What is FlashPlayerPlugin_32_0_0_270.exe?

FlashPlayerPlugin_32_0_0_270.exe is part of Shockwave Flash and developed by Adobe according to the FlashPlayerPlugin_32_0_0_270.exe version information.

FlashPlayerPlugin_32_0_0_270.exe's description is "Adobe Flash Player 32.0 r0"

FlashPlayerPlugin_32_0_0_270.exe is digitally signed by Adobe Inc..

FlashPlayerPlugin_32_0_0_270.exe is usually located in the 'c:\Windows\SysWOW64\Macromed\Flash\' folder.

None of the anti-virus scanners at VirusTotal reports anything malicious about FlashPlayerPlugin_32_0_0_270.exe.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on FlashPlayerPlugin_32_0_0_270.exe:

PropertyValue
Product nameShockwave Flash
Company nameAdobe
File descriptionAdobe Flash Player 32.0 r0
Internal nameAdobe Flash Player 32.0
Original filenameSAFlashPlayer.exe
Legal copyrightAdobe® Flash® Player. Copyright © 1996-2019 Adobe. All Rights Reserved. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
Legal trademarkAdobe Flash Player
Product version32,0,0,270
File version32,0,0,270

Here's a screenshot of the file properties when displayed by Windows Explorer:

Product nameShockwave Flash
Company nameAdobe
File descriptionAdobe Flash Player 32.0 r0
Internal nameAdobe Flash Player 32.0
Original filenameSAFlashPlayer.exe
Legal copyrightAdobe® Flash® Player. Copyright ©..
Legal trademarkAdobe Flash Player
Product version32,0,0,270
File version32,0,0,270

Digital signatures [?]

FlashPlayerPlugin_32_0_0_270.exe has a valid digital signature.

PropertyValue
Signer nameAdobe Inc.
Certificate issuer nameDigiCert EV Code Signing CA (SHA2)
Certificate serial number0d2caccd3e9eec06738410ba31bf6595

VirusTotal report

None of the 70 anti-virus programs at VirusTotal detected the FlashPlayerPlugin_32_0_0_270.exe file.

None of the 70 anti-virus programs detected the FlashPlayerPlugin_32_0_0_270.exe file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_recreated": [
        "\\??\\MountPointManager"
    ],
    "regkey_written": [
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\FFlags",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByDirection",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2\\Settings",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Sort",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\LogicalViewMode",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Mode",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\UserStartTime",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:PID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupView",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ColInfo",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:FMTID",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\\CheckSetting",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\LastAdvertisement",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\IconSize",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Desktop\\TaskbarWinXP"
    ],
    "dll_loaded": [
        "C:\\Windows\\system32\\kernel32.dll",
        "kernel32",
        "api-ms-win-core-sysinfo-l1-2-1",
        "api-ms-win-core-localization-l1-2-1",
        "kernel32.dll",
        "api-ms-win-core-synch-l1-2-0",
        "C:\\Windows\\system32\\uxtheme.dll",
        "ntmarta.dll",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
        "cryptbase.dll",
        "api-ms-win-security-systemfunctions-l1-1-0",
        "ole32.dll",
        "API-MS-Win-Security-SDDL-L1-1-0.dll",
        "C:\\Windows\\system32\\xmllite.dll",
        "OLEAUT32.dll",
        "profapi.dll",
        "comctl32.dll",
        "C:\\Windows\\system32\\user32.dll",
        "C:\\Windows\\system32\\shell32.dll",
        "api-ms-win-core-fibers-l1-1-1",
        "ADVAPI32.dll",
        "rpcrt4.dll",
        "advapi32",
        "C:\\Windows\\system32\\version.dll"
    ],
    "file_opened": [
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\acro_rd_dir",
        "C:\\",
        "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\Icon Cache",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\APSPrivateData2",
        "C:\\Users\\cuck\\AppData\\Local\\Macromedia\\Flash Player",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache",
        "C:\\Windows\\System32"
    ],
    "regkey_opened": [
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Adobe\\FlashPlayer\\FeatureLockDown",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KnownFolderSettings",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Adobe\\FlashPlayer\\11.0\\FeatureLockDown",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
        "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
        "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_CURRENT_USER\\(Default)",
        "HKEY_CURRENT_CONFIG\\(Default)",
        "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
        "HKEY_LOCAL_MACHINE\\(Default)",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
        "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
        "HKEY_USERS\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
        "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
        "HKEY_CLASSES_ROOT\\(Default)",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
        "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1"
    ],
    "regkey_deleted": [
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupCollapseState",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemOrder",
        "HKEY_CURRENT_USER\\System\\CurrentControlSet\\Control\\Network\\ShowWirelessConnectingOnStart",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemPos800x600x96(1)"
    ],
    "file_exists": [
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
        "C:\\Users\\cuck\\AppData\\LocalLow",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
        "C:\\Users\\cuck",
        "C:\\Users\\cuck\\Desktop",
        "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player",
        "C:\\cuckoo_1788.ini",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\Icon Cache",
        "C:\\cuckoo_2204.ini",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\APSPrivateData2",
        "C:\\Users\\cuck\\AppData\\Local\\Macromedia\\Flash Player",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\acro_rd_dir"
    ],
    "mutex": [
        "Local\\Shell.CMruPidlList",
        "{100184D2-BDC3-477a-B8D3-65548B67914C}_2420"
    ],
    "file_failed": [
        "C:\\Users\\cuck\\AppData\\Roaming\\Justsystem",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME??",
        "C:\\cuckoo_1788.ini",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP?_?",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP??",
        "C:\\Windows\\SysWOW64\\Macromed\\Flash\\mms.cfg"
    ],
    "guid": [
        "{9b63616c-36b2-46bc-959f-c1593952d19b}",
        "{1a1f4206-0688-4e7f-be03-d82ec69df9a5}",
        "{c08956a2-1cd3-11d1-b1c5-00805fc1270e}",
        "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
        "{a47979d2-c419-11d9-a5b4-001185ad2b89}",
        "{7007acc7-3202-11d1-aad2-00805fc1270e}",
        "{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
        "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}",
        "{ba126ad1-2166-11d1-b1d0-00805fc1270e}",
        "{faedcf69-31fe-11d1-aad2-00805fc1270e}",
        "{ba126ae5-2166-11d1-b1d0-00805fc1270e}",
        "{000214e6-0000-0000-c000-000000000046}"
    ],
    "command_line": [
        "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin\" --channel=2420.0058F40C.1033384170 --type=renderer"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlot",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\prnfldr.dll,-8036",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\InProcServer32\\(Default)",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\SortOrderIndex",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{21EC2020-3AEA-1069-A2DD-08002B30309D}\\SortOrderIndex",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClearRecentDocsOnExit",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\InProcServer32\\LoadWithoutCOM",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Roamable",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\RelativePath",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
        "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PromotedIconCache",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\LocalizedString",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResource",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalizedName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Icon",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\System.ItemNameDisplay",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
        "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\netshell.dll,-1200",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\System.ItemNameDisplay",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Name",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParentFolder",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Description",
        "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InitFolderHandler"
    ],
    "directory_enumerated": [
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
        "C:\\Users\\cuck\\AppData\\LocalLow",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
        "C:\\Users\\cuck\\AppData",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
        "C:\\Users\\cuck\\AppData\\Local\\Temp",
        "C:\\Users\\cuck",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\Users",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
        "C:\\Users\\cuck\\AppData\\Local"
    ],
    "directory_created": [
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\acro_rd_dir",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache",
        "C:\\Users\\cuck\\AppData",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe",
        "C:\\Users\\cuck\\AppData\\LocalLow",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache",
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
        "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player",
        "C:\\Users\\cuck\\AppData\\Local\\Macromedia",
        "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player",
        "C:\\Users\\cuck\\AppData\\Roaming",
        "C:\\Users",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\APSPrivateData2",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
        "C:\\Users\\cuck",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
        "C:\\Users\\cuck\\AppData\\Local",
        "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\Icon Cache",
        "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
        "C:\\Users\\cuck\\AppData\\Local\\Macromedia\\Flash Player"
    ]
}

