Sample details: 3d6a6b943cf3eab703d8324a14324910 --

Hashes
MD5: 3d6a6b943cf3eab703d8324a14324910
SHA1: 2beb0ad87e6fad37c25dbaf1310bfe9757d00ef1
SHA256: 969597212421ab51589be001e0d70f38b44459b32a2acee2d709b3649e4d16ac
SSDEEP: 6144:7gWTBJrXwAxxf7Xlj73+EIVQ325ZYm6OGNLaqYs8:7gWTrrXrlJ73+EF3vm6fe1s8
Details
File Type: MS-DOS
Added: 2018-02-28 23:30:01
Yara Hits
YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasOverlay | YRP/HasModified_DOS_Message | YRP/maldoc_find_kernel32_base_method_1 | YRP/domain | YRP/url | YRP/contentis_base64 | YRP/DebuggerCheck__QueryInfo | YRP/ThreadControl__Context | YRP/anti_dbg | YRP/inject_thread | YRP/network_http | YRP/network_tcp_socket | YRP/network_dns | YRP/network_dga | YRP/escalate_priv | YRP/screenshot | YRP/win_mutex | YRP/win_registry | YRP/win_token | YRP/win_files_operation | YRP/Advapi_Hash_API | YRP/CRC32_poly_Constant | YRP/CRC32_table | YRP/BASE64_table | YRP/Str_Win32_Winsock2_Library | YRP/Str_Win32_Wininet_Library | YRP/Str_Win32_Internet_API | YRP/Str_Win32_Http_API |
Strings
		`.data
.idata
@.reloc
Qkkbal
[-&LMb#{'
w+OQvr
)\ZEo^m/
H*0"ZOW
l!;b	F
mj>zjZ
IiGM>nw
ewh/?y
OZw3(?
V_:X1:
								
Invalid parameter passed to C runtime function.
```hhh
xppwpp
HTTP/1.1
Connection: Close
&8<8D8L8T8\8d8l8t8|8@\
9$9,94
@;,T:\:d:l:t:|:
;$;,;4;<;D;L;
b`Wk<t<|<
%$=,=4=<=D=L=T=\=d=l
0$0,040<0D0L0T0\0d0
6<2D2L2T2\2d2l2t2|2
3$3,343
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
0123456789
abcdefghijklmnopqrstuvwxyz
^_`abcdefghijklmnopqrstuvwxyz
NFw-T-
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
kP&Kkl
kGiWkl
kG/_+l
kR+Ckl
kQ2xkl
RegDeleteKeyExW
script
DELETE
CONNECT
OPTIONS
PROPFIND
PROPPATCH
SEARCH
UNLOCK
REPORT
MKACTIVITY
CHECKOUT
M-SEARCH
NOTIFY
SUBSCRIBE
UNSUBSCRIBE
connection
proxy-connection
content-length
transfer-encoding
upgrade
chunked
keep-alive
http://www.google.com/
http://www.bing.com/
ObtainUserAgentString
Authorization
Basic 
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
|$$$}rstuvwxyz{$$$$$$$>?@ABCDEFGHIJKLMNOPQRSTUVW$$$$$$XYZ[\]^_`abcdefghijklmnopq
GetProductInfo
GetFileInformationByHandleEx
SetFileInformationByHandle
YGAS_\u_KY
6;4.:4	$80 1'
_rpk}wn6Xpxpdy
v@@BRDP
Eix~ A`jhfjga
MACITHVZ
9m$8,4
.TJFZPEI]'
F<".2)!15",6J
u\_VZR
vRIWT[?
UPLMHSJ
sp~oWCKphzzGLEHX
dgipUE|RQXxPJp^^JQOSY
XDG5~ritl
 6$&')
.6 $,8
BLTBFNZ
F{x}YnfmTbupgptDf^
.9<+<8
uSJZJW_Oe@SEI~BGEB@n
_|nNnq]~sywVzadnAgld[
;95#7!nus$B
9.>m'!046yd`5M]
N +748H
ZGDA6vaar~vmw|}ikln;&rw`xeidk2.(A
FVGFMTJ]
lfxnebf$ws*`zf
"(6 +,(#f,2.
