MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b38fa923237a10bbc09ba4808fd0e1f56f39a3de2bb0cfc11a591cdaddf7d58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuasarRAT


Vendor detections: 17


Intelligence 17 IOCs YARA 25 File information Comments 1

SHA256 hash: 2b38fa923237a10bbc09ba4808fd0e1f56f39a3de2bb0cfc11a591cdaddf7d58
SHA3-384 hash: d0696aab1767e29ab2e34eaa811e3fa2351b7dda533b1f9bb5b861f3fd778650b64869fc51832ba0561eae31ab3403cb
SHA1 hash: 392ec955d7b5c5da965f7af9f929b89c33409b03
MD5 hash: 4522bc113a6f5b984e9ffac278f9f064
humanhash: steak-oklahoma-papa-salami
File name:sharpmonoinjector.exe
Download: download sample
Signature QuasarRAT
File size:3'266'048 bytes
First seen:2024-12-17 06:32:25 UTC
Last seen:2025-01-27 10:34:55 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'076 x AgentTesla, 20'036 x Formbook, 12'353 x SnakeKeylogger)
ssdeep 98304:6WV5SgjlbwPdRl5fGO4ZL0luiel9uRJk3HZ2b/aryTnrfvnM3A2Ozvg:FTQzo
Threatray 994 similar samples on MalwareBazaar
TLSH T161E56B1437F84E33E1AFEAB2D5F05452A2F1FC2AB363E70B9481667A1D43B5049427A7
TrID 40.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
31.6% (.CPL) Windows Control Panel Item (generic) (57583/11/19)
9.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
5.7% (.EXE) Win64 Executable (generic) (10522/11/4)
3.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
Magika pebin
Reporter lontze7
Tags:exe QuasarRAT