Generic

[
    {
        "process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
        "process_name": "644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
        "pid": 2420,
        "summary": {
            "file_recreated": [
                "\\??\\MountPointManager"
            ],
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\acro_rd_dir",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache",
                "C:\\Users\\cuck\\AppData",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe",
                "C:\\Users\\cuck\\AppData\\LocalLow",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
                "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player",
                "C:\\Users\\cuck\\AppData\\Local\\Macromedia",
                "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\APSPrivateData2",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
                "C:\\Users\\cuck",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
                "C:\\Users\\cuck\\AppData\\Local",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\Icon Cache",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
                "C:\\Users\\cuck\\AppData\\Local\\Macromedia\\Flash Player"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\kernel32.dll",
                "kernel32",
                "api-ms-win-core-sysinfo-l1-2-1",
                "api-ms-win-core-localization-l1-2-1",
                "kernel32.dll",
                "api-ms-win-core-synch-l1-2-0",
                "C:\\Windows\\system32\\uxtheme.dll",
                "ntmarta.dll",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
                "cryptbase.dll",
                "api-ms-win-security-systemfunctions-l1-1-0",
                "ole32.dll",
                "API-MS-Win-Security-SDDL-L1-1-0.dll",
                "OLEAUT32.dll",
                "profapi.dll",
                "comctl32.dll",
                "C:\\Windows\\system32\\user32.dll",
                "C:\\Windows\\system32\\shell32.dll",
                "api-ms-win-core-fibers-l1-1-1",
                "ADVAPI32.dll",
                "rpcrt4.dll",
                "advapi32",
                "C:\\Windows\\system32\\version.dll"
            ],
            "file_failed": [
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME??",
                "C:\\Users\\cuck\\AppData\\Roaming\\Justsystem",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP??",
                "C:\\Windows\\SysWOW64\\Macromed\\Flash\\mms.cfg",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP?_?"
            ],
            "regkey_opened": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Adobe\\FlashPlayer\\FeatureLockDown",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KnownFolderSettings",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Adobe\\FlashPlayer\\11.0\\FeatureLockDown",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FolderDescriptions",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\KnownFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
                "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
                "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_CURRENT_USER\\(Default)",
                "HKEY_CURRENT_CONFIG\\(Default)",
                "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
                "HKEY_LOCAL_MACHINE\\(Default)",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
                "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
                "HKEY_USERS\\(Default)",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PropertyBag",
                "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
                "HKEY_CLASSES_ROOT\\(Default)",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
                "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1"
            ],
            "file_exists": [
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\acro_rd_dir",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
                "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player",
                "C:\\Users\\cuck",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\Icon Cache",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\APSPrivateData2",
                "C:\\Users\\cuck\\AppData\\Local\\Macromedia\\Flash Player",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
                "C:\\Users\\cuck\\AppData\\LocalLow"
            ],
            "mutex": [
                "{100184D2-BDC3-477a-B8D3-65548B67914C}_2420"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AssetCache",
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\acro_rd_dir",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
                "C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Users\\cuck\\AppData\\Roaming\\Macromedia\\Flash Player",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\Icon Cache",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\APSPrivateData2",
                "C:\\Users\\cuck\\AppData\\Local\\Macromedia\\Flash Player",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\NativeCache",
                "C:\\Windows\\System32"
            ],
            "command_line": [
                "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin\" --channel=2420.0058F40C.1033384170 --type=renderer"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParsingName",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Stream",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Description",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\FolderTypeID",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\RelativePath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Description",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PublishExpandedPath",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Category",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\StreamResourceType",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\PreCreate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalRedirectOnly",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Stream",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Icon",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\StreamResource",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\LocalizedName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParsingName",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InfoTip",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Name",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\ParentFolder",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Security",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\Roamable",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\\Attributes",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\explorer\\FolderDescriptions\\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\\InitFolderHandler",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US"
            ],
            "directory_enumerated": [
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Speech",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP12",
                "C:\\Users\\cuck\\AppData\\LocalLow",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP8_1",
                "C:\\Users\\cuck\\AppData",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IMJP9_0",
                "C:\\Users\\cuck\\AppData\\Local\\Temp",
                "C:\\Users\\cuck",
                "C:\\Users\\cuck\\AppData\\LocalLow\\Microsoft\\IME12",
                "C:\\Users\\cuck\\AppData\\Roaming",
                "C:\\Users",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe",
                "C:\\Users\\cuck\\AppData\\Roaming\\Adobe\\Flash Player\\AFCache",
                "C:\\Users\\cuck\\AppData\\Local"
            ]
        },
        "first_seen": 1570755210.9375,
        "ppid": 2736
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1570755210.5781,
        "ppid": 376
    },
    {
        "process_path": "C:\\Windows\\explorer.exe",
        "process_name": "explorer.exe",
        "pid": 1788,
        "summary": {
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\FFlags",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByDirection",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2\\Settings",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Sort",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\LogicalViewMode",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\Mode",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\UserStartTime",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\LanguageList",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:PID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupView",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ColInfo",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupByKey:FMTID",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100\\CheckSetting",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\LastAdvertisement",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\IconSize",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Desktop\\TaskbarWinXP"
            ],
            "dll_loaded": [
                "C:\\Windows\\system32\\xmllite.dll"
            ],
            "file_opened": [
                "C:\\"
            ],
            "regkey_opened": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{01979c6a-42fa-414c-b8aa-eee2c8202018}.check.100",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StuckRects2"
            ],
            "regkey_deleted": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\GroupCollapseState",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemOrder",
                "HKEY_CURRENT_USER\\System\\CurrentControlSet\\Control\\Network\\ShowWirelessConnectingOnStart",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Bags\\1\\Desktop\\ItemPos800x600x96(1)"
            ],
            "file_exists": [
                "C:\\cuckoo_1788.ini",
                "C:\\Users\\cuck\\Desktop",
                "C:\\cuckoo_2204.ini"
            ],
            "mutex": [
                "Local\\Shell.CMruPidlList"
            ],
            "file_failed": [
                "C:\\cuckoo_1788.ini"
            ],
            "guid": [
                "{9b63616c-36b2-46bc-959f-c1593952d19b}",
                "{1a1f4206-0688-4e7f-be03-d82ec69df9a5}",
                "{c08956a2-1cd3-11d1-b1c5-00805fc1270e}",
                "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
                "{a47979d2-c419-11d9-a5b4-001185ad2b89}",
                "{7007acc7-3202-11d1-aad2-00805fc1270e}",
                "{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
                "{2fb499a3-cfce-480f-a5f3-2453db7a2b7a}",
                "{ba126ad1-2166-11d1-b1d0-00805fc1270e}",
                "{faedcf69-31fe-11d1-aad2-00805fc1270e}",
                "{ba126ae5-2166-11d1-b1d0-00805fc1270e}",
                "{000214e6-0000-0000-c000-000000000046}"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\LocalizedString",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\System.ItemNameDisplay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\SortOrderIndex",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\prnfldr.dll,-8036",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10",
                "HKEY_CURRENT_USER\\Local Settings\\MuiCache\\2\\52C64B7E\\@C:\\Windows\\system32\\netshell.dll,-1200",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\System.ItemNameDisplay",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\{B725F130-47EF-101A-A5F1-02608C9EEBAC} 10",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\InProcServer32\\LoadWithoutCOM",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlot",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{21EC2020-3AEA-1069-A2DD-08002B30309D}\\SortOrderIndex",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\InProcServer32\\(Default)",
                "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\MUI\\StringCacheSettings\\StringCacheGeneration",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\NodeSlots",
                "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PromotedIconCache",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7007ACC7-3202-11D1-AAD2-00805FC1270E}\\LocalizedString",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU\\MRUListEx",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\BagMRU Size",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClearRecentDocsOnExit"
            ]
        },
        "first_seen": 1570755211.1406,
        "ppid": 1740
    }
]

