Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
tiodtk2cfy.exe

Overview

General Information

Sample name:tiodtk2cfy.exe
renamed because original name is a hash value
Original sample name:b56be916b1ca250cd9fe04b283e0c3ee.exe
Analysis ID:1368193
MD5:b56be916b1ca250cd9fe04b283e0c3ee
SHA1:8f10d4274fb142a1b296702d5a430e95d3225e9b
SHA256:a1586d89fcbda8b94c59634a7d68ba4b6e884c68a92355c6487068d2212b6043
Tags:exenjratRAT
Infos:

Detection

Njrat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected Njrat
.NET source code contains potential unpacker
Connects to many ports of the same IP (likely port scanning)
Contains functionality to disable the Task Manager (.Net Source)
Contains functionality to spread to USB devices (.Net source)
Creates autorun.inf (USB autostart)
Disables zone checking for all users
Drops PE files to the startup folder
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies the windows firewall
Uses netsh to modify the Windows network and firewall settings
Abnormal high CPU Usage
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Creates a window with clipboard capturing capabilities
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May infect USB drives
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • tiodtk2cfy.exe (PID: 7508 cmdline: C:\Users\user\Desktop\tiodtk2cfy.exe MD5: B56BE916B1CA250CD9FE04B283E0C3EE)
    • server.exe (PID: 7592 cmdline: "C:\Users\user\AppData\Roaming\server.exe" MD5: B56BE916B1CA250CD9FE04B283E0C3EE)
      • netsh.exe (PID: 7644 cmdline: netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\server.exe" "server.exe" ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
        • conhost.exe (PID: 7652 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • Microsoft Corporation.exe (PID: 8036 cmdline: "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe" MD5: B56BE916B1CA250CD9FE04B283E0C3EE)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
NjRATRedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
  • AQUATIC PANDA
  • Earth Lusca
  • Operation C-Major
  • The Gorgon Group
https://malpedia.caad.fkie.fraunhofer.de/details/win.njrat
{"Campaign ID": "VicTim", "Version": "0.7d", "Install Name": "a1d56127836419435d08d7cc0808a629", "Install Dir": "system", "Registry Value": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Network Seprator": "|'|'|"}
SourceRuleDescriptionAuthorStrings
tiodtk2cfy.exeJoeSecurity_NjratYara detected NjratJoe Security
    tiodtk2cfy.exeWindows_Trojan_Njrat_30f3c220unknownunknown
    • 0x115d2:$a1: get_Registry
    • 0x15a3d:$a2: SEE_MASK_NOZONECHECKS
    • 0x156df:$a3: Download ERROR
    • 0x15c8f:$a4: cmd.exe /c ping 0 -n 2 & del "
    • 0x13c1c:$a5: netsh firewall delete allowedprogram "
    tiodtk2cfy.exeCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
    • 0x15c8f:$x1: cmd.exe /c ping 0 -n 2 & del "
    • 0x137a8:$s1: winmgmts:\\.\root\SecurityCenter2
    • 0x156fd:$s3: Executed As
    • 0x124f0:$s5: Stub.exe
    • 0x156df:$s6: Download ERROR
    • 0x1376a:$s8: Select * From AntiVirusProduct
    tiodtk2cfy.exeNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
    • 0x15a3d:$reg: SEE_MASK_NOZONECHECKS
    • 0x156c3:$msg: Execute ERROR
    • 0x15717:$msg: Execute ERROR
    • 0x15c8f:$ping: cmd.exe /c ping 0 -n 2 & del
    tiodtk2cfy.exeMALWARE_Win_NjRATDetects NjRAT / BladabindiditekSHen
    • 0x13c1c:$s1: netsh firewall delete allowedprogram
    • 0x13c6e:$s2: netsh firewall add allowedprogram
    • 0x15c8f:$s3: 63 00 6D 00 64 00 2E 00 65 00 78 00 65 00 20 00 2F 00 63 00 20 00 70 00 69 00 6E 00 67
    • 0x156c3:$s4: Execute ERROR
    • 0x15717:$s4: Execute ERROR
    • 0x156df:$s5: Download ERROR
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeJoeSecurity_NjratYara detected NjratJoe Security
      C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeWindows_Trojan_Njrat_30f3c220unknownunknown
      • 0x115d2:$a1: get_Registry
      • 0x15a3d:$a2: SEE_MASK_NOZONECHECKS
      • 0x156df:$a3: Download ERROR
      • 0x15c8f:$a4: cmd.exe /c ping 0 -n 2 & del "
      • 0x13c1c:$a5: netsh firewall delete allowedprogram "
      C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
      • 0x15c8f:$x1: cmd.exe /c ping 0 -n 2 & del "
      • 0x137a8:$s1: winmgmts:\\.\root\SecurityCenter2
      • 0x156fd:$s3: Executed As
      • 0x124f0:$s5: Stub.exe
      • 0x156df:$s6: Download ERROR
      • 0x1376a:$s8: Select * From AntiVirusProduct
      C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
      • 0x15a3d:$reg: SEE_MASK_NOZONECHECKS
      • 0x156c3:$msg: Execute ERROR
      • 0x15717:$msg: Execute ERROR
      • 0x15c8f:$ping: cmd.exe /c ping 0 -n 2 & del
      C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeMALWARE_Win_NjRATDetects NjRAT / BladabindiditekSHen
      • 0x13c1c:$s1: netsh firewall delete allowedprogram
      • 0x13c6e:$s2: netsh firewall add allowedprogram
      • 0x15c8f:$s3: 63 00 6D 00 64 00 2E 00 65 00 78 00 65 00 20 00 2F 00 63 00 20 00 70 00 69 00 6E 00 67
      • 0x156c3:$s4: Execute ERROR
      • 0x15717:$s4: Execute ERROR
      • 0x156df:$s5: Download ERROR
      Click to see the 20 entries
      SourceRuleDescriptionAuthorStrings
      00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_NjratYara detected NjratJoe Security
        00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmpWindows_Trojan_Njrat_30f3c220unknownunknown
        • 0x115f2:$a1: get_Registry
        • 0x15a5d:$a2: SEE_MASK_NOZONECHECKS
        • 0x156ff:$a3: Download ERROR
        • 0x15caf:$a4: cmd.exe /c ping 0 -n 2 & del "
        • 0x13c3c:$a5: netsh firewall delete allowedprogram "
        00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmpNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
        • 0x15a5d:$reg: SEE_MASK_NOZONECHECKS
        • 0x156e3:$msg: Execute ERROR
        • 0x15737:$msg: Execute ERROR
        • 0x15caf:$ping: cmd.exe /c ping 0 -n 2 & del
        00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_NjratYara detected NjratJoe Security
          00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmpWindows_Trojan_Njrat_30f3c220unknownunknown
          • 0x113d2:$a1: get_Registry
          • 0x1583d:$a2: SEE_MASK_NOZONECHECKS
          • 0x154df:$a3: Download ERROR
          • 0x15a8f:$a4: cmd.exe /c ping 0 -n 2 & del "
          • 0x13a1c:$a5: netsh firewall delete allowedprogram "
          Click to see the 4 entries
          SourceRuleDescriptionAuthorStrings
          0.0.tiodtk2cfy.exe.470000.0.unpackJoeSecurity_NjratYara detected NjratJoe Security
            0.0.tiodtk2cfy.exe.470000.0.unpackWindows_Trojan_Njrat_30f3c220unknownunknown
            • 0x115d2:$a1: get_Registry
            • 0x15a3d:$a2: SEE_MASK_NOZONECHECKS
            • 0x156df:$a3: Download ERROR
            • 0x15c8f:$a4: cmd.exe /c ping 0 -n 2 & del "
            • 0x13c1c:$a5: netsh firewall delete allowedprogram "
            0.0.tiodtk2cfy.exe.470000.0.unpackCN_disclosed_20180208_cDetects malware from disclosed CN malware setFlorian Roth
            • 0x15c8f:$x1: cmd.exe /c ping 0 -n 2 & del "
            • 0x137a8:$s1: winmgmts:\\.\root\SecurityCenter2
            • 0x156fd:$s3: Executed As
            • 0x124f0:$s5: Stub.exe
            • 0x156df:$s6: Download ERROR
            • 0x1376a:$s8: Select * From AntiVirusProduct
            0.0.tiodtk2cfy.exe.470000.0.unpackNjratdetect njRAT in memoryJPCERT/CC Incident Response Group
            • 0x15a3d:$reg: SEE_MASK_NOZONECHECKS
            • 0x156c3:$msg: Execute ERROR
            • 0x15717:$msg: Execute ERROR
            • 0x15c8f:$ping: cmd.exe /c ping 0 -n 2 & del
            0.0.tiodtk2cfy.exe.470000.0.unpackMALWARE_Win_NjRATDetects NjRAT / BladabindiditekSHen
            • 0x13c1c:$s1: netsh firewall delete allowedprogram
            • 0x13c6e:$s2: netsh firewall add allowedprogram
            • 0x15c8f:$s3: 63 00 6D 00 64 00 2E 00 65 00 78 00 65 00 20 00 2F 00 63 00 20 00 70 00 69 00 6E 00 67
            • 0x156c3:$s4: Execute ERROR
            • 0x15717:$s4: Execute ERROR
            • 0x156df:$s5: Download ERROR
            No Sigma rule has matched
            Timestamp:192.168.2.418.197.239.550070193542814856 12/30/23-07:00:48.954923
            SID:2814856
            Source Port:50070
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550072193542814856 12/30/23-07:00:49.937293
            SID:2814856
            Source Port:50072
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550071193542814856 12/30/23-07:00:49.443578
            SID:2814856
            Source Port:50071
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550074193542814856 12/30/23-07:00:50.928621
            SID:2814856
            Source Port:50074
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949844193542814856 12/30/23-06:58:53.964218
            SID:2814856
            Source Port:49844
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949845193542814856 12/30/23-06:58:54.461893
            SID:2814856
            Source Port:49845
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550073193542814856 12/30/23-07:00:50.430940
            SID:2814856
            Source Port:50073
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949846193542814856 12/30/23-06:58:54.962969
            SID:2814856
            Source Port:49846
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550078193542814856 12/30/23-07:00:52.921914
            SID:2814856
            Source Port:50078
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949847193542814856 12/30/23-06:58:55.462477
            SID:2814856
            Source Port:49847
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550075193542814856 12/30/23-07:00:51.423156
            SID:2814856
            Source Port:50075
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550079193542814856 12/30/23-07:00:53.417118
            SID:2814856
            Source Port:50079
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550076193542814856 12/30/23-07:00:51.914234
            SID:2814856
            Source Port:50076
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550077193542814856 12/30/23-07:00:52.429766
            SID:2814856
            Source Port:50077
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949843193542814856 12/30/23-06:58:53.458642
            SID:2814856
            Source Port:49843
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949832193542814856 12/30/23-06:58:47.148856
            SID:2814856
            Source Port:49832
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949831193542814856 12/30/23-06:58:46.651530
