Sample details: f07e614daff14a245a7ff5f7b7e8556f --

Hashes
MD5: f07e614daff14a245a7ff5f7b7e8556f
SHA1: 9276de6d8ee8802dc9af1dda648d097fa943df02
SHA256: ce13a5517a690071aa38f7d3c65d15b9e14059a0f51be987c8f6d25d386efdfe
SSDEEP: 3072:1kDM7YJ7jH8EERp8Eu/8bh7nYOo6RUUKI9jop6:1kDYiWll+VUKF8
Details
File Type: PE32
Yara Hits
YRP/VC8_Microsoft_Corporation | YRP/Microsoft_Visual_Cpp_8 | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/HasOverlay | YRP/HasDigitalSignature | YRP/HasRichSignature | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/Check_OutputDebugStringA_iat | YRP/anti_dbg | YRP/inject_thread | YRP/screenshot | YRP/win_mutex | YRP/win_private_profile | YRP/win_files_operation | YRP/Big_Numbers0 |
Source
http://backpinging.com/m1/setup.exe
Strings
		!This program cannot be run in DOS mode.
:Richz
`.rdata
@.data
sw!qGgR 
899}834
nQkk1Mc1aZgExu
meP#knt
mst&nen
Wr]ueF]me
C`lse|bndPf
krt!clF&ge
m\oe__
C>L_DMFX
>JR}Km!
PDcltr@
2ubt9$
?p`ciu
R>NFTB@REyLiconsos9\Wtkdo
`me]GsW
fcrnpl32M
8Asdjch/ino -
7rsJjat0
Rt|dkSt;e
5ism.ro
+am}[an
h r`` ik
`.oiat
@;iat<
#reybc
ER{~<=
]C)Z]S
:e]mI=
==X2ue,y
?+F3g&
5;5N5/6
+`m}\`n
e-r1dsa
0@]$/t
Aoe.`r,
Dnq9hay
Deyhse
`}htMwnc
Ge1Fnm8dmdYlm
"hsM:itl0Khl0S`m
GeaUqonhrs
YusrigmA]
NLDLY51.
OgfCog`t0Mdy
RerIdlpydKp~@
yUayzdE
KFeaEnlqjqP
d\Xgbr
pnfa\Vi+dnw.\Bu
rdn!VdrngnnIRtn
PeSersdzpmR_nuiybfe
Btrobmt
mcneof-dyc
NMSQFKL
@ihn.k`l9
ro3kva
Dht k`dd
qn _`aozq
330,66f!)a0$/,4<3b-<0ea
c0e-d27.
fbrztnfaYVi{anw
/54056-
d81x)c8  76~<,
JeKYEenmYg0R
:rpdle
?ea=gmXcfd	kfe
WlC`nje
RWlL<mlE/ngr
RWlMJXml0Bal0JYm0C
>eaJgd`i]Hl_\l
^[ent@e
>eaGYp
SYr|j]tpqk
>eqGac
>e1E]r.fgn
RblWD]\obs<i_a[tZpqA
_EuaapAM
yslrn]lA
)slr9afA
\]l.0&d9^
Kh0^dEUV[uaV=x
b]s^Egk
IerBdo^TCed
OT_CoTYt
I]yPy9
Je2>he;J]yPy9
Je2Pme_wNaYc]EU@
IerR]t
/HD#I(W
=@O$?RB
$)V`E95
Kjo]V[8
OCC:9T@
<OBJlRC>:
oSm-00n%13
KJ.W91
J@Z"+NL	?9F
jqy[Ysui\d
Yi1[gr0gma
b3+-7.Z--?h,f
^%cpi0esi]2
8%8cf1-\h02b6)5
g]0]+/f!h(e
-4~f%4
*1-o6[38[]22*[8!*8a
16 7*c
4a86/82
h[2M3/2
h*-!*)4
c,ap"[1
d.ah7[d`"12
2)au8^7
X+e|"47
Z--ZZf!6^d
3]5,48211*4
d+7s7%9ng^-
-1of]1n6
b(f`eY-,d\1x6-8
 11#c%6
.23)4a
d+9 !47
e0b<)86 !Yc
/-a`+cx`.f
_-c~d[-
0%0/`.1
4304%9!c*-0e.a/185
+9^01bu0%c
c--!a]1
%b3d,e,a-3A5*
b%al00-s
%4d1)-
d0d 6.3
_.1qK%3sb\-
0%d!a+2
L\ezCan
9EbNKE
B9LA?PNA
K<umQacdYq
Fe!rgr6
ag5Y]r
7=F$>gn3L_
HgNpqHllnea
cda{]]r
c_e^n]aaIj_c
]f0J\e
KoIIOrDX]
Ltzmac
Oaczsf
Eacbji
TaecFfd
qle8^lr$[
r]n.bj
-CEbYt^
9S@TFeq30
R<O]qamt[]r
m>i{F]r]PYr
]eiyUOepK]nq
LmeaXYl
4ar1qYlMpan!ajD
JanrZe_pqM,Lmai7aebFj
Dj2;s)0]B<N
qKt_DYm
o*.o1-
DfocNKutU]
kDgnOIqt
Pr@bas0QYn2Ndi{