Signatures

[
    {
        "markcount": 3,
        "families": [],
        "description": "Checks if process is being debugged by a debugger",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741515,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1570755211.0315,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 72
            },
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741811,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1570755211.0315,
                    "tid": 2968,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 73
            },
            {
                "call": {
                    "category": "system",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 0,
                    "nt_status": -1073741515,
                    "api": "IsDebuggerPresent",
                    "return_value": 0,
                    "arguments": {},
                    "time": 1570755211.0315,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 84
            }
        ],
        "references": [],
        "name": "checks_debugger"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "This executable has a PDB path",
        "severity": 1,
        "marks": [
            {
                "category": "pdb_path",
                "ioc": "E:\\r\\ws\\St_Make\\code\\build\\win\\results\\SandboxPlugin\\Release\\Win32\\FlashPlayerPlugin.pdb",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "has_pdb"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
        "severity": 1,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "GlobalMemoryStatusEx",
                    "return_value": 1,
                    "arguments": {},
                    "time": 1570755211.0625,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 509
            }
        ],
        "references": [],
        "name": "antivm_memory_available"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".gfids",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 0,
        "families": [],
        "description": "One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.",
        "severity": 2,
        "marks": [],
        "references": [],
        "name": "dumped_buffer"
    },
    {
        "markcount": 0,
        "families": [],
        "description": "Checks whether any human activity is being performed by constantly checking whether the foreground window changed",
        "severity": 2,
        "marks": [],
        "references": [
            "https:\/\/www.virusbtn.com\/virusbulletin\/archive\/2015\/09\/vb201509-custom-packer.dkb"
        ],
        "name": "antisandbox_foregroundwindows"
    },
    {
        "markcount": 445,
        "families": [],
        "description": "Potentially malicious URLs were found in the process memory dump",
        "severity": 2,
        "marks": [
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_camera_and_mic_de",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_private_browsing_se",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_private_browsing_sk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_private_browsing_si",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_camera_and_mic_dk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/www.adobe.com\/go\/flash-player-updates_ro",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/get3.adobe.com\/tw\/flashplayer\/update\/osx",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_advanced_kr",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/www.adobe.com\/go\/flash-player-updates_rs",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_ee",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_private_browsing_ar",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/get3.adobe.com\/dk\/flashplayer\/update\/osx",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_playback_ee",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_en",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_es",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_storage_cz",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_playback_es",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_privacy_controls_kr",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_privacy_controls_bg",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_storage_it",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_privacy_controls_br",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_storage_il",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_private_browsing_hu",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_private_browsing_hr",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_advanced_ee",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_advanced_en",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_trusted_locations_ar",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/get3.adobe.com\/jp\/flashplayer\/update\/ppapiosx",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/fp_learn_more_usage_data_dk",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_advanced_es",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/fp_learn_more_usage_data_de",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_playback_nl",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_playback_no",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/fp_learn_more_usage_data",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/get3.adobe.com\/cz\/flashplayer\/update\/osx",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_trusted_locations_jp",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/fp_learn_more_usage_data_cn",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_chromium_de",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_privacy_controls_pl",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_ro",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_peer_assisted_networking_ar",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/fp_learn_more_usage_data_cz",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_il",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/get3.adobe.com\/cz\/flashplayer\/update\/ppapiosx",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_privacy_controls_pt",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "https:\/\/get3.adobe.com\/se\/flashplayer\/update\/ppapiosx",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_advanced_lt",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_pt",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_advanced_lv",
                "type": "ioc",
                "description": null
            },
            {
                "category": "url",
                "ioc": "http:\/\/www.adobe.com\/go\/learn_fp_settings_protected_content_pl",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "memdump_urls"
    },
    {
        "markcount": 1,
        "families": [],
        "description": "Allocates execute permission to another process indicative of possible code injection",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0x000001d0",
                        "allocation_type": 4096,
                        "base_address": "0x000cf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1672
            }
        ],
        "references": [],
        "name": "allocates_execute_remote_process"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
        "severity": 3,
        "marks": [
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtSetValueKey",
                    "return_value": 0,
                    "arguments": {
                        "index": 0,
                        "key_handle": "0x0000000000000f84",
                        "value": "\u0014\u0000\u0000\u0000\u0005\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0010\u0000\u0000\u0000\u0014\u0000\u0000\u0000IL \u0006\u0010\u0000$\u0000\u0018\u0000\u0010\u0000\u0010\u0000\u00ff\u00ff\u00ff\u00ff!\u0010\u00ff\u00ff\u00ff\u00ff\u00ff\u00ff\u00ff\u00ffBM6\u0000\u0000\u0000\u0000\u0000\u0000\u00006\u0000\u0000\u0000(\u0000\u0000\u0000\u0010\u0000\u0000\u0000@\u0002\u0000\u0000\u0001\u0000 \u0000\u0000\u0000\u0000\u0000\u0000\u0090\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000",
                        "reg_type": 3,
                        "regkey": "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\PastIconsStream"
                    },
                    "time": 1570754791.5349,
                    "tid": 1828,
                    "flags": {
                        "reg_type": "REG_BINARY"
                    }
                },
                "pid": 1788,
                "type": "call",
                "cid": 1285
            },
            {
                "call": {
                    "category": "registry",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtSetValueKey",
                    "return_value": 0,
                    "arguments": {
                        "index": 0,
                        "key_handle": "0x00000000000001e0",