            SID:2814856
            Source Port:49831
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949840193542814856 12/30/23-06:58:51.198140
            SID:2814856
            Source Port:49840
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949830193542814856 12/30/23-06:58:46.139598
            SID:2814856
            Source Port:49830
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550080193542814856 12/30/23-07:00:53.911195
            SID:2814856
            Source Port:50080
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949763193542033132 12/30/23-06:57:58.658795
            SID:2033132
            Source Port:49763
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550060193542814856 12/30/23-07:00:44.073546
            SID:2814856
            Source Port:50060
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550061193542814856 12/30/23-07:00:44.563845
            SID:2814856
            Source Port:50061
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550081193542814856 12/30/23-07:00:54.395316
            SID:2814856
            Source Port:50081
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949762193542033132 12/30/23-06:57:56.539963
            SID:2033132
            Source Port:49762
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550082193542814856 12/30/23-07:00:58.229074
            SID:2814856
            Source Port:50082
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550064193542814856 12/30/23-07:00:46.036167
            SID:2814856
            Source Port:50064
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550063193542814856 12/30/23-07:00:45.540599
            SID:2814856
            Source Port:50063
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550062193542814856 12/30/23-07:00:45.053977
            SID:2814856
            Source Port:50062
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550068193542814856 12/30/23-07:00:47.982577
            SID:2814856
            Source Port:50068
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550067193542814856 12/30/23-07:00:47.495787
            SID:2814856
            Source Port:50067
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550069193542814856 12/30/23-07:00:48.469821
            SID:2814856
            Source Port:50069
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550065193542814856 12/30/23-07:00:46.523306
            SID:2814856
            Source Port:50065
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550066193542814856 12/30/23-07:00:47.015523
            SID:2814856
            Source Port:50066
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949773193542033132 12/30/23-06:58:10.061344
            SID:2033132
            Source Port:49773
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749910193542033132 12/30/23-06:59:28.395113
            SID:2033132
            Source Port:49910
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949777193542033132 12/30/23-06:58:13.628186
            SID:2033132
            Source Port:49777
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949822193542814856 12/30/23-06:58:42.080105
            SID:2814856
            Source Port:49822
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949771193542033132 12/30/23-06:58:08.096308
            SID:2033132
            Source Port:49771
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949779193542033132 12/30/23-06:58:15.550531
            SID:2033132
            Source Port:49779
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749912193542033132 12/30/23-06:59:29.368484
            SID:2033132
            Source Port:49912
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749894193542814856 12/30/23-06:59:19.912088
            SID:2814856
            Source Port:49894
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949824193542814856 12/30/23-06:58:43.090902
            SID:2814856
            Source Port:49824
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949826193542814856 12/30/23-06:58:44.099384
            SID:2814856
            Source Port:49826
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550081193542033132 12/30/23-07:00:54.154302
            SID:2033132
            Source Port:50081
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949828193542814856 12/30/23-06:58:45.123472
            SID:2814856
            Source Port:49828
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749890193542814856 12/30/23-06:59:17.969044
            SID:2814856
            Source Port:49890
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749892193542814856 12/30/23-06:59:18.951027
            SID:2814856
            Source Port:49892
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949841193542033132 12/30/23-06:58:52.214516
            SID:2033132
            Source Port:49841
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749908193542033132 12/30/23-06:59:26.520668
            SID:2033132
            Source Port:49908
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749918193542033132 12/30/23-06:59:32.288100
            SID:2033132
            Source Port:49918
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749906193542033132 12/30/23-06:59:25.530242
            SID:2033132
            Source Port:49906
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850007193542033132 12/30/23-07:00:17.003332
            SID:2033132
            Source Port:50007
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749904193542033132 12/30/23-06:59:24.562802
            SID:2033132
            Source Port:49904
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749914193542033132 12/30/23-06:59:30.329855
            SID:2033132
            Source Port:49914
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850009193542033132 12/30/23-07:00:17.992635
            SID:2033132
            Source Port:50009
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949820193542814856 12/30/23-06:58:41.006653
            SID:2814856
            Source Port:49820
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949775193542033132 12/30/23-06:58:11.898804
            SID:2033132
            Source Port:49775
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749916193542033132 12/30/23-06:59:31.315995
            SID:2033132
            Source Port:49916
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949764193542033132 12/30/23-06:57:59.930348
            SID:2033132
            Source Port:49764
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749900193542033132 12/30/23-06:59:22.575675
            SID:2033132
            Source Port:49900
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749921193542033132 12/30/23-06:59:33.759908
            SID:2033132
            Source Port:49921
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749902193542033132 12/30/23-06:59:23.554900
            SID:2033132
            Source Port:49902
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949766193542033132 12/30/23-06:58:02.485767
            SID:2033132
            Source Port:49766
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949787193542033132 12/30/23-06:58:21.859503
            SID:2033132
            Source Port:49787
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949811193542814856 12/30/23-06:58:36.302287
            SID:2814856
            Source Port:49811
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749923193542033132 12/30/23-06:59:34.726286
            SID:2033132
            Source Port:49923
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949768193542033132 12/30/23-06:58:04.876943
            SID:2033132
            Source Port:49768
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949789193542033132 12/30/23-06:58:23.169791
            SID:2033132
            Source Port:49789
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949834193542814856 12/30/23-06:58:48.171147
            SID:2814856
            Source Port:49834
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949813193542814856 12/30/23-06:58:37.354950
            SID:2814856
            Source Port:49813
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949815193542814856 12/30/23-06:58:38.422230
            SID:2814856
            Source Port:49815
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949836193542814856 12/30/23-06:58:49.179643
            SID:2814856
            Source Port:49836
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949817193542814856 12/30/23-06:58:39.473534
            SID:2814856
            Source Port:49817
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949838193542814856 12/30/23-06:58:50.173808
            SID:2814856
            Source Port:49838
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949843193542033132 12/30/23-06:58:53.218383
            SID:2033132
            Source Port:49843
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550066193542033132 12/30/23-07:00:46.770843
            SID:2033132
            Source Port:50066
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749879193542814856 12/30/23-06:59:12.631314
            SID:2814856
            Source Port:49879
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850010193542033132 12/30/23-07:00:18.477026
            SID:2033132
            Source Port:50010
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949845193542033132 12/30/23-06:58:54.222789
            SID:2033132
            Source Port:49845
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949819193542814856 12/30/23-06:58:40.501000
            SID:2814856
            Source Port:49819
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550064193542033132 12/30/23-07:00:45.792625
            SID:2033132
            Source Port:50064
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949847193542033132 12/30/23-06:58:55.219909
            SID:2033132
            Source Port:49847
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749875193542814856 12/30/23-06:59:09.576470
            SID:2814856
            Source Port:49875
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749896193542814856 12/30/23-06:59:20.882239
            SID:2814856
            Source Port:49896
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749877193542814856 12/30/23-06:59:11.657337
            SID:2814856
            Source Port:49877
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749898193542814856 12/30/23-06:59:21.850035
