Analyzing...
|
File Name:   MICROSOFT_SUPPORT.exe
SHA1:   43e9bace7bff8bd80e87096546c89dea4b69609f
MD5:   b7f1a5e0e33aacce3c01d6a22121d050
First Seen Date:  2017-09-15 01:06:25.869211 ( )
Number of Clients Seen:   3
Last Analysis Date:  2017-09-15 04:08:24.615146 ( )
Human Expert Analysis Result:   No human expert analysis verdict given to this sample yet.
Analysis Summary
Analysis Type | Date | Verdict | |
---|---|---|---|
Signature Based Detection | 2017-09-15 04:08:24.615146 | Clean | |
Static Analysis Overall Verdict | 2017-09-15 04:08:24.615146 | No Threat Found | help |
Dynamic Analysis Overall Verdict | 2017-09-15 04:08:24.615146 | No Threat Found | help |
Precise Detectors Overall Verdict | 2017-09-15 04:08:24.615146 | No Match | help |
Static Analysis
Static Analysis Overall Verdict | Result |
---|---|
No Threat Found | help |
Detector | Result | |
---|---|---|
Optional Header LoaderFlags field is valued illegal | Clean | |
Non-ascii or empty section names detected | Clean | |
Illegal size of optional Header | Clean | |
Packer detection on signature database | Unknown | help |
Based on the sections entropy check! file is possibly packed | Clean | |
Timestamp value suspicious | Clean | |
Header Checksum is zero! | Clean | |
Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
Anti-vm present | Suspicious | |
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Clean | |
TLS callback functions array detected | Clean |
Dynamic Analysis
Dynamic Analysis Overall Verdict | Result |
---|---|
No Threat Found | help |
Suspicious Behaviors | |
---|---|
Creates a child process | |
Writes to address space of another process | |
Uses a function clandestinely | |
Reads memory of another process | |
Opens a file in a system directory | |
Has no visible windows |
Behavioral Information
{"h_key": "80000002", "samDesired": "20119", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "74275a00", "lpSubKey": "Software\\Microsoft\\Fusion\\GACChangeNotification\\Default"}
18c
12c
318
1b0
bc
cc
b4
2c4
180
c8
1a4
128
328
b8
33c
338
C:\MICROSOFT_SUPPORT.exe
C:\Windows\system32\mscoree.dll
C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
C:\Windows\SysWOW64\ieframe.dll
C:\Windows\system32\PROPSYS.dll
file
.exe
program
ConfigMask
DisplayName
NoClientChecks
CLRLoadLogDir
ForceLog
MissingDependencies
System
NIUsageMask
NIDependencies
SIG
LoggingLevel
LogResourceBinds
OnlyUseLatestCLR
Status
DevOverrideEnable
UseLegacyIdentityFormat
ILUsageMask
System.Xml
mscorlib
ILDependencies
FrameTabWindow
DisableMSIPeek
SystemSetupInProgress
LegacyPolicyTimeStamp
EnablePunycode
DisableSecuritySettingsCheck
LastModTime
Modules
CacheLocation
System.Configuration
MVID
VersioningLog
LogFailures
DisableConfigCache
index1
TabProcGrowth
InstallRoot
Latest
LatestIndex
FrameMerging
CreateUriCacheSize
GCStressStart
GCStressStartAtJit
AdminTabProcs
EvalationData
SpecialFoldersCacheSize
DownloadCacheQuotaInKB
SessionMerging
ConfigString
EnableLog
{"lDistanceToMove": "ffff6000", "dwMoveMethod": "2", "lpDistanceToMoveHigh": "66ed94", "hFile": "1f8"}
{"lDistanceToMove": "fffffc00", "dwMoveMethod": "2", "lpDistanceToMoveHigh": "0", "hFile": "260"}
{"lDistanceToMove": "fffffff8", "dwMoveMethod": "2", "lpDistanceToMoveHigh": "66ed94", "hFile": "1f8"}
{"lDistanceToMove": "fffffc00", "dwMoveMethod": "2", "lpDistanceToMoveHigh": "0", "hFile": "358"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\GAC_32\\mscorlib\\2.0.0.0__b77a5c561934e089\\sorttbls.nlp", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\MICROSOFT_SUPPORT.exe", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\System32", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\enterprisesec.config.cch", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\system32\\l_intl.nls", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\GAC_32\\mscorlib\\2.0.0.0__b77a5c561934e089\\sortkey.nlp", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\pubpol1.dat", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "2", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\setup.msi", "dwDesiredAccess": "c0000000", "dwShareMode": "0"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\System32\\msiexec.exe", "dwDesiredAccess": "20000", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\machine.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\MICROSOFT_SUPPORT.exe.config", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "\\??\\C:\\Windows\\SysWOW64\\ieframe.dll", "dwDesiredAccess": "80", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\system32\\rsaenh.dll", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000008.db", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db", "dwDesiredAccess": "80000000", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\index1c2.dat", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\security.config.cch", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\security.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\enterprisesec.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\machine.config", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.2.0.System.Xml__b77a5c561934e089"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\.NETFramework\\Policy\\APTCA"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "AppPatch"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\30bc7c4f\\3f50fe4f"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Policy\\AppPatch"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "IL\\19ab8d57\\c91dbb2\\5e"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\181938c6\\7950e2c5"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.2.0.System.Configuration__b03f5f7f11d50a3a"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610"}