                        "value": "\u0014\u0000\u0000\u0000\u0007\u0000\u0000\u0000\u0001\u0000\u0001\u0000\u0004\u0000\u0000\u0000\u0014\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000{\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u00e3\u0007\n\u0000F\u0000b\u0000y\u0000i\u0000r\u0000 \u0000C\u0000P\u0000 \u0000v\u0000f\u0000f\u0000h\u0000r\u0000f\u0000:\u0000 \u00001\u0000 \u0000z\u0000r\u0000f\u0000f\u0000n\u0000t\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000e\u0000\u0000\u0000v\u00ae x\u00e3#)B\u0082\u00c1\u00e4\u001c\u00b6}[\u009c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u00b3\u0086;4\u00e6\u00ee\u00d4\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\r !\u008f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000d\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000\u00e3\u0007\n\u0000F\u0000c\u0000r\u0000n\u0000x\u0000r\u0000e\u0000f\u0000:\u0000 \u00006\u00007\u0000%\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u000f\u0000\u0000\u0000s\u00ae x\u00e3#)B\u0082\u00c1\u00e4\u001c\u00b6}[\u009c\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0086\u00e2\u009e\u00956\u0005\u00d4\u0001\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\r !\u008f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0002\u0000\u0000\u0000{\u0000S\u00003\u00008\u0000O\u0000S\u00004\u00000\u00004\u0000-\u00001\u0000Q\u00004\u00003\u0000-\u00004\u00002\u0000S\u00002\u0000-\u00009\u00003\u00000\u00005\u0000-\u00006\u00007\u0000Q\u0000R\u00000\u0000O\u00002\u00008\u0000S\u0000P\u00002\u00003\u0000}\u0000\\\u0000r\u0000k\u0000c\u0000y\u0000b\u0000e\u0000r\u0000e\u0000.\u0000r\u0000k\u0000r\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000}\u00c0\u0000\u0000\u0000\u0000\u0000\u0000\u0001\u0000\u0000\u0000\u00e3\u0007\n\u0000H\u0000a\u0000v\u0000q\u0000r\u0000a\u0000g\u0000v\u0000s\u0000v\u0000r\u0000q\u0000 \u0000a\u0000r\u0000g\u0000j\u0000b\u0000e\u0000x\u0000 \u0000A\u0000b\u0000 \u0000V\u0000a\u0000g\u0000r\u0000e\u0000a\u0000r\u0000g\u0000 \u0000n\u0000p\u0000p\u0000r\u0000f\u0000f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000",
                        "reg_type": 3,
                        "regkey": "HKEY_CURRENT_USER\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\TrayNotify\\IconStreams"
                    },
                    "time": 1570754791.5349,
                    "tid": 1828,
                    "flags": {
                        "reg_type": "REG_BINARY"
                    }
                },
                "pid": 1788,
                "type": "call",
                "cid": 1287
            }
        ],
        "references": [],
        "name": "creates_largekey"
    },
    {
        "markcount": 47,
        "families": [],
        "description": "Manipulates memory of a non-child process indicative of process injection",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2420 manipulating memory of non-child process 2204",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 8192,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x000001d0",
                        "allocation_type": 4096,
                        "base_address": "0x000b0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1667
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 65536,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 1,
                        "process_handle": "0x000001d0",
                        "allocation_type": 8192,
                        "base_address": "0x000c0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_NOACCESS",
                        "allocation_type": "MEM_RESERVE"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1669
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0x000001d0",
                        "allocation_type": 4096,
                        "base_address": "0x000cf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1672
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1676
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1678
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1681
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1683
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1686
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1688
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1691
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1693
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1696
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1698
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1701
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1703
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1706
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1708
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1711
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1713
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1716
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1718
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1721
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1723
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1726
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1728
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1731
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1733
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1736
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1738
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1741
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1743
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1746
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1748
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1751
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1753
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1756
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1758
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1761
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1763
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1766
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1768
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1771
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1773
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 8,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_WRITECOPY"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1776
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1778
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtProtectVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "length": 4096,
                        "protection": 32,
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READ"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1780
            }
        ],
        "references": [
            "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
        ],
        "name": "injection_modifies_memory"
    },
    {
        "markcount": 52,
        "families": [],
        "description": "Potential code injection by writing to the memory of another process",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2420 injected into non-child 2204",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8R\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2,\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f0\f\u0000\u00c7D$\u0004p\u0011\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf010"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1675
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8R\u0000\u0000\u0000\u00ba(\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb00a4"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1677
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b80\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0018\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f0\f\u0000\u00c7D$\u0004 \u0013\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf050"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1680
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b80\u0000\u0000\u0000\u00bah\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafd54"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1682
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8:\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\b\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f0\f\u0000\u00c7D$\u0004\u00e0\u0014\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf090"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1685
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8:\u0000\u0000\u0000\u00ba\u00a8\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafe4c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1687
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u0013\u0001\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\b\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f0\f\u0000\u00c7D$\u0004\u0000\u0016\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf0d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1690
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u0013\u0001\u0000\u0000\u00ba\u00e8\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb132c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1692