            SID:2814856
            Source Port:49898
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550068193542033132 12/30/23-07:00:47.740606
            SID:2033132
            Source Port:50068
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949795193542033132 12/30/23-06:58:26.878298
            SID:2033132
            Source Port:49795
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749932193542033132 12/30/23-06:59:39.117147
            SID:2033132
            Source Port:49932
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749756193542814856 12/30/23-06:57:48.292899
            SID:2814856
            Source Port:49756
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949794193542033132 12/30/23-06:58:26.283659
            SID:2033132
            Source Port:49794
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949798193542033132 12/30/23-06:58:28.628830
            SID:2033132
            Source Port:49798
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949791193542033132 12/30/23-06:58:24.422556
            SID:2033132
            Source Port:49791
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949799193542033132 12/30/23-06:58:29.212613
            SID:2033132
            Source Port:49799
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749906193542814856 12/30/23-06:59:25.770785
            SID:2814856
            Source Port:49906
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749752193542814856 12/30/23-06:57:39.966123
            SID:2814856
            Source Port:49752
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749751193542814856 12/30/23-06:57:37.519223
            SID:2814856
            Source Port:49751
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749759193542814856 12/30/23-06:57:51.839689
            SID:2814856
            Source Port:49759
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949801193542814856 12/30/23-06:58:30.584406
            SID:2814856
            Source Port:49801
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949802193542814856 12/30/23-06:58:31.147560
            SID:2814856
            Source Port:49802
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749907193542814856 12/30/23-06:59:26.275930
            SID:2814856
            Source Port:49907
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749933193542033132 12/30/23-06:59:39.601760
            SID:2033132
            Source Port:49933
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749873193542814856 12/30/23-06:59:08.594471
            SID:2814856
            Source Port:49873
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949764193542814856 12/30/23-06:58:00.172622
            SID:2814856
            Source Port:49764
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949765193542814856 12/30/23-06:58:01.473265
            SID:2814856
            Source Port:49765
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749902193542814856 12/30/23-06:59:23.793402
            SID:2814856
            Source Port:49902
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850015193542033132 12/30/23-07:00:21.543091
            SID:2033132
            Source Port:50015
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749872193542814856 12/30/23-06:59:08.108252
            SID:2814856
            Source Port:49872
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850014193542033132 12/30/23-07:00:20.575513
            SID:2033132
            Source Port:50014
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949790193542033132 12/30/23-06:58:23.797823
            SID:2033132
            Source Port:49790
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749899193542033132 12/30/23-06:59:22.091446
            SID:2033132
            Source Port:49899
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850011193542033132 12/30/23-07:00:18.962037
            SID:2033132
            Source Port:50011
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949831193542033132 12/30/23-06:58:46.408297
            SID:2033132
            Source Port:49831
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749755193542814856 12/30/23-06:57:46.372600
            SID:2814856
            Source Port:49755
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949832193542033132 12/30/23-06:58:46.906902
            SID:2033132
            Source Port:49832
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949805193542814856 12/30/23-06:58:32.805845
            SID:2814856
            Source Port:49805
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949806193542814856 12/30/23-06:58:33.355460
            SID:2814856
            Source Port:49806
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749903193542814856 12/30/23-06:59:24.315420
            SID:2814856
            Source Port:49903
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550060193542033132 12/30/23-07:00:43.834106
            SID:2033132
            Source Port:50060
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749929193542033132 12/30/23-06:59:37.653403
            SID:2033132
            Source Port:49929
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850018193542033132 12/30/23-07:00:22.786929
            SID:2033132
            Source Port:50018
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850029193542033132 12/30/23-07:00:28.229769
            SID:2033132
            Source Port:50029
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949779193542814856 12/30/23-06:58:15.792812
            SID:2814856
            Source Port:49779
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749936193542033132 12/30/23-06:59:41.043152
            SID:2033132
            Source Port:49936
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949768193542814856 12/30/23-06:58:05.118313
            SID:2814856
            Source Port:49768
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949769193542814856 12/30/23-06:58:06.230283
            SID:2814856
            Source Port:49769
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749925193542033132 12/30/23-06:59:35.700120
            SID:2033132
            Source Port:49925
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749926193542033132 12/30/23-06:59:36.181869
            SID:2033132
            Source Port:49926
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850019193542033132 12/30/23-07:00:23.274007
            SID:2033132
            Source Port:50019
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949785193542033132 12/30/23-06:58:20.502867
            SID:2033132
            Source Port:49785
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749937193542033132 12/30/23-06:59:41.527798
            SID:2033132
            Source Port:49937
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949784193542033132 12/30/23-06:58:19.803732
            SID:2033132
            Source Port:49784
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749745193542814856 12/30/23-06:57:21.884586
            SID:2814856
            Source Port:49745
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949780193542033132 12/30/23-06:58:16.840242
            SID:2033132
            Source Port:49780
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949781193542033132 12/30/23-06:58:17.605537
            SID:2033132
            Source Port:49781
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749741193542814856 12/30/23-06:57:11.514602
            SID:2814856
            Source Port:49741
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749749193542814856 12/30/23-06:57:32.353860
            SID:2814856
            Source Port:49749
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749761193542814856 12/30/23-06:57:55.069798
            SID:2814856
            Source Port:49761
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949776193542814856 12/30/23-06:58:13.018301
            SID:2814856
            Source Port:49776
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749748193542814856 12/30/23-06:57:29.753082
            SID:2814856
            Source Port:49748
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949775193542814856 12/30/23-06:58:12.140545
            SID:2814856
            Source Port:49775
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850005193542033132 12/30/23-07:00:16.032843
            SID:2033132
            Source Port:50005
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850026193542033132 12/30/23-07:00:26.716616
            SID:2033132
            Source Port:50026
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749862193542814856 12/30/23-06:59:03.086640
            SID:2814856
            Source Port:49862
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550070193542033132 12/30/23-07:00:48.719328
            SID:2033132
            Source Port:50070
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749883193542814856 12/30/23-06:59:14.575085
            SID:2814856
            Source Port:49883
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749861193542814856 12/30/23-06:59:02.584434
            SID:2814856
            Source Port:49861
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850004193542033132 12/30/23-07:00:15.549435
            SID:2033132
            Source Port:50004
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850025193542033132 12/30/23-07:00:26.230594
            SID:2033132
            Source Port:50025
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749882193542814856 12/30/23-06:59:14.082439
            SID:2814856
            Source Port:49882
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949771193542814856 12/30/23-06:58:08.334196
            SID:2814856
            Source Port:49771
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850001193542033132 12/30/23-07:00:14.107818
            SID:2033132
            Source Port:50001
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850022193542033132 12/30/23-07:00:24.731564
            SID:2033132
            Source Port:50022
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550073193542033132 12/30/23-07:00:50.186982
            SID:2033132
            Source Port:50073
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949772193542814856 12/30/23-06:58:09.337276
            SID:2814856
            Source Port:49772
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749744193542814856 12/30/23-06:57:19.294692
            SID:2814856
