Updating p1i

Posted by / 13-Mar-2015 03:27

Updating p1i

The Trojan creates and/or writes to the following file(s): C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv Stub_x64(601 bytes)C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc Ldr_x64(857 bytes)C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc (3073 bytes)C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv_x64(3361 bytes)C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv (601 bytes)C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc (845 bytes) The process Idc Ldr.exe:1584 makes changes in the file system. anxa=APNStub&anxv=7.19.0.44&anxe=Offer Check Event&anxr=Twu B1Ilc&reason=offer Made Clean&tb-type=vanilla,vanspe&tpid=NDV-SP&trgb=IE&result=1&ft=install&udbr=iexplore.exe_6_10.0.9200.16521hxxp://www106.com/v6/apnu/update? tb=NDV-SP&cbid=^B2X&v=31.19.1.0&r=0&build=0&tbguid=77084FD2-73AB-4C69-BD6E-6CCA1E45E0B0&id=E49BE05E-944B-42E5-8321-48F1F908ACD8&locale=en_US&dtid=^YYYYYY^YY^UA&os-lang=en&tbv=12.28.1.1293&apn_dbr=iexplore.exe_6_10.0.9200.16521&iev=10.0.9200.16521&ffv=29.0.1&gcv=41.0.2272.118hxxp://www187.apnanalytics.com/tr.gif? anxa=APNStub&anxv=7.19.0.44&anxe=Installer Event&anxp=^B2X^YYYYYY^YY^UA&anxr=t Yr5Qosu&ietbs=NDV-SP:vanilla,vanspe&ie Version Installed=10.0.9200.16521&apn_dbr=iexplore.exe_6_10.0.9200.16521&user Selection=hp:1;ds:1&default Search Choice=1&reason=offer Made Clean&ff Version Installed=29.0.1.5239&os Architecture=64&tb-type=vanilla,vanspe&install Api Attempts=1&unzipping Time=0.11&ie_hpr=0&msi Error Data=None&browsers=1_IE&os Detail=6.1.1.sp1.x64&anxtv=12.28.1&msi Error Code=&tpid=NDV-SP&offer Check Time=0.92&install Api Time=0.28&user_dbr=iexplore.exe_6_10.0.9200.16521&anxt=77084FD2-73AB-4C69-BD6E-6CCA1E45E0B0&locale=en_US&execution Time=4.95&ie_ds=0&cr Version Installed=41.0.2272.118&Target Browser=IE&msi Version=5.0.7601.17807&msi Exit Code=0&installation Result=success&download Time=2.48&setup Time=0.25&homepage Choice=1hxxp://www187.apnanalytics.com/tr.gif?

The Trojan creates and/or writes to the following file(s): C:\Users\"%Current User Name%"\App Data\Local\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv (114 bytes) The process %original file name%.exe:1912 makes changes in the file system. anxa=TBNotifier&anxv=31.19.1.0&anxt=77084FD2-73AB-4C69-BD6E-6CCA1E45E0B0&anxtv=12.28.1.1293&anxp=^B2X^YYYYYY^YY^UA&tbnguid=3CBBACF0-15D0-44D7-A238-A35DD11B65B4&cr_tboff=0&cr_nt=0&ie_nt=0&cr_start=0&os Architecture=64&pid=NDV-SP&apnu Build Number=0&cr_hb=0&anxr=Wm5r K7r-&ie_hpr=0&os Detail=6.1.1.sp1.x64&cr_ds=0&anxe=apnu Daily Config&ff_tboff=0&ie_tboff=0&ff_tbon=0&cr_signin=0&ff_hpr=0&apnu Revision Number=0&ie_ds=0&cr_tbon=0&ie_tbon=0&ff_nt=0&ff_crm=-4hxxp://www187.apnanalytics.com/tr.gif?

The Trojan creates and/or writes to the following file(s): C:\Users\"%Current User Name%"\App Data\Local\Temp\Microsoft Visual C 2010 x86 Redistributable Setup_20150515_204643649(147736 bytes)C:\Users\"%Current User Name%"\App Data\Local\Temp\HFIE0html (22 bytes)C:\Users\"%Current User Name%"\App Data\Local\Temp\Setup_20150515_204643509(51982 bytes)C:92de540935f07b706498\(147 bytes)C:92de540935f07b706498\Setup (811 bytes)C:\Users\"%Current User Name%"\App Data\Local\Temp\Microsoft Visual C 2010 x86 Redistributable Setup_20150515_204643649-MSI_vc_txt (158631 bytes)C:\Users\"%Current User Name%"\App Data\Local\Temp\HFIE18html (27528 bytes)C:\Users\"%Current User Name%"\App Data\Local\Temp\Setup_20150515_2 (2036 bytes) The process Setup.exe:1840 makes changes in the file system.