`jtbinjY}jdek{"yjg
("<*!&"
5",-#3j!;/
pwcddJ0gG?jG:./i\'12rY 4?
gSCAF@B
6,*.(1+
>$"& 9#
"0!;vmk
6(+{`f1G
 tim8@_q$\
%0&s;? **g|~)
?"!$ h~
<:$w|rrm$",
tzzd(;
Pzzvr~M5/&E9+"A=7>]
:'$!lx{p)t
UJRO@DX
53rTOI
dddbqir
Jeebhm{y~|)4vzxk|
pOK@LUR
nJI^NYZ
=ENOH8
+(+&;!86h>n.#&'&5.6-
Ktp{wni;X|`r0\sz`
I`utafgBonazf}
56;&<%
10%3:;
z-gVR	<*!3'nsw"jj;h?AC
;"4+%.'{`Z
*}R_nx
</,)>"7`
Fig_CF
7108?7+..
8-*I^__CRSSk
KWTNaoZ]DBZFLwRX]MY
&1;32$SX]:-14X:
QOPV%+pt`|n*EX[^>!=#
_yjl!:yyy
TLW//eDELX_
hBLAUY]U
9=uVVU_^HVQ/zcg6IM
&&?/#8b
4>4&=nws,UQ
LPSVIYYJ
247!-6
/1*/37	<,
0&%;25
"0)k';%
ym|eagx~+a
E@S_BQM
3$3!)-7h,0.
IKOXtnu|dv`pAvcbg`b~]
|~zn]KHaFONR^
kPdTDAWGx_J\yZDIPGD
WVJXgdv\ji
uHBQUBRDrbENXD[FPChb[]T^IL
sng{LtuakvUes}fcc
t)<8*>
Accept-Language: 
SHGetKnownFolderPath
FCICreate
FCIAddFile
FCIFlushCabinet
FCIDestroy
IsWow64Process
gdiplus.dll
GdiplusStartup
GdiplusShutdown
GdipCreateBitmapFromHBITMAP
GdipDisposeImage
GdipGetImageEncodersSize
GdipGetImageEncoders
GdipSaveImageToStream
userenv.dll
CreateEnvironmentBlock
DestroyEnvironmentBlock
del "%s"
if exist "%s" goto d
@echo off
del /F "%s"
aeiouy
bcdfghjklmnpqrstvwxzGetProcAddress
LoadLibraryA
V0WQPRV
N0WPRQV
Np;Ntt
tm9_ th9_$tc
GD)_p)_l
Nlf+Np
Vlf+Vd
N09F0u
O@;H s
O@;H(s
Oh;O\sR
Gh9Ghr
@PAQBR
wkPSQR
Genuu8
ntelu0
ineIu(
0SSSSS
0SSSSS
URPQQh4
v	N+D$
UQPXY]Y[
L$$QPWV
<SVj83
t$ PVh
w$E;o |
L$$;O 
D$$;G 
w$E;o |
D$$;G }U
D$$;G |
D$(PVV
D$(PVV
9w<t	;_h
tV;_ls
<KvD<M
<KvF<Mw{
l$,;D$(
D$0;\$(s
D$$@PV
}X;_ls+
D$$;D$
D$0K;\$(s
T$ ;T$
L$ ;L$
L$ @PV
T$ ;T$
L$ ;L$
L$ @PV
T$0;Wdu
 !""""""##$%&'())))))**+,-./JJJJJJJJ00J1234555676789:;<:;<JJJJJ=>?@ABCDEFG
xB9T$@t3;
;L$0vH
9|$<tZ
9l$(tK
PQQh$`
HHt*Ht
L$\UVW
T$pSSR
QVVVVVVSW
SSSSSS
D$,PSSSS
D$(PWQS
T$(jvY
D$(VPj
/_^][YY
ItKIt)IIt
9w v>SU
l$ +T$ 
|SUVWjy
D$\j P
f9GLt#8G
D$$jPj
D$$jPj
D$4j:SP
f;D$Nu
f;D$Pt>G
D$zf9G6
D$|f9G8
D$$?*P
QQSUVW
_^][YY
;\$ wVr
tx;\$$wrr
;|$ sj3
D$$QQP
D$,PSS
L$ PPP
QQSVjX
SUj [3
^f90u	j
_^][YY
< t:<	|
SUVWj 
L$0[j	
s?j\_f9
l$ j\_
j [j	B^
Cj ];\$
QQSUVW
_^][YY
D$8_^][
<	w%fkN
Ct7Ht.
