From fb587fe8099c38584bc1ab2f1de7deaa995df1be Mon Sep 17 00:00:00 2001 From: Victor Julien Date: Tue, 14 Jun 2022 11:52:17 +0200 Subject: [PATCH] tests: add dcerpc/smb test --- tests/dcerpc-smb-test-01/README.md | 2 ++ tests/dcerpc-smb-test-01/input.pcap | Bin 0 -> 72904 bytes tests/dcerpc-smb-test-01/test.rules | 3 +++ tests/dcerpc-smb-test-01/test.yaml | 16 ++++++++++++++++ 4 files changed, 21 insertions(+) create mode 100644 tests/dcerpc-smb-test-01/README.md create mode 100644 tests/dcerpc-smb-test-01/input.pcap create mode 100644 tests/dcerpc-smb-test-01/test.rules create mode 100644 tests/dcerpc-smb-test-01/test.yaml diff --git a/tests/dcerpc-smb-test-01/README.md b/tests/dcerpc-smb-test-01/README.md new file mode 100644 index 000000000..1effb79cd --- /dev/null +++ b/tests/dcerpc-smb-test-01/README.md @@ -0,0 +1,2 @@ +Pcap from: +20171220_smb_psexec_add_user.pcap diff --git a/tests/dcerpc-smb-test-01/input.pcap b/tests/dcerpc-smb-test-01/input.pcap new file mode 100644 index 0000000000000000000000000000000000000000..a1ec294a290edf61c709c2061ea29684bdb2c44d GIT binary patch literal 72904 zc-pMI1zc6z+P=N$?oR3M5TqNVy9Jc)4(Sq*?w0N@>244Z0YQ)s=>}=|FW7sZS2^lA z-}k%cffCK(H?(P5p5a2a5|Eq=@FE~I5cz=IF11K?# zG=P74y$^u~hynm?SoHz`Z%CQw_5#=^z!SFp4M0G0s&016IK0|EvH z3IYNSdLJ>J@27|lvHpsCA5oh2J|fOv(ST7wTH4>ZdtM>}qZ)am5&<&W{uL4WpNQ{) z5uXC1J^fXVR9FoUIlg<8qY*GFl032ib%*I+N;iQ~vVak?eibDatMMTU(=Vf73s75^ zK3HdRt0W^N@ZjG4@dWVrxVr`X@gM_${_Afm@~4o%l&+%`;{KJ%KV?8cksowl2!I1v zfQ9eR$4-KfNz>hDjLq=KNhDy_WAfM_0EoVaVCO$)4DzqL|2AVm02lxn6aXk`D4HiE z#Sjd(9C%ST8L0*J@G0`Y&aWJ{M+Ac7ApNUGhZw-CH^Akggq{;5BrPNe1O#Y?1(R6@ z4-*$8Ebuirh%W~yC?O;aO@M^&87c@U=)-NmU$?OTx&`~8G;B5v6IBKU9+{Q3gRX(0 zk*SrTfv%~QuA-PQ8#4!|fQ^OWOM63IQ)4S@JHvYiZG^x9X>fpt^D%R{NUWxN2ZdN4 zF&}gHyn>TQ=HH4vyw4wA@J9zheqavrUpj~bMEXxzb-*UvKkw`L!ma(w8(+9-CSSPE z8B9zJzw_h=*M9IM%NH&k+!rnd7%kz4;vfJkU$_8ZNZ$-#+l0sj{(+bU1qJ~i0{-S~ zU+}hD4j*dL~{QLXeJ&L4j#C^sgXS%ih({e zgTA$ugSEXigN3#JOABBeXJ8Eb`;w^lzXB}F7u*os7yRX^h};Yt;HkNr#m1Iwt%xI2 zk9iFZ-a*I3H*Dekm)d4?lsKN>xWi~jBMesUkiHA(+6MA^@Q58s*nUyddR3rUJNp(^ z^Dqh(JFBaAU3Y>U$><11=7q^ueDUCFb}f)J^%b-C>%Ep$gX7niVv!K5dkfa_{H=}< z>5_%t&ulp2!-=^fMfgpGY52Jr&WP=Wu`iE2ePEiZ6q68cMNJ~JpPt_e8uc}Y(@JE; zc51!tU~`?bLIlsARA995(4s%xxES41%>7i9@g*WMmgzLWfgCI^w$}^nNkSFU?H<=T z>Gc5^*p$1a5#1##6-gp4rj!GLDsqg#kegYXPE?xjSb_-DDuW|fXl^c3-|l>f%hnn# zCrbTm&5ZWmn3U*n%shT_ZI1V3W~vp+FZ7<9^MH}QJwTYjGMM&4qEx_wUz++z=h`1o z9bQCLX`NWI?~m3CnZh=YRXB;MX9COL-!r_4?jIQqSLv==`TdH;%&2_c3?U`HIu-F^M zDdMB=gb=dC8L1JU+6~v2bW!)oO&U9AvZ9STgm=^c6}!%HkN?Jy>( z=q}7>RaO1-k8DF0SD0z6>TU^6V>3x$ub{j%f<-V*ClCZU?gVGqYji2>_{#dAnx#o* z{a;K*tik!4H*g-#9Ez<`dLak;zxxvM47`0h4n!i@zW`z@o`7UdNS?5CNRaql>q+8r zby`Ox+*2ig>W_(%($*sS-RRG%7z5Tv-OH*i2#6(~hIKLBF4-T^fZE}iX`;4f3NKom7LD(hHtfAez+nGX$AsuTmgMz5J3UJ;2-N_DMJVV(@h|TrD8IM#vj7Ix|f4 z%E%xnN{dDG@Q~@S6Kdag>*JcrjrXD51mKPu8Yc6!#%EhDgVV})bhbn4Rz-J?BKR%D z3p?bXO=e)R4Y{|f&GGj?#qM$COW%18(=28c2k!y`ofZb(1>vYHTY^P$IOfv9B?pMR z{zhS6jN>TTpnh@jR(h~<@)AlZ#}~4I$rm!`q3g-=g-ikWg-kG!$$(zRFSF+M!@h&A zp?r>X9T(Z?{WiXISxw;*(^rr{;N*M(rGUE!r8L8PKbUj+mgI z{GqLUY0DBd#))JxjB>w3HW#Pjj(rNWQ3G8RcK+tbNIzKnsDH9I{4Ksfb@S5aU0u6~ zg!oG@xa}$P(s%`{6?viMyZCXs`k4ho{WP>RmtFd{BDu{T$=*ZJ6FiXVhUj?PHOzwqlx zO`2$S6`O*}NS?~Y9uxMW#5}d#LdqLqbs^gH;L{If*5uCC_H;JA+Sw^D!>WaR*4gQM6~VS+ z{+a7%g^jO|3OHh(kU`JTIV@d4e{Dr66@Z{L6Ucp|7th^d9hBPzQP+|iJKXREMsX>j z`?(hb+S0s)BN;zWNeSN^O?@LA1_f8!*)FK37Ko7e`n7nXvFj6XPP-UN9xpzQAlvso zT_8*&3<~)&UuvOisDp*`B0-&BVlswD)VkfB%czZ8)}dQGW269%S{N!Pn@fXy*@V9^ z9ek`wPc0fT+G|RqX!u~)XxvY-yS%iqR_UmG=7s+cuf%OSd9xeQKGgC zi%CyHT&n#A?uM_d)XSZ1-@Z^ON8@;>5d+xi${Eta{FY)GNW4BU1Xa3&&HAX=vHHNK zyhsr8m!hxNzrgsXR|?~!Y>O0bWr}O}cHoz;;KVuwo-%#dqDL(!v&(S6b4#IAZlKh@ z5Y);*9`XvD>2jK-72+zOgrS|eL zMQOq_%?ehzcl3yw`9UH543N6dKgN5DRlW$>NCMSTPJT-k-BY=|s#7pg?kwvi(2nNE z6dOKp%Wm<^26-ly*xIsh0`N?