{"hKey": "128", "phkResult": "0", "lpSubKey": "LocalIntranet"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.6.3.ScreenConnect.Windows__4b14c015c87c1ad8"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_32"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-3979321414-2393373014-2172761192-1000\\Installer\\Assemblies\\Global"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.6.3.ScreenConnect.WindowsInstaller__4b14c015c87c1ad8"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.2.0.System__b77a5c561934e089"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Classes\\Installer\\Assemblies\\Global"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "IL\\3f50fe4f\\265c633d\\60"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\MICROSOFT_SUPPORT.exe"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\v2.0.50727\\Security\\Policy"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\3122e316\\2287207d"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "IL\\424bd4d8\\324708cb\\5c"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "310", "phkResult": "0", "lpSubKey": "Microsoft\\Internet Explorer\\Security"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "314", "phkResult": "0", "lpSubKey": "Microsoft\\Internet Explorer\\Security"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Installer\\Assemblies\\Global"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Security\\Policy\\Extensions\\NamedPermissionSets"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "IL\\7950e2c5\\4b5f28af\\5f"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\StrongName"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.6.3.ScreenConnect.ClientInstallerRunner__4b14c015c87c1ad8"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Policy\\"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-3979321414-2393373014-2172761192-1000"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-3979321414-2393373014-2172761192-1000\\Installer\\Assemblies\\C:|MICROSOFT_SUPPORT.exe"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "System\\Setup"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\30bc7c4f\\3f50fe4f\\18"}
{"hKey": "128", "phkResult": "0", "lpSubKey": "Internet"}
{"hKey": "b8", "phkResult": "0", "lpSubKey": "v2.0.50727.00000"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "v2.0"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\181938c6\\7950e2c5\\16"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Installer\\Assemblies\\C:|MICROSOFT_SUPPORT.exe"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Classes\\Installer\\Assemblies\\C:|MICROSOFT_SUPPORT.exe"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "MICROSOFT_SUPPORT.exe"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "index1c2"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion\\PublisherPolicy\\Default"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_PROTOCOL_LOCKDOWN"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "Standards"}
{"hKey": "1a4", "phkResult": "0", "lpSubKey": "policy.6.3.ScreenConnect.Core__4b14c015c87c1ad8"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "Upgrades"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\51df596f\\3fed2ed7"}
{"hKey": "288", "phkResult": "0", "lpSubKey": "FEATURE_LOCALMACHINE_LOCKDOWN"}
{"hKey": "184", "phkResult": "0", "lpSubKey": "NI\\7f9fce53\\1f4813bb"}
<NULL>
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
Global\CLR_CASOFF_MUTEX
{"nNumberOfBytesToWrite": "166000", "lpOverlapped": "0", "lpBuffer": "3a47370", "lpNumberOfBytesWritten": "66ec88", "hFile": "1fc"}
"C:\Windows\System32\msiexec.exe" /i "C:\Users\win7\AppData\Local\Temp\setup.msi"
mscoree.dll
ADVAPI32.dll
SHLWAPI.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
ntdll
advapi32.dll
shell32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
ole32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\OLEAUT32.dll
OLEAUT32.dll
AdvApi32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
kernel32
CRYPTSP.dll
CRYPTBASE.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
kernel32.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
psapi.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
bcrypt.dll
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll
propsys.dll
comctl32.dll
C:\Windows\SysWOW64\ieframe.dll
SHELL32.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
ntmarta.dll
Secur32.dll
API-MS-WIN-DOWNLEVEL-SHLWAPI-L1-1-0.DLL
C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\security.config.cch.2392.241765
C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\enterprisesec.config.cch.2392.241765
C:\Users\win7\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.2392.241796
OpenProcess
OpenProcessW
ShellExecuteEx
ShellExecuteExW
Precise Detectors Analysis Results
Detector Name | Date | Verdict | Reason | |
---|---|---|---|---|
Static Precise Trojan Detector 2 | 2017-09-15 04:07:59.879522 | No Match | help | NotDetected |
Static Precise Trojan Detector 3 | 2017-09-15 04:07:59.889137 | No Match | help | NotDetected |
Static Precise Adware InstallCore Detector 1 | 2017-09-15 04:07:59.905876 | No Match | help | NotDetected |
Static Precise Trojan Generic Cryptor Detector 1 | 2017-09-15 04:07:59.906854 | No Match | help | NotDetected |
Static Precise PUA Detector 1 | 2017-09-15 04:07:59.928119 | No Match | help | NotDetected |
Static Precise Virus Detector | 2017-09-15 04:07:59.936644 | No Match | help | NotDetected |
Static Precise Trojan Detector | 2017-09-15 04:07:59.949041 | No Match | help | NotDetected |
Static Precise Virus Detector 2 | 2017-09-15 04:07:59.957919 | No Match | help | NotDetected |
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Additional File Information
Property | Value |
---|
Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
---|