Ot2Ht)HHt
	tLHt&Ht
:u9j	X
t+Ht#+
BY;L$ u
_^][YY
t"WPPVh|
_^][YY
D$hPUUU
D$hPUUj
SUVWj8
QSUVWj
QSVWj$[S
QQVWjd
t.Ht$HHt
D$D_^[
D$tPQ3
9ERCPt
u1< uN
T$(9t$
;D$ u%P
L$$9D$H
Kt<Kt"Kt	Kt3Kt
D$8+D$,
SUVWQPh
u79^$u
HHtEHHus
uW;_ttR
;AXw8R
QQSUVW
D$ ;D$
X_^][YY
QX+Q\u
A\;AXr	j
P8\$0t	j
D$$SUV
D$ SUVWP
9t$$r(w
9T$ r 
tv9t$,r(w
9T$(r 
tB9t$4r%w
tlHtSHt;Ht4Ht
ttHtUHt=Ht6Hup
CE;l$ }
tW9w0u"VVj
tuHtlHt*Ht
L$ QPW
tMHt?Ht
u68D$ Qj
t$$Wu\
tC9l$,u=Uj
T$,_^]
}t9_PtP;wPuK
T$(_^][
QQSUVW
_^][YY
PQPhOR
%t'<&t
9l$ u>
|$$PQR
|$0Pj@UV
ZWSSSSP
t#SSWU
SUVWjz
7\1#sa
D$<PQQj
D$ PWV
GGj<ZRP
tDHt:Ht
\$ WUSj
\$$WVUPS
\$$WVU
t$4WQUS
D$ _^][YY
t29\$$tIj
@SUVWh|
WWWhdw
t$$WWU
L$,+L$@j
D$0+D$Dj
_^][YY
D$ ;D$$r
_^][YY
T$ Rj j
9D$ vp
@;t$ r
PH_^][
T$HRSP
\$,9\7
0t"Huqj@
T$$9T$(
>DAVEuAh
=DAVEu"
9|$$t&U
s49>t)
T$$!l$$
t99>~.
D$4_^][
t-HHt!HHt
=ERCPt
D$`PQj
VVVVVV
u$f9]9u
Ht>HuNj
_^][YY
t$$QQW
t$$QQW
f9C t1j
f9C4tDj
G ;F t
G$;F$t
G(;F(u
G,;F,u
L$%9D$
tANNt4Nt(Nt
QQSUVW
t	j\Xf
_^][YY
f9D9 v
L$ ;\$
8SUVWj83
D$Gf9n
QSUVkt$
f9G4tJf9F4u
F4f;G4t
t$f9Q u
SUVWj83
O _^][
t*Ht Ht
^[_]YY
_jzZjaY
QSUVW3
K4;MTtW
D$(Pjd
D$(GET
D$DPj"VWQ
D$0Pj-W
D$@Pj"SWQ
t$PUSV
D$lj$P
_^][YY
t^HtFHuj
D$@PWQ
8\$(tB
u!SSWj
D$$;E4t
t$DSSR
t#;o4u
t$4SVj
t3;_<u
ttHu3j(
D$4PWQ
tFSSWj
D$ SPW
QQSUWj
u$;ATu
T$(9p,u
D$4PWU
t$ Ph(
D$8j2P
t$ WPSQU
jaXjAZ
j0Yj	Zf;
t49l$pt
tNHt$HuD9w
D$<jBP
L$,CSV
9\$ u	
t$T;T$ }
D$\PhM
j?_f9y
:u f9A
<0r	<9w
<0r	<9w
9=lSERt
9=mYPEt'=
EATt =iASVu
9=jTATt
SUVWj~3
l$ PUUh
QQSUVW2
_^][YY
D$8 t 9\$Pul
It5It(Iu7
j Yf9L]
WWPVUj
SSPVUj
D$XCSP
D$XPSh
lUVWjd
FPHt%j
FPHHu!j
tXHtWHt'Ht&Huf
]f9l$8u%j
f9t$ u
D$HPQQ
D$jf9l$hu
9D$ u>
9D$@~kU
l$0PQQ
@f9l$hj
]f9l$hu
L$0u^3
D$PPWV
D$ PQQ
SUVWh 
\$$Pj 
Ht\HtQHHt1
_^][YY
l$ 9\$
SUVWjh
T$4SUVW
f#D$<f;D$<t
t$8USV
D$ PUS
L$,;GH
|$h!|Lj
D$$j!PW
9~Hv73
<0|-<9
X_^][YY
marioA
&cUi6h
Qkkbal
Tw	`Rw
,OwL OwJ
NtTerminateProcess
NtCreateFile
LdrLoadDll
LdrGetDllHandle
NtQueryInformationProcess
ntdll.dll
CreateFileW
WaitForSingleObject
WriteFile
FlushFileBuffers
GetLastError
SetLastError
CloseHandle
ExpandEnvironmentStringsW
GetCommandLineW
GetNativeSystemInfo
GetDriveTypeW
GetSystemDefaultUILanguage
GetLogicalDrives
GetTickCount
GetProcessTimes
GetModuleFileNameW
lstrcmpW
GlobalMemoryStatusEx
GetUserDefaultUILanguage
GetDiskFreeSpaceExW
lstrcpyW
GetVolumeInformationW
GetModuleHandleW
GetProcAddress
FindFirstFileW
FindClose
FindNextFileW
InitializeCriticalSection
DeleteCriticalSection
lstrlenA
FreeLibrary
IsBadReadPtr
VirtualFreeEx
VirtualAllocEx
LoadLibraryA
WriteProcessMemory
GetCurrentThread
SetThreadPriority
TryEnterCriticalSection
SetEvent
LeaveCriticalSection
EnterCriticalSection