NioEanMNana
Be_IHaqogl
Zbs1.1
%8/2860/1d<
.8$D/a
0]dcY%4
^-e	d4
da#2]5#
16,2810]%0"
lfdj:k\
8jrpSlVp7ki
kfsaddl)
*1 fZe
.-od11
mYd{hdlM&,x]k
w$m\i/
\s$4leH
)\>R\.0;]
l]t^m&e
2`eynTv,,0\mooe_3`eYn&eUi
Rp6%M]
jesije
_deOi`a3mgrXofi!oji{g
S06%M]
fje{`] 
b] 8Dpc
b]s^!jukedl
LhPod^e_dfc
 %EUbdu.hgnP9le{1aoK!dl9
Ydcfar06Yli%^iodoayQ
Qgwm0joam[oi
XnT przeja
kannIYl
@TCzklr
]rcl[e^
Kh</]d\^[e
.TP,/Ym@I]rn
aY`Hoil[y
la{aYrq
kynH]m
[r`j\li
CJEY?aco4lo
]rnkgnI
Foqf^y
-dop3Y
_lrZ_Keq
]rcf[e^
EB\JKeoEac
Cgn!1gl>bl0
1ni>bk\
A9M>bjvdb]
neo,ao
`[oA6fg
'MTS"8'
+laK[Yl:a]=
YsnhebyD
hjsd_f=
_ko3*&WD`\ob+&Md;goY=hp
po`[e^,gr
5]=r*an
<qhkc_,httbf>W
6apa,gn
<1hhe;i]n.<6 
demgfd0clA^5]m
O4a^6]moaqI
acoako
c\ob5&Cj/eo{
:o{8jo
 '*]rn+gn(
-6gc05ko
CjcE+le>8mr0
3mby.[Kp>LovZf=
d_eh("'}I'>}I4/
Xhe[g]nqFkspbZld
cemZfd
fks@bZlT
>>&a|R
>=* {B
;a5lF/
cxQkXT
]W9PFa
;tK1pSw
PkC3-Q`
v_K>/0#
![;%7DB
o*1c,&
$NP}G%KJ
.&z9w<
K-*80M
PShzA$AI
-a8Mv/
eiB::0^
/+0#swE@M
t$<"u	3
>=Yt1j
< tK<	tG
j@j ^V
0SSSSS
0SSSSS
0SSSSS
0A@@Ju
URPQQh0
t"SS9]
PPPPPPPP
PPPPPPPP
;t$,v-
UQPXY]Y[
t+WWVPV
v	N+D$
O'-`#1
PW+%Gb{&
CorExitProcess
runtime error 
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program: 
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetModuleHandleA
SetErrorMode
GetProcAddress
LoadLibraryA
CloseHandle
CompareFileTime
CompareStringA
CompareStringW
CreateDirectoryA
CreateEventA
CreateEventW
CreateFileA
CreateFileMappingA
CreateFileW
CreateMutexW
CreateProcessA
CreateProcessW
CreateThread
CreateTimerQueueTimer
DeleteCriticalSection
DeleteFileA
DeleteTimerQueueTimer
DeviceIoControl
DuplicateHandle
EnterCriticalSection
EnumCalendarInfoA
EnumSystemLocalesA
ExitProcess
ExitThread
ExpandEnvironmentStringsA
ExpandEnvironmentStringsW
FileTimeToDosDateTime
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileA
FindNextFileA
FindResourceA
FindResourceW
FlushInstructionCache
FormatMessageA
FormatMessageW
FreeLibrary
FreeResource
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetComputerNameA
GetComputerNameExW
GetComputerNameW
GetConsoleMode
GetConsoleScreenBufferInfo
GetCurrentDirectoryA
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDateFormatA
GetDiskFreeSpaceA
GetDriveTypeA
GetEnvironmentVariableA
GetEnvironmentVariableW
GetExitCodeProcess
GetExitCodeThread
GetFileAttributesA
GetFileAttributesExW
GetFileSize
GetFileTime
GetFileType
GetFullPathNameA
GetHandleInformation
GetLastError
GetLocalTime
GetLocaleInfoA
GetLocaleInfoW
GetLogicalDriveStringsA
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetPrivateProfileStringA
GetPrivateProfileStringW
GetProcessHeap
GetStartupInfoA
GetStdHandle
GetStringTypeExA
GetStringTypeW
GetSystemDefaultLangID
GetSystemDirectoryA
GetSystemDirectoryW
GetSystemInfo
GetSystemTime
GetSystemTimeAsFileTime
GetTempPathA
GetTempPathW
GetThreadContext
GetThreadLocale
GetThreadPriority
GetTickCount
GetUserDefaultLangID
GetVersion
GetVersionExA
GetVersionExW
GetVolumeInformationA
GetWindowsDirectoryA
GetWindowsDirectoryW
GlobalAddAtomA
GlobalAlloc
GlobalDeleteAtom
GlobalFindAtomA
GlobalFree
GlobalHandle
GlobalLock
GlobalMemoryStatus
GlobalReAlloc
GlobalUnlock
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
InitializeCriticalSection
InterlockedCompareExchange
InterlockedDecrement
InterlockedExchange
InterlockedExchangeAdd
InterlockedIncrement
IsBadReadPtr
IsDebuggerPresent
LeaveCriticalSection
LoadLibraryExA
LoadLibraryExW
LoadLibraryW
LoadResource
LocalAlloc
LocalFree
LocalReAlloc
LockResource
MapViewOfFile
MoveFileA
MulDiv
MultiByteToWideChar
OpenEventW
OpenProcess
OutputDebugStringA
OutputDebugStringW
QueryPerformanceCounter
QueueUserWorkItem
RaiseException
ReadConsoleW
ReadFile
RegisterWaitForSingleObject
RemoveDirectoryA
ResetEvent
ResumeThread
RtlUnwind
SearchPathW
SetConsoleCursorPosition
SetConsoleMode
SetCurrentDirectoryA
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableW
SetEvent
SetFilePointer
SetLastError
SetThreadLocale
SetThreadPriority
SetUnhandledExceptionFilter
SizeofResource
SuspendThread
TerminateProcess
TerminateThread
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
UnmapViewOfFile
UnregisterWait
VerSetConditionMask
VerifyVersionInfoW
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WaitForSingleObject
WideCharToMultiByte
WriteConsoleW
WriteFile
WritePrivateProfileStringA
WritePrivateProfileStringW
WriteProcessMemory
lstrcatW
lstrcmpW
lstrcmpiW
lstrcpyA
lstrcpyW
lstrcpynA
lstrcpynW
lstrlenA
lstrlenW
KERNEL32.dll
LoadIconA
USER32.dll
CreateCompatibleDC
GetStockObject
BitBlt
CombineRgn
CopyMetaFileW
CreateBitmap
CreateCompatibleBitmap
CreateDCW
CreateDIBSection
CreateDIBitmap
CreateEllipticRgn
CreateFontIndirectW
CreateHatchBrush
CreatePalette
CreatePatternBrush
CreatePen
CreatePolygonRgn
CreateRectRgn
CreateRectRgnIndirect
CreateRoundRectRgn
CreateSolidBrush
DPtoLP
DeleteDC
DeleteObject
Ellipse
EnumFontFamiliesExW
EnumFontFamiliesW
Escape
ExcludeClipRect
ExtFloodFill
ExtSelectClipRgn
ExtTextOutW
FillRgn
FrameRgn
GetBkColor
GetBoundsRect
GetClipBox
GetDeviceCaps
GetLayout
GetMapMode
GetNearestPaletteIndex
GetObjectType
GetObjectW
GetPaletteEntries
GetPixel
GetRgnBox