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8$\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0014\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f1\f\u0000\u00c7D$\u0004\u0010\u0017\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf110"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1695
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8$\u0000\u0000\u0000\u00ba(\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc28"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1697
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u001a\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u001c\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f1\f\u0000\u00c7D$\u0004@ \u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf150"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1700
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u001a\u0000\u0000\u0000\u00bah\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafb30"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1702
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u000f\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f1\f\u0000\u00c7D$\u0004\u0010\"\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf190"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1705
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u000f\u0000\u0000\u0000\u00ba\u00a8\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafa18"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1707
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f2\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f1\f\u0000\u00c7D$\u00040\"\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf1d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1710
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f2\u0000\u0000\u0000\u00ba\u00e8\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1008"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1712
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f6\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f2\f\u0000\u00c7D$\u0004\u00e0\u00ec\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf210"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1715
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f6\u0000\u0000\u0000\u00ba(\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1068"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1717
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u009a\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f2\f\u0000\u00c7D$\u0004\u00b0\u00eb\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf250"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1720
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u009a\u0000\u0000\u0000\u00bah\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb078c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1722
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8G\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u001c\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f2\f\u0000\u00c7D$\u0004\u0080\u00ef\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf290"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1725
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8G\u0000\u0000\u0000\u00ba\u00a8\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baff94"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1727
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b84\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f2\f\u0000\u00c7D$\u0004\u0000\u00f1\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf2d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1730
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b84\u0000\u0000\u0000\u00ba\u00e8\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafdb8"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1732
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00fe\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f3\f\u0000\u00c7D$\u0004\u00d0\u00b7\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf310"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1735
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00fe\u0000\u0000\u0000\u00ba(\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1128"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1737
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8#\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f3\f\u0000\u00c7D$\u0004 \u00b4\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf350"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1740
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8#\u0000\u0000\u0000\u00bah\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc10"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1742
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f9\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f3\f\u0000\u00c7D$\u0004\u0090\u00b5\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf390"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1745
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f9\u0000\u0000\u0000\u00ba\u00a8\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb10b0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1747
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\n\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f3\f\u0000\u00c7D$\u0004\u00b0\u001c\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf3d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1750
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\n\u0000\u0000\u0000\u00ba\u00e8\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf99c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1752
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8!\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f4\f\u0000\u00c7D$\u0004@\u001c\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf410"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1755
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8!\u0000\u0000\u0000\u00ba(\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafbe0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1757
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8-\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f4\f\u0000\u00c7D$\u0004\u00b0\u00b6\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf450"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1760
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8-\u0000\u0000\u0000\u00bah\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafd08"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1762
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8,\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0014\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f4\f\u0000\u00c7D$\u0004p\u001c\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf490"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1765
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8,\u0000\u0000\u0000\u00ba\u00a8\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafcf0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1767
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8%\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2(\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f4\f\u0000\u00c7D$\u0004\u0080\u00ca\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf4d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1770
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8%\u0000\u0000\u0000\u00ba\u00e8\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc40"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1772
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8'\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\b\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f5\f\u0000\u00c7D$\u0004\u00c0\u00cb\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf510"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1775
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8'\u0000\u0000\u0000\u00ba(\u00f5\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc70"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1777
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u0090\u0005\u0000\u0000P\u0005\u0000\u0000\u0094\u0017z\u0000\u0015\u0000\u0000\u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1779
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00d0\u00f4\f\u0000\u0010\u00f5\f\u0000\u00d0\u00f3\f\u0000\u0010\u00f4\f\u0000\u0090\u00f4\f\u0000\u0010\u00f3\f\u0000P\u00f3\f\u0000\u0090\u00f3\f\u0000P\u00f4\f\u0000\u0010\u00f0\f\u0000P\u00f0\f\u0000\u0090\u00f0\f\u0000\u00d0\u00f0\f\u0000\u0010\u00f1\f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000P\u00f1\f\u0000\u0090\u00f1\f\u0000\u00d0\u00f1\f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0010\u00f2\f\u0000P\u00f2\f\u0000\u0090\u00f2\f\u0000\u00d0\u00f2\f\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000\u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x002834c8"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1781