-f)_ZB;N2k}1TQCx$O<7HP{DxJX**b~(fUThGrQ?l zZ7+o8pa_agIr45ym(av=zOc`ivaw(YbM2iEH0yJt zn48RQ(AtG8Q+RROk%F0BWMvv?nVK)+t13Zj>=Sc*dD$goneIk*j$_o=huxZY^8%IB z6NLIr3all+W|r(5F3l0Thj<>m!?<1m@BBXOEUJD^#M?Gb^~w;w(l>QFU)-r}t;?Fb zV%u@KOycu#f=Co`g-Ez*G8Q1#g5l{h4z&779N;KSYKQ>dq2Icg*f{9V&?5zu8|v+$oSEdn`7d@qvQxTTnauvU)4vM>RxqxV z5ODTvHPrupv@R$N4&VWfPI-PcbEJ}{f0#K^|2*Hhf@_XsBQ>V&o+PMC?#qM_B9S38xU3lS? z^)T~C64*6lR2~&OA#$h0JxTz={c3tiC(ZCMy(Ig0yP2@$u>p4-B7aSR9#4*7els}&A_ND{egRc@@@0Bhg+{Qg zCg$?l80YupB>?q+OrQ5mK2;fDupod;xF2RfSw8Q;eUkNjew^EY0<3)knSA{JHM2p= za$$1%Yb0O|Zn>vO@*NhJyTnfr8Nf`8S#+@%>Gc#r?g`x*(Dsq;PWP3MPSF8?@7m|tWG@%lL#24gz>-Y=lm&SLa-Uf}Ftb+R>(*cSSAo_3;2+{6|D1u@=>z?XwOe`!=Ko`6 z5I^___M6NcD6`Gum1U>R(%~-)#%imd{h;Ef3zCovVNyZAa zLK@@py#me9_@NE{@j(9hr8n@rSHl3j!u%Zr=7-Pk6-r3{aVf3iffw~7UUxv1K!yC4 z7bpL|l!p8RFYwM0g#{02^R^{=KJ<4+sDp*u5x+zuQnfay|0@^a>yVpC;F*B8i9Wr7VdD zoB(97`}e_L1O;#751^!PKm%xzCGb#I<^Ml&{L54saKJa<{kLD4`bC=c!BqQ4rq%(|@4q*d)aoHn$>Y>v{zK}|nfCHf zj27z3*UjTpI&mUVfT?T$RK?&Qs+jf;J^Y0igfdA=tK>nwyKDfjAw>v}+?;<_C0{@|#`fFhD z*TE0`{9bvcEI42W_1@*!BpW92aaLHV5{p4cJ$ zEX(|7!zCH|X>R7On z1S$;&1`hvK=jx5s^T7Do&x~2!-97JsvjV;?J?V$8NBMV*p?{;4Q2}eK`JGWN;tPwK zWv*oZKQW&DFBs4MJq+l6c$fZ{ivMx{{wfbp0_LI)Je2^dz~SIO1GfKE<_-ku;YsyR zo5B6zN)9ad8aVWE02l%+0g3=?;Ex0FUG0C1!~iVe0xC%UK2=a41yaP^1*d~DW@T%PRAyCfm>f!I`aITZZO6t)b;YU}d3^Rt9{WtZH?HBcs z?Qf^>A1P~5$Rs*oP#4XKF@#0Ba%}xaZQ;*qf9`Kav3eis;>OQ)k!=E~xEfd&+gacJ zS}pVsOn;@eEdBeKeaV=~5_r|e!{y$=Kh;IL|DrC^{oSvi|3UG?US`@K`A$|4knQ{-}@nT`lHL2Y=Y^1N}uG z131Czd*IsjGgo$ZcQ1h2{XVlzI|-*JWgjnY<~{zSP{{!?}(#?ij$m&SkMD*s<_ zmH&JA!}-G;;s0wNbKig5JEENNNA~3p?7@Cw4|JnB@~OoA#M6@F&+LEa$d{)e_{2=p zaf$}1Jva1UU;S^`Lp)+n%qD+#rGze1W+oh<_Z@2DAND;NKaHGzX8#4N|5sy(rxHN5 zS3vfFuAzS)IsM2U?l(#)qbpIVo~M1mI+ysI>dS2OC-!Xr1$(x?M`?fcWN5!t{Eupa zesDl9@V@s~eCwqv9{6HD;(G;Detyqa@UM|`=KE?Jn+DB?Gej!cQ23-;COHrE$YwxGyHE<5f&AFamhJ^RE))Q z6_RZs{=ev-q5joBL;jNGz1ofs;DGy;hvi=}oRF@(SBrJ=GeeM&=17i=`w8;VUyBw6 zzhn42wG3wP^EI6l&*DUn^WB^TO#T~&oWEem`L{}M_#YOy9(pDH zKl1(Xz<1?mzMR0m7<2{5H^5Qg&wLSoqu7Jh*ys6|EJ%FrU;`NvSC#(@zA%r*SHI$` zX8`%9XKeKY-@8YASAdES?)f5c|M?mFJGCi^E;zo2-`-(FP^P`cNyz=*JY!-0%kfpQ z!5_H}J#bxq#Pz`43oH=G^+m?&pSdFaMrm~>ZO7BSfq~-LkK66yoGJeoTwxz^eLTLp zSG#5SN3JywTyKBo3KrNL`7H5%Zm!w!XRg0f>)5-J3)k8gkb@ZIXC6=z{lDP~`(JVu zFoFa`1Mj1M#nm5c_+i0}{%5Yw65YMPX@OkXLjT$vQU6gXtYXtdWQIbN$HY6QGh}pwH-Ge=RTv z{cf`bb2Ce?xhRfs3 zAI2N@kbl~6se53;{WB8?abVUv_e^~0|GeSyyNquO6i0l<-;xsCd9+`-9_ zJWn2b>GDI*;POLH@lQ?b|7TSlq=MidMLzD3fJWebXcch(T4 zVF}X2G!ROL@{74`Eif}H62Qax*jExgtg-vdXr&+d3LHa0`pF{;pc{Rqm9!7Nd z;VLgQ!PHiq7FJbYIO-^p{e702-X0VYbys&-{&WcO?9zrLC78C*9jK<5f*arK;C#B) zZWAdj_yGB8=^V4+^g%wMx&DD3)%4EEHHw27S$qC7!MgJLl2PTxIau4PJFo}WK^Z`kdSw}Y!WaE@)EHMcI{O=ip%@FKDs zGl@FJUfw;Z*U|o(osGQhML?D*x}HvI?F4rFes}kB(B$c$9J>S*-dKz1b))%GgY8$u z-sh?EJASM?avAEw^C=DGc+3h%A7JQ{V^2{^sK1lZ4k@lfVGy&lBXHUzz3hLAqLt9g z;oOZi3ZPnIL8xNEUivh)5SMFIUk9dMV;=j~8O0({@ldO&AlMz>@k#Z>3Pj#c#>Q@|XM zX`}G{{GAh|D)Rbg~aS%Vo)bXgA!P1 zJ@eKm^$z)JX5AV19D?@M`AkWwdHP&Jwz96L)3SwtxZmLd)EKIN3HP9*h=8`#8O}#m z`OBA{&zFLRKP)u$8wY7?nuHD92;Z?>28iCqv5HZ&h)_#I!nO2`Zoz~M3idb^G90ZY2X!5E*868TzxhhNr zkM_b0u~2hP6cOsxvrgTw31TM;$(Lm2p&fctjtnvSc^v=rJFAysK}giOS`zdvRjjd| z8**7qNAd(11u93KbbT`dy`v)cHtoKgkZO3e`&>I2@%?+45JBw zsWfVpE^B)C>~uTzR`)rW{|ADvQAx|0(kwBqErz@5@noGF=behk$~Q(}g=T4at%OZI zEnb;`=mYBtQ#s2%RT2WtL8J!#QcGOZS;-1o%v(&7dcJ0|{QwUV3Ud%@AMxs*go-Jc zrHiO3R_w@pOfdWPUDBN|YLi3ArCG9hRFoOqq7=B>pb{*SdO9oS5_9!$ZmKQL&mql< zFXC<}%_hY`UBGnsMHO78O5+g;ijXAHFny%F*EP{dKHS2*1ZOyHuoptdSrE*Rn~!qK z%FSKCJgQp37C{DU)exQSPJcsn^O;f%Uj9XdvzyO1FwmDAa^Bz}nWIbxzLxN_dI9X< zIlS#pygj~L`C08GUDgyU5p(9?)9hDo&-o~8vym z+*woD{hB7A`hBeb-raV%HVhx$ccNC;!{7m5@8t6^KCkf@c&f`PhZ4`&HrE z-MV1Hw07kD}9=MpVkNDfH}T=>v3YfLt-?B0ETuLd^UqB`92U#KxJNK4va zxeL7ZFTTytHY*vYiN*Y;KG2vf{h5G4?GjQPm9<5i!t9#_m!CgP&}O84G9yaDC>Ytw zLaGmm7k+IABZ=6Qm_|ne%_YS2$i5&1^%qlmC$x$eWup=_@Zv?