Intelligence


File Origin
# of uploads :
3
# of downloads :
298
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
asyncrat
ID:
1
File name:
241127-xqsswsslej_pw_infected.zip
Verdict:
Malicious activity
Analysis date:
2024-12-16 11:37:57 UTC
Tags:
arch-exec loader github telegram opendir auto asyncrat vidar stealer quasarrat lumma sliver miner payload hausbomber dcrat evasion amadey botnet jeefo rat njrat bladabindi neshta remcos tas17 upx mouseloader discord xworm meterpreter meduzastealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.9%
Tags:
infosteal autorun quasar
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Launching a process
DNS request
Creating a file in the %temp% directory
Setting a keyboard event handler
Running batch commands
Creating a process with a hidden window
Creating a file
Unauthorized injection to a recently created process
Restart of the analyzed sample
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm certreq crypto expand explorer hook infostealer keylogger lolbin obfuscated quasarrat rat remote runonce schtasks stealer stealer
Result
Threat name:
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Hides that the sample has been downloaded from the Internet (zone.identifier)
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Generic Downloader
Yara detected Quasar RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1576473 Sample: sharpmonoinjector.exe Startdate: 17/12/2024 Architecture: WINDOWS Score: 100 163 VIPEEK1990-25013.portmap.host 2->163 171 Multi AV Scanner detection for domain / URL 2->171 173 Found malware configuration 2->173 175 Malicious sample detected (through community Yara rule) 2->175 177 9 other signatures 2->177 15 sharpmonoinjector.exe 5 2->15         started        signatures3 process4 file5 159 C:\Users\user\AppData\...\iJy0HgdWHjNN.bat, DOS 15->159 dropped 161 C:\Users\user\...\sharpmonoinjector.exe.log, CSV 15->161 dropped 165 Uses ping.exe to sleep 15->165 167 Uses schtasks.exe or at.exe to add and modify task schedules 15->167 169 Hides that the sample has been downloaded from the Internet (zone.identifier) 15->169 19 cmd.exe 1 15->19         started        22 sharpmonoinjector.exe 15->22         started        25 schtasks.exe 1 15->25         started        27 3 other processes 15->27 signatures6 process7 file8 179 Uses ping.exe to sleep 19->179 181 Uses ping.exe to check the status of other devices and networks 19->181 29 sharpmonoinjector.exe 4 19->29         started        33 conhost.exe 19->33         started        35 PING.EXE 1 19->35         started        37 chcp.com 1 19->37         started        149 C:\Users\user\AppData\...\OuevXVfOiSml.bat, DOS 22->149 dropped 183 Hides that the sample has been downloaded from the Internet (zone.identifier) 22->183 39 cmd.exe 22->39         started        41 schtasks.exe 22->41         started        43 conhost.exe 25->43         started        signatures9 process10 file11 151 C:\Users\user\AppData\...\6FOtZlcPAeIW.bat, DOS 29->151 dropped 197 Hides that the sample has been downloaded from the Internet (zone.identifier) 29->197 45 cmd.exe 1 29->45         started        48 schtasks.exe 1 29->48         started        199 Uses ping.exe to sleep 39->199 50 sharpmonoinjector.exe 39->50         started        53 conhost.exe 39->53         started        55 chcp.com 39->55         started        57 PING.EXE 39->57         started        59 conhost.exe 41->59         started        signatures12 process13 file14 185 Uses ping.exe to sleep 45->185 61 sharpmonoinjector.exe 4 45->61         started        65 conhost.exe 45->65         started        67 PING.EXE 1 45->67         started        69 chcp.com 1 45->69         started        71 conhost.exe 48->71         started        143 C:\Users\user\AppData\...\pptrklDTl5QX.bat, DOS 50->143 dropped 187 Hides that the sample has been downloaded from the Internet (zone.identifier) 50->187 73 cmd.exe 50->73         started        75 schtasks.exe 50->75         started        signatures15 process16 file17 153 C:\Users\user\AppData\...\sQHcmL5mR8uz.bat, DOS 61->153 dropped 201 Hides that the sample has been downloaded from the Internet (zone.identifier) 61->201 77 cmd.exe 1 61->77         started        80 schtasks.exe 1 61->80         started        203 Uses ping.exe to sleep 73->203 82 sharpmonoinjector.exe 73->82         started        85 conhost.exe 73->85         started        87 chcp.com 73->87         started        89 PING.EXE 73->89         started        91 conhost.exe 75->91         started        signatures18 process19 file20 189 Uses ping.exe to sleep 77->189 93 sharpmonoinjector.exe 77->93         started        97 conhost.exe 77->97         started        99 chcp.com 77->99         started        101 PING.EXE 77->101         started        103 conhost.exe 80->103         started        145 C:\Users\user\AppData\...