            Source Port:49744
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850059193542814856 12/30/23-07:00:43.466411
            SID:2814856
            Source Port:50059
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550077193542033132 12/30/23-07:00:52.186665
            SID:2033132
            Source Port:50077
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949814193542033132 12/30/23-06:58:37.646709
            SID:2033132
            Source Port:49814
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949835193542033132 12/30/23-06:58:48.442153
            SID:2033132
            Source Port:49835
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749892193542033132 12/30/23-06:59:18.710203
            SID:2033132
            Source Port:49892
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850058193542814856 12/30/23-07:00:42.973648
            SID:2814856
            Source Port:50058
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550078193542033132 12/30/23-07:00:52.683987
            SID:2033132
            Source Port:50078
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749891193542033132 12/30/23-06:59:18.218918
            SID:2033132
            Source Port:49891
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749895193542033132 12/30/23-06:59:20.153537
            SID:2033132
            Source Port:49895
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749869193542814856 12/30/23-06:59:06.630731
            SID:2814856
            Source Port:49869
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850000193542033132 12/30/23-07:00:13.595230
            SID:2033132
            Source Port:50000
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850021193542033132 12/30/23-07:00:24.247127
            SID:2033132
            Source Port:50021
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749896193542033132 12/30/23-06:59:20.640929
            SID:2033132
            Source Port:49896
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550074193542033132 12/30/23-07:00:50.682277
            SID:2033132
            Source Port:50074
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949815193542033132 12/30/23-06:58:38.185220
            SID:2033132
            Source Port:49815
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949836193542033132 12/30/23-06:58:48.938117
            SID:2033132
            Source Port:49836
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949809193542814856 12/30/23-06:58:35.250061
            SID:2814856
            Source Port:49809
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749920193542814856 12/30/23-06:59:33.515224
            SID:2814856
            Source Port:49920
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749865193542814856 12/30/23-06:59:04.588452
            SID:2814856
            Source Port:49865
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749886193542814856 12/30/23-06:59:16.032780
            SID:2814856
            Source Port:49886
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749866193542814856 12/30/23-06:59:05.087576
            SID:2814856
            Source Port:49866
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850055193542814856 12/30/23-07:00:41.504089
            SID:2814856
            Source Port:50055
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949839193542033132 12/30/23-06:58:50.449348
            SID:2033132
            Source Port:49839
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749887193542814856 12/30/23-06:59:16.514863
            SID:2814856
            Source Port:49887
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949818193542033132 12/30/23-06:58:39.751349
            SID:2033132
            Source Port:49818
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949819193542033132 12/30/23-06:58:40.262690
            SID:2033132
            Source Port:49819
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850054193542814856 12/30/23-07:00:41.016431
            SID:2814856
            Source Port:50054
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749911193542033132 12/30/23-06:59:28.906034
            SID:2033132
            Source Port:49911
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749953193542033132 12/30/23-06:59:49.899296
            SID:2033132
            Source Port:49953
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949774193542033132 12/30/23-06:58:10.980764
            SID:2033132
            Source Port:49774
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949770193542033132 12/30/23-06:58:07.067339
            SID:2033132
            Source Port:49770
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949778193542033132 12/30/23-06:58:14.453525
            SID:2033132
            Source Port:49778
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749927193542814856 12/30/23-06:59:36.906209
            SID:2814856
            Source Port:49927
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849977193542033132 12/30/23-07:00:01.827518
            SID:2033132
            Source Port:49977
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749730193542814856 12/30/23-06:56:58.554147
            SID:2814856
            Source Port:49730
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949823193542814856 12/30/23-06:58:42.580546
            SID:2814856
            Source Port:49823
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749923193542814856 12/30/23-06:59:34.964003
            SID:2814856
            Source Port:49923
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550080193542033132 12/30/23-07:00:53.665144
            SID:2033132
            Source Port:50080
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749851193542814856 12/30/23-06:58:57.593735
            SID:2814856
            Source Port:49851
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949786193542814856 12/30/23-06:58:21.432065
            SID:2814856
            Source Port:49786
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849973193542033132 12/30/23-06:59:59.823165
            SID:2033132
            Source Port:49973
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749878193542033132 12/30/23-06:59:11.903318
            SID:2033132
            Source Port:49878
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849989193542814856 12/30/23-07:00:08.436279
            SID:2814856
            Source Port:49989
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749893193542814856 12/30/23-06:59:19.436193
            SID:2814856
            Source Port:49893
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850036193542033132 12/30/23-07:00:31.626776
            SID:2033132
            Source Port:50036
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949782193542814856 12/30/23-06:58:18.587636
            SID:2814856
            Source Port:49782
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749760193542033132 12/30/23-06:57:53.252164
            SID:2033132
            Source Port:49760
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949811193542033132 12/30/23-06:58:36.061798
            SID:2033132
            Source Port:49811
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949827193542814856 12/30/23-06:58:44.610808
            SID:2814856
            Source Port:49827
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849995193542814856 12/30/23-07:00:11.352583
            SID:2814856
            Source Port:49995
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849985193542814856 12/30/23-07:00:06.458086
            SID:2814856
            Source Port:49985
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849981193542814856 12/30/23-07:00:04.500208
            SID:2814856
            Source Port:49981
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849991193542814856 12/30/23-07:00:09.404969
            SID:2814856
            Source Port:49991
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849999193542814856 12/30/23-07:00:13.331950
            SID:2814856
            Source Port:49999
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749909193542033132 12/30/23-06:59:27.121367
            SID:2033132
            Source Port:49909
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749919193542033132 12/30/23-06:59:32.776505
            SID:2033132
            Source Port:49919
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850008193542033132 12/30/23-07:00:17.503665
            SID:2033132
            Source Port:50008
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749957193542033132 12/30/23-06:59:51.858230
            SID:2033132
            Source Port:49957
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749915193542033132 12/30/23-06:59:30.824594
            SID:2033132
            Source Port:49915
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749947193542033132 12/30/23-06:59:46.987477
            SID:2033132
            Source Port:49947
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749905193542033132 12/30/23-06:59:25.049008
            SID:2033132
            Source Port:49905
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749964193542033132 12/30/23-06:59:55.271906
            SID:2033132
            Source Port:49964
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749922193542033132 12/30/23-06:59:34.244220
            SID:2033132
            Source Port:49922
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749943193542033132 12/30/23-06:59:44.719248
            SID:2033132
            Source Port:49943
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849987193542033132 12/30/23-07:00:07.206315
            SID:2033132
            Source Port:49987
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949767193542033132 12/30/23-06:58:03.713667
            SID:2033132
            Source Port:49767
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949788193542033132 12/30/23-06:58:22.517327
            SID:2033132
            Source Port:49788
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749959193542814856 12/30/23-06:59:53.069861
            SID:2814856
            Source Port:49959
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849966193542033132 12/30/23-06:59:56.364852
            SID:2033132
            Source Port:49966
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949833193542814856 12/30/23-06:58:47.656166
            SID:2814856
            Source Port:49833