^2%o@l?qB-`y(C(# z$6pCTSi!F3?X2@GJJdTaCt&uju1<}_Qm7jo|LAT+B^Eci5@+>kjipkbnPohWyK8~U zOF8VjwIabGYq?Zau+&x0V#iv0iv-F|?<4ds7=zKBnn;etYXH zyn57_uhGFEAeD)U{Uu8TGtMooMd>;Dq$#8M#GMJA>7^OgQS#F(9o0 zz0;@(FPth=pPeYtW1{&ivbs-+H|x?*Gi}rLPFdLd1ZQWg_URsy?81?@yJ<@i*SO4h zgkC$A6Q3;S)te$0rj1`1ncIGoZ{%-0PFuODP_-K@(0g)V!HE{eMs)b}JZT8uKJx>o zS+T*|Cn|dp*$7Hp_HIt&gprlHPLy?Td!*)lJXiI((ja$PBu6A&a->pLa5?*y5K$@D zuDi)6=IyP*W6n-=tcp^kU3_I)rkY9z+>(lW+W@Rd*eBXV%=KhS$pr>u3}j|dpDgSd zX~Ld{&fH>T%8?JfJ;{6;4m+BOW-4D4ykM0>N)ud>ahyFN?*(6@QK#eB_Cf%(f;j8_ zJItcufwR5?bQOFRS0}!4YwJb+)+*B1EEi1W%_aGgJ@X6r2g&bl&xQ?cpAP%sntNcy z$3b5i1c$*1DY@P86Lii^GCrG3r|@~oNiwn}7GS~WhQVR3!xQPYP8=PnM#s^7C>mvm z^#QBjIZsZw9}0$sP>i_DhhEq2#*tGSYeU(lk>LHuWS4yBPH1uXMV~S>A&i&_ldoFb z9E~nq+;b=Eqq&4>EtVFSB&A3oXb|(0>8nMzU4HWj@0LDh6@S^m5A`vHI$MWhHW0@t z%;p}WGAj4f{pJG!^6VtO;}e4^JNYHy@>R6O`AhBjy@fCTcfyt8N=! z)4!S$jqtj7cli2sNO$_Rzkh%g)z@S0L^$KsJWnc4BZ?jB+%dE*s^E1k{>?P!T+bPP z6zqB$Yz@+LigvPmA-T-K8RVYgcgKG2mV9G@JZ2@*7d&{>uPOIuQD(2-lARebPt6Ox z6_%Qk-^O653VDB)sU3oe`4llVp|M!e0DS$U*P7afj3S)eOdMPCX2NP%VrVn-M6bK@ z4%Sq}46MS4jE5~P_i~ZGrp_lrti}PUCcIBs`BkfpQ|52ZCTi`O8fpe$j5(z+<#3GJ zK8D#XSLbqyd9lZ+etI>&jl;uJ+}b)77KvJ5QJ3RiCYG*^rO|Zi_d(%(=ttT8^yZRJ zdK3^5<0X#5_KCRaOleQ9Q=LZV@yx?t!$P6d#pcoK%fBC`7c4;ZJLhA)i_;?t=D^~Y zKU60-0r78apqsK*tBC@^!DybdeLMLC+v4gqb6X0qifM@w9w}N3Ir~;mjSai3v0BSw zPdBPQEf2;yR|_!W6z03GkMe&~f>&o-kxV~^)5JThvGL)f?^u!R!759+tzT3Q(|*? zyfAy+tnK&B0OG;+iY?|P)B#wMM8e@IsMFs00n4wqje82x<7c#{BjH~4PdgP2A#~y+ z;6BAELZ5|_dQs3O*qpidg6nmA3#S(Zw&j5aG$b=_WO?jN#!v=~N11Lx!UXhnY@?a5 zMEeqXfFC73vCy+H8HREfh5SyD)T_dL5Ce$Ls+p3FuaT zr`-41pK?;|RT%>Pog!LM@ebiBMM%o94!UtU&M6U*NYs~_qZ24nsa1C!>eN0A#*=yl zbD1w{+J6{+HwfEb5tg$#-CaHxY`~YI7&svuN5HITv=@X!EHF{GqKKH||4L#>(c>Mc z33g^-19F9T#8n*1$=$PSZFjkscqRJNTY!lVMzZp@TqM9LGP<7$)(EH>jJ7vj0`K@|} z;FU9m50*b=d1w*wQcbL90Dn>1r}qe5SVN)I70fNFn4&CI1+%xTvORE*YvS=nMwa=B!Xv_l$dFQJ+ z&rvUhR-iV_v{;7_wp!`o(+K2!53j+kuR%U+SKD`^@ZH34FZ0}B#sY13-OKv(cT+Pu z3Tm11o`jH(`4LB+&eyn~9qd^?7|Dt~ufVZ;riJEi%W?8yH=yVHd9>L;-^K78nnRkd zir!PUw-`2OE-vuY<114vSf1@$h{QvrMbW}@aR@eFvs~jgN6NGqaW#-_bPm?=Ro;I! zOKuFIMDX~QcS z#GM%umY%IN^&=6JD3#j?>b{xya15GYVg9Lh%zYXzgPqIArLS1!Q2)}NzTgaB^`c`( z&=RzkrYydm%R&6afkN?nPM$p*=M(UAiw5x7$z!h;DLFgHNN8)K=&?^1aV?D(dQ9lU zSk)B#-WhNUO1Nz3#_aRKpnzv33W9nLyvMlqTC^rBv6)ZyT>#3AzKWdg2s7%;u{rK7F18 zY5tzKSjroaE)nZM91)SyiArNojufKjX{GX2R!zG|9!eoc^%~I?e@_W7>lVo#GQpvW zyF!ZT)ufd}n{RQL6gaX|8<+(X!l$~gm3-j@(dsOkW1F;CW@3t;zgL?`F>#B)=p&%d zH*zj;5KHk1Vn)xm0vNg%+eJhxJ4E*ko^CeJ^L~&b&x^CmNR`YVdVw|KBvv%?MQPWz zm1xzhrsF8fdw~tn!!=QGuHt33t1Qn4HWg=@(rGlA#=r~`zN|vZ>q*odR4U|M57dgZ z!M*h)>=5nDiB!hJ_`9qPgB`wtN+a?>%{cy@D*MgQL8f*p6wKpA7jml`erkX?HDnBJB ztj}0alx@b`-f<(?m~pm(x?8=v^`(k*K#dya_mh1}CFlgzz}S~kRLe4ZdXZ$^EiD(h z*!d-HY=mWkz1*fKW^ZUxV;IaveYH@BKgx1Rf@iHv#0Ubi@gUu40xKGKOauNp!1#Fl z;EO*#Q*MpkN~EY>_M}+N*bHvl`C0714$hi{)!mu4Cr&L#*S^Vo+SjjS zfDd*GVbPQg&ntY1PtFEz6=1MckrIyd&BW9^oB>GA)t>T82 z_+{$1o}I{`!?{&Wk!%bLq)p~BLvR|t9Ne2};i#!Yw_{M{R`I*(T1Z4R4AV3G-6y50 z)=dO$pmP&zsi93MHwFzwb3tvFr+fsKW>|)t%!l&b6c?I=Fm5-R@*&!68j8V(K4yht zGI?PQWq0z3q=WLAwyHPEOHU=~4h23~gY55_eUH?VaAb*HxRrxG89d8rBpdc2=4>bA zkfo5BS5v=()4Wiq88I{7BIrAcGahEufpUAYm3MFdIA?JxMQI0E8f_I8kuxj^@n8HI;l#9Q@t_BgC;`3 zWYE8WU18XeNB*XTS_{Sdnm^iqFU(J;SC=zh6s^ykc7emD$EO=zEnyI`ta*K144=xM zw6Ad!ZQc~uCO^@qQn~b!IP85WXJ}?fw*ZkMQxGw;p9(Vz=9raAmG6t`*XNcBAZyP! z3ug`D?VL88C=HEqHUp5st#K{{{Om8e?76Jn&4)6JW$ z!_I5l2r5VP-^$PLMl`*7@=n{cA>1QuBnS7+Ig|!g1D23BV!Au%&{ zLK?IV3azw1U{4xCR~dWFmd?#uHWe8oH^0qd(oP+^bp?*<%99vvJ06yCE_gD8nc~Np zg~srrHAVNt+#{>UK4fB@%gkIo1fTD0Ha39?`m*W6M^!h-@1!13Q8GJ>8VTj%jZS&| z3a3Wp72TKk9o7w_t}J+q;9DJ8fhflT(KZ0nT~a7HCF1hJ0YY(O<Ck`;E? zwrByQ(Z2KyAXUS?IZl9n%V}qj5NYBuco^xhb#t03hR7T5Va?