNSNWpNNNNWNNNENPtiNNNXN28jNNNXPjVPwzxK2cRspTRZNb5cS9LK2usJwF8NNNRANb5cS9bGOORRRjHJRjLeBtxEOtVEOcRVLDpEO5SugWjEOjAiZDNNPusn/tRGPORVRjxEPFjTSuZUNPfVNORUS9LGOjNEOusJRjLEOuRSZpNWNb5cTAbK1usnS9nAYjNNNFtlNNNXqNHNNOfXXjNTXtNGZNHNctNNNNbNNORNStfPomZNNNbGOkVUXQDNNNbZPNwLTgtAPEsnS9nAYjNNNEZRPOsnRjtJRjxeDjtK2uZXSuZYXl0PRDxEP281NNNXRjjFQPt2NNNXXQpNNNbJRDDUTvt4NNNXNNpn1tfEPksJRjfEPkRXZp0EPEsJRjxEPERVZopEOOLbBDNNPuZSRDHK2usJwF8NNNRGOuRRTuRTSuRTwzxbBNNNPtNEOtbeNNLdNNNGZNVNXNNNNNfNNORNN3WYNNOjXQbNNNbbBjNNPaZwNNNXPjpPomjNNNc0VtNNNDbeNNLdRmNRNRbNNNNZNNNENNWiZDNNPuuopm0NNNbYNz8kNNNXTAbZSt0eUjpPPEuiCtNNPu8DXQ8NNNbbDNNNPz9ONNNXWtxL1t0WPQUqO29PNNNXPvfNOvbNNOZjNDNUNNNNQDNNRDNHPvfNOvcTNNVJztVKztVLzvtENNNTNPbNNNNGZNZNVNNNNN4NNORNsttNNNE+PDNNOU4XNNNRXORNNNLNpwfNNUNXXjNTXuZjNtNFNNNNQjNNRDNPNluQNNNXXRDNNNbXXjNTXtNNRmNONNjNNNNDNNNENNVbEDNNPtbeNNLdRmNONONNNNNENNNENANWNNNPXPRNNNbXXjNTXuZjNDNZNNNNQtNNRDNPXRLNNNbXXjNTXuZjNtNqNNNNRtNNRDNPwNLNNOfH/tRYOljVXNRNNPfXXjHNNtbeNNLdWtNQ/uHTNNNoXvLNNvt |