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749938193542814856 12/30/23-06:59:42.272685
            SID:2814856
            Source Port:49938
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949812193542814856 12/30/23-06:58:36.835456
            SID:2814856
            Source Port:49812
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749901193542033132 12/30/23-06:59:23.075689
            SID:2033132
            Source Port:49901
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749917193542814856 12/30/23-06:59:32.043952
            SID:2814856
            Source Port:49917
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749955193542814856 12/30/23-06:59:51.120533
            SID:2814856
            Source Port:49955
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749868193542033132 12/30/23-06:59:05.905389
            SID:2033132
            Source Port:49868
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749889193542033132 12/30/23-06:59:17.247936
            SID:2033132
            Source Port:49889
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949837193542814856 12/30/23-06:58:49.679623
            SID:2814856
            Source Port:49837
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749934193542814856 12/30/23-06:59:40.323985
            SID:2814856
            Source Port:49934
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849978193542814856 12/30/23-07:00:02.576014
            SID:2814856
            Source Port:49978
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849983193542033132 12/30/23-07:00:05.234340
            SID:2033132
            Source Port:49983
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749960193542033132 12/30/23-06:59:53.321128
            SID:2033132
            Source Port:49960
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949842193542033132 12/30/23-06:58:52.917769
            SID:2033132
            Source Port:49842
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949800193542033132 12/30/23-06:58:29.782591
            SID:2033132
            Source Port:49800
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949816193542814856 12/30/23-06:58:38.952892
            SID:2814856
            Source Port:49816
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949821193542033132 12/30/23-06:58:41.279188
            SID:2033132
            Source Port:49821
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749913193542814856 12/30/23-06:59:30.084234
            SID:2814856
            Source Port:49913
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850006193542814856 12/30/23-07:00:16.760624
            SID:2814856
            Source Port:50006
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749859193542814856 12/30/23-06:59:01.585982
            SID:2814856
            Source Port:49859
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850048193542814856 12/30/23-07:00:37.736713
            SID:2814856
            Source Port:50048
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550067193542033132 12/30/23-07:00:47.256829
            SID:2033132
            Source Port:50067
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749860193542033132 12/30/23-06:59:01.845457
            SID:2033132
            Source Port:49860
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749881193542033132 12/30/23-06:59:13.355381
            SID:2033132
            Source Port:49881
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949846193542033132 12/30/23-06:58:54.722012
            SID:2033132
            Source Port:49846
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850027193542814856 12/30/23-07:00:27.496245
            SID:2814856
            Source Port:50027
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850032193542033132 12/30/23-07:00:29.691730
            SID:2033132
            Source Port:50032
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749951193542814856 12/30/23-06:59:49.163586
            SID:2814856
            Source Port:49951
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850002193542814856 12/30/23-07:00:14.817994
            SID:2814856
            Source Port:50002
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550063193542033132 12/30/23-07:00:45.301340
            SID:2033132
            Source Port:50063
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749864193542033132 12/30/23-06:59:03.844410
            SID:2033132
            Source Port:49864
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749885193542033132 12/30/23-06:59:15.300659
            SID:2033132
            Source Port:49885
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850053193542033132 12/30/23-07:00:40.266642
            SID:2033132
            Source Port:50053
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749930193542814856 12/30/23-06:59:38.383930
            SID:2814856
            Source Port:49930
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949804193542033132 12/30/23-06:58:32.016402
            SID:2033132
            Source Port:49804
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949825193542033132 12/30/23-06:58:43.358709
            SID:2033132
            Source Port:49825
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850040193542814856 12/30/23-07:00:33.829919
            SID:2814856
            Source Port:50040
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749897193542814856 12/30/23-06:59:21.371867
            SID:2814856
            Source Port:49897
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850023193542814856 12/30/23-07:00:25.504623
            SID:2814856
            Source Port:50023
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850044193542814856 12/30/23-07:00:35.791284
            SID:2814856
            Source Port:50044
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749855193542814856 12/30/23-06:58:59.561215
            SID:2814856
            Source Port:49855
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749747193542033132 12/30/23-06:57:26.909123
            SID:2033132
            Source Port:49747
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949808193542033132 12/30/23-06:58:34.389036
            SID:2033132
            Source Port:49808
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949829193542033132 12/30/23-06:58:45.412490
            SID:2033132
            Source Port:49829
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849998193542033132 12/30/23-07:00:12.595313
            SID:2033132
            Source Port:49998
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749741193542033132 12/30/23-06:57:11.270022
            SID:2033132
            Source Port:49741
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749948193542814856 12/30/23-06:59:47.711739
            SID:2814856
            Source Port:49948
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749949193542814856 12/30/23-06:59:48.194602
            SID:2814856
            Source Port:49949
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749743193542033132 12/30/23-06:57:16.443459
            SID:2033132
            Source Port:49743
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849999193542033132 12/30/23-07:00:13.088344
            SID:2033132
            Source Port:49999
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749742193542033132 12/30/23-06:57:13.847951
            SID:2033132
            Source Port:49742
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749944193542814856 12/30/23-06:59:45.216851
            SID:2814856
            Source Port:49944
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849993193542033132 12/30/23-07:00:10.142760
            SID:2033132
            Source Port:49993
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850058193542033132 12/30/23-07:00:42.731334
            SID:2033132
            Source Port:50058
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749943193542814856 12/30/23-06:59:44.723176
            SID:2814856
            Source Port:49943
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749945193542814856 12/30/23-06:59:46.180591
            SID:2814856
            Source Port:49945
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850057193542033132 12/30/23-07:00:42.242902
            SID:2033132
            Source Port:50057
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850059193542033132 12/30/23-07:00:43.221744
            SID:2033132
            Source Port:50059
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749857193542033132 12/30/23-06:59:00.347550
            SID:2033132
            Source Port:49857
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749859193542033132 12/30/23-06:59:01.345120
            SID:2033132
            Source Port:49859
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849994193542033132 12/30/23-07:00:10.626827
            SID:2033132
            Source Port:49994
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749856193542033132 12/30/23-06:58:59.842821
            SID:2033132
            Source Port:49856
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849967193542814856 12/30/23-06:59:57.092698
            SID:2814856
            Source Port:49967
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849997193542033132 12/30/23-07:00:12.105095
            SID:2033132
            Source Port:49997
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850054193542033132 12/30/23-07:00:40.775184
            SID:2033132
            Source Port:50054
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749947193542814856 12/30/23-06:59:47.226861
            SID:2814856
            Source Port:49947
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850055193542033132 12/30/23-07:00:41.261760
            SID:2033132
            Source Port:50055
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849968193542814856 12/30/23-06:59:57.609467
            SID:2814856
            Source Port:49968
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749946193542814856 12/30/23-06:59:46.733187
            SID:2814856
            Source Port:49946
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849995193542033132 12/30/23-07:00:11.110412
            SID:2033132
            Source Port:49995
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850056193542033132 12/30/23-07:00:41.748672
            SID:2033132
            Source Port:50056