(>g1K&gx+tQo#4Rz3 z>6P9*;@-wrBX_LZnr2%xU|R!t&Y8pGomnMiSvfGLuAR5K9z@i{(H*524&oLmlr?Bt z#g7s*nfwHAiV(@RllG}^u22;@mcVsAOYW~i-3`Qh}F^v$TYa8mXL za_Tgyd`ZzJSggq=+59kfhNr{a7IDUFXZrQ2SKFcd6QUlGx2`KOde_~Y2QcD!TFoyg zBuktwh~^e?x2mIZ-01Sjjy6|7)NJOh(y0>!3jkL**ps1wNX-g!t^yRB5_Egts`|Fa zsmSm#dkFAx(ntnwhe2DR-vUnASB7-6Cn@ya6pR?V4_8`U=fb_Gw&T^1Ec5|Di$O@~ zXBzUmdA~71d+Q`&K4A3)gnDMQs%cDZOLew1yr6p}GZ4MABuNZ4$O58hCKapBEY-RV zW|Mu@u`%CkjV^yEjmL1KT`1gi!oTCV;RD#Q{}JhM*S>P#9F)qF?M+dP4^o7qFtDr~ zxmev?friM|9-;^c^6o78{j?bH^+;Z#U;D_U5S7t}&h`V^fCKl<{cx2itz+wR=*@PD zS7r$k%9Wpbn5}|JnMa$s|BEoA(tw84m|BhzACLY9^riQ+ZPsF1o8=qd7ig1f8n%&bR~0P3_U#kK&6r?6G) zb4+6)GhxbRA!5u0OlUfs9AmPxRs;5R9>P%-#>WHY`aMHzws9#X*B5Jw(yHD=mYLpZ z6I-{Ag*b8vsu-P18}L0`E}y4^vS8oVYI{6O?Rf*1GKVR+T<%lEdMUW&%Hc_#T$JFA zs!;IRK8bTn@O#8_=3=elO3ZIN!AiZcm>-E1FSLeZD$qn2^tnQ))x42d*CAD7)$w%_ zMfRF>*2MyqU;|0r3*~jqkoI1U(6=Xmu2x)U-CV)yA6LC_o#Lg`aem9+ZEcYINiS#}M#$s1XaPA($d?ly6{1>Nq zG75Ib(&!JP1wwD#7ZvK`vKq^kEhT5A-D_ei<@J-rNQL+cW*JBF024b4cUCnjTu?#4+%6j$Rm-?91+ zzLY=`<&~JL!HC)?2PcC2`pS(y!C%E!scP_(@8%1S=CYc8>|NU%GkSUDkE2=YAs$8~ z+M01nc7a>w`gzpn5V*{;CgdLR;QK=SHnjT8m=}mW2xUA$ncJ^bzrN$w?j&0#=6@G# zl$m3(IAd?52e}|@GMDmh*nWJP^vj2N*6TIR9jzDrWl||e|W-f9X zs-?Rrx^ZZBSwjZ5sC_<>NUVb9Uzoj}5xWcDk4BZ|C+!|3&uI7r@{~Rr&4~@Hwcj~n z0dRVG^(2r6FNaQ_ir)7se$Dq=Pj?*bQDlzE5HU>UqP^EML_>7Hwb{uL5DexVL{35; z_}fIXv}Ye>(yZ>lc<|o5pBOh2ctCEihEQKXv=h~Mc3U#?N3a>VP}A{901 z$v$dDUel|#y_G5!qNDH2&r{Upd9Cynk$j?X3 z$@5?aXzlf#a-`1obF5yjg5K)P+Ihg7cJ~Lqu3#V89i7=ls=U+2^T(DY9cZ}oC6^MB zzgkgKf_m?FY5gLCr=FGnOVmkau$7as4P%#CNFa|1?-TIAn9M2!#N!J+g1+ZfFj}jE zG&;{kK-#KH>#=MmLxeAvykiscmZLs(A1!rb}J7O6=FH=b?4k@KB9p#@q53P&OvX!{mOy+_ff z9p;VKtVgdTgrZ3WID_9DjGLAaq!e03bbPRMIxR^aLL^q^dcFzI-yIK)uPy|Kz^?Mb z&5I2t{RMP!_`qIvaQd$EzU}!9xR&A?o#NZoQ8QW`J|?K`>X9*OP)(JgtL;I-^lD$R zwv5r>q2@*(+Lu`c=c2TN*|E)w%Jeh4}VtOA7fD%d*6h|g!GEjrQK*&y{TAu0aug}EsQr?c3oK0 zJ0>=VEIWO-`h^U}*QG80{Ee4A_$!P{L$I|2#Pf`HT>2gyT3e?+PZoxRkOvD*4v6U~ z72K+&s&Azgf^-l!biC_hO7OOCv@eA<}+aAf?ISMh5z-mvT_{6DSEw&XJ=0%VQZA5 z%xCUC8+pUccE9;oe3!R;vXGZXD?6=f={JeFVNRCQXub}rLN_ zI4d7v`eTo5Fs1yy#VwNUejLcff8PsX^Ccu%_euhczlDV{InqFs=j&RfM;|!s+mz-s zEyt!Sk&KC%i?}eFegvPpt3^+CcS#LT)H0qu7T@~HR`#nhSJS-EMaCza>6QfjaD6XH z(xbxkqo$Et^wlup{KYW>2P-n|R4HKyMm&$?Eu?7P6!mQy0ysaIF)Yp*^K}-`X%Pp% z>o}QEp75F9Q}vD=H+Pex(x9p>X_d~}r4$blO)V6jvn6o$tpVxW{)9sBW=tlL6;jJ! z$Pabf$#xz2Uil(k%V&-5`M&hh)k{hO$?>=qL{QLv5MHyz=oQJW^H!9$O{0hJCnZDv z>Hm3o_@6kjQy+aV#;-Y2hwA?Sd1=u8@tZ6mz*u8cfQR$(H(98QT0 zhXVOV62@9dVC zu`Jz4)BhST7H(JTgq%6GOh#;!9wV4vdw(8hffdx zm)Iw3XnItnak)H1sYl!T*@9#CErze`k5mY~j&wPuxu)?JEtNG177w-Zq(!ELs?VOY zOh&IFT$_LfHeC5hf7h)W5crVFx`iGuiDV^7=+p`a5>m&{4XOh-R&0W|1_#*tUcF84 z$*+N}PmOdeU8{^|-v2s%-n*d*sB-N)B5^d6xd z`*`!@0<9Tc*o5pj6IQ;%wHiFB@Gpdk8fIlIW5Nq*=}tRfkt!T*&zDkHo?CxnK(PpX zJIBaQ2-kIb5Jp;P?%~~DV8m*?1`-9+ucD-6d;WBJHEUYI7c}|J`x@FB7h2qYDX!VV zq=qPhm9%&(PLeIujXry{w~X^>WTUQjHQ)-Jk+|mH>Mv~%pJTr>1{gM2MnVmtucgM| zqGW*T!Xr2Fc5|1$90j8tXujkzLSao|PYv6i!^HT=>Zo!=4AUNI8cx(ARjwsJDEb;k zzZ5-;yAFl=j_WII^LlEjWdv;+47f0*IRjvHK-Y<#h*hP9#9MAqK}2zJ#UrlM=L{h| zq+P^7mJd0QLv^VZ31qOY&M|#OE6kKsgpPJLihVz?b10n)gfNJEREfrk=tTTF-S-A> zPh&T4&2qhP7VVAK1?*TA^+@2GXRWKLAvG^BrNO#PWZkz0-@pV6OrP>J6+3^% z;cw@ZGOW_egOw|UVF!7?{5%aiKxIk4)0>AzX%*X6d!sQZ7VCpROWwgSUM$<7-ooH3 zCaW{a@ocO{C*=iYvx#Efq%z@7lT`Q4h`i6n{3;11pBNj81aoP9pDWORha^xXTI|Lk zDWn>@J48Bd{j_)Yso?#b+Nc-CDe_F!cw90z1E@P|MO{SxBz*aEDwOUv*E;;+O}KQh z(in+KDm9*y9o}AGC?~H-%Bshf z@F5v{kG4o+3duU(%`qb@qd)&{A*cq@rPZA%mb}`;YWHNiFu_$~CPMNiJ~uk)bn|oJ z^`0ocdr<~$LrNP4*|O}%~*KUlNkc_KI%kG>P#3U*@5(2PjDWIxVFYnk&tdH z_9|Xe18wh81H!Vty>bE7ZWx(?phbi)W(@Kow{J)1{p$;;_XF=7+RD?y${G2}kcIGH z95YNX?AjoBEfA^=L6EKUYY}S>6D#xVyw3zld8@G>+7uv!-n0Z2ZEa`298gzUniAP87@l1}Ns%Wu+s0g?AYdr?;P ziclUMmwi(YJF4>aDZ9<-cQ&zN^!6{U+r)~4=cl0wSCzO~H6K4L zr;#+{=#!df&8&9_v?hf=g&-X5v?f##KEG^lR&0O6Xh0(rzeN!FEM%hUv*1yKt6xe) z(@ri;f*4(qq3W_^nK=KVv+?c@hAzVCgzJq2v4Q)+t0xut8E(z>$Jxh20Rpcks?