CreateEventW
WaitForMultipleObjects
HeapReAlloc
HeapAlloc
HeapFree
HeapDestroy
HeapCreate
lstrlenW
lstrcatW
CreateRemoteThread
OpenProcess
Process32FirstW
Process32NextW
CreateToolhelp32Snapshot
CreateThread
lstrcmpA
LoadLibraryW
GetPrivateProfileStringW
GetPrivateProfileIntW
SystemTimeToFileTime
GetTimeZoneInformation
GetLocalTime
GetSystemTime
QueryPerformanceCounter
GlobalLock
GlobalUnlock
GetCurrentProcessId
CreateDirectoryW
SetFileAttributesW
TlsGetValue
TlsSetValue
TlsAlloc
UnregisterWait
RegisterWaitForSingleObject
lstrcmpiA
GetThreadContext
SetThreadContext
VirtualQuery
GetCurrentProcess
FlushInstructionCache
VirtualAlloc
VirtualProtect
GetCurrentThreadId
ResumeThread
WideCharToMultiByte
GetComputerNameW
GetVersionExW
GetVolumeNameForVolumeMountPointW
MapViewOfFile
UnmapViewOfFile
CreateProcessW
CreateFileMappingW
DuplicateHandle
LocalFree
TlsFree
GetThreadPriority
TerminateThread
VirtualFree
GetExitCodeThread
ExitProcess
GetSystemTimeAsFileTime
WTSGetActiveConsoleSessionId
lstrcmpiW
DosDateTimeToFileTime
SetEndOfFile
SetFilePointerEx
SetFileTime
GetFileAttributesW
ReadFile
GetTempPathW
GetFileSizeEx
GetFileTime
DeleteFileW
GetFileInformationByHandle
CreateMutexW
OpenMutexW
ReleaseMutex
lstrcpyA
RemoveDirectoryW
MoveFileExW
FileTimeToDosDateTime
GetTempFileNameW
lstrcpynA
FileTimeToLocalFileTime
ResetEvent
MultiByteToWideChar
GetEnvironmentVariableW
Thread32First
Thread32Next
GetProcessId
GetHandleInformation
SetErrorMode
OpenEventW
KERNEL32.dll
GetSystemMetrics
GetLastInputInfo
CharUpperW
CharLowerA
ToUnicode
GetKeyboardState
CharLowerW
ExitWindowsEx
GetClipboardData
TranslateMessage
PostQuitMessage
GetCursorPos
GetIconInfo
DrawIcon
LoadCursorW
CharToOemW
DispatchMessageW
PeekMessageW
MsgWaitForMultipleObjects
USER32.dll
RegCreateKeyExW
RegQueryValueExW
RegQueryInfoKeyW
RegDeleteKeyW
RegDeleteValueW
RegOpenKeyExW
RegFlushKey
RegEnumKeyExW
RegCloseKey
RegSetValueExW
GetLengthSid
InitiateSystemShutdownExW
CryptGetHashParam
CryptAcquireContextW
CryptReleaseContext
CryptCreateHash
CryptDestroyHash
CryptHashData
GetTokenInformation
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
ConvertStringSecurityDescriptorToSecurityDescriptorW
GetSecurityDescriptorSacl
SetSecurityDescriptorSacl
EqualSid
CryptVerifySignatureW
CryptGetKeyParam
CryptImportKey
CryptDestroyKey
OpenProcessToken
GetSidSubAuthority
OpenThreadToken
GetSidSubAuthorityCount
CreateProcessAsUserW
LookupPrivilegeValueW
AdjustTokenPrivileges
IsWellKnownSid
ConvertSidToStringSidW
ADVAPI32.dll
PathFindFileNameW
PathRemoveBackslashW
PathGetDriveNumberW
PathRemoveFileSpecW
PathRemoveExtensionW
UrlUnescapeA