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u0000\u0000\u000b\u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x002838ac"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1782
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b0\u00fa\u00baw\u00d0\u00f9\u00baw4\u00fe\u00bawH\u00fb\u00baw@\u00fc\u00baw(\u0000\u00bbw\u00c8\u00fa\u00baw\u00e8\u00f9\u00baw@\u0000\u00bbw\u00c8\u00fb\u00bawp\u00fc\u00baw&\u00e0\u00bbw\u00b5\u00e6\u00bbw\u00b7\u0084\u00bcwI\u0002\u00bdw\u00d1\u00e5\u00c3w\u008e\u009d\u00bdw\u0085\u00df\u00bbw|\u00c2\u00bew\u00e0\u00c4\u00c0w\u00f1V\u00c6w\u00a4\u0000\u00bbw",
                        "process_handle": "0x000001d0",
                        "base_address": "0x00283428"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1784
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u0004\u0000\u0000\u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x00283400"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1788
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u0000\u0000 \u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x00283484"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1789
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u0000\u0000\b\u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x00283488"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1790
            }
        ],
        "references": [],
        "name": "injection_write_memory"
    },
    {
        "markcount": 2,
        "families": [],
        "description": "Resumed a suspended thread in a remote process potentially indicative of process injection",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2420 resumed a thread in remote process 2204",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtResumeThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_handle": "0x000001a0",
                        "suspend_count": 1,
                        "process_identifier": 2204
                    },
                    "time": 1570755213.2965,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1811
            }
        ],
        "references": [
            "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
        ],
        "name": "injection_resumethread"
    },
    {
        "markcount": 59,
        "families": [],
        "description": "Executed a process and injected code into it, probably while unpacking",
        "severity": 5,
        "marks": [
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtResumeThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_handle": "0x00000168",
                        "suspend_count": 1,
                        "process_identifier": 2420
                    },
                    "time": 1570755211.0625,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 517
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "CreateProcessInternalW",
                    "return_value": 1,
                    "arguments": {
                        "thread_identifier": 2096,
                        "thread_handle": "0x0000019c",
                        "process_identifier": 2204,
                        "current_directory": "",
                        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
                        "track": 1,
                        "command_line": "\"C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin\" --channel=2420.0058F40C.1033384170 --type=renderer",
                        "filepath_r": "C:\\Users\\cuck\\AppData\\Local\\Temp\\644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a.bin",
                        "stack_pivoted": 0,
                        "creation_flags": 16778252,
                        "process_handle": "0x000001d0",
                        "inherit_handles": 0
                    },
                    "time": 1570755211.1715,
                    "tid": 2460,
                    "flags": {
                        "creation_flags": "CREATE_BREAKAWAY_FROM_JOB|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|DETACHED_PROCESS"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1650
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtGetContextThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_handle": "0x0000019c"
                    },
                    "time": 1570755211.1715,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1654
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 8192,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x000001d0",
                        "allocation_type": 4096,
                        "base_address": "0x000b0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1667
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "buffer": "f68051dfd456dd48d0e8c7131bfdbc1c83eb5048",
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000b0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1668
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 65536,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 1,
                        "process_handle": "0x000001d0",
                        "allocation_type": 8192,
                        "base_address": "0x000c0000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_NOACCESS",
                        "allocation_type": "MEM_RESERVE"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1669
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 2204,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 64,
                        "process_handle": "0x000001d0",
                        "allocation_type": 4096,
                        "base_address": "0x000cf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {
                        "protection": "PAGE_EXECUTE_READWRITE",
                        "allocation_type": "MEM_COMMIT"
                    }
                },
                "pid": 2420,
                "type": "call",
                "cid": 1672
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8R\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2,\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f0\f\u0000\u00c7D$\u0004p\u0011\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf010"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1675
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8R\u0000\u0000\u0000\u00ba(\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb00a4"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1677
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b80\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0018\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f0\f\u0000\u00c7D$\u0004 \u0013\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf050"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1680
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b80\u0000\u0000\u0000\u00bah\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafd54"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1682
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8:\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\b\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f0\f\u0000\u00c7D$\u0004\u00e0\u0014\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf090"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1685
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8:\u0000\u0000\u0000\u00ba\u00a8\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafe4c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1687
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u0013\u0001\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\b\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f0\f\u0000\u00c7D$\u0004\u0000\u0016\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf0d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1690
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u0013\u0001\u0000\u0000\u00ba\u00e8\u00f0\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb132c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1692
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8$\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0014\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f1\f\u0000\u00c7D$\u0004\u0010\u0017\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf110"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1695
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8$\u0000\u0000\u0000\u00ba(\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc28"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1697
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u001a\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u001c\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f1\f\u0000\u00c7D$\u0004@ \u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf150"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1700
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u001a\u0000\u0000\u0000\u00bah\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafb30"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1702
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u000f\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f1\f\u0000\u00c7D$\u0004\u0010\"\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf190"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1705