The Trojan creates and/or writes to the following file(s): C:\Users\"%Current User Name%"\App Data\Local\Temp\carambis_driver_updater_24bf3170a264d8d90ee6b9abe3abd7acd0c5f668(5158553 bytes)C:\Users\"%Current User Name%"\App Data\Local\Tempbf3170a264d8d90ee6b9abe3abd7acd0c5f668(512 bytes) The process APNSetup.exe:2700 makes changes in the file system. anxa=APNStub&anxv=7.19.0.44&anxe=Installer Event&anxp=&anxr=x2Pu99GY&ietbs=NDV-SP:vanilla,vanspe&cr_tboff=0&ie Version Installed=10.0.9200.16521&user Selection=hp:1;ds:1&default Search Choice=1&reason=offer Made Clean&cr_start=-4&ff Version Installed=29.0.1.5239&os Architecture=64&tb-type=vanilla,vanspe&cr_hb=-4&install Api Attempts=1&unzipping Time=0.31&ie_hpr=1&msi Error Data=Installation failure.&browsers=1_IE&os Detail=6.1.1.sp1.x64&anxtv=12.28.1&msi Error Code=&error Condition=msi Installation Failure&tpid=NDV-SP&offer Check Time=0.83&install Api Time=0.41&user_dbr=iexplore.exe_6_10.0.9200.16521&anxt=77084FD2-73AB-4C69-BD6E-6CCA1E45E0B0&cr_ds=-4&ff_tboff=0&ff_tbon=0&ie_tboff=0&ff_hpr=-4&execution Time=5.90&ie_ds=0&cr Version Installed=41.0.2272.118&Target Browser=IE&msi Version=5.0.7601.17807&cr_tbon=0&ie_tbon=0&msi Exit Code=2&installation Result=fail&download Time=&ff_crm=-4&setup Time=0.19&homepage Choice=1hxxp://anx.apnanalytics.com/tr.gif?

The Trojan creates and/or writes to the following file(s): C:\Program Data\APN\APN-Stub\NDV-SP\(8 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Chrome Utils (4 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\Meta DataB8944BA8AD0EFDF0E01A43EF62BECD0_45BA4D4769FDB8508CEACDC73D403554 (1504 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\ContentD266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater (4 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\Meta DataD266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (696 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC (4 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\ContentA19ADAD9D098E039450ABBEDD5616EB_F7B10375EAC02BAADDA45DA11949EA52 (1 bytes)C:\Program Data\APN\APN-Stub\NDV-SP (4 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar (4 bytes)C:\Users\"%Current User Name%"\App Data\Local\Microsoft\Windows\Temporary Internet Files\Content. anxa=TBNotifier&anxv=31.19.1.0&anxt=77084FD2-73AB-4C69-BD6E-6CCA1E45E0B0&anxtv=12.28.1.1293&anxp=^B2X^YYYYYY^YY^UA&tbnguid=3CBBACF0-15D0-44D7-A238-A35DD11B65B4&cr_tboff=0&cr_nt=0&ie_nt=0&cr_start=0&os Architecture=64&pid=NDV-SP&apnu Build Number=0&cr_hb=0&anxr=Wm5r K7r-&ie_hpr=0&os Detail=6.1.1.sp1.x64&cr_ds=0&anxe=apnu Daily Config&ff_tboff=0&ie_tboff=0&ff_tbon=0&cr_signin=0&ff_hpr=0&apnu Revision Number=0&ie_ds=0&cr_tbon=0&ie_tbon=0&ff_nt=0&ff_crm=-4hxxp://tbapi.com/v6/apnu/update?

MD5: 301c88cae3b189bb4c65ff97cb810d1e SHA1: b3836879a3744ebc5c30a4c6b347f044d39be03a SHA256: 723423dcfe5f1b468f79f789a475d9585b2d9d367550dc10c7aa7f37c70f143d SSDeep: 24576: Qhwv6Rj KJ7OYu7qg Og J5y Vih LKuovdm Prqi TGda Oc IZb:mx Kxg JEVi RKd1yr5TKDcy Size: 941080 bytes File type: EXE Platform: WIN32 Entropy: Packed PEID: UPoly Xv05_v6 Company: Carambis (MEDIA FOG LTD.) Created at: 2014-12-18 Analyzed on: Windows7Ada SP1 64-bit The Trojan creates the following process(es): APNSetup1.exe:448TBNotifier.exe:580vcredist_x86.exe:820carambis_driver_updater_24bf3170a264d8d90ee6b9abe3abd7acd0c5f668.exe:2764Idc Ldr.exe:1860Idc Ldr.exe:1584%original file name%.exe:1912APNSetup.exe:2700apnmcp.exe:2292vcredist_x64.exe:3060Setup.exe:1060Setup.exe:1840Offercast2910_NDV_.exe:1904Offercast2910_NDV_.exe:2988Msi Exec.exe:208Msi Exec.exe:1172Idc Ldr_x64.exe:2888 The Trojan injects its code into the following process(es): No processes have been created.

