.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ----  -------------.
!  WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS                                                            !
`--------------  - ---  ---------- -------- -------- -------- -------- ----------------- -  ---- ---- --'

                                           ATM MALWARE NOTICE 
                    4a75be18a3fe0033a9ebdb8f4af81c94e03581d19b5b4373e74e41283fd2615f
 
Date...........: 2019-05-17
Family.........: DispCash.19
File name......: USBLOGGER.exe
File size......: 15.00 KB
Type file......: EXE/Windows
Virscan........: VT - HA
Documentation..: https://twitter.com/r3c0nst/status/1129641730813366274
Additional note: Technical detail about the serial check: twitter.com/CyberCrimeWHQ/status/1129932869277814784

Entropy:


Binary Histogram:



=== SCREENSHOT === 



=== PEDUMP REPORT === 
=== MZ Header === signature: "MZ" bytes_in_last_block: 144 0x90 blocks_in_file: 3 3 num_relocs: 0 0 header_paragraphs: 4 4 min_extra_paragraphs: 0 0 max_extra_paragraphs: 65535 0xffff ss: 0 0 sp: 184 0xb8 checksum: 0 0 ip: 0 0 cs: 0 0 reloc_table_offset: 64 0x40 overlay_number: 0 0 reserved0: 0 0 oem_id: 0 0 oem_info: 0 0 reserved2: 0 0 reserved3: 0 0 reserved4: 0 0 reserved5: 0 0 reserved6: 0 0 lfanew: 232 0xe8 === DOS STUB === 00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......| === RICH Header === LIB_ID VERSION TIMES_USED 205 cd 50929 c6f1 1 1 206 ce 50929 c6f1 19 13 203 cb 50929 c6f1 4 4 207 cf 50929 c6f1 5 5 1 1 0 0 73 49 185 b9 30716 77fc 5 5 207 cf 60315 eb9b 7 7 204 cc 60315 eb9b 1 1 === PE Header === signature: "PE\x00\x00" # IMAGE_FILE_HEADER: Machine: 332 0x14c x86 NumberOfSections: 4 4 TimeDateStamp: "2019-05-13 13:27:39" PointerToSymbolTable: 0 0 NumberOfSymbols: 0 0 SizeOfOptionalHeader: 224 0xe0 Characteristics: 258 0x102 EXECUTABLE_IMAGE, 32BIT_MACHINE # IMAGE_OPTIONAL_HEADER32: Magic: 267 0x10b 32-bit executable LinkerVersion: 11.0 SizeOfCode: 8192 0x2000 SizeOfInitializedData: 10752 0x2a00 SizeOfUninitializedData: 0 0 AddressOfEntryPoint: 10161 0x27b1 BaseOfCode: 4096 0x1000 BaseOfData: 12288 0x3000 ImageBase: 4194304 0x400000 SectionAlignment: 4096 0x1000 FileAlignment: 512 0x200 OperatingSystemVersion: 6.0 ImageVersion: 0.0 SubsystemVersion: 6.0 Reserved1: 0 0 SizeOfImage: 28672 0x7000 SizeOfHeaders: 1024 0x400 CheckSum: 0 0 Subsystem: 3 3 WINDOWS_CUI DllCharacteristics: 33088 0x8140 DYNAMIC_BASE, NX_COMPAT TERMINAL_SERVER_AWARE SizeOfStackReserve: 1048576 0x100000 SizeOfStackCommit: 4096 0x1000 SizeOfHeapReserve: 1048576 0x100000 SizeOfHeapCommit: 4096 0x1000 LoaderFlags: 0 0 NumberOfRvaAndSizes: 16 0x10 === DATA DIRECTORY === EXPORT rva:0x 0 size:0x 0 IMPORT rva:0x 3684 size:0x 64 RESOURCE rva:0x 0 size:0x 0 EXCEPTION rva:0x 0 size:0x 0 SECURITY rva:0x 0 size:0x 0 BASERELOC rva:0x 6000 size:0x 4b0 DEBUG rva:0x 0 size:0x 0 ARCHITECTURE rva:0x 0 size:0x 0 GLOBALPTR rva:0x 0 size:0x 0 TLS rva:0x 0 size:0x 0 LOAD_CONFIG rva:0x 3378 size:0x 40 Bound_IAT rva:0x 0 size:0x 0 IAT rva:0x 3000 size:0x 118 Delay_IAT rva:0x 0 size:0x 0 CLR_Header rva:0x 0 size:0x 