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849996193542033132 12/30/23-07:00:11.636031
            SID:2033132
            Source Port:49996
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749858193542033132 12/30/23-06:59:00.844263
            SID:2033132
            Source Port:49858
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849969193542814856 12/30/23-06:59:58.095277
            SID:2814856
            Source Port:49969
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850029193542814856 12/30/23-07:00:28.466902
            SID:2814856
            Source Port:50029
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849973193542814856 12/30/23-07:00:00.069190
            SID:2814856
            Source Port:49973
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849970193542814856 12/30/23-06:59:58.576787
            SID:2814856
            Source Port:49970
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849974193542814856 12/30/23-07:00:00.562308
            SID:2814856
            Source Port:49974
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849977193542814856 12/30/23-07:00:02.069880
            SID:2814856
            Source Port:49977
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749747193542825564 12/30/23-06:57:27.233979
            SID:2825564
            Source Port:49747
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849966193542814856 12/30/23-06:59:56.605198
            SID:2814856
            Source Port:49966
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849975193542814856 12/30/23-07:00:01.086540
            SID:2814856
            Source Port:49975
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849991193542033132 12/30/23-07:00:09.163787
            SID:2033132
            Source Port:49991
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849976193542814856 12/30/23-07:00:01.573004
            SID:2814856
            Source Port:49976
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849992193542033132 12/30/23-07:00:09.652740
            SID:2033132
            Source Port:49992
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849965193542814856 12/30/23-06:59:56.116605
            SID:2814856
            Source Port:49965
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849990193542033132 12/30/23-07:00:08.679646
            SID:2033132
            Source Port:49990
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849971193542814856 12/30/23-06:59:59.069362
            SID:2814856
            Source Port:49971
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849972193542814856 12/30/23-06:59:59.556918
            SID:2814856
            Source Port:49972
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749751193542033132 12/30/23-06:57:37.279473
            SID:2033132
            Source Port:49751
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749730193542033132 12/30/23-06:56:58.314971
            SID:2033132
            Source Port:49730
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749731193542033132 12/30/23-06:57:00.892532
            SID:2033132
            Source Port:49731
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949799193542814856 12/30/23-06:58:29.449482
            SID:2814856
            Source Port:49799
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749752193542033132 12/30/23-06:57:39.791208
            SID:2033132
            Source Port:49752
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949798193542814856 12/30/23-06:58:28.873869
            SID:2814856
            Source Port:49798
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850049193542033132 12/30/23-07:00:38.002839
            SID:2033132
            Source Port:50049
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749732193542033132 12/30/23-06:57:03.485136
            SID:2033132
            Source Port:49732
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749753193542033132 12/30/23-06:57:41.950785
            SID:2033132
            Source Port:49753
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949796193542814856 12/30/23-06:58:27.711457
            SID:2814856
            Source Port:49796
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850047193542033132 12/30/23-07:00:37.016103
            SID:2033132
            Source Port:50047
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949797193542814856 12/30/23-06:58:28.289196
            SID:2814856
            Source Port:49797
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850046193542033132 12/30/23-07:00:36.524654
            SID:2033132
            Source Port:50046
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850048193542033132 12/30/23-07:00:37.496687
            SID:2033132
            Source Port:50048
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949795193542814856 12/30/23-06:58:27.120834
            SID:2814856
            Source Port:49795
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850043193542033132 12/30/23-07:00:35.064965
            SID:2033132
            Source Port:50043
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850044193542033132 12/30/23-07:00:35.550765
            SID:2033132
            Source Port:50044
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749750193542033132 12/30/23-06:57:34.687734
            SID:2033132
            Source Port:49750
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949793193542814856 12/30/23-06:58:25.915869
            SID:2814856
            Source Port:49793
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850019193542814856 12/30/23-07:00:23.516431
            SID:2814856
            Source Port:50019
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850045193542033132 12/30/23-07:00:36.039234
            SID:2033132
            Source Port:50045
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850018193542814856 12/30/23-07:00:23.027394
            SID:2814856
            Source Port:50018
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949794193542814856 12/30/23-06:58:26.526085
            SID:2814856
            Source Port:49794
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749849193542814856 12/30/23-06:58:56.589692
            SID:2814856
            Source Port:49849
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850017193542814856 12/30/23-07:00:22.536265
            SID:2814856
            Source Port:50017
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850038193542814856 12/30/23-07:00:32.847377
            SID:2814856
            Source Port:50038
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749871193542033132 12/30/23-06:59:07.380827
            SID:2033132
            Source Port:49871
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749872193542033132 12/30/23-06:59:07.866667
            SID:2033132
            Source Port:49872
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749848193542814856 12/30/23-06:58:56.080050
            SID:2814856
            Source Port:49848
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850037193542814856 12/30/23-07:00:32.357774
            SID:2814856
            Source Port:50037
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850039193542814856 12/30/23-07:00:33.338541
            SID:2814856
            Source Port:50039
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749851193542033132 12/30/23-06:58:57.350136
            SID:2033132
            Source Port:49851
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850040193542033132 12/30/23-07:00:33.587063
            SID:2033132
            Source Port:50040
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749870193542033132 12/30/23-06:59:06.892440
            SID:2033132
            Source Port:49870
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749873193542033132 12/30/23-06:59:08.354127
            SID:2033132
            Source Port:49873
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749874193542033132 12/30/23-06:59:08.860526
            SID:2033132
            Source Port:49874
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850016193542814856 12/30/23-07:00:22.047418
            SID:2814856
            Source Port:50016
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949792193542814856 12/30/23-06:58:25.292661
            SID:2814856
            Source Port:49792
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749852193542033132 12/30/23-06:58:57.840227
            SID:2033132
            Source Port:49852
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749940193542814856 12/30/23-06:59:43.253908
            SID:2814856
            Source Port:49940
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850013193542814856 12/30/23-07:00:20.180218
            SID:2814856
            Source Port:50013
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850034193542814856 12/30/23-07:00:30.897052
            SID:2814856
            Source Port:50034
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749875193542033132 12/30/23-06:59:09.335661
            SID:2033132
            Source Port:49875
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749876193542033132 12/30/23-06:59:11.164509
            SID:2033132
            Source Port:49876
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749941193542814856 12/30/23-06:59:43.737971
            SID:2814856
            Source Port:49941
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749962193542814856 12/30/23-06:59:54.541480
            SID:2814856
            Source Port:49962
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850035193542814856 12/30/23-07:00:31.380008
            SID:2814856
            Source Port:50035
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949791193542814856 12/30/23-06:58:24.664666
            SID:2814856
            Source Port:49791
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749853193542033132 12/30/23-06:58:58.326027
            SID:2033132
            Source Port:49853
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749855193542033132 12/30/23-06:58:59.316698
            SID:2033132
            Source Port:49855
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850042193542033132 12/30/23-07:00:34.574205
            SID:2033132
            Source Port:50042
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749942193542814856 12/30/23-06:59:44.234619
            SID:2814856
            Source Port:49942