IE5\HDZ3KS6S\Setup[1](808 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\(15 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\ContentB8944BA8AD0EFDF0E01A43EF62BECD0_45BA4D4769FDB8508CEACDC73D403554 (1 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\Meta DataA19ADAD9D098E039450ABBEDD5616EB_F7B10375EAC02BAADDA45DA11949EA52 (1480 bytes) The process vcredist_x64.exe:3060 makes changes in the file system. tb=NDV-SP&cbid=^B2X&v=31.19.1.0&r=0&build=0&tbguid=77084FD2-73AB-4C69-BD6E-6CCA1E45E0B0&id=E49BE05E-944B-42E5-8321-48F1F908ACD8&locale=en_US&dtid=^YYYYYY^YY^UA&os-lang=en&tbv=12.28.1.1293&apn_dbr=iexplore.exe_6_10.0.9200.16521&iev=10.0.9200.16521&ffv=29.0.1&gcv=41.0.2272.1180..........0.....

The Trojan creates and/or writes to the following file(s): C:\a2bc9aa8af392cd2c7e7be\Graphics\(10 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Sys Req Not (1 bytes)C:\a2bc9aa8af392cd2c7e7be40\Localized (979 bytes)C:\a2bc9aa8af392cd2c7e7be\Setup (12353 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\(809 bytes)C:\a2bc9aa8af392cd2c7e7be82\Setup (18 bytes)C:\a2bc9aa8af392cd2c7e7be\Splash (1098 bytes)C:\a2bc9aa8af392cd2c7e7be\(2482 bytes)C:\a2bc9aa8af392cd2c7e7be28\Localized (565 bytes)C:\a2bc9aa8af392cd2c7e7be33\Localized (1027 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate2(894 bytes)C:\a2bc9aa8af392cd2c7e7be\vc_(70265 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate8(894 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate7(894 bytes)C:\a2bc9aa8af392cd2c7e7be\Parameter (282 bytes)C:\a2bc9aa8af392cd2c7e7be (4 bytes)C:\a2bc9aa8af392cd2c7e7be$shtdwn$(788 bytes)C:\a2bc9aa8af392cd2c7e7be31\Setup (18 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate6(894 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Sys Req (1 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\(1 bytes)C:\a2bc9aa8af392cd2c7e7be\Setup (581 bytes)C:\a2bc9aa8af392cd2c7e7be42\Localized (976 bytes)C:\a2bc9aa8af392cd2c7e7be49\Setup (391 bytes)C:\a2bc9aa8af392cd2c7e7be\vc_(2392 bytes)C:\a2bc9aa8af392cd2c7e7be\(5264 bytes)C:\a2bc9aa8af392cd2c7e7be28\Setup (14 bytes)C:\a2bc9aa8af392cd2c7e7be82\Localized (150 bytes)C:\a2bc9aa8af392cd2c7e7be\DHtml (16 bytes)C:\a2bc9aa8af392cd2c7e7be36\Localized (672 bytes)C:\a2bc9aa8af392cd2c7e7be40\(2985 bytes)C:\a2bc9aa8af392cd2c7e7be33\(7 bytes)C:\a2bc9aa8af392cd2c7e7be41\Setup (15 bytes)C:\a2bc9aa8af392cd2c7e7be28\(3478 bytes)C:\a2bc9aa8af392cd2c7e7be42\Setup (15 bytes)C:\a2bc9aa8af392cd2c7e7be52\(3141 bytes)C:\a2bc9aa8af392cd2c7e7be49\Localized (909 bytes)C:\a2bc9aa8af392cd2c7e7be36\Setup (666 bytes)C:\a2bc9aa8af392cd2c7e7be31\Localized (840 bytes)C:\a2bc9aa8af392cd2c7e7be\Setup (4781 bytes)C:\a2bc9aa8af392cd2c7e7be49\(2867 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics (4 bytes)C:\a2bc9aa8af392cd2c7e7be52\Localized (31 bytes)C:\a2bc9aa8af392cd2c7e7be\Display (1950 bytes)C:\a2bc9aa8af392cd2c7e7be\(7 bytes)C:\a2bc9aa8af392cd2c7e7be\(1013 bytes)C:\a2bc9aa8af392cd2c7e7be\Ui (1318 bytes)C:\a2bc9aa8af392cd2c7e7be31\(2414 bytes)C:\a2bc9aa8af392cd2c7e7be41\Localized (142 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate3(894 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate1(894 bytes)C:\a2bc9aa8af392cd2c7e7be33\Setup (17 bytes)C:\a2bc9aa8af392cd2c7e7be52\Setup (833 bytes)C:\a2bc9aa8af392cd2c7e7be82\(2657 bytes)C:\a2bc9aa8af392cd2c7e7be41\(3169 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\(10 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate5(894 bytes)C:\a2bc9aa8af392cd2c7e7be42\(5772 bytes)C:\a2bc9aa8af392cd2c7e7be\(14 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\(1 bytes)C:\a2bc9aa8af392cd2c7e7be36\(3123 bytes)C:\a2bc9aa8af392cd2c7e7be\Graphics\Rotate4(894 bytes)C:\a2bc9aa8af392cd2c7e7be40\Setup (461 bytes) The process Setup.exe:1060 makes changes in the file system.