&1K z-5KzPToI252w>8mOM^I|IGxU@q$R*Eu)KZ8Iw!dXBd21GR*|t?yEif|DynNw zZz?r~>GD@&v${p*E@cGl|JH%apzBUljUqvE>^VRZO;p-2S}!-rIw{>R|9|bh1z1$;8a6z1r^L`DAkrlr zl1fQRNT+m%q@;i%-6|<1DJCTyl8T^&f*>Ih(joE9%+_;cHnYw?XP^K7zH?o`B@Dyx zdO!F5zR$DPde=O6Nbq_dF%n6g*;2Y<)xENJ##+^C_gBdH_$i-XB6fT*HnyvEv2-Aw zTCQX!%OYt%kE-R}6K}bkMY+6=dF2HIzig}y(fc9!537$@P>FC2TB`X*~Y$%uCG7j`_P)9+H2Xo zRI_}m=IN@eu0pUzJlkUoVb}N1s+dW_&B4^3iL05*o#`rfM91aTdo>;XdB3NmQo5_$(^DG^ynIqiUhm1gww!-Goc!;MLgg^Diyd z=X38E-+tNoh~WL<%DkakjN|#keR7w8wz<{Im%1vNKE|mo&WBLRT*P%#CiaZHyaLvj z%2lT-C9yo`^ofa)NcRrz%f~beJj8fB>!~xNjLpIw4-2+Za`&fw+k1HJSmGQyY3?{X zntjU32p`B)JombtKh@+d^CMS5Cy{FVh8XL~RhEKJY%Q!P{gq2hc^Roc&Mzs0C^Y7| zRGBGU9;Ar8|L8@e`&q60ylINgyGzpPK5atHMQ$l=sdnJoQd*1Icpdl2yUgPmbg)uw zP%19(z1Hb9706j)&hUgBzdUAB8cf)IJN2}|(uq*1jvM^3W41BBU}$RW!+Z&QMVCKz zME9qFyQS8vz0=p$5`$KotkFyGo}axfJFC~ilf^@P@o57#TLp`~{yK&Z8!35%@o+*@ zQ~U!{Y^$3d1f)ele0EQt;=A6+r$kwbM_s3(rEhY5lJc35{Q@dwCo#E)Zv59zxuTnl znQ?^ynCo_U^6%(1-<3C?8$SNL8F@NEyU^Rq;3rKCQ7;dAy)0u~N^+U{ErZ`cw>2mak{FgJ6p!^dyz z;YXa9H$>{9uyai@3x2$19OMXC&>EQ{9Y1Un-j=xbPOKq1WaWAdru%68r@TO>q;qxN zd$F4@w0RzeOmjz6-Lv1qZZ;l6yGBqBvF1R<&D$F2z*9lu# z=H?PjUz?IBzAK_B__THV36CXH>uozD=4US)y%*(df+=p=kZgn$iRpUsF3~Hr*tJKKQ3MGWmpR}w3+-y|psSUmyI+B{ zvt`ZKq!p(TIs(nqebCLy>Q~z+%q7+42D==N_k!1NzFN=xq!GRt{XFi5sT_-ugNEk2 zqd<=COIo7-m7F?!v&tbHFXfcfr7*LNu3r*w8a3rt4Ir5FO2{+Tj@QIqH9_+yiLY$x zvY2Z-za^T3SBpjeY*41^4v&;VxNwo?KpV=J%q^<~>`GsbaH3GV&jqrq9rMU9>FEs5 z=o_(HP;Z8ae6pXNb)2CuF1Fq?xs_Cv*VLw4r><=6`o1g3wO{B#x&Iv;euL{8ROSWm zH)LY&o%eAjpZJ1NDSy*V<|Wsx)t2ro-rVzGVe5Fh^E-7kU#vwhOJ@Z=J9+*Ul4;aA-ad=yDJYwIbbwJ=EO$f(|b9OEq?F`Z60 zzu>p?wz)w#IC?9^ks=i2S%q4!c&9;8d#Oa9CRnhSYDh8j2VYY%TkyR?ZNe{Z!A$A4 zOO#_To(T3}n|7@G*qF~g^Sc~pKVE4c(Qq?o9E(sc;CZ*^!@BZr+R2RVJWiU`OZN77 zt`{A4489~im$`mWX&UNv$&vY+`9^z#EREtfta;X~7DcU651j$QMGfCOQ|}_QF1gJ5 zvP2Z5bZKF`w7&lFP~CXo6K>&J4sj4WRp2z+x$YjU6b!O8KgpLVZTz1Tb7G8}iF+%P zZ_S*2%$=CPYQ+*~%2*|fpBDP=qQt^*T?W0MO*xwAi+;yaZOIbu>Dvr`!s_CLQ3?#{ z*RQb^uti=L4Cn6dxo_g7U#C1Yf&|P4ZJMOY}2j#>W-`Tqdc5AH}hXUk(U9 zSu4BFe&_CVi=2h~fSin)0pWS-L~xYNjHQO0ku3JbKt&u0+OLTewYC?SZW7^?(HVTV zCb&l5(S;>WJ`?CvQOQV^w#?wudr7r0^a8b4|9Qo}+f(|t!~Ik+o{?N?pSwV$bnEeR z9_p~p`O$pSCmMKcltJ`jfdR7`EkoU;U)-`WtcqxGE-B{L52Q){P*P5AxNhfZ%4k#A zw@vrf^o|k#5Yt;^q{u|9tjE;*v}p{CpDSOH)_#_$# z)mCVh61%~VRTec`(>6p4quF(K3aQJgPyTg9Vx5+tP6?w_w({w`fEEKWS}_S zgJ!H)G(r>dO4RwTti2IJinz>Wo@vL9Lt@j5nrB0^rkLCoF14?{JE}5~-pBJpJyap_ z2ok7c5x^+NxLaO9YruZ}s9t@}iC6f6@0;E7LN5lDiX1WK^rz-t82DNfg=vuqi*{5o zp^h|->8TR8$=v(Z3Goxf`&B)B7z3L0-?uyB&YZE;qnp2ZKSO*IZLXtuzUD`2m0Chi zt8VzRbSP2%0mJa-BFg8mSRxAcw@NoC-fEvS(POLf6OcD<|8nu``>gPrB`sy%_W6lgHxdwMs!b>1z~DXaw;O3hWjq8AOg ztmkCXDZlY#CGf7-$6AvjAKKoa$DW2e)iz9*@M_tE@cWwFZc3qx6g0jqbl6nQ<>Y1A z!!ls!vl8p}wLIb_ZVSrAN;%p`-gMZFrqNcuTP27$@pV4TbScSM!6iNgH<9AnMHLT^ z1(93BHC5B4_1^>an>t(w-zH2hg^mt@@!XAV@ZujF;dVA6RQ%g}nC|K;S}wUEQN zKR`n=<7%9rlL{IZnbkt1A3u1&L~lCHbe~__F?SY4r2y$|MyBGhMp(7iZF!A>{k$)O zeGz^g@-68!jW*1~9Z^k6B@Zn#AK;2J8GOxrIKJphf;qvb*!osSi%*M0A8k%3jcl1^ z`Bjb3u9=>HgohW0Djwr)nSu7c+b#~PY-K@w8E!MALU-bc@NES|Q?G=H1cxAfM>kW* z-92I*(#S!l0?vOyEwt^-t`!}NQ(MlK}A1UZdS>1#z+hgfXJ#^7^s-nJ9D zRi#Yl#{H%15KP3+=X$U@(jO;CZ?qL);Q7hg)IWgB{PiJ6Zy^p3QQ5)LMZ2psy80aw zPtnqpUTpT7sBC7e7ce^#hUT?AlCEO9DJmshBwRj4&Bmd+$b-BU%yrL5#foaINP-3j ziMLXJkzsa0zk#^&&1kBAn%7PfvHr4kubbf`(<@V+vTNTg-{jfby&l5v!8u&45GQQSK5@4i^c_K@m2i%52@ry zhbL_ce8UVc>!`nVe^K#5O1N6Yd+yF`o}g)J?Yx|LT3RXLOt#ut+vKoSuSc^Oqdm_h zT=!@gQ)bmZfop7Bq73iSVPj}_tMv>!Q3ojzc74>*H+4fB{h^+U=3&%+PNU@6o3)^3 zy9=qCO_%NDpWUksq7Sj_y}k0N*1SfN_9c1J7Xb(6L~+No0#xpsXd>LWGI$?MK&)hm z6hwV$CTByEb6f0a@x61%o1?{eT#>k@!2EvW<>V?1_i4kF>r3zZz?-ezIR_Ljgd0h%`>m`%twkXZ67;B z(!qaEsY2NO%w&WwR-Y-K&*S}yzB4Ekpl9x+>y>C6y*?pCdj(Zzw&f#@Z>&6cz#2Z% z_tDrE>9T9~RSGW~l4}y2!Es8RVXPS#Hi_Wn5prn{(zz#1x5%t;uGlCaULc)&eg3<` z?DiwYqfm*5DEtzK8!