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u000f\u0000\u0000\u0000\u00ba\u00a8\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafa18"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1707
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f2\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f1\f\u0000\u00c7D$\u00040\"\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf1d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1710
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f2\u0000\u0000\u0000\u00ba\u00e8\u00f1\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1008"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1712
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f6\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f2\f\u0000\u00c7D$\u0004\u00e0\u00ec\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf210"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1715
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f6\u0000\u0000\u0000\u00ba(\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1068"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1717
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u009a\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f2\f\u0000\u00c7D$\u0004\u00b0\u00eb\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf250"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1720
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u009a\u0000\u0000\u0000\u00bah\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb078c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1722
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8G\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u001c\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f2\f\u0000\u00c7D$\u0004\u0080\u00ef\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf290"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1725
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8G\u0000\u0000\u0000\u00ba\u00a8\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baff94"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1727
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b84\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f2\f\u0000\u00c7D$\u0004\u0000\u00f1\u001c\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf2d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1730
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b84\u0000\u0000\u0000\u00ba\u00e8\u00f2\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafdb8"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1732
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00fe\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f3\f\u0000\u00c7D$\u0004\u00d0\u00b7\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf310"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1735
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00fe\u0000\u0000\u0000\u00ba(\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb1128"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1737
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8#\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f3\f\u0000\u00c7D$\u0004 \u00b4\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf350"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1740
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8#\u0000\u0000\u0000\u00bah\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc10"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1742
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f9\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\f\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f3\f\u0000\u00c7D$\u0004\u0090\u00b5\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf390"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1745
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\u00f9\u0000\u0000\u0000\u00ba\u00a8\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bb10b0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1747
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\n\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f3\f\u0000\u00c7D$\u0004\u00b0\u001c\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf3d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1750
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8\n\u0000\u0000\u0000\u00ba\u00e8\u00f3\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77baf99c"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1752
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8!\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f4\f\u0000\u00c7D$\u0004@\u001c\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf410"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1755
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8!\u0000\u0000\u0000\u00ba(\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafbe0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1757
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8-\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0010\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\fP\u00f4\f\u0000\u00c7D$\u0004\u00b0\u00b6\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf450"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1760
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8-\u0000\u0000\u0000\u00bah\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafd08"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1762
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8,\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\u0014\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0090\u00f4\f\u0000\u00c7D$\u0004p\u001c\u0016\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf490"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1765
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8,\u0000\u0000\u0000\u00ba\u00a8\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafcf0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1767
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8%\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2(\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u00d0\u00f4\f\u0000\u00c7D$\u0004\u0080\u00ca\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf4d0"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1770
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8%\u0000\u0000\u0000\u00ba\u00e8\u00f4\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc40"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1772
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8'\u0000\u0000\u00003\u00c9\u008dT$\u0004d\u00ff\u0015\u00c0\u0000\u0000\u0000\u0083\u00c4\u0004\u00c2\b\u0000\u0083\u00ec\bR\u008bT$\f\u0089T$\b\u00c7D$\f\u0010\u00f5\f\u0000\u00c7D$\u0004\u00c0\u00cb\u0015\u0000Z\u00c3",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf510"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1775
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u00b8'\u0000\u0000\u0000\u00ba(\u00f5\f\u0000\u00ff\u00e2",
                        "process_handle": "0x000001d0",
                        "base_address": "0x77bafc70"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1777
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 2204,
                        "buffer": "\u0090\u0005\u0000\u0000P\u0005\u0000\u0000\u0094\u0017z\u0000\u0015\u0000\u0000\u0000",
                        "process_handle": "0x000001d0",
                        "base_address": "0x000cf000"
                    },
                    "time": 1570755211.1875,
                    "tid": 2460,
                    "flags": {}
                },
                "pid": 2420,
                "type": "call",
                "cid": 1779
            }
        ],
        "references": [],
        "name": "injection_runpe"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 662,
            "time": 6.2229070663452,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5342,
            "time": 12.237704992294,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7186,
            "time": 6.1624610424042,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7514,
            "time": 4.1558129787445,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7842,
            "time": 6.1800911426544,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8170,
            "time": 4.7980201244354,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8498,
            "time": 3.0573620796204,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 8826,
            "time": 4.6750841140747,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28236,
            "time": 4.1742060184479,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36620,
            "time": 6.2634191513062,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "49a883fb6055162764428d63c43945b86be5d85c26cf655f2ef22bb4f57876ef",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "9dee956d540a498248be8a69b446c5b27a46b7b5f4af0e11290ddb64dfa7fdfa",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