StrCmpNIA
PathIsURLW
wvnsprintfW
wvnsprintfA
StrStrIW
PathIsDirectoryW
PathRenameExtensionW
StrRChrA
StrCmpIW
StrChrW
StrCmpW
StrCmpNA
StrCmpNIW
StrCmpNW
StrChrA
PathQuoteSpacesW
PathAddBackslashW
PathUnquoteSpacesW
PathSkipRootW
PathMatchSpecW
PathFindExtensionW
SHLWAPI.dll
SHGetFolderPathW
ShellExecuteW
CommandLineToArgvW
SHELL32.dll
GetUserNameExW
DeleteSecurityContext
DecryptMessage
EncryptMessage
Secur32.dll
CoSetProxyBlanket
CoCreateInstance
CoUninitialize
CoInitializeSecurity
CoInitializeEx
CLSIDFromString
StringFromGUID2
CoTaskMemFree
CreateStreamOnHGlobal
ole32.dll
CreateCompatibleBitmap
CreateCompatibleDC
SelectObject
DeleteObject
CreateDCW
GetDeviceCaps
DeleteDC
BitBlt
GDI32.dll
GetAddrInfoW
freeaddrinfo
WSAGetOverlappedResult
WSASend
WSARecv
getaddrinfo
FreeAddrInfoW
WSAStringToAddressW
WSAAddressToStringA
WSACreateEvent
WSAEventSelect
WSAEnumNetworkEvents
WSAAddressToStringW
WSAIoctl
WSACloseEvent
WS2_32.dll
PFXImportCertStore
CertDeleteCertificateFromStore
CertOpenSystemStoreW
CertCloseStore
CertEnumCertificatesInStore
CertDuplicateCertificateContext
PFXExportCertStoreEx
CryptUnprotectData
CRYPT32.dll
HttpSendRequestExA
HttpQueryInfoA
InternetConnectA
InternetCrackUrlA
InternetReadFile
InternetSetOptionA
InternetWriteFile
HttpOpenRequestA
HttpEndRequestA
HttpAddRequestHeadersA
InternetOpenA
InternetCloseHandle
InternetQueryOptionA
WININET.dll
OLEAUT32.dll
NetUserGetInfo
NetApiBufferFree
NetUserEnum
NETAPI32.dll
GetAdaptersAddresses
IPHLPAPI.DLL
GetFileVersionInfoW
VerQueryValueW
GetFileVersionInfoSizeW
VERSION.dll
_errno
memset
memcpy
_purecall
memmove
strcmp
memcmp
strtoul
_ultow
memchr
_vsnwprintf
_vsnprintf
msvcrt.dll
RtlUnwind
SetFilePointer
OutputDebugStringA
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
_except_handler3
(141@1L1X1d1p1|1
5 6$6(6,6064686<6@6t6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
? ?$?(?,?0?4?8?
d0l0t0|0
1$1,141<1
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
0`0d0h0l0p0t0x0|0
1X2\2`2
7$7(7,7074787<7@7D7
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:`<d<h<l<p<t<x<|<
> >$>(>,>0>4>8><>@>D>H>L>P>t>x>|>
7<7o8y8~8
9':1:w:
C3l3{3
6)8C:Q:
=<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
61k1r1~1
2.2:2G2a2n2z2
303<3I3s3
=#=B=->_>
5F6L6R6X6^6d6k6r6y6
6 6$6)606a6|6
:*:_:x:
==>L>W>
)000P032
3K4V4|7
1!1%1)1-1115191=1A1E1I1M1Q1U1Y1]1a1e1i1m1q1u1y1}1
2!2%2)2-212
3!3%3)3-3135393=3A3E3I3M3Q3U3Y3]3a3e3i3
<A=T=x=
8$9*:A:a:v:{:
=6>O>^>e>j>t>}>
0'141^1x1
647G7w7
8"8&8+828;8S8
>.>Y>g>
3!3(3-353I3
=#>4>S>Z>
5/6T6x6
667C7t7
</<Y<v<
=0Z0t0
1+121>1D1V1\1o1u1
2$2*2P2
5 5t687
>H>U>j>
?"?(?6?H?O?a?i?