_FRIX5FU{H)n#R9q~5 z3f`-DQ+098lNex{&=T+3OUm8%Nv(-$-zi+C8Gb&D`B{H^p%e{UiHt?SYe~MOGzbH! zBHogKJfvg$*3jh0SnR82f3^?$H3@sRt$V(&zdo{N>8pO%pB#_bdPVC;l%JT=d2Q2V z*02!DvsMPPHfUQZbo?`XF60qR-Xq$ceYtzJoMN>_2YVr3kxGf9U&?>-spJ$(A?_hh zo<{Zlb}2^pQRCQW4s+DSAnH6xYO<$m-_g8Pwd|>RZ@a0LQTA5iCkN~qB)nxG$HSJz zoQQn-?%7sNBt`8l-mKir<*pC%s(ufVGlCzL(YcH~@J06JlsVEbyD*x1|AsVw^-G@Q%lj&thnA&s4?k0CjDLSqV?a1UJqLO;GsUvHYnIzjJy8);@Am$UbI0@A?^Dfh zzx5xbYFxQL=%+h=G;i6k!GN?FQgwSW-DsDSYq=pnizJhMKAH5c`8K_Kr~`N1dHwvM zGh~#ECe5nR3YtocXEtVL4GXwt=m~-|^z*2CwRE(|>RCSEd6c?%%kY06HoeaFm0s~k zGGnK!rPjo)8yq`CJ>``1v6kk;MMp-3e(E&?VQOApYPra!%O#(Y1d$#MWkqU~ydM-= zX%X<=T;qHwp%k*rC*3av9wNbOaW=QkUb;x^ToxC1%qwlAs|(#jG) z`IHo_vXT|>;qIFP4bJ(cv6P$mG>dl(YQ#9`b4IR=EV;as%3}4LUXtwepJeMOVEGOQMD zJ>Cc0Q+anKOJt3BD5f4ygjeh#n@t%p;X9qVy9Y-5Nm~~sqhbl2vv zim(q)i0nJAX1{a9%u~x7uXsPZjFciVdvxC}SzL68XT=1=|Xn z$K;BcM?)+=hm|+&HQDe%=C&yw%^Q^dayc3Tw$1F(ctlzY94!{`L=PDsS49New?N+iO+m)`6N6>)GZOQEs(AQ4- zm645aYsOCUXxZtNQtOzDVV9KZjwDtK|yZpWmo1eaH{=YFP>lC& zRk!mLpQ)lu8qCBq$R{rd7CGS1>~hkY4i0H$&ND5bS`$xJw%)MeHe1NXVA1}*0&cPm z+aH^G8m%_bQgoQ)bj$9pAp6=BDfJ?Z|Z zsA$vmTI==fnH$*kBup>B?qZhDj%wG+*S#Nq6-1kh_0N225VE^cuoBk&bndZHm&o-t zU(%t;GpvfCWiuA-dehY``F<3eTdJn`Qq_(cv102(?%!(jKYGp|I)07B>l!ni-&aP% zrqDiHn_Bp?w3zAeOd5eVPCvn;>7~o2nW^pSb?GQo7v0i#WHUlm$WTbzDkTVv=dl{h zA`cQshXXGx-71NFF`u|WR@FpX*M=V~XL2WME0s)PP-W`{LF2xx@(cd6S69;Q4)3`p z{9w$Cl?iaU7O(rmvHsKB`^rC}9=x-1GWS=aSfyyWTv>o!j05T(9oU#GHr}sao_W?b zk0Y>x%y38Na>;sx%eLFr%3Co_#REGw<(J-_Q)0c}7u$lsAf}@;&a}65wyv5CwWRI( zy(GMm_C)?Nu9te*h)6N>>a<5O5q8N4k!*I8pA89nE+Sv9rHzAKbX(iK(yGK^Awx;jQbc@x%kW63iDES_KLpxdy{r z2{AiUckaKps23BouDsM1*}!;j-CP?7cg3XzFDLiK{F4`7I3lgOKtBqY%1E@9aG$7G zhPlbS!`?z}y+2cbN$#m((m4C9pJXMKhr!T|-LzXna-rc*h`UJ_EM+dc4m@HAOQqt{ zWg2RXAnw^*&7n-jYP6rlObH@o1d+NEugcN~dI_hfd-v7MrCyJgl9;Zou#%SRCD1!p zy>VYQqw(@AsB*nNjR~RHxHxUeDmgzjNmGWxgv6jDThH~))#eoih#Mc zQBo;p<+bJx+Z&vk!%)`{+GTlWRB|N?qkYZoLGF;9;8~$JF5ii*k$Tti^yoZCLI+9O zZw;pk5gDORXDSe-8+R7W+9nU^Xbj#cyO(Sx{G2TQ{>y2rBh%b?nIa!9Zf9EpN}b`p zQLLF=No=FF$z82L*3@^E%~xLO;n+QRhC1M{Y%Doz9T|bX7LKcT4)vhoVRnbzWA@oG zf-)xmq4HZag-cOpwRYDgD>R=IC$f-?1w6i1yx($V=55DL!3#G$Up$r8f|qu^l&kMZ zvz_>5wm?R1FH@H+c=^uSE*arR#iyaGGCQ5syLXm8hTP@ltLh>G3$ly|j8d`Uu{9%= z@s5`h!~H+nO^F|?U9*)pyiY}HbZ?#UTFIdH$I|=miCpt-E~=$VJxNbVw>N6*a?i5M zuN${$qrb-2KnbHulWh+8$}k01Zdr^NjGze?LfywT_hy!_>F02E#E9u3FKl2*pAg(n zqNU0__mtbDvhX8j^tz|c4Z;Qur9yYqal*kRO`lIhx1Ms*-<8L+mVM%;-zhCnmT5G2 z%Td*N_D<4*9IBYtr>ZHEN0-mP7~>oWGx5IB`nhoL5qI|;!~X3Lj0ZtU_Q*{P zgJIRG;_RZLL2p)Hc>U0PZO0o;wy%KlqA_A*S*8y)@$-aHqYGH@C0^gt#WuQNx3IleN~`KqHHf@}f!4Zur=J9KWt3k~TPW&(}4lTH~6B zHmyFUuaJ!W+%-R`bfx(-M5>=PCaW{0c}h*9Q%8dEx5bL^Zx-uP6mcsUR~?poj+Nbe zIw`fzQmwB;%X&TYRZ|#gr?HB|4?J3TuQ?Cc{ZxW_!QDJqz7DWOlc|JWGYO3`xy&~XH!*Zp{FXgCHcev-= zgl9?3l}TF++zI0kqHOg7R5c4c>BQtEAINPyya~orKs*FZCYh5uL|KPJX3w;!8h1x)+!ONtDvps~!0c7pD#_w9A z&z`UQ>R`Xf9~SX-GFs!t+7r!G{;BQ(ooj-^bFbIMh$vP49=%AN<0h5=7J24~{7%>w zRpXQPTjm-)t}J(D!n;<}v~D?a3fb$6LQX}+esaH;!#P(wYD#N@Z!vg;4T z21*G7I741)z>+ENuy!!A^|8V3<}N#XuM>UrYGb7Rovg)JZ8XMbjNlhBSyETMYA}chBhE!# zE$2%~FlaenM!sS0$9`LX{`uB`e%9;WhkVU;cNg{UXS*qQx;?04-W6SN=8z(nw&7@X9pNK=we5bAvDJ@>FO2HG+9&0_ zjBTGbala5bByV;e=Z?M-+j3)|yeRy(_PukVkzUyNiAF8KAN;ji)H z?vcAiFuUE;(QKKExqzRMh<`QY>8pcaEkAbuB^2$xgQb34i4d102Rw`9rLcY0^vB+G zEW_nj#|4bG92fYSb+jL~9qJ2G&@5jXi14BbWecpVEX`Zvye{0)Alt%ILhVgip0IGA z1NA$RE*A#Q`3COw;Jmdo+{}R2M5tMrCRk!L!a8R^7gEToT%f!OeQ8|v*A9Sq;0*N72)L{>$OvdC9;pr1)22G-sIe~&U_eNbL(|# zaaU~vHS&NQrXl7N{nlxWIRQ-Fyw6|PBXx3gDSVwPO1d!S3gyf%@R-<}xK3>IKN#N| zt;6j>wei1lBu#3OLnRTV*fk-=SMj0Ti{q2t_`cC6<{dS|>nLZJ%@WzPS&X}%qyKn{ zCzWcEycR=`y9+Oqg(TYr(P!jyutq(^Q@7*E>QsF0gaN9$t<3MoEc9xeKXW1$S9SQ1 zztC;?&T7lFf#HLWD@!(L zH;`-+>fXp;F>`*;Th~t}!6jqfkyfYPmUR8D62C^@-l)T-pI(PJj!XhCpA6GAGzKB` zhZC(oIL}cNg}BYL1zh~Tq3Ln7xYcI(Jtyx#(NKu;YkSk96hSdB%vfikkd}Id{H~7- z_51dN1J^_OuO23e^nHD=e^WhfAobn7E3ZhLKc$hquzMZ)?