GetSystemPaletteEntries
GetTextCharsetInfo
GetTextColor
GetTextExtentPoint32W
GetTextFaceW
GetTextMetricsW
GetViewportExtEx
GetViewportOrgEx
GetWindowExtEx
GetWindowOrgEx
IntersectClipRect
LPtoDP
LineTo
MoveToEx
OffsetRgn
OffsetViewportOrgEx
OffsetWindowOrgEx
PatBlt
Polygon
Polyline
PtInRegion
PtVisible
RealizePalette
RectVisible
Rectangle
RestoreDC
SaveDC
ScaleViewportExtEx
ScaleWindowExtEx
SelectClipRgn
SelectObject
SelectPalette
SetBkColor
SetBkMode
SetDIBColorTable
SetLayout
SetMapMode
SetPaletteEntries
SetPixel
SetPixelV
SetPolyFillMode
SetROP2
SetRectRgn
SetTextAlign
SetTextColor
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetWindowOrgEx
StretchBlt
TextOutW
GDI32.dll
RegQueryValueExW
RegOpenKeyW
GetUserNameA
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
TlsAlloc
TlsFree
InitializeCriticalSectionAndSpinCount
GetOEMCP
IsValidCodePage
LCMapStringA
LCMapStringW
GetStringTypeA
111QueryValueExW
VirtualAllocEx
kernel32
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
wwwwwwwp
wwwwwwwwwx
wwwwwwwwwwww
wwwwwwwwwwwww
wwwwwwwwwwwwwww
wwxwwwwwwwwwwwwww
wwwwwwwwwwwwxwxp
wwwwwwwwwwwwwwwp
wwwwwwwwx
wwwwwwww
wwwwwwww
wwwwwwwww
wwwwww
wwwwwww
wwwwwwww
wwwwwwww
ffffffffffffffffffff
wwwwwwwwwwwwwwwwwwwv
wwwwwwwwwwwwwwwwwwwv
wwwwwwwwwwwwwwwwwwwv
ffffffffffffffffffff
wwwwwwwwwwwwwwwwwwwwwp
wwwwww
wwwwwwww
wwwwwwwwww
wwwwwww
wwwwwwww
ffffffffffffff`
gwwwwwwwwwwwww`
gwwwwwwwwwwwww`
gwwwwwwwwwwwww`
ffffffffffffff`
wwwwwww
wwwwwww
wwwwwww
ffffffffgwwwwwwvgwwwwwwvffffffff
iC4444!
wH44844440!!
wDCCCCC>884444##
n[CCFHHFCCCCC>844444
wHDHH`b`HHHHHFCCCC>88444
nHHbbnnnlbbbb`HHHHFCCCCC8888
xxxxnnnnlbbbb[HHHDCCC>888
xxxwnnnibbb4
HDCCCC88
xxxnnni[kk
FFDCCCC
wxxxxxxx!
xxxnn[
FHDCCCD8nnxxxxxxD
nnwwnnn[
nnnnn[
b848CCC
nw$$Dbb[HHHC
wwwbbb[[[H
448C8b
xxxwwwnnib!
!444=8vV
!048C[
wibbH[H!
vibnlbb[[[bC!
Db`[[HH[H!
ibb[aiw
)))))))))))))))))))))))))))))))))))))))))
)***+,,,,-.///<<KKLLLMNNNNQQQQQQQQQQQQQQ)
)***+,,,,-.///<<KKLLLNNNNNQQQQQQQQQQQQQQ)
)***+,,,,-.///<<KKLLLMNNNNPQQQQQQQQQQQQQ)
)))))))))))))))))))))))))))))))))))))))))
TTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTTT
\7****
Z55555-***
b>>>>>><555--*
bZZ___^ZZZ>>><55/-*
hxnnnnhhb__ZZZ<<<55/-
|nnhh__Z
*>>5-*
||xnhhT
ZZddZ7nbbhT
|hZ7n|i^T
Z_hn|||{{{xih_Z-
|bi_bb
xihZTT-
TZTT7-7x
ZTZZZbv
 !!!%&&11@AAAEEEIJJJJJJ
!!!%&&11@AAAEEEIJJJJJJ
!!!%&&11@AAAEEEEJJJJJJ
&&&&&&
------A
B$4)##*)(%##
##B$4@?>=<:9863.)#B$$10,*)(%#####;B$$B2
22BB$$BB7"
"7BBBB$$B222B222B222BB$$DDDDDDDDDDDDDD$
AWH'Z*
"z-- e"
1@S>+t
td+Y]>F
	tcX)i
Ww^1<',
(P`#cm&
133C__
284Dgg
T*tuu111
2nEww7
,,,0??