0 rva:0x 0 size:0x 0 === SECTIONS === NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS .text 1000 1e01 2000 400 0 0 0 0 60000020 R-X CODE .rdata 3000 cee e00 2400 0 0 0 0 40000040 R-- IDATA .data 4000 120c 200 3200 0 0 0 0 c0000040 RW- IDATA .reloc 6000 664 800 3400 0 0 0 0 42000040 R-- IDATA DISCARDABLE === IMPORTS === MODULE_NAME HINT ORD FUNCTION_NAME KERNEL32.dll 55f Sleep KERNEL32.dll 2b5 GetProcAddress KERNEL32.dll 3c0 LoadLibraryA KERNEL32.dll 16 AllocConsole KERNEL32.dll 213 GetConsoleWindow KERNEL32.dll 2dd GetStdHandle KERNEL32.dll 17b FillConsoleOutputCharacterA KERNEL32.dll 17a FillConsoleOutputAttribute KERNEL32.dll 20e GetConsoleScreenBufferInfo KERNEL32.dll 4d3 SetConsoleCursorPosition KERNEL32.dll 5e6 WriteConsoleA KERNEL32.dll 228 GetCurrentThreadId KERNEL32.dll 224 GetCurrentProcessId KERNEL32.dll 43c QueryPerformanceCounter KERNEL32.dll 388 IsProcessorFeaturePresent KERNEL32.dll 383 IsDebuggerPresent KERNEL32.dll 117 DecodePointer KERNEL32.dll 13c EncodePointer KERNEL32.dll 2f4 GetSystemTimeAsFileTime USER32.dll 117 GetAsyncKeyState USER32.dll 31c ShowWindow MSVCP110.dll 2d3 ?_Winerror_map@std@@YAPBDH@Z MSVCP110.dll 2da ?_Xlength_error@std@@YAXPBD@Z MSVCP110.dll 2db ?_Xout_of_range@std@@YAXPBD@Z MSVCP110.dll 2d7 ?_Xbad_alloc@std@@YAXXZ MSVCP110.dll 2be ?_Syserror_map@std@@YAPBDH@Z MSVCR110.dll 62a memmove MSVCR110.dll 63a rand MSVCR110.dll 64b srand MSVCR110.dll 4ca _time64 MSVCR110.dll 15d _CxxThrowException MSVCR110.dll 178 __CxxFrameHandler3 MSVCR110.dll 681 vsprintf_s MSVCR110.dll 62c memset MSVCR110.dll 37c _lock MSVCR110.dll 4e6 _unlock MSVCR110.dll 22b _calloc_crt MSVCR110.dll 1ac __dllonexit MSVCR110.dll 422 _onexit MSVCR110.dll 70 ??1type_info@@UAE@XZ MSVCR110.dll 16f _XcptFilter MSVCR110.dll 215 _amsg_exit MSVCR110.dll 1b4 __getmainargs MSVCR110.dll 73 ??3@YAXPAX@Z MSVCR110.dll 5cc exit MSVCR110.dll 279 _exit MSVCR110.dll 22c _cexit MSVCR110.dll 23c _configthreadlocale MSVCR110.dll 1f2 __setusermatherr MSVCR110.dll 2ff _initterm_e MSVCR110.dll 2fe _initterm MSVCR110.dll 1b5 __initenv MSVCR110.dll 294 _fmode MSVCR110.dll 23b _commode MSVCR110.dll 270 _except_handler4_common MSVCR110.dll 24b _crt_debugger_hook MSVCR110.dll 1aa __crtUnhandledException MSVCR110.dll 1a9 __crtTerminateProcess MSVCR110.dll 13b ?terminate@@YAXXZ MSVCR110.dll 1a8 __crtSetUnhandledExceptionFilter MSVCR110.dll 306 _invoke_watson MSVCR110.dll 23f _controlfp_s MSVCR110.dll 71 ??2@YAPAXI@Z MSVCR110.dll 431 _purecall MSVCR110.dll 1f0 __set_app_type MSVCR110.dll 628 memcpy === Packer / Compiler === MS Visual C++ v8.0
=== Strings ===
File pos Mem pos ID Text ======== ======= == ==== 00000000004D 00000040004D 0 !This program cannot be run in DOS mode. 0000000000BF 0000004000BF 0 jDR)j 0000000000C7 0000004000C7 0 jDR*j 0000000000CF 0000004000CF 0 jRich 0000000001E0 0000004001E0 0 .text 000000000208 000000400208 0 .rdata 00000000022F 00000040022F 0 @.data 000000000258 000000400258 0 .reloc 000000001693 000000402293 0 PVhH3@ 000000001782 000000402382 0 PVSj W 000000001908 000000402508 0 t%WhP*@ 0000000020F7 000000402CF7 0 VVVVV 00000000258C 