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749963193542814856 12/30/23-06:59:55.027646
            SID:2814856
            Source Port:49963
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850036193542814856 12/30/23-07:00:31.869023
            SID:2814856
            Source Port:50036
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850014193542814856 12/30/23-07:00:20.683832
            SID:2814856
            Source Port:50014
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949790193542814856 12/30/23-06:58:24.039838
            SID:2814856
            Source Port:49790
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749854193542033132 12/30/23-06:58:58.817855
            SID:2033132
            Source Port:49854
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850041193542033132 12/30/23-07:00:34.083405
            SID:2033132
            Source Port:50041
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850030193542814856 12/30/23-07:00:28.954437
            SID:2814856
            Source Port:50030
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749735193542033132 12/30/23-06:57:08.663103
            SID:2033132
            Source Port:49735
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850031193542814856 12/30/23-07:00:29.445787
            SID:2814856
            Source Port:50031
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749754193542033132 12/30/23-06:57:44.074834
            SID:2033132
            Source Port:49754
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749756193542033132 12/30/23-06:57:48.050572
            SID:2033132
            Source Port:49756
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749733193542033132 12/30/23-06:57:06.081901
            SID:2033132
            Source Port:49733
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850012193542814856 12/30/23-07:00:19.695001
            SID:2814856
            Source Port:50012
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749755193542033132 12/30/23-06:57:46.129320
            SID:2033132
            Source Port:49755
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749759193542033132 12/30/23-06:57:51.599816
            SID:2033132
            Source Port:49759
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749729193542814856 12/30/23-06:56:56.048636
            SID:2814856
            Source Port:49729
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749961193542814856 12/30/23-06:59:54.054177
            SID:2814856
            Source Port:49961
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850033193542814856 12/30/23-07:00:30.416672
            SID:2814856
            Source Port:50033
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850011193542814856 12/30/23-07:00:19.203057
            SID:2814856
            Source Port:50011
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850032193542814856 12/30/23-07:00:29.928847
            SID:2814856
            Source Port:50032
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749960193542814856 12/30/23-06:59:53.565099
            SID:2814856
            Source Port:49960
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850010193542814856 12/30/23-07:00:18.717437
            SID:2814856
            Source Port:50010
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749757193542033132 12/30/23-06:57:49.875086
            SID:2033132
            Source Port:49757
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749850193542033132 12/30/23-06:58:56.842955
            SID:2033132
            Source Port:49850
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749952193542033132 12/30/23-06:59:49.412198
            SID:2033132
            Source Port:49952
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749954193542033132 12/30/23-06:59:50.385891
            SID:2033132
            Source Port:49954
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749735193542814856 12/30/23-06:57:08.903912
            SID:2814856
            Source Port:49735
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849976193542033132 12/30/23-07:00:01.334423
            SID:2033132
            Source Port:49976
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749956193542033132 12/30/23-06:59:51.364436
            SID:2033132
            Source Port:49956
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850039193542033132 12/30/23-07:00:33.093585
            SID:2033132
            Source Port:50039
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850050193542814856 12/30/23-07:00:38.709977
            SID:2814856
            Source Port:50050
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949787193542814856 12/30/23-06:58:22.099907
            SID:2814856
            Source Port:49787
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749928193542814856 12/30/23-06:59:37.398460
            SID:2814856
            Source Port:49928
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849978193542033132 12/30/23-07:00:02.331532
            SID:2033132
            Source Port:49978
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749879193542033132 12/30/23-06:59:12.389730
            SID:2033132
            Source Port:49879
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749964193542814856 12/30/23-06:59:55.513903
            SID:2814856
            Source Port:49964
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850035193542033132 12/30/23-07:00:31.140226
            SID:2033132
            Source Port:50035
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850037193542033132 12/30/23-07:00:32.119237
            SID:2033132
            Source Port:50037
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749850193542814856 12/30/23-06:58:57.083342
            SID:2814856
            Source Port:49850
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749877193542033132 12/30/23-06:59:11.416435
            SID:2033132
            Source Port:49877
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749731193542814856 12/30/23-06:57:01.133659
            SID:2814856
            Source Port:49731
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749922193542814856 12/30/23-06:59:34.483645
            SID:2814856
            Source Port:49922
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749926193542814856 12/30/23-06:59:36.421423
            SID:2814856
            Source Port:49926
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949785193542814856 12/30/23-06:58:20.746863
            SID:2814856
            Source Port:49785
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849972193542033132 12/30/23-06:59:59.314289
            SID:2033132
            Source Port:49972
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749761193542033132 12/30/23-06:57:54.828622
            SID:2033132
            Source Port:49761
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949810193542033132 12/30/23-06:58:35.529677
            SID:2033132
            Source Port:49810
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749950193542033132 12/30/23-06:59:48.439896
            SID:2033132
            Source Port:49950
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850033193542033132 12/30/23-07:00:30.175204
            SID:2033132
            Source Port:50033
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749733193542814856 12/30/23-06:57:06.321693
            SID:2814856
            Source Port:49733
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749924193542814856 12/30/23-06:59:35.446750
            SID:2814856
            Source Port:49924
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850007193542814856 12/30/23-07:00:17.242018
            SID:2814856
            Source Port:50007
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949783193542814856 12/30/23-06:58:19.316332
            SID:2814856
            Source Port:49783
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849974193542033132 12/30/23-07:00:00.317197
            SID:2033132
            Source Port:49974
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849984193542814856 12/30/23-07:00:05.970954
            SID:2814856
            Source Port:49984
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849994193542814856 12/30/23-07:00:10.865713
            SID:2814856
            Source Port:49994
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849992193542814856 12/30/23-07:00:09.897175
            SID:2814856
            Source Port:49992
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849996193542814856 12/30/23-07:00:11.851716
            SID:2814856
            Source Port:49996
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850009193542814856 12/30/23-07:00:18.231993
            SID:2814856
            Source Port:50009
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849980193542814856 12/30/23-07:00:04.012515
            SID:2814856
            Source Port:49980
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849988193542814856 12/30/23-07:00:07.946788
            SID:2814856
            Source Port:49988
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849990193542814856 12/30/23-07:00:08.920614
            SID:2814856
            Source Port:49990
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849998193542814856 12/30/23-07:00:12.837253
            SID:2814856
            Source Port:49998
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849980193542033132 12/30/23-07:00:03.827429
            SID:2033132
            Source Port:49980
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849970193542033132 12/30/23-06:59:58.337721
            SID:2033132
            Source Port:49970
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849986193542814856 12/30/23-07:00:06.958269
            SID:2814856
            Source Port:49986
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949789193542814856 12/30/23-06:58:23.407334
            SID:2814856
            Source Port:49789
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749958193542033132 12/30/23-06:59:52.342235
            SID:2033132
            Source Port:49958
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849982193542814856 12/30/23-07:00:04.987660
            SID:2814856
            Source Port:49982
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749948193542033132 12/30/23-06:59:47.472154
            SID:2033132
            Source Port:49948
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849969193542033132 12/30/23-06:59:57.853566