nz{{3C
0,!Je"
Lod2;3
G,--9Z
G&+}2;3
X\\dvv
`KKK,--
>}MkW)
A@OW'c
a>};ld
z=B)XXX
%:+%*a
;NX*144B
KT*eJa
SS[9t|
kwl_k?i
d&_E~-
1::*,-.s
J (	DPBf
Y\\d~v
IIO].I
bvvNk|
tvt0?7
-[PIBwO/
a~312s
!H2}]0<:
0q`m\!
9uRo.*
sip5'$
D)E),e,
1:>F__
8&jD$q
O7[]~$_e
r&yFX(
c~=@f$
P;U(`F]
y[V#O)"
===X54
kuT+edr
)LLL`rb
=}=8}j
D8iP-D
71S/bzf
3tm"i?Y
iLOMKM
hooG__
zz{  p
?7~M+%
D+tAOIK
}~5+%9V
SQYV!0p'
tJ3c6~]
DSV80O
mcRHg#
Yd3YDq
zBA+llw
qRk54i
pidtwf
>vT|W-
" $gp;
]VM	ibX?ng\mjcZ7
ph^	og]
jcYPunc
{ti[ng^
ph^-vncw{sh
wocC|sh
yrhxMG@
g_U0og]jqi_I
wod0ypeZumb{wpd
~sr{tj
xm	tla&|sg_
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1"  xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0">
    <assemblyIdentity
            processorArchitecture="x86"
            name="ODBCAD32"
            version="6.0.0.0"
            type="win32"/>
    <description>Microsoft ODBC Administrator</description>
    <!--Identify the application security requirements-->
    <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
        <security>
            <requestedPrivileges>
                <requestedExecutionLevel
                        level="highestAvailable"
                        uiAccess="false"/>
            </requestedPrivileges>
        </security>
    </trustInfo>
    <asmv3:application>
       <asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
            <autoElevate>true</autoElevate>
       </asmv3:windowsSettings>
    </asmv3:application>
    <dependency>
        <dependentAssembly>
          <assemblyIdentity
              type="win32"
              name="Microsoft.Windows.Common-Controls"
              version="6.0.0.0"
              processorArchitecture="*"
              publicKeyToken="6595b64144ccf1df"
              language="*"
          />
        </dependentAssembly>
    </dependency>
</assembly>
SRSBNKIMKBDTICYWHY0
190910133454Z
391231235959Z0
SRSBNKIMKBDTICYWHY0
:2v%sq
SRSBNKIMKBDTICYWHY
AddTrust AB1&0$
AddTrust External TTP Network1"0 
AddTrust External CA Root0
050607080910Z
200530104838Z0
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
http://ocsp.usertrust.com0
9f*<Z,m
Salt Lake City1
The USERTRUST Network1!0
http://www.usertrust.com1
UTN-USERFirst-Object0
110427000000Z
200530104838Z0z1
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA0
1http://crl.usertrust.com/UTN-USERFirst-Object.crl0t
1http://crt.usertrust.com/UTNAddTrustObject_CA.crt0%
http://ocsp.usertrust.com0
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA0
190502000000Z
200530104838Z0
Greater Manchester1
Salford1
Sectigo Limited1+0)
"Sectigo SHA-1 Time Stamping Signer0
https://sectigo.com/CPS0B
1http://crl.sectigo.com/COMODOTimeStampingCA_2.crl0r
1http://crt.sectigo.com/COMODOTimeStampingCA_2.crt0#
http://ocsp.sectigo.com0
SRSBNKIMKBDTICYWHY
Greater Manchester1
Salford1
COMODO CA Limited1 0
COMODO Time Stamping CA
0WrI0	
190911013333Z0#
[Y'r)k