\SIVvseWusjjB.bat, DOS 82->145 dropped 191 Hides that the sample has been downloaded from the Internet (zone.identifier) 82->191 105 cmd.exe 82->105         started        107 schtasks.exe 82->107         started        signatures21 process22 file23 155 C:\Users\user\AppData\...\WKmd1cx2Hydy.bat, DOS 93->155 dropped 205 Hides that the sample has been downloaded from the Internet (zone.identifier) 93->205 109 cmd.exe 93->109         started        112 schtasks.exe 93->112         started        207 Uses ping.exe to sleep 105->207 114 sharpmonoinjector.exe 105->114         started        117 conhost.exe 105->117         started        119 chcp.com 105->119         started        121 PING.EXE 105->121         started        123 conhost.exe 107->123         started        signatures24 process25 file26 193 Uses ping.exe to sleep 109->193 125 sharpmonoinjector.exe 109->125         started        129 conhost.exe 109->129         started        131 chcp.com 109->131         started        133 PING.EXE 109->133         started        135 conhost.exe 112->135         started        147 C:\Users\user\AppData\...\fahGJfQVD76h.bat, DOS 114->147 dropped 195 Hides that the sample has been downloaded from the Internet (zone.identifier) 114->195 137 cmd.exe 114->137         started        139 schtasks.exe 114->139         started        signatures27 process28 file29 157 C:\Users\user\AppData\...\WU72vqrNhyBK.bat, DOS 125->157 dropped 209 Hides that the sample has been downloaded from the Internet (zone.identifier) 125->209 141 schtasks.exe 125->141         started        211 Uses ping.exe to sleep 137->211 signatures30 process31
Threat name:
ByteCode-MSIL.Backdoor.Quasar
Status:
Malicious
First seen:
2024-12-11 21:47:16 UTC
File Type:
PE (.Net Exe)
Extracted files:
3
AV detection:
28 of 38 (73.68%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:quasar botnet:zjeb discovery spyware trojan
Behaviour
Runs ping.exe
Scheduled Task/Job: Scheduled Task
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Enumerates physical storage devices
System Network Configuration Discovery: Internet Connection Discovery
Checks computer location settings
Quasar RAT
Quasar family
Quasar payload
Malware Config
C2 Extraction:
VIPEEK1990-25013.portmap.host:25013
Verdict:
Malicious
Tags:
rat quasar_rat stealer Win.Malware.Generic-9883083-0
YARA:
malware_windows_quasarrat win_quasar_rat_client MAL_QuasarRAT_May19_1 MALWARE_Win_Quasarstealer
Unpacked files
SH256 hash:
2b38fa923237a10bbc09ba4808fd0e1f56f39a3de2bb0cfc11a591cdaddf7d58
MD5 hash:
4522bc113a6f5b984e9ffac278f9f064
SHA1 hash:
392ec955d7b5c5da965f7af9f929b89c33409b03
Detections:
QuasarRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_NoneWindowsUA
Author:ditekSHen
Description:Detects Windows executables referencing non-Windows User-Agents
Rule name:INDICATOR_SUSPICIOUS_GENInfoStealer
Author:ditekSHen
Description:Detects executables containing common artifacts observed in infostealers
Rule name:MALWARE_Win_QuasarStealer
Author:ditekshen
Description:Detects Quasar infostealer
Rule name:MAL_QuasarRAT_May19_1
Description:Detects QuasarRAT malware
Rule name:MAL_QuasarRAT_May19_1
Author:Florian Roth (Nextron Systems)
Description:Detects QuasarRAT malware
Reference:https://blog.ensilo.com/uncovering-new-activity-by-apt10
Rule name:MAL_QuasarRAT_May19_1_RID2E1E
Author:Florian Roth
Description:Detects QuasarRAT malware
Reference:https://blog.ensilo.com/uncovering-new-activity-by-apt10
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:Multifamily_RAT_Detection
Author:Lucas Acha (http://www.lukeacha.com)
Description:Generic Detection for multiple RAT families, PUPs, Packers and suspicious executables
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:quasarrat_kingrat
Author:jeFF0Falltrades
Rule name:RansomPyShield_Antiransomware
Author:XiAnzheng
Description:Check for Suspicious String and Import combination that Ransomware mostly abuse(can create FP)
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RC6_Constants
Author:chort (@chort0)
Description:Look for RC6 magic constants in binary
Reference:https://twitter.com/mikko/status/417620511397400576
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:win_quasar_rat_client
Author:Matthew @ Embee_Research
Description:Detects strings present in Quasar Rat Samples.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