070I0S0Y0a0k0
9k:{:@;
;0<6<~<
4!4%4)4-4145494=4A4E4I4M4Q4U4Y4]4a4e4i4m4q4u4y4}4
425A6E6I6M6Q6U6Y6]6a6D8k8
8+939c9::u:
=*>H>x>
4,535=5C5
6C6R6Y6_6q6x6
5&6W6m6
7#7'7/757;7@7G7
<0<E<o<}<
= =4=H=\=t=
1!1%1)1-6<6[6
9*:9:i:t:
=,=1=7=F=L=[=a=p=v=
>)>/>:>@>K>Q>\>b>m>s>~>
?&?3?;?C?j?x?
2!2D2X2
3+3F3c3
9J:_:~:
>S?\?c?i?{?
000^0f0
1)1.191>1\1b1|1
2&2+23282@2E2M2R2Z2_2g2l2
3!3,333C3U3[3g3o3
4"434?4O4[4c4k4r4
5-6]6~7
7&8B8k8
92:W:]:
;$;7;O;f;
090C0w0
:,:U:`:m:
::;H;^;h;
<B<M<Z<q<w<~<
2O2p2x2~2
4]6c6o6}6
9%9A9M9g9v9
=&=.=L=
>(?;?t?
5 5'5J5k5t5
6T7]7d7j7x7
8)868F8Q8Y8g8q8
4)4Q4|4
5#5'5/5T5[5z5
576D6Y6
9 9*93979<9C9L9
:.:<:H:t:z:
:$;N;n;
</<_<q<
=#=-=S=k=u=G>Z>
60?0F0K0U0^0b0g0n0w0
151L1z1
6$6?6K6\6c6
7&7G7y7
<9>n?}?
1M1;2@2x2}2
4<4w4|4
5)687y7
081K1m1
<*=[=}=
0#0B0H0d0j0
1+1c1m1
3+41484=4I4
4D5N5q5c6
7/7=7T7
4(5R5W5\5u5
616R6r6
6O7T7Y7w7
:&:E:`:
='=2=B=R=Y=i=t=
2/2P2o2
<4=7>G>y>
&0H0u0
0J1_1f1}1
425_5y5
8+989W9z9
:':=:E:W:_:q:y:
<"<M<d<
<3=:=C=^=l=
> >'>,>8>>>D>J>N>S>Z>w>
9<:O:X:_:e:w:~:
7@7Q7Z7a7f7p7y7}7
="=W=j=
>&>/>6>:>?>F>V>y>
5*5B5Z5r5
6(636C6v6
?.?>?G?N?S?]?f?j?o?v?|?
0\0d0m0
7.7D7b7}7
8-8L8e8o8
9O9j9y9
<*<W<]<
> >6>=>
9"9g9z9t;
>9>P>Z>
5d6m6x6
717@7z7
#0)0U0f0
2K2n263
5L5R5b5y5
6;6G6l6
6:7K7_7i7~7Q8
=&=0=6=R=Z=b=
> >'>5>`>f>p>z>
><?D?N?V?
1:1I1d1
1#2)2.282I2Y2f2u2
373?3a3n3
4"4G4e4r4
5C5_5e5k5q5~5
546E6o6u6
7"7:7@7V7]7c7l7
7	8l8u8
9I9Q9X9d9
:,:8:L:W:
<5=U=e=q=
>">'>Y>^>
?-?d?p?w?
;!;d;t;
=$=7=H=
=H=6>U>
345L5}5m6
6<8D8N8h8|8
<(=2=8=>=
?+?1?9?D?S?Y?
90D0l0~3
888=8D9t9
:0<?<(=
60676=6O6V6Z6a647
>$>(>4>8>D>H>T>X>d>h>t>x>
?$?(?4?8?T?X?