            SID:2033132
            Source Port:49969
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749963193542033132 12/30/23-06:59:54.785800
            SID:2033132
            Source Port:49963
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749942193542033132 12/30/23-06:59:43.992910
            SID:2033132
            Source Port:49942
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749946193542033132 12/30/23-06:59:46.488338
            SID:2033132
            Source Port:49946
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749916193542814856 12/30/23-06:59:31.555556
            SID:2814856
            Source Port:49916
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849988193542033132 12/30/23-07:00:07.700870
            SID:2033132
            Source Port:49988
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749918193542814856 12/30/23-06:59:32.529835
            SID:2814856
            Source Port:49918
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849967193542033132 12/30/23-06:59:56.850603
            SID:2033132
            Source Port:49967
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749939193542814856 12/30/23-06:59:42.759589
            SID:2814856
            Source Port:49939
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749944193542033132 12/30/23-06:59:44.971902
            SID:2033132
            Source Port:49944
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749869193542033132 12/30/23-06:59:06.391520
            SID:2033132
            Source Port:49869
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749912193542814856 12/30/23-06:59:29.607772
            SID:2814856
            Source Port:49912
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749954193542814856 12/30/23-06:59:50.627454
            SID:2814856
            Source Port:49954
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749848193542033132 12/30/23-06:58:55.841355
            SID:2033132
            Source Port:49848
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849982193542033132 12/30/23-07:00:04.772515
            SID:2033132
            Source Port:49982
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849984193542033132 12/30/23-07:00:05.732245
            SID:2033132
            Source Port:49984
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749867193542033132 12/30/23-06:59:05.403704
            SID:2033132
            Source Port:49867
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749888193542033132 12/30/23-06:59:16.761193
            SID:2033132
            Source Port:49888
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749933193542814856 12/30/23-06:59:39.842196
            SID:2814856
            Source Port:49933
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749937193542814856 12/30/23-06:59:41.768490
            SID:2814856
            Source Port:49937
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849965193542033132 12/30/23-06:59:55.878341
            SID:2033132
            Source Port:49965
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949820193542033132 12/30/23-06:58:40.765520
            SID:2033132
            Source Port:49820
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749958193542814856 12/30/23-06:59:52.581860
            SID:2814856
            Source Port:49958
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749961193542033132 12/30/23-06:59:53.811310
            SID:2033132
            Source Port:49961
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849986193542033132 12/30/23-07:00:06.716982
            SID:2033132
            Source Port:49986
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749914193542814856 12/30/23-06:59:30.573264
            SID:2814856
            Source Port:49914
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849979193542814856 12/30/23-07:00:03.071228
            SID:2814856
            Source Port:49979
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949822193542033132 12/30/23-06:58:41.834391
            SID:2033132
            Source Port:49822
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749956193542814856 12/30/23-06:59:51.605514
            SID:2814856
            Source Port:49956
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749935193542814856 12/30/23-06:59:40.802367
            SID:2814856
            Source Port:49935
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749940193542033132 12/30/23-06:59:43.008933
            SID:2033132
            Source Port:49940
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749861193542033132 12/30/23-06:59:02.343732
            SID:2033132
            Source Port:49861
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749882193542033132 12/30/23-06:59:13.841892
            SID:2033132
            Source Port:49882
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850050193542033132 12/30/23-07:00:38.576098
            SID:2033132
            Source Port:50050
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949824193542033132 12/30/23-06:58:42.848389
            SID:2033132
            Source Port:49824
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850049193542814856 12/30/23-07:00:38.223716
            SID:2814856
            Source Port:50049
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949801193542033132 12/30/23-06:58:30.343483
            SID:2033132
            Source Port:49801
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949803193542033132 12/30/23-06:58:31.468455
            SID:2033132
            Source Port:49803
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850026193542814856 12/30/23-07:00:26.960595
            SID:2814856
            Source Port:50026
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850028193542814856 12/30/23-07:00:27.990273
            SID:2814856
            Source Port:50028
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749858193542814856 12/30/23-06:59:01.085903
            SID:2814856
            Source Port:49858
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749863193542033132 12/30/23-06:59:03.347715
            SID:2033132
            Source Port:49863
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749884193542033132 12/30/23-06:59:14.818821
            SID:2033132
            Source Port:49884
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749880193542033132 12/30/23-06:59:12.872848
            SID:2033132
            Source Port:49880
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850005193542814856 12/30/23-07:00:16.273723
            SID:2814856
            Source Port:50005
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949781193542814856 12/30/23-06:58:17.843270
            SID:2814856
            Source Port:49781
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749865193542033132 12/30/23-06:59:04.346123
            SID:2033132
            Source Port:49865
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749886193542033132 12/30/23-06:59:15.787605
            SID:2033132
            Source Port:49886
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850045193542814856 12/30/23-07:00:36.282306
            SID:2814856
            Source Port:50045
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949805193542033132 12/30/23-06:58:32.563530
            SID:2033132
            Source Port:49805
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850024193542814856 12/30/23-07:00:25.988529
            SID:2814856
            Source Port:50024
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850031193542033132 12/30/23-07:00:29.206057
            SID:2033132
            Source Port:50031
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749910193542814856 12/30/23-06:59:28.641541
            SID:2814856
            Source Port:49910
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850052193542033132 12/30/23-07:00:39.896763
            SID:2033132
            Source Port:50052
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749729193542033132 12/30/23-06:56:55.865512
            SID:2033132
            Source Port:49729
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949826193542033132 12/30/23-06:58:43.862219
            SID:2033132
            Source Port:49826
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749952193542814856 12/30/23-06:59:49.653812
            SID:2814856
            Source Port:49952
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850047193542814856 12/30/23-07:00:37.254319
            SID:2814856
            Source Port:50047
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850003193542814856 12/30/23-07:00:15.304449
            SID:2814856
            Source Port:50003
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749931193542814856 12/30/23-06:59:38.869094
            SID:2814856
            Source Port:49931
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749852193542814856 12/30/23-06:58:58.076573
            SID:2814856
            Source Port:49852
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850041193542814856 12/30/23-07:00:34.323025
            SID:2814856
            Source Port:50041
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949809193542033132 12/30/23-06:58:35.007968
            SID:2033132
            Source Port:49809
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850020193542814856 12/30/23-07:00:24.001117
            SID:2814856
            Source Port:50020
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749854193542814856 12/30/23-06:58:59.057474
            SID:2814856
            Source Port:49854
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850001193542814856 12/30/23-07:00:14.328187
            SID:2814856
            Source Port:50001
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749744193542033132 12/30/23-06:57:19.050041
            SID:2033132
            Source Port:49744
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749748193542033132 12/30/23-06:57:29.511857
            SID:2033132
            Source Port:49748
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749856193542814856 12/30/23-06:59:00.087695
            SID:2814856
            Source Port:49856
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949828193542033132 12/30/23-06:58:44.882263
            SID:2033132
            Source Port:49828
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749950193542814856 12/30