QuasarRAT

Executable exe 2b38fa923237a10bbc09ba4808fd0e1f56f39a3de2bb0cfc11a591cdaddf7d58

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments



Avatar
commented on 2024-12-17 06:35:59 UTC

RAT King Parser (https://github.com/jeFF0Falltrades/rat_king_parser) Output:

{
"sha256": "2b38fa923237a10bbc09ba4808fd0e1f56f39a3de2bb0cfc11a591cdaddf7d58",
"yara_possible_family": "quasarrat",
"key": "8d30291da05634b15c2f6cdaae2bfe85ff9fc99c3e1aa36522ff2f4827d71495",
"salt": "bfeb1e56fbcd973bb219022430a57843003d5644d21e62b9d4f180e7e6c33941",
"config": {
"\ub622\u866d\u703f\u9767\u1b12\uc671\u35d5\u78f5\u1582\ua2af\ufbe4\u908d\ua67d\u96e4\u6ef6\u2a51\u6c2d\u584d\u29a1\ua0f8": false,
"\u0429\u69f8\u12f1\u3999\u9c10\u6a03\ufb2e\u21b7\u9d0c\u8076\u865f\uce41\uf019\ubee0\u4734\ubc76\u12e5\ub46a\u840e\u52f2": true,
"\u521f\u28bc\u7033\ueb3e\u7080\u051c\ud3c7\u4f36\u2429\u33ed\u3d0f\ud48a\u0a3b\u9d40\u18ba\u34ec\u489e\u96ae\u75e6\ufd61": false,
"\uab76\u94ac\u948a\u2402\u4f0b\u5c6b\u9941\u37a1\u0b24\ufb29\ua525\u72cd\u16fc\u4e09\u9d8b\ufffd\u76c1\u3dc1\u956a\u6225": true,
"\uf088\u4b3f\u027f\uad0c\u0338\u4990\u6fe9\u4eeb\u28cf\u8ff9\ua278\u679e\uef72\u3baf\u333f\u374f\u9ce2\uf289\u26ca\u9218": false,
"\u431e\ufdb0\ueb7d\u8cc0\ue876\ucaab\u235d\u1685\uac7e\ubad1\u48a0\u0ef1\u1eb1\ue9fe\u59e6\u8790\ufa60\u2626\u645f\u53da": false,
"\ub241\u0e05\u783b\u72a9\ud6c2\u7ed4\ua297\u5d6f\ud1b6\ud4f3\u0551\u1345\ub61c\u8343\uae99\u25b3\u4bb5\u9942\ufa6b\u17ef": false,
"\u0f4c\ufc25\ua003\u5868\uee36\uf008\uc1de\u9658\uaa1f\u666a\uef79\u509e\u61b4\u0600\ua975\u502d\u561f\u4e04\ub381\u30bf": 3000,
"\u44b2\u2581\u01b4\u41fc\u1f54\uc891\uf00c\uf0af\u79a7\ua38a\uc420\uebaf\u5d67\u35dc\u0450\u0a9d\ubde4\u8826\u94ca\u5125": "APPLICATIONDATA",
"\u92c5\ufffd\ua49e\u91f4\ube42\ucdc6\u5e7c\u5723\u0d3e\u922f\ua9db\ub84f\ue981\u2077\ub53f\uc03c\u82ab\u40a2\ued19\ua706": "1.4.1",
"\u6dc8\u4094\u46da\u37fd\u3dc4\u2f0b\u39e6\ua78f\uca7d\ub87c\u21c6\u394f\u8aca\u2837\ub7ef\ud51f\uf7de\ubbf0\u3e68\uf502": "VIPEEK1990-25013.portmap.host:25013;",
"\ube0d\ufffd\u870e\uefb6\u6eca\u890a\ud7d6\ube1a\u872a\u9a78\u97cc\u9df8\ua2c7\ucb2a\ub126\ue39e\u1567\u8ed5\u5f8b\u4cbb": "SubDir",
"\u76b0\u3ae6\u5427\u7315\u0c7c\uf043\u560f\u77f7\ubbd7\u5519\ud787\ua72f\ue82a\u8724\u4f3a\u8253\u2f74\ufa43\ud394\u86f7": "Client.exe",
"\ud25b\ua4f6\uc980\u0f84\u9ca4\u2dfa\u4cbe\u742e\ua666\ua63b\u6c17\u9a6c\u57b1\u0ccf\uf3f7\u4409\ue69b\u6e11\u4e97\u1e0b": "ebef1e3c-805b-4b1a-aa24-bf4dcab44476",
"\u15af\ue1bb\u800e\u0471\ucc0d\u858d\u53f9\u3d8e\ued09\u252a\u56d8\uc756\u6472\u0974\uaac1\ufc62\u645f\u27f3\ued38\u91cb": "Windows Security Service",
"\u963e\ua2da\u1a90\uac80\ud180\u6766\u3938\u4c00\ud656\u0dab\ub025\u4007\u638f\u27de\u4736\ubbf7\u0702\u78b0\u1e15\u6834": "3EBA8BC34FA983893A9B07B831E7CEB183F7492D",
"\uf762\uc0d6\u292c\u9b71\u4110\u890d\u2718\ub893\u8039\ud5a1\ufb6d\u7c6c\u76aa\u35f7\u5dbf\u8a7e\u4a86\u5246\u7733\u39fd": "ZJEB",