00000040318C 0 generic 000000002594 000000403194 0 unknown error 0000000025C0 0000004031C0 0 iostream 0000000025CC 0000004031CC 0 iostream stream error 000000002600 000000403200 0 system 00000000260C 00000040320C 0 CSCWCNG.dll 000000002618 000000403218 0 CscCngOpen 000000002624 000000403224 0 CscCngReset 000000002630 000000403230 0 CscCngClose 00000000263C 00000040323C 0 CscCngDispense 00000000264C 00000040324C 0 CscCngTransport 00000000265C 00000040325C 0 CscCngStatusRead 000000002670 000000403270 0 CscCngStatusWrite 000000002684 000000403284 0 CscCngCasRefInit 000000002698 000000403298 0 CscCngEncryption 0000000026AC 0000004032AC 0 CscCngRecovery 0000000026BC 0000004032BC 0 CscCngService 0000000026CC 0000004032CC 0 Load CSCWCNG OK 0000000026E0 0000004032E0 0 Load CSCWCNG FAILED 0000000026F8 0000004032F8 0 CFailed 0x%X 000000002708 000000403308 0 %d,%.2d; 000000002714 000000403314 0 DFail 0x%X 000000002720 000000403320 0 invalid string position 000000002738 000000403338 0 string too long 000000002748 000000403348 0 %d--->[ %d | %d ] 000000002C02 000000403802 0 Sleep 000000002C0A 00000040380A 0 GetProcAddress 000000002C1C 00000040381C 0 LoadLibraryA 000000002C2C 00000040382C 0 AllocConsole 000000002C3C 00000040383C 0 GetConsoleWindow 000000002C50 000000403850 0 GetStdHandle 000000002C60 000000403860 0 FillConsoleOutputCharacterA 000000002C7E 00000040387E 0 FillConsoleOutputAttribute 000000002C9C 00000040389C 0 GetConsoleScreenBufferInfo 000000002CBA 0000004038BA 0 SetConsoleCursorPosition 000000002CD6 0000004038D6 0 WriteConsoleA 000000002CE4 0000004038E4 0 KERNEL32.dll 000000002CF4 0000004038F4 0 ShowWindow 000000002D02 000000403902 0 GetAsyncKeyState 000000002D14 000000403914 0 USER32.dll 000000002D22 000000403922 0 ?_Xbad_alloc@std@@YAXXZ 000000002D3C 00000040393C 0 ?_Xlength_error@std@@YAXPBD@Z 000000002D5C 00000040395C 0 ?_Xout_of_range@std@@YAXPBD@Z 000000002D7C 00000040397C 0 ?_Syserror_map@std@@YAPBDH@Z 000000002D9C 00000040399C 0 ?_Winerror_map@std@@YAPBDH@Z 000000002DBA 0000004039BA 0 MSVCP110.dll 000000002DCA 0000004039CA 0 _purecall 000000002DD6 0000004039D6 0 ??2@YAPAXI@Z File pos Mem pos ID Text ======== ======= == ==== 000000002DE6 0000004039E6 0 ??3@YAXPAX@Z 000000002DF6 0000004039F6 0 vsprintf_s 000000002E04 000000403A04 0 memmove 000000002E16 000000403A16 0 srand 000000002E1E 000000403A1E 0 _time64 000000002E28 000000403A28 0 _CxxThrowException 000000002E3E 000000403A3E 0 __CxxFrameHandler3 000000002E54 000000403A54 0 memcpy 000000002E5E 000000403A5E 0 memset 000000002E66 000000403A66 0 MSVCR110.dll 000000002E76 000000403A76 0 _lock 000000002E7E 000000403A7E 0 _unlock 000000002E88 000000403A88 0 _calloc_crt 000000002E96 000000403A96 0 __dllonexit 000000002EA4 000000403AA4 0 _onexit 000000002EAE 000000403AAE 0 ??1type_info@@UAE@XZ 000000002EC6 000000403AC6 0 _XcptFilter 000000002ED4 000000403AD4 0 _amsg_exit 000000002EE2 000000403AE2 0 __getmainargs 000000002EF2 000000403AF2 0 __set_app_type 000000002F0C 000000403B0C 0 _exit 000000002F14 000000403B14 0 _cexit 000000002F1E 000000403B1E 0 _configthreadlocale 000000002F34 000000403B34 0 __setusermatherr 000000002F48 000000403B48 0 _initterm_e 000000002F56 000000403B56 0 _initterm 000000002F62 000000403B62 0 __initenv 000000002F6E 000000403B6E 0 _fmode 000000002F78 000000403B78 0 _commode 000000002F84 000000403B84 0 _except_handler4_common 000000002F9E 000000403B9E 0 _crt_debugger_hook 000000002FB4 000000403BB4 0 __crtUnhandledException 000000002FCE 000000403BCE 0 __crtTerminateProcess 000000002FE6 000000403BE6 0 ?terminate@@YAXXZ 000000002FFA 000000403BFA 0 __crtSetUnhandledExceptionFilter 00000000301E 000000403C1E 0 _invoke_watson 000000003030 000000403C30 0 _controlfp_s 000000003040 000000403C40 0 EncodePointer 000000003050 000000403C50 0 DecodePointer 000000003060 000000403C60 0 IsDebuggerPresent 000000003074 000000403C74 0 IsProcessorFeaturePresent 000000003090 000000403C90 0 QueryPerformanceCounter 0000000030AA 000000403CAA 0 GetCurrentProcessId 0000000030C0 000000403CC0 0 GetCurrentThreadId 0000000030D6 000000403CD6 0 GetSystemTimeAsFileTime 000000003200 000000404000 0 CSCCNG 000000003220 000000404020 0 .?AVerror_category@std@@ 000000003244 000000404044 0 .?AV_Generic_error_category@std@@ 000000003270 000000404070 0 .?AV_Iostream_error_category@std@@ 00000000329C 00000040409C 0 .?AV_System_error_category@std@@ 0000000032C8 0000004040C8 0 .?AVtype_info@@ 000000003409 000000406009 0 010Q0l0 000000003427 000000406027 0 1C1H1N1Z1b1h1v1 00000000344F 00000040604F 0 1#2)212K2P2g2l2t2z2 000000003491 000000406091 0 3*383=3Q3W3a3e3{3 0000000034C1 0000004060C1 0 4*42484B4L4V4 0000000034CF 0000004060CF 0 4j4t4~4 0000000034F1 0000004060F1 0 5'5/575?5E5O5S5k5q5{5 000000003515 000000406115 0 5R6q627V7\7v7|7 00000000352B 00000040612B 0 8j9}9 File pos Mem pos ID Text ======== ======= == ==== 000000003531 000000406131 0 92:8: 000000003543 000000406143 0 <!<1<N<T<a<m<z< 00000000356D 00000040616D 0 = ='===F=M=U=_=i=v= 00000000359B 00000040619B 0 >'>4>D>L>R>_>q>y> 0000000035C5 0000004061C5 0 ?&?6?>?D?Q?c?k?w? 0000000035F1 0000004061F1 0 0'0.090G0P0U0e0u0~0 00000000361D 00000040621D 0 1%151>1E1U1e1n1u1 000000003647 000000406247 0 2%2.252E2P2 00000000366D 00000040626D 0 3$3,333G3U3g3 000000003693 000000406293 0 4*404C4X4c4y4 0000000036AF 0000004062AF 0 5P5\5b5t5~5 0000000036E1 0000004062E1 0 6#6(6-636;6O6i6 000000003709 000000406309 0 7!7'7,747:7@7M7S7]7|7 000000003731 000000406331 0 798>8Q8X8k8 00000000375F 00000040635F 0 9$9*949>9N9 00000000376B 00000040636B 0 9n9w9 00000000377F 00000040637F 0 ;-;K;_;e; 000000003789 000000406389 0 <+<7<F<O<\< 0000000037A9 0000004063A9 0 ="=(=.=4=:=@=b=q= 0000000037D9 0000004063D9 0 1 1$1(1,10141@1D1H1T1X1\1 0000000037F3 0000004063F3 0 1d1h1l1p1t1x1|1 000000003823 000000406423 0 1d3h3l3p3 00000000383F 00000040643F 0 4(4,40484P4 00000000384B 00000040644B 0 4d4t4x4|4 000000003871 000000406471 0 5 585d5t5 000000003885 000000406485 0 6 6@6\6 0000000038A5 0000004064A5 0 0<0h0 00000000004D 00000040004D 0 !This program cannot be run in DOS mode. 0000000000BF 0000004000BF 0 jDR)j 0000000000C7 0000004000C7 0 jDR*j 0000000000CF 0000004000CF 0 jRich 0000000001E0 0000004001E0 0 .text 000000000208 000000400208 0 .rdata 00000000022F 00000040022F 0 @.data 000000000258 000000400258 0 .reloc 000000001693 000000402293 0 PVhH3@ 000000001782 000000402382 0 PVSj W 000000001908 000000402508 0 t%WhP*@ 0000000020F7 000000402CF7 0 VVVVV 00000000258C 00000040318C 0 generic 000000002594 000000403194 0 unknown error 0000000025C0 0000004031C0 0 iostream 0000000025CC 0000004031CC 0 iostream stream error 000000002600 000000403200 0 system 00000000260C 00000040320C 0 CSCWCNG.dll 000000002618 000000403218 0 CscCngOpen 000000002624 000000403224 0 CscCngReset 000000002630 000000403230 0 CscCngClose 00000000263C 00000040323C 0 CscCngDispense 00000000264C 00000040324C 0 CscCngTransport 00000000265C 00000040325C 0 CscCngStatusRead 000000002670 000000403270 0 CscCngStatusWrite 000000002684 000000403284 0 CscCngCasRefInit 000000002698 000000403298 0 CscCngEncryption 0000000026AC 0000004032AC 0 CscCngRecovery 0000000026BC 0000004032BC 0 CscCngService 0000000026CC 0000004032CC 0 Load CSCWCNG OK 0000000026E0 0000004032E0 0 Load CSCWCNG FAILED 0000000026F8 0000004032F8 0 CFailed 0x%X 000000002708 000000403308 0 %d,%.2d; File pos Mem pos ID Text ======== ======= == ==== 000000002714 000000403314 0 DFail 0x%X 000000002720 000000403320 0 invalid string position 000000002738 000000403338 0 string too long 000000002748 000000403348 0 %d--->[ %d | %d ] 000000002C02 000000403802 0 Sleep 000000002C0A 00000040380A 0 GetProcAddress 000000002C1C 00000040381C 0 LoadLibraryA 000000002C2C 00000040382C 0 AllocConsole 000000002C3C 00000040383C 0 GetConsoleWindow 000000002C50 000000403850 0 GetStdHandle 000000002C60 000000403860 0 FillConsoleOutputCharacterA 000000002C7E 00000040387E 0 FillConsoleOutputAttribute 000000002C9C 00000040389C 0 GetConsoleScreenBufferInfo 000000002CBA 0000004038BA 0 SetConsoleCursorPosition 000000002CD6 0000004038D6 0 WriteConsoleA 000000002CE4 0000004038E4 0 KERNEL32.dll 000000002CF4 0000004038F4 0 ShowWindow 000000002D02 000000403902 0 GetAsyncKeyState 000000002D14 000000403914 0 USER32.dll 000000002D22 000000403922 0 ?_Xbad_alloc@std@@YAXXZ 000000002D3C 00000040393C 0 ?_Xlength_error@std@@YAXPBD@Z 000000002D5C 00000040395C 0 ?_Xout_of_range@std@@YAXPBD@Z 000000002D7C 00000040397C 0 ?_Syserror_map@std@@YAPBDH@Z 000000002D9C 00000040399C 0 ?_Winerror_map@std@@YAPBDH@Z 000000002DBA 0000004039BA 0 MSVCP110.dll 000000002DCA 0000004039CA 0 _purecall 000000002DD6 0000004039D6 0 ??2@YAPAXI@Z 000000002DE6 0000004039E6 0 ??3@YAXPAX@Z 000000002DF6 0000004039F6 0 vsprintf_s 000000002E04 000000403A04 0 memmove 000000002E16 000000403A16 0 srand 000000002E1E 000000403A1E 0 _time64 000000002E28 000000403A28 0 _CxxThrowException 000000002E3E 000000403A3E 0 __CxxFrameHandler3 000000002E54 000000403A54 0 memcpy 000000002E5E 000000403A5E 0 memset 000000002E66 000000403A66 0 MSVCR110.dll 000000002E76 000000403A76 0 _lock 000000002E7E 000000403A7E 0 _unlock 000000002E88 000000403A88 0 _calloc_crt 000000002E96 000000403A96 0 __dllonexit 000000002EA4 000000403AA4 0 _onexit 000000002EAE 000000403AAE 0 ??1type_info@@UAE@XZ 000000002EC6 000000403AC6 0 _XcptFilter 000000002ED4 000000403AD4 0 _amsg_exit 000000002EE2 000000403AE2 0 __getmainargs 000000002EF2 000000403AF2 0 __set_app_type 000000002F0C 000000403B0C 0 _exit 000000002F14 000000403B14 0 _cexit 000000002F1E 000000403B1E 0 _configthreadlocale 000000002F34 000000403B34 0 __setusermatherr 000000002F48 000000403B48 0 _initterm_e 000000002F56 000000403B56 0 _initterm 000000002F62 000000403B62 0 __initenv 000000002F6E 000000403B6E 0 _fmode 000000002F78 000000403B78 0 _commode 000000002F84 000000403B84 0 _except_handler4_common 000000002F9E 000000403B9E 0 _crt_debugger_hook 000000002FB4 000000403BB4 0 __crtUnhandledException 000000002FCE 000000403BCE 0 __crtTerminateProcess File pos Mem pos ID Text ======== ======= == ==== 000000002FE6 000000403BE6 0 ?terminate@@YAXXZ 000000002FFA 000000403BFA 0 __crtSetUnhandledExceptionFilter 00000000301E 000000403C1E 0 _invoke_watson 000000003030 000000403C30 0 _controlfp_s 000000003040 000000403C40 0 EncodePointer 000000003050 000000403C50 0 DecodePointer 000000003060 000000403C60 0 IsDebuggerPresent 000000003074 000000403C74 0 IsProcessorFeaturePresent 000000003090 000000403C90 0 QueryPerformanceCounter 0000000030AA 000000403CAA 0 GetCurrentProcessId 0000000030C0 000000403CC0 0 GetCurrentThreadId 0000000030D6 000000403CD6 0 GetSystemTimeAsFileTime 000000003200 000000404000 0 CSCCNG 000000003220 000000404020 0 .?AVerror_category@std@@ 000000003244 000000404044 0 .?AV_Generic_error_category@std@@ 000000003270 000000404070 0 .?AV_Iostream_error_category@std@@ 00000000329C 00000040409C 0 .?AV_System_error_category@std@@ 0000000032C8 0000004040C8 0 .?AVtype_info@@ 000000003409 000000406009 0 010Q0l0 000000003427 000000406027 0 1C1H1N1Z1b1h1v1 00000000344F 00000040604F 0 1#2)212K2P2g2l2t2z2 000000003491 000000406091 0 3*383=3Q3W3a3e3{3 0000000034C1 0000004060C1 0 4*42484B4L4V4 0000000034CF 0000004060CF 0 4j4t4~4 0000000034F1 0000004060F1 0 5'5/575?5E5O5S5k5q5{5 000000003515 000000406115 0 5R6q627V7\7v7|7 00000000352B 00000040612B 0 8j9}9 000000003531 000000406131 0 92:8: 000000003543 000000406143 0 <!<1<N<T<a<m<z< 00000000356D 00000040616D 0 = ='===F=M=U=_=i=v= 00000000359B 00000040619B 0 >'>4>D>L>R>_>q>y> 0000000035C5 0000004061C5 0 ?&?6?>?D?Q?c?k?w? 0000000035F1 0000004061F1 0 0'0.090G0P0U0e0u0~0 00000000361D 00000040621D 0 1%151>1E1U1e1n1u1 000000003647 000000406247 0 2%2.252E2P2 00000000366D 00000040626D 0 3$3,333G3U3g3 000000003693 000000406293 0 4*404C4X4c4y4 0000000036AF 0000004062AF 0 5P5\5b5t5~5 0000000036E1 0000004062E1 0 6#6(6-636;6O6i6 000000003709 000000406309 0 7!7'7,747:7@7M7S7]7|7 000000003731 000000406331 0 798>8Q8X8k8 00000000375F 00000040635F 0 9$9*949>9N9 00000000376B 00000040636B 0 9n9w9 00000000377F 00000040637F 0 ;-;K;_;e; 000000003789 000000406389 0 <+<7<F<O<\< 0000000037A9 0000004063A9 0 ="=(=.=4=:=@=b=q= 0000000037D9 0000004063D9 0 1 1$1(1,10141@1D1H1T1X1\1 0000000037F3 0000004063F3 0 1d1h1l1p1t1x1|1 000000003823 000000406423 0 1d3h3l3p3 00000000383F 00000040643F 0 4(4,40484P4 00000000384B 00000040644B 0 4d4t4x4|4 000000003871 000000406471 0 5 585d5t5 000000003885 000000406485 0 6 6@6\6 0000000038A5 0000004064A5 0 0<0h0
=== DOWNLOAD ===