@!#(otqFZd_}~Y@NP+%hc!6! z&v#2kv_kKejBEV;Zpr$4fE~%|U}GtqI2ITQM1v08kqlAauh>f8EM%ek`-jvI_-YsAwz)dLUp$Cr0vj!qW4Ww z;q6T8P`jLer_&n@di8yD&|S#myC;!)Q>7k8>P0wG-`B<65`mKXB@i}{HX^$mM9>`_ zp6zKHhe|A_(F*eO_h!=vNG-V*T-!r+Dw`_-Wum{@WI=me7k z&de58<*QsbDk8$dQG^mp`0o-M_W-bmB+SDREO4Ay3~mVga%f-qBGEthko=ukM9@*v z4Ysuy(Hyr{*7wwJsFx7IL06((%vH-6qa;!|w~3mXvI0d~QUKVWa~d{#G2lophoDV_ zkUW6g3EZC(i~wo!CF*kl5v0_hNzu#9I=lOb`g0z^eLxYL6rzJdA-@YfiCa$q8?{k7!^fET>-E=RE{cVK zBz}RBh<=>JNJkXO`LV}L-@fYw3GVrdz~%tapGfn8SyaMx$NqEQ z+?%4X=iqz&azegdhJ4qCd{u?~qz-$I4_J|P4l03+Q*x3x z_f(or>eh_OSr-?j1QloA?T;pi??@W^$&RwF!6gARQSB- z20^|EdAxX%hM&l1VH(yP*Dy*6f<6bL;hnBO?7bc%>d;Jus8@d-?di|IuT{$XeCV;u6LDVmJgDZ%*hTpY_rIk_a z!*{2Dr-Xce1Xw~~u7hBCIBucy{R5O+(m~)7f(WspoCiJrjSz4g6Tvhv^VNveN(jZYPM7pj+gQuTJ6Pc%VA0^cU)|_}{3*&LB_7 zcPJN5Wq_3!=5z<9J}wWoSY6y5Y-lfd<~`s_jEIZ$z2sR+E^jg=<{eSSSG(i?NhN*( zLB0%mynK?1ljPrEDpns?@eVcweFa2CtY$vgKu-`=VtNF~$B4xjf}avI`^Cs%FAHAg zK~#yOKqpmV@xNJ#|EZgIIbbb@IoXk~!|7H5VW1g$Vw;TwT#FG!Zza7KR$5JyZ1;{w zusp0_|L@jf-k+5W?}S>MRSuZy7Ge4x!s*-WAB3Z<4wjtyCIFo37!XA02PPOOkVrD+ zVO=_6xU8;%DAmCuhawiP0IbC@hdJ>1)Q(YC9K$4F$U0<6U=FcNc)lXw^1KM40SghWz- z1>jnI76GJfhjwi2N6#ZDSKLjfVCLriUuY>E)VWy2p>Jr zv*MUG;987`iz~@h&YYcTxo81O_AB^B)c;8>W_%1-i@(EEEQeFE2ZFvHQj2#;%z$e# zGXmu726ApzR>VB*E|F;(ZQ#XevfVCLrdPcqsryGQU*f8jM@q>KeT8t?A z1f4K_6Jg3c7hFYNLrGi4zgvs>epWJ~6KZkt6Tnor3e$J@xW2Jr{y}*95PjeD-33l{ zEC?br0o77|Fz0t(7l=F*s|`~_l~$1*VUaZT{_A*f-Vdl7TMwHOiN zp|}yHR96avj_n(qyVoZu{z@$_uL0ZySc7r90>|xl2wLdcd2vP)coTpX0n+!qYWF@d z<-bQ+v#!%S^Vtu6cLmXr*|BM%Pzwls9R_{*IP^HHU(m~+0z*HC=rE%By7(eka)#zs zLqF&ETn0RJL=*WK^bfUwJ9jXrHE<-{{D8tARVM`P2YLKHR^&8bS%o=(fkjUo3v!C9 zM|Qldq9FZ20}31sL_dT4MFac?*6)y_fFZ$*v%n(9A>m{Hf@IhQ42kt0)}sFgq*4f^ z3y{YbPMR#|$Twh@F3jO3%P0hvt~#Mqg0$Qpql6n`0Bz{OT&KXCaDnOm3XH+vqz%1) z`WPb$Omv?*bkJb#Dq*9(SV?l268wf9&(9dQA?N@W#3pP(ES?Y}^qkbckOO!@upw9w zQQzu@;&8YlWWjK_WOn& zBIr59K8y|dNrp0BJg%KBItZw=Pm}M5Qn!2 zGl=Qtkgy=yu8y|?Bz7A{>;fFItq_Dz*KPT`alpi~Bf1{SL~5QpX_FycG%mgBFVGLa zUHzAcowUXPIvjWhBbFA9*xPk+2_jHpYpj8{s}Vt;;`JXB;-I5x^V}o%oUxyV->z<# zWgzIvzU%%S_o3uD`Nb+I(pxrwB=5jT{(79`1Q7_@6$r^3PENoib09!!5W3}5Dn=n( z%U@meXzqpMe>8h%9Wj9JU>Q0oHxsNt;Fm+Me=K4jzk{U`1Zw;}HzTTpuP@MfsS$9F ze3rSv-+t{~HaBqGQnOKkF6Z@y0( zI|6rEz)hIE`9WV;N1_ z=If{k2Dp0H3_%FsApHI$mu|vTC`#xY`H&CnAdHB^#Z(-e(9id(DlZDS^XV|Z`nwLo zJHSzVILVWmh#V4yHS`jX+5vDBh|bMDKDqktuwTQY%DDK`Qx^p}f0GFnGCQV2BdLEFM2 z|IvMG-Y$R#0wX7#z7jzv;}}%N#1-HJ0YuOjqvH&@b3kTYTEW*#J*@lT4+MUhrxv*Y z5_6 zIOwPDsi*F#r|zkz?y0BlssG=&r$RITK5*tAgJu4XI8vKJy=gYSWi7z zPd!*qJy`#DJXrri<{yV;{`TXUpGNmr=Ev*-fli%VPn}#(om@|yTu+@`|96~Rp_%^x zIP-smW&XC~nV$*gSLWyN0D(^ZU{C#EPyJv|{a{c1VE=dgV4<1+5IFOHf@S{Jr1gb(KAJl|6NpJ$02mb(Q_!ah3fGnSTP7`CE=>elGW4ncrs_1UmJmJ@uwN z^`<@brakqh{eQ=s_Fp-{{)Nmx3CsM=$1}eG>#xjTf(Zhh`pKU9$)5Vjp8Cn2`pN$9 z_{l;u{}FKJhjpkVZaSX%MaF(*eoh7u=+u?=)Rp$smG;z?_SBX3f5(*;)<47z@SP$@ zuy=~+9)BxBlDdD8RIECoG#mEOAMXn2a|5g&upY6*ua4Ibsn}oj!%hzbI(5iBb;vz+ z$USw)J$1#0|$Yzr5_P%)g2R0-gHop8D*b`s|+i?4J7U{_ptg z{)NmB>&8!9e?0RmZU4&rnT{aPsax-!d+PYF5ZKXnd1 zbqC5>QzsOmz^Uy};H8b9!Kg`ZV;fk>ie zW#S5}h!Xw0tD3#Jugzq*F z=VPi7+j-?o>3I3y`dn(*5B#GUKT~U>yv!G z@4}Y=rxV6iN@@! zr4WHLlDJ5VqJXJ`_wKR`ap=unTY*ryd|IA5O_Z&^AT(`;AUt{v2Tps9m*ef9MA8Rv zq1Em+0#*5cfmQ9*(Q$=#ZNyL{gr;&WE2-UBvDy*!ezNR`&b@fv^KwQuL;fotr9kT9 zvY_^0{ToV$OpZHwy?fJQ_Hv?{>&2b=fppl^G)9Y|`RA;wCRkMV6je5}W8YJ$=DjuQ z%o2*ED7q595uLzLBC`K6rtsZ24Q?-O$BF)W^;*rvKwGIdYrV}gR~YUzix2rT({;Bc zWD0M69yQ^Q&gMs&D;H2upcn~ezxKRkqmQL{;tiey5la$gC-|t;CAf z){1p4iI+t^S1yIq_dap!6mOM_P>CCpFpHDp*-7D&B3|0gG-s^oRS#Lk+9&F;I9u#v zQp_W|@zB3B+t&Jm&uUaC9?fVvPH2 z0cwCeZa9hON-#2v=N>qoOZ|h4m>@i31?kq;c##E7XbE?EGoNeUyd z>jk1{=IA;*gLyS&b~s6s`SqKz|FY`^A?Q!87tm<jgY=DB_SCfNic}o@ihU zI89zbP-jD3FPsB`T`v$JJ{(WRd5Qbom&tqkYnM1)*gsq^;5h%?