The Trojan creates and/or writes to the following file(s): C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\toolbar_x64(272 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv_x64(561 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\(178 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\common appdata\Ask Partner Network\Toolbar\{Partner ID}\CRX\(308 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\Meta DataD266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1212 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Chrome Utils\native_messaging_host_(285 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\ContentA19ADAD9D098E039450ABBEDD5616EB_F7B10375EAC02BAADDA45DA11949EA52 (1 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Chrome Utils\APNNative Msg (156 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC\Idc (460 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\appdata\Mozilla\Firefox\Profiles\{Default Profiles Folder}\extensions\[email protected](765 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\(97 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\(2 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\(73 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\Ask Toolbar Installer-12.28.1_(516 bytes)C:\Program Data\APN\APN-Stub\NDV-SP34(40 bytes)C:\Users\"%Current User Name%"\App Data\Local\Temp\APN-Stub\NDV-SP\Stb8665fac0-1198-479e-85d6-725d8d40bbe1(8720 bytes)C:\Program Data\APN\APN-Stub\NDV-SP43(41 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\Meta DataB8944BA8AD0EFDF0E01A43EF62BECD0_45BA4D4769FDB8508CEACDC73D403554 (1212 bytes)C:\Program Data\APN\APN-Stub\NDV-SP49(37 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\common appdata\Ask Partner Network\Toolbar\Shared\CRX\(698 bytes)C:\Program Data\APN\APN-Stub\NDV-SP41(39 bytes)C:\Users\"%Current User Name%"\App Data\Local\Microsoft\Windows\Temporary Internet Files\Content.

IE5\HDZ3KS6S\Setup[1](808 bytes)C:\Program Data\APN\APN-Stub\NDV-SP45(37 bytes)C:\Program Data\APN\APN-Stub\NDV-SP33(13 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\{Partner ID}\(180 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC\Idc Ldr_x64(182 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv (111 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\ContentD266D9E1E69FA1EEFB9699B009B34C8_0A9BFDD75B598C2110CBF610C078E6E6 (1 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\common appdata\Ask Partner Network\Toolbar\{Partner ID}\CRX\{Crx_Version}\(565 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\(390 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\(155 bytes)C:\Program Data\APN\APN-Stub\NDV-SP31(43 bytes)C:\Program Data\APN\APN-Stub\NDV-SP36(41 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\(677 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\{Partner ID}\(11 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Toolbar (45 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Update (105 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\(223 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\{Partner ID}\Passport_x64(12 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\ContentB8944BA8AD0EFDF0E01A43EF62BECD0_45BA4D4769FDB8508CEACDC73D403554 (1 bytes)C:\Program Data\APN\APN-Stub\NDV-SP40(41 bytes)C:\Program Data\APN\APN-Stub\NDV-SP70(38 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC\Idc (171 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\Apn (4545 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Updater\IDC\Idc Srv Stub_x64(130 bytes)C:\Users\"%Current User Name%"\App Data\Local Low\Microsoft\Cryptnet Url Cache\Meta DataA19ADAD9D098E039450ABBEDD5616EB_F7B10375EAC02BAADDA45DA11949EA52 (1194 bytes)C:\Program Data\APN\APN-Stub\NDV-SP\program files\Ask Partner Network\Toolbar\Service (114 bytes) The process TBNotifier.exe:580 makes changes in the file system.

The Trojan creates and/or writes to the following file(s): C:\Program Data\Ask Partner Network\Toolbar\NDV-SP\Updater\Config\Config.31.19.1.0-5(179 bytes)C:\Users\"%Current User Name%"\App Data\Local\Microsoft\Windows\Temporary Internet Files\Content.

updating p1i-39updating p1i-31updating p1i-34

One thought on “updating p1i”