"\u5ebf\u34e0\u2017\u50b9\u3a26\ue5a2\u2b18\u47fe\u8e1c\u6c2c\u8c2b\u466c\u46d9\u3dbb\ufe17\u3c2e\u1253\u8c7a\u2aca\u775b": "Logs",
"\u1e3c\u99e1\u68f1\ufdd0\u66e4\uefa5\u70f0\u7ece\u127a\ud0fa\u81f6\u4f11\u891d\u7cbc\u0f80\u9315\ucfa8\u6406\ud278\uf898": "cCvxFDIRSBTVgjxA+FzUmUm4eipxOTgFKn5bIVroKQVm+pQPQXVI0uoHpJ2oqnkAVE/yni6zjPYrxZbu5WSIh5F3b8x86rN6YJjzGU2rpAQ7NFMwvJrZBLpeKnaAmyKPTzc2HoodYHP12a3jGx8DHsG+pwRDUAdTwtRS+7HlxQ39nVzHl/IQAvvSfaK38J88wBBG7fVU5K6YUUNV6IBct9MkEddDF0FiJ6Xig5cVHXV2apjXZLO/1LjYM/m6cClYjHDV+YCz+1ML6otCVt4GGG0kBYSghY981NaYwauWKcgxZiDeeLuscFzV5UYfyZonl7tiNKOqf7Gbps/SynZ1nU8OC7MmsKliICuXkMm73g3UPA+XfotBa/YtywLOeuj6K1VBALH8rQOBW6SBXV0FSY+ehNHT4Ypjc3V7vfnx8fQr8H0evvF4lUOTn9IuRfEuQrB+1DCoguAW6X7bmAnP+qyZCOGMWMKWcfXQ2Eugh4do7+Y+hQXl8FpGWOrMbhuzB1zyxeXiZCGu655rn2trI2X+QeXmKB9cMl8prxMAU0mAyaI/VQwGXIrr1rQDYn8C0AZ2hXLGkXA+YzD2HnmWu8iCPUQZMfIVThuyW7R4AgXG3hq+brfWGa95tKM0JVclfl5tN6BykGNO8cqWhXcThS419pr+qRzHH5yHF2H6fqw=",
"\uafcb\uc31a\u9899\uce49\u9bcf\u2607\u2874\uc321\u6643\u53d2\u71a4\ub7fe\u4da6\u60d3\u902b\u962e\ubd21\u7e20\u9c61\u7bb5": "MIIE9DCCAtygAwIBAgIQAI3K9pAZ4XgQRdabp+h10TANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTIzMDcxNzE4NTAzNVoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAnK/D8zUxCMKXvR9zuwJFENJvWenVPCLVhVt2QYyE+6aaQW0CwCEzO6lGnHSKI1hVZ0vvx1VLNBqyELx5gRfCfvaRL0s7Vkr62VIWetxdUzGnd2BKOl62rbCVtvH9BkSXhaOM0pJ+NY4JWhG+07jVWKSx67yYNYGdkfF/G2TsPudqRBqNHpTgP00O/RE5eD8lqBp+rWthPa77QUtx1DPmkWD41DYsIRo3xpHn/Kwj1KlDK1V0XpKcPpM9Xpw0krF3ncsuO2Sy4bJvlOZjLBhR1m9D69K/C6bQ0CpKQ4Pb0seyRiuG2fJOurrSW7Nit5fJu+zygXm3pVlFVlrotHAbiAFtbbmacOCZLaY6Yh5GxRIoWEdQaeIk3Bj+UZIOxC+KUWM5UfAbg5RNMh74bR8POI5dyM83ElvGTuLKKWJ5HbXo/PePsr1EhYux2YG2J7L6pmHK5eVjgygl7h6Sx0KwcpXOXL5A4RJtDF10MTbjcreF+PaJCIOZk3gXEqy1BjQiu+1xLrDhlJDMvIDuTKigVnezzCMyqoC9cIDzpZXstpUXjDNF+HyWGWQzSn9Afsz4Y07UEsBRlaiTKjIMdiI77TfZI/ELatW7mRQJMuUFftESRXRgcgSUAPIj+HP1a7/ftIPCkZyQUTkLtLOIKaENTRKfecdlK6mNp7+mQ0PEea8CAwEAAaMyMDAwHQYDVR0OBBYEFOaaTSt/Do9H2TeZcD1iaELohyyxMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQENBQADggIBACjZMz2q4CCCHf9oJq7QlKPj6YSI4cvF97liRZN41KNUCVkN4ai6901q1hEYqQuJsRPzIDQIunbT18Y5eeXWtUzy004XR8rlWGStaXoIf+KyPuwC4dFHr8bQ9UHcrZJAvJVynn3BjmsXJzHPRcnXOa3EX3+LBDJsMC7RZhrymeGxmbb/OYRhu4eftRSsCQwrS4AFCsJ0MvpbdDR+8zqEgNEX/eSDv5HOE7ObYwuTfE1vE+5UxsnQoVApDB2AvOrMTByvhUKt+7AANC8teikKTgeanjlljw+T98Nl+Y/wgJ8JVIIXIQuDLTvA7hXcZZoGFxBsOQTbsFG4N1DvAW0dfCPIJCbxIgvaDEL6GDllvbDyUr8YRKNERDsKNmTaCTeaJ4pCOyxglvwcvz8GzumMwaXtk7zdNr/ufxt4OQJzyl5Xq67bLXotn4zRD4rnj8XxY2YVCOo/1aDYg3CYpg9msmciMeql3vmXP7C4Wgs0nFAKCwYcGFvXkZu47DN9X6tU6f+KI6a9B3nAAIqOxHO+RCoyrd7rVOyf6uLi9NP19rpGcO5mLUvSEkEBRKncKuq6p7I7fSgldqhn9470SpMeroBOewXxCYFklCNVzGHSQ3I618glXVn50lHPMhvEUWJ3aJv6GzJYpn2UNSTsNEietvIYpry7NSTvrgr8cy6lE1WB",
"\u8548\u970d\u6188\u187a\uc932\uf31a\u1423\ue0e5\u4183\ue2a8\u2303\ufc53\u02f7\ua754\u30ba\ubb96\ub809\u662b\u0d4c\u7578": "",
"\u5728\uf408\u88a2\u9646\uf6d9\ud19c\u0e3e\ue084\u9cee\u5a40\uee42\ufffd\u2044\u9d23\ubf87\uf4c7\ub5cf\uaa58\u2485\u35b3": ""
}
}