_2LZ#DJ|p&TBJX7 zi$n-Ug>h>K$8ENMkTGN}NOcwb(L3`CyxaLNZUqn^oz>loi9W2RPV_K9XP~l{;03vW zJODU_|3Cxbpg@E2__>B&5WXP%r@IFdD7e=5f?V3FU>RT9cVQ4A3iNqYqsZuQ)Lleb z^OzuZ!b_&euveb^S`O;x4#a8F@+iMC24$<)7qEXd%nJ=nc3f9u$XZK@gf{1A-U0T8 zN5odAV_?%g_b%jT&77)(fk&N0KO_Hrjcoe@wSons!E_uyu476h1f4fT$0ud#z^z~f z5g=n0VTd&BB_~LejdUB~OYDZWg8jWy?Z46y2EEA-12hYHJbMzUA5>r_Xyh;9NcD!m zKY)@Nn+F@H6j3W!M9_DvFrO}&BJ+jc$~0d`SN#EP1#5V0is8bhnBi|zEE65ts@l-S z*2T)u$-~{t!u_8q{G{oH@(-tuKS#X^i5lvfwQ!PP<6v}{VE5nzJMa%OVTA}5xqcNk zP$eS6tqX_*GkCd4Z{}fOwJw&>(;)K-T7<|OiT)%M)MQH--f#=`pD7-4Pyk~`_$NDm z7!?x0enS1{%R!cq)c&iiOF@1QjeOT112hWxdGsW`dsJY4ZRBt*0Zdry;!>-i9smPk zu)(qs*=r$+9Mpv}RMVrU&Nwo<-P30EjTb@WzuRl^9Gefwu!wnnMhyP#cUnh0%G&L+ zGLaLPw>N*xwEfbUH2?#I3;}_BLUILdfH7bihaT5BwF(k#H$-ET*Nd>hI}vFtgdoz? zFNMaWiK-m(i8!`CrBOjZ8ms>Wjn!c@`PY0PJTYRd-<)RPZMz7qQX9qm!zw13+>_YNtOMCqPf zm%u~miWk4M?}S7;1$jJm()xY}#)N5~dtCdp0RJFUXNdL}2wuSkFG8ffFro(6G2kgJ z@s(#qW)~-PuhyypY0vW)wCDM`j={g#?ZHRF|BAN4Cul4DGgA8Bj#E+K4r-C%a(Fi+ zVyFx8r;{`u0As;4et2BtbTepTYLmaCFB+V_NdMwQkvt4gUu>AZ`EdHafkfS*4wjt!Q3dPMun44h+c;t<6`gYXCW!!+CNXjq+=VnCF?mo+&8n|OU zc)=y16ik*>kffOQ!Mrfbk~T{CX@2btSLFSJa01J`9S1d*aVEW}|n z4tQOj#pib>J$~}PQI|3POLe*SHlX$}2SIYUH(r?A*TrSZLr++l1A(KCOdki@3rNi`D4bGA)XOU@Q?}p#J^-FuIJAi8%_oTX*Pn zWRecNro|CNnj#6FUJT^CIJ|mp5=Ca}@V~L9G5@iqkxz^m8f{4o;N@1B*&q4aiWg>k0pahS47cfz7;DseO7C4ABpCMqx+obujopBg09p*qeO*UzaL`&HN-o~ ztT=NC5?L0c?v4jb18XRO$f}dlu!Lut!5H)WN4hsXSE&CR8e+la<&!kjiUnMoFf&7P zxEmxbvg+dQB}31T8wG*aCZcE`oA^3rw5k0dr_Iip17EfOJ8Ki`FXrWlSU_FzVY+4? z*Y#eqe~_gtMAvG_OjuLsx7#UE%XGG}_oWKwV+} zh~#j$KUvDw#od>Ho(E6w0qcq=+Tw_O&K4T2Au4}?Dv`l0ioc^P_FvSsJq~bVgWx15 z$omqIXy+ihM%U2+Z)`{*h?G7k*-QYOOW0v}w{}^!UJnd#!PYVXaAN~zsYpHnr^Oru zWja)gH67rM4MYg>O}=NpPqe>m#UqbO^SSZn-`&_)PdIkj`8dyaz=SZKr{H)__YbnN zf$(fciuvcu&M3d}Ed5&)zZ?H~z4s>=m%leeJi2GKHZD2`jT(C4*%0#i$MqjW&_$3O zNELJ$qz3r|C{mInzzeA`cSSJvalWl=AZVf2{C;rK{`o>G%5QxCjuh>8qr4f434F5= zev#J#<=1j96%+n;25^K#hXga%gdj73JZ*5&1#uNH5sX6yI1UdW=xQMx>YRa*g+z~N zbLb)hWEqDTVbg=Cs?Q8Y-CI`JgdsWT=%me|n?J|==jISSBo~1}P*2ae6OQq?Kvt07 zTfs~l34fl+LszfdB`1xOW)b+e*Fis2eJ)y@^t^_Gt>r&=bpCiAdS<2Rs^SiPZeYd+ zIeX{mh~EtH6;S_V43Ie_2y>)A&jBQD6`18BIWOECsI803Vt`%?LehmXeGbva6(XkR zucDqW`jV-U;~-`&N$I;b6W-h<1WQ9QrGrS(O$V5se8todoh5J@SuNf zihx1bGQ>#50Qp06>PZR0NoDV(ofd0ILe7eSPLB48KM=t~#rhXe=~;Ff`T}*%DJ+qF zxSg^h~$E*ndARA6~u;k82F>v{kMS$h3i9<7{$_F!XlCa2O&#O9M z1av_WvZVu-FPN(*`Pgx`Y&an(r=XW+%tC?77b1i;Lc*V)5I%5S=+Kc8ut+NVyX9;9 z0U*z$FrH`Nc%FhpQU>AqL&alYp5+h};gv5X-nL(IE_|%`Xn7fJa}xZUhalE(|DXsL zvjBO9`C*ce!tq>I7ndyw`LC0n@|OT0U_Uur%94{XatfoeR|8 z)RIRq=SXdhxdT=5arNUE(HWogM?(`K6wQ^QV`z>m^{C?{f8vGJKZWv+QEW&Zq2SHR1;RX$L_0MRKf8$0G!9i-oSp#xhSId4gjLc^< z9v)%8(Cn80as#^;2#gEI4FpjR8I+q^w3E?b{R=dD(XNknZPU(2Qz->xI9uWTLc{q8 caAh*VRwn;(ZgR-{gKW{%A!nN;^B~aw0o);c$p8QV literal 0 Hc-jL100001 diff --git a/tests/dcerpc-smb-test-01/test.rules b/tests/dcerpc-smb-test-01/test.rules new file mode 100644 index 000000000..0706f9b06 --- /dev/null +++ b/tests/dcerpc-smb-test-01/test.rules @@ -0,0 +1,3 @@ +alert tcp any any -> any any (flow:to_server; dcerpc.iface:367abb81-9844-35f1-ad32-98f038001003; dcerpc.opnum:15; sid:1;) +alert smb any any -> any any (flow:to_server; dcerpc.iface:367abb81-9844-35f1-ad32-98f038001003; dcerpc.opnum:15; sid:2;) +alert dcerpc any any -> any any (flow:to_server; dcerpc.iface:367abb81-9844-35f1-ad32-98f038001003; dcerpc.opnum:15; sid:3;) diff --git a/tests/dcerpc-smb-test-01/test.yaml b/tests/dcerpc-smb-test-01/test.yaml new file mode 100644 index 000000000..e3e492cf8 --- /dev/null +++ b/tests/dcerpc-smb-test-01/test.yaml @@ -0,0 +1,16 @@ +checks: +- filter: + count: 2 + match: + event_type: alert + alert.signature_id: 1 +- filter: + count: 2 + match: + event_type: alert + alert.signature_id: 2 +- filter: + count: 2 + match: + event_type: alert + alert.signature_id: 3 -- 2.47.2