Hashes [?]

PropertyValue
MD5a8a20341972261406303afb71190db4b
SHA256644a36c4270977b2bab2c3b19cbe2ebfe321c21ae5725df5b2fe080cb00c200a

Error Messages

These are some of the error messages that can appear related to flashplayerplugin_32_0_0_270.exe:

flashplayerplugin_32_0_0_270.exe has encountered a problem and needs to close. We are sorry for the inconvenience.

flashplayerplugin_32_0_0_270.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.

Adobe Flash Player 32.0 r0 has stopped working.

End Program - flashplayerplugin_32_0_0_270.exe. This program is not responding.

flashplayerplugin_32_0_0_270.exe is not a valid Win32 application.

flashplayerplugin_32_0_0_270.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.

What will you do with the file?

To help other users, please let us know what you will do with the file:



Malware or legitimate?

If you feel that you need more information to determine if your should keep this file or remove it, please read this guide.

Please select the option that best describe your thoughts on the information provided on this web page


Free online surveys

And now some shameless self promotion ;)

A screenshot of FreeFixer's scan result.Hi, my name is Roger Karlsson. I've been running this website since 2006. I want to let you know about the FreeFixer program. FreeFixer is a freeware tool that analyzes your system and let you manually identify unwanted programs. Once you've identified some malware files, FreeFixer is pretty good at removing them. You can download FreeFixer here. It runs on Windows 2000/XP/2003/2008/2016/2019/Vista/7/8/8.1/10. Supports both 32- and 64-bit Windows.

If you have questions, feedback on FreeFixer or the freefixer.com website, need help analyzing FreeFixer's scan result or just want to say hello, please contact me. You can find my email address at the contact page.

Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply