.- - -----÷M÷E÷N÷U÷------------------------------------------------------------- --- ---- -------------.
! WALL ! STATS ! GOODIES ! YARA ! FAQ ! RSS ! EMV !
`-------------- - --- ---------- -------- -------- -------- -------- ----------------- - ---- ---- --'
ATM MALWARE NOTICE
4a75be18a3fe0033a9ebdb8f4af81c94e03581d19b5b4373e74e41283fd2615f
Date...........: 2019-05-17
Family.........: DispCash.19
File name......: USBLOGGER.exe
File size......: 15.00 KB
Type file......: EXE/Windows
Virscan........: VT - HA
Documentation..: https://twitter.com/r3c0nst/status/1129641730813366274
Additional note: Technical detail about the serial check: twitter.com/CyberCrimeWHQ/status/1129932869277814784
Entropy:
Binary Histogram:
=== SCREENSHOT ===
=== PEDUMP REPORT ===
=== MZ Header ===
signature: "MZ"
bytes_in_last_block: 144 0x90
blocks_in_file: 3 3
num_relocs: 0 0
header_paragraphs: 4 4
min_extra_paragraphs: 0 0
max_extra_paragraphs: 65535 0xffff
ss: 0 0
sp: 184 0xb8
checksum: 0 0
ip: 0 0
cs: 0 0
reloc_table_offset: 64 0x40
overlay_number: 0 0
reserved0: 0 0
oem_id: 0 0
oem_info: 0 0
reserved2: 0 0
reserved3: 0 0
reserved4: 0 0
reserved5: 0 0
reserved6: 0 0
lfanew: 232 0xe8
=== DOS STUB ===
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th|
00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno|
00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS |
00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
=== RICH Header ===
LIB_ID VERSION TIMES_USED
205 cd 50929 c6f1 1 1
206 ce 50929 c6f1 19 13
203 cb 50929 c6f1 4 4
207 cf 50929 c6f1 5 5
1 1 0 0 73 49
185 b9 30716 77fc 5 5
207 cf 60315 eb9b 7 7
204 cc 60315 eb9b 1 1
=== PE Header ===
signature: "PE\x00\x00"
# IMAGE_FILE_HEADER:
Machine: 332 0x14c x86
NumberOfSections: 4 4
TimeDateStamp: "2019-05-13 13:27:39"
PointerToSymbolTable: 0 0
NumberOfSymbols: 0 0
SizeOfOptionalHeader: 224 0xe0
Characteristics: 258 0x102 EXECUTABLE_IMAGE, 32BIT_MACHINE
# IMAGE_OPTIONAL_HEADER32:
Magic: 267 0x10b 32-bit executable
LinkerVersion: 11.0
SizeOfCode: 8192 0x2000
SizeOfInitializedData: 10752 0x2a00
SizeOfUninitializedData: 0 0
AddressOfEntryPoint: 10161 0x27b1
BaseOfCode: 4096 0x1000
BaseOfData: 12288 0x3000
ImageBase: 4194304 0x400000
SectionAlignment: 4096 0x1000
FileAlignment: 512 0x200
OperatingSystemVersion: 6.0
ImageVersion: 0.0
SubsystemVersion: 6.0
Reserved1: 0 0
SizeOfImage: 28672 0x7000
SizeOfHeaders: 1024 0x400
CheckSum: 0 0
Subsystem: 3 3 WINDOWS_CUI
DllCharacteristics: 33088 0x8140 DYNAMIC_BASE, NX_COMPAT
TERMINAL_SERVER_AWARE
SizeOfStackReserve: 1048576 0x100000
SizeOfStackCommit: 4096 0x1000
SizeOfHeapReserve: 1048576 0x100000
SizeOfHeapCommit: 4096 0x1000
LoaderFlags: 0 0
NumberOfRvaAndSizes: 16 0x10
=== DATA DIRECTORY ===
EXPORT rva:0x 0 size:0x 0
IMPORT rva:0x 3684 size:0x 64
RESOURCE rva:0x 0 size:0x 0
EXCEPTION rva:0x 0 size:0x 0
SECURITY rva:0x 0 size:0x 0
BASERELOC rva:0x 6000 size:0x 4b0
DEBUG rva:0x 0 size:0x 0
ARCHITECTURE rva:0x 0 size:0x 0
GLOBALPTR rva:0x 0 size:0x 0
TLS rva:0x 0 size:0x 0
LOAD_CONFIG rva:0x 3378 size:0x 40
Bound_IAT rva:0x 0 size:0x 0
IAT rva:0x 3000 size:0x 118
Delay_IAT rva:0x 0 size:0x 0
CLR_Header rva:0x 0 size:0x 0
rva:0x 0 size:0x 0
=== SECTIONS ===
NAME RVA VSZ RAW_SZ RAW_PTR nREL REL_PTR nLINE LINE_PTR FLAGS
.text 1000 1e01 2000 400 0 0 0 0 60000020 R-X CODE
.rdata 3000 cee e00 2400 0 0 0 0 40000040 R-- IDATA
.data 4000 120c 200 3200 0 0 0 0 c0000040 RW- IDATA
.reloc 6000 664 800 3400 0 0 0 0 42000040 R-- IDATA DISCARDABLE
=== IMPORTS ===
MODULE_NAME HINT ORD FUNCTION_NAME
KERNEL32.dll 55f Sleep
KERNEL32.dll 2b5 GetProcAddress
KERNEL32.dll 3c0 LoadLibraryA
KERNEL32.dll 16 AllocConsole
KERNEL32.dll 213 GetConsoleWindow
KERNEL32.dll 2dd GetStdHandle
KERNEL32.dll 17b FillConsoleOutputCharacterA
KERNEL32.dll 17a FillConsoleOutputAttribute
KERNEL32.dll 20e GetConsoleScreenBufferInfo
KERNEL32.dll 4d3 SetConsoleCursorPosition
KERNEL32.dll 5e6 WriteConsoleA
KERNEL32.dll 228 GetCurrentThreadId
KERNEL32.dll 224 GetCurrentProcessId
KERNEL32.dll 43c QueryPerformanceCounter
KERNEL32.dll 388 IsProcessorFeaturePresent
KERNEL32.dll 383 IsDebuggerPresent
KERNEL32.dll 117 DecodePointer
KERNEL32.dll 13c EncodePointer
KERNEL32.dll 2f4 GetSystemTimeAsFileTime
USER32.dll 117 GetAsyncKeyState
USER32.dll 31c ShowWindow
MSVCP110.dll 2d3 ?_Winerror_map@std@@YAPBDH@Z
MSVCP110.dll 2da ?_Xlength_error@std@@YAXPBD@Z
MSVCP110.dll 2db ?_Xout_of_range@std@@YAXPBD@Z
MSVCP110.dll 2d7 ?_Xbad_alloc@std@@YAXXZ
MSVCP110.dll 2be ?_Syserror_map@std@@YAPBDH@Z
MSVCR110.dll 62a memmove
MSVCR110.dll 63a rand
MSVCR110.dll 64b srand
MSVCR110.dll 4ca _time64
MSVCR110.dll 15d _CxxThrowException
MSVCR110.dll 178 __CxxFrameHandler3
MSVCR110.dll 681 vsprintf_s
MSVCR110.dll 62c memset
MSVCR110.dll 37c _lock
MSVCR110.dll 4e6 _unlock
MSVCR110.dll 22b _calloc_crt
MSVCR110.dll 1ac __dllonexit
MSVCR110.dll 422 _onexit
MSVCR110.dll 70 ??1type_info@@UAE@XZ
MSVCR110.dll 16f _XcptFilter
MSVCR110.dll 215 _amsg_exit
MSVCR110.dll 1b4 __getmainargs
MSVCR110.dll 73 ??3@YAXPAX@Z
MSVCR110.dll 5cc exit
MSVCR110.dll 279 _exit
MSVCR110.dll 22c _cexit
MSVCR110.dll 23c _configthreadlocale
MSVCR110.dll 1f2 __setusermatherr
MSVCR110.dll 2ff _initterm_e
MSVCR110.dll 2fe _initterm
MSVCR110.dll 1b5 __initenv
MSVCR110.dll 294 _fmode
MSVCR110.dll 23b _commode
MSVCR110.dll 270 _except_handler4_common
MSVCR110.dll 24b _crt_debugger_hook
MSVCR110.dll 1aa __crtUnhandledException
MSVCR110.dll 1a9 __crtTerminateProcess
MSVCR110.dll 13b ?terminate@@YAXXZ
MSVCR110.dll 1a8 __crtSetUnhandledExceptionFilter
MSVCR110.dll 306 _invoke_watson
MSVCR110.dll 23f _controlfp_s
MSVCR110.dll 71 ??2@YAPAXI@Z
MSVCR110.dll 431 _purecall
MSVCR110.dll 1f0 __set_app_type
MSVCR110.dll 628 memcpy
=== Packer / Compiler ===
MS Visual C++ v8.0
=== Strings ===
File pos Mem pos ID Text
======== ======= == ====
00000000004D 00000040004D 0 !This program cannot be run in DOS mode.
0000000000BF 0000004000BF 0 jDR)j
0000000000C7 0000004000C7 0 jDR*j
0000000000CF 0000004000CF 0 jRich
0000000001E0 0000004001E0 0 .text
000000000208 000000400208 0 .rdata
00000000022F 00000040022F 0 @.data
000000000258 000000400258 0 .reloc
000000001693 000000402293 0 PVhH3@
000000001782 000000402382 0 PVSj W
000000001908 000000402508 0 t%WhP*@
0000000020F7 000000402CF7 0 VVVVV
00000000258C 00000040318C 0 generic
000000002594 000000403194 0 unknown error
0000000025C0 0000004031C0 0 iostream
0000000025CC 0000004031CC 0 iostream stream error
000000002600 000000403200 0 system
00000000260C 00000040320C 0 CSCWCNG.dll
000000002618 000000403218 0 CscCngOpen
000000002624 000000403224 0 CscCngReset
000000002630 000000403230 0 CscCngClose
00000000263C 00000040323C 0 CscCngDispense
00000000264C 00000040324C 0 CscCngTransport
00000000265C 00000040325C 0 CscCngStatusRead
000000002670 000000403270 0 CscCngStatusWrite
000000002684 000000403284 0 CscCngCasRefInit
000000002698 000000403298 0 CscCngEncryption
0000000026AC 0000004032AC 0 CscCngRecovery
0000000026BC 0000004032BC 0 CscCngService
0000000026CC 0000004032CC 0 Load CSCWCNG OK
0000000026E0 0000004032E0 0 Load CSCWCNG FAILED
0000000026F8 0000004032F8 0 CFailed 0x%X
000000002708 000000403308 0 %d,%.2d;
000000002714 000000403314 0 DFail 0x%X
000000002720 000000403320 0 invalid string position
000000002738 000000403338 0 string too long
000000002748 000000403348 0 %d--->[ %d | %d ]
000000002C02 000000403802 0 Sleep
000000002C0A 00000040380A 0 GetProcAddress
000000002C1C 00000040381C 0 LoadLibraryA
000000002C2C 00000040382C 0 AllocConsole
000000002C3C 00000040383C 0 GetConsoleWindow
000000002C50 000000403850 0 GetStdHandle
000000002C60 000000403860 0 FillConsoleOutputCharacterA
000000002C7E 00000040387E 0 FillConsoleOutputAttribute
000000002C9C 00000040389C 0 GetConsoleScreenBufferInfo
000000002CBA 0000004038BA 0 SetConsoleCursorPosition
000000002CD6 0000004038D6 0 WriteConsoleA
000000002CE4 0000004038E4 0 KERNEL32.dll
000000002CF4 0000004038F4 0 ShowWindow
000000002D02 000000403902 0 GetAsyncKeyState
000000002D14 000000403914 0 USER32.dll
000000002D22 000000403922 0 ?_Xbad_alloc@std@@YAXXZ
000000002D3C 00000040393C 0 ?_Xlength_error@std@@YAXPBD@Z
000000002D5C 00000040395C 0 ?_Xout_of_range@std@@YAXPBD@Z
000000002D7C 00000040397C 0 ?_Syserror_map@std@@YAPBDH@Z
000000002D9C 00000040399C 0 ?_Winerror_map@std@@YAPBDH@Z
000000002DBA 0000004039BA 0 MSVCP110.dll
000000002DCA 0000004039CA 0 _purecall
000000002DD6 0000004039D6 0 ??2@YAPAXI@Z
File pos Mem pos ID Text
======== ======= == ====
000000002DE6 0000004039E6 0 ??3@YAXPAX@Z
000000002DF6 0000004039F6 0 vsprintf_s
000000002E04 000000403A04 0 memmove
000000002E16 000000403A16 0 srand
000000002E1E 000000403A1E 0 _time64
000000002E28 000000403A28 0 _CxxThrowException
000000002E3E 000000403A3E 0 __CxxFrameHandler3
000000002E54 000000403A54 0 memcpy
000000002E5E 000000403A5E 0 memset
000000002E66 000000403A66 0 MSVCR110.dll
000000002E76 000000403A76 0 _lock
000000002E7E 000000403A7E 0 _unlock
000000002E88 000000403A88 0 _calloc_crt
000000002E96 000000403A96 0 __dllonexit
000000002EA4 000000403AA4 0 _onexit
000000002EAE 000000403AAE 0 ??1type_info@@UAE@XZ
000000002EC6 000000403AC6 0 _XcptFilter
000000002ED4 000000403AD4 0 _amsg_exit
000000002EE2 000000403AE2 0 __getmainargs
000000002EF2 000000403AF2 0 __set_app_type
000000002F0C 000000403B0C 0 _exit
000000002F14 000000403B14 0 _cexit
000000002F1E 000000403B1E 0 _configthreadlocale
000000002F34 000000403B34 0 __setusermatherr
000000002F48 000000403B48 0 _initterm_e
000000002F56 000000403B56 0 _initterm
000000002F62 000000403B62 0 __initenv
000000002F6E 000000403B6E 0 _fmode
000000002F78 000000403B78 0 _commode
000000002F84 000000403B84 0 _except_handler4_common
000000002F9E 000000403B9E 0 _crt_debugger_hook
000000002FB4 000000403BB4 0 __crtUnhandledException
000000002FCE 000000403BCE 0 __crtTerminateProcess
000000002FE6 000000403BE6 0 ?terminate@@YAXXZ
000000002FFA 000000403BFA 0 __crtSetUnhandledExceptionFilter
00000000301E 000000403C1E 0 _invoke_watson
000000003030 000000403C30 0 _controlfp_s
000000003040 000000403C40 0 EncodePointer
000000003050 000000403C50 0 DecodePointer
000000003060 000000403C60 0 IsDebuggerPresent
000000003074 000000403C74 0 IsProcessorFeaturePresent
000000003090 000000403C90 0 QueryPerformanceCounter
0000000030AA 000000403CAA 0 GetCurrentProcessId
0000000030C0 000000403CC0 0 GetCurrentThreadId
0000000030D6 000000403CD6 0 GetSystemTimeAsFileTime
000000003200 000000404000 0 CSCCNG
000000003220 000000404020 0 .?AVerror_category@std@@
000000003244 000000404044 0 .?AV_Generic_error_category@std@@
000000003270 000000404070 0 .?AV_Iostream_error_category@std@@
00000000329C 00000040409C 0 .?AV_System_error_category@std@@
0000000032C8 0000004040C8 0 .?AVtype_info@@
000000003409 000000406009 0 010Q0l0
000000003427 000000406027 0 1C1H1N1Z1b1h1v1
00000000344F 00000040604F 0 1#2)212K2P2g2l2t2z2
000000003491 000000406091 0 3*383=3Q3W3a3e3{3
0000000034C1 0000004060C1 0 4*42484B4L4V4
0000000034CF 0000004060CF 0 4j4t4~4
0000000034F1 0000004060F1 0 5'5/575?5E5O5S5k5q5{5
000000003515 000000406115 0 5R6q627V7\7v7|7
00000000352B 00000040612B 0 8j9}9
File pos Mem pos ID Text
======== ======= == ====
000000003531 000000406131 0 92:8:
000000003543 000000406143 0 <!<1<N<T<a<m<z<
00000000356D 00000040616D 0 = ='===F=M=U=_=i=v=
00000000359B 00000040619B 0 >'>4>D>L>R>_>q>y>
0000000035C5 0000004061C5 0 ?&?6?>?D?Q?c?k?w?
0000000035F1 0000004061F1 0 0'0.090G0P0U0e0u0~0
00000000361D 00000040621D 0 1%151>1E1U1e1n1u1
000000003647 000000406247 0 2%2.252E2P2
00000000366D 00000040626D 0 3$3,333G3U3g3
000000003693 000000406293 0 4*404C4X4c4y4
0000000036AF 0000004062AF 0 5P5\5b5t5~5
0000000036E1 0000004062E1 0 6#6(6-636;6O6i6
000000003709 000000406309 0 7!7'7,747:7@7M7S7]7|7
000000003731 000000406331 0 798>8Q8X8k8
00000000375F 00000040635F 0 9$9*949>9N9
00000000376B 00000040636B 0 9n9w9
00000000377F 00000040637F 0 ;-;K;_;e;
000000003789 000000406389 0 <+<7<F<O<\<
0000000037A9 0000004063A9 0 ="=(=.=4=:=@=b=q=
0000000037D9 0000004063D9 0 1 1$1(1,10141@1D1H1T1X1\1
0000000037F3 0000004063F3 0 1d1h1l1p1t1x1|1
000000003823 000000406423 0 1d3h3l3p3
00000000383F 00000040643F 0 4(4,40484P4
00000000384B 00000040644B 0 4d4t4x4|4
000000003871 000000406471 0 5 585d5t5
000000003885 000000406485 0 6 6@6\6
0000000038A5 0000004064A5 0 0<0h0
00000000004D 00000040004D 0 !This program cannot be run in DOS mode.
0000000000BF 0000004000BF 0 jDR)j
0000000000C7 0000004000C7 0 jDR*j
0000000000CF 0000004000CF 0 jRich
0000000001E0 0000004001E0 0 .text
000000000208 000000400208 0 .rdata
00000000022F 00000040022F 0 @.data
000000000258 000000400258 0 .reloc
000000001693 000000402293 0 PVhH3@
000000001782 000000402382 0 PVSj W
000000001908 000000402508 0 t%WhP*@
0000000020F7 000000402CF7 0 VVVVV
00000000258C 00000040318C 0 generic
000000002594 000000403194 0 unknown error
0000000025C0 0000004031C0 0 iostream
0000000025CC 0000004031CC 0 iostream stream error
000000002600 000000403200 0 system
00000000260C 00000040320C 0 CSCWCNG.dll
000000002618 000000403218 0 CscCngOpen
000000002624 000000403224 0 CscCngReset
000000002630 000000403230 0 CscCngClose
00000000263C 00000040323C 0 CscCngDispense
00000000264C 00000040324C 0 CscCngTransport
00000000265C 00000040325C 0 CscCngStatusRead
000000002670 000000403270 0 CscCngStatusWrite
000000002684 000000403284 0 CscCngCasRefInit
000000002698 000000403298 0 CscCngEncryption
0000000026AC 0000004032AC 0 CscCngRecovery
0000000026BC 0000004032BC 0 CscCngService
0000000026CC 0000004032CC 0 Load CSCWCNG OK
0000000026E0 0000004032E0 0 Load CSCWCNG FAILED
0000000026F8 0000004032F8 0 CFailed 0x%X
000000002708 000000403308 0 %d,%.2d;
File pos Mem pos ID Text
======== ======= == ====
000000002714 000000403314 0 DFail 0x%X
000000002720 000000403320 0 invalid string position
000000002738 000000403338 0 string too long
000000002748 000000403348 0 %d--->[ %d | %d ]
000000002C02 000000403802 0 Sleep
000000002C0A 00000040380A 0 GetProcAddress
000000002C1C 00000040381C 0 LoadLibraryA
000000002C2C 00000040382C 0 AllocConsole
000000002C3C 00000040383C 0 GetConsoleWindow
000000002C50 000000403850 0 GetStdHandle
000000002C60 000000403860 0 FillConsoleOutputCharacterA
000000002C7E 00000040387E 0 FillConsoleOutputAttribute
000000002C9C 00000040389C 0 GetConsoleScreenBufferInfo
000000002CBA 0000004038BA 0 SetConsoleCursorPosition
000000002CD6 0000004038D6 0 WriteConsoleA
000000002CE4 0000004038E4 0 KERNEL32.dll
000000002CF4 0000004038F4 0 ShowWindow
000000002D02 000000403902 0 GetAsyncKeyState
000000002D14 000000403914 0 USER32.dll
000000002D22 000000403922 0 ?_Xbad_alloc@std@@YAXXZ
000000002D3C 00000040393C 0 ?_Xlength_error@std@@YAXPBD@Z
000000002D5C 00000040395C 0 ?_Xout_of_range@std@@YAXPBD@Z
000000002D7C 00000040397C 0 ?_Syserror_map@std@@YAPBDH@Z
000000002D9C 00000040399C 0 ?_Winerror_map@std@@YAPBDH@Z
000000002DBA 0000004039BA 0 MSVCP110.dll
000000002DCA 0000004039CA 0 _purecall
000000002DD6 0000004039D6 0 ??2@YAPAXI@Z
000000002DE6 0000004039E6 0 ??3@YAXPAX@Z
000000002DF6 0000004039F6 0 vsprintf_s
000000002E04 000000403A04 0 memmove
000000002E16 000000403A16 0 srand
000000002E1E 000000403A1E 0 _time64
000000002E28 000000403A28 0 _CxxThrowException
000000002E3E 000000403A3E 0 __CxxFrameHandler3
000000002E54 000000403A54 0 memcpy
000000002E5E 000000403A5E 0 memset
000000002E66 000000403A66 0 MSVCR110.dll
000000002E76 000000403A76 0 _lock
000000002E7E 000000403A7E 0 _unlock
000000002E88 000000403A88 0 _calloc_crt
000000002E96 000000403A96 0 __dllonexit
000000002EA4 000000403AA4 0 _onexit
000000002EAE 000000403AAE 0 ??1type_info@@UAE@XZ
000000002EC6 000000403AC6 0 _XcptFilter
000000002ED4 000000403AD4 0 _amsg_exit
000000002EE2 000000403AE2 0 __getmainargs
000000002EF2 000000403AF2 0 __set_app_type
000000002F0C 000000403B0C 0 _exit
000000002F14 000000403B14 0 _cexit
000000002F1E 000000403B1E 0 _configthreadlocale
000000002F34 000000403B34 0 __setusermatherr
000000002F48 000000403B48 0 _initterm_e
000000002F56 000000403B56 0 _initterm
000000002F62 000000403B62 0 __initenv
000000002F6E 000000403B6E 0 _fmode
000000002F78 000000403B78 0 _commode
000000002F84 000000403B84 0 _except_handler4_common
000000002F9E 000000403B9E 0 _crt_debugger_hook
000000002FB4 000000403BB4 0 __crtUnhandledException
000000002FCE 000000403BCE 0 __crtTerminateProcess
File pos Mem pos ID Text
======== ======= == ====
000000002FE6 000000403BE6 0 ?terminate@@YAXXZ
000000002FFA 000000403BFA 0 __crtSetUnhandledExceptionFilter
00000000301E 000000403C1E 0 _invoke_watson
000000003030 000000403C30 0 _controlfp_s
000000003040 000000403C40 0 EncodePointer
000000003050 000000403C50 0 DecodePointer
000000003060 000000403C60 0 IsDebuggerPresent
000000003074 000000403C74 0 IsProcessorFeaturePresent
000000003090 000000403C90 0 QueryPerformanceCounter
0000000030AA 000000403CAA 0 GetCurrentProcessId
0000000030C0 000000403CC0 0 GetCurrentThreadId
0000000030D6 000000403CD6 0 GetSystemTimeAsFileTime
000000003200 000000404000 0 CSCCNG
000000003220 000000404020 0 .?AVerror_category@std@@
000000003244 000000404044 0 .?AV_Generic_error_category@std@@
000000003270 000000404070 0 .?AV_Iostream_error_category@std@@
00000000329C 00000040409C 0 .?AV_System_error_category@std@@
0000000032C8 0000004040C8 0 .?AVtype_info@@
000000003409 000000406009 0 010Q0l0
000000003427 000000406027 0 1C1H1N1Z1b1h1v1
00000000344F 00000040604F 0 1#2)212K2P2g2l2t2z2
000000003491 000000406091 0 3*383=3Q3W3a3e3{3
0000000034C1 0000004060C1 0 4*42484B4L4V4
0000000034CF 0000004060CF 0 4j4t4~4
0000000034F1 0000004060F1 0 5'5/575?5E5O5S5k5q5{5
000000003515 000000406115 0 5R6q627V7\7v7|7
00000000352B 00000040612B 0 8j9}9
000000003531 000000406131 0 92:8:
000000003543 000000406143 0 <!<1<N<T<a<m<z<
00000000356D 00000040616D 0 = ='===F=M=U=_=i=v=
00000000359B 00000040619B 0 >'>4>D>L>R>_>q>y>
0000000035C5 0000004061C5 0 ?&?6?>?D?Q?c?k?w?
0000000035F1 0000004061F1 0 0'0.090G0P0U0e0u0~0
00000000361D 00000040621D 0 1%151>1E1U1e1n1u1
000000003647 000000406247 0 2%2.252E2P2
00000000366D 00000040626D 0 3$3,333G3U3g3
000000003693 000000406293 0 4*404C4X4c4y4
0000000036AF 0000004062AF 0 5P5\5b5t5~5
0000000036E1 0000004062E1 0 6#6(6-636;6O6i6
000000003709 000000406309 0 7!7'7,747:7@7M7S7]7|7
000000003731 000000406331 0 798>8Q8X8k8
00000000375F 00000040635F 0 9$9*949>9N9
00000000376B 00000040636B 0 9n9w9
00000000377F 00000040637F 0 ;-;K;_;e;
000000003789 000000406389 0 <+<7<F<O<\<
0000000037A9 0000004063A9 0 ="=(=.=4=:=@=b=q=
0000000037D9 0000004063D9 0 1 1$1(1,10141@1D1H1T1X1\1
0000000037F3 0000004063F3 0 1d1h1l1p1t1x1|1
000000003823 000000406423 0 1d3h3l3p3
00000000383F 00000040643F 0 4(4,40484P4
00000000384B 00000040644B 0 4d4t4x4|4
000000003871 000000406471 0 5 585d5t5
000000003885 000000406485 0 6 6@6\6
0000000038A5 0000004064A5 0 0<0h0
=== DOWNLOAD ===
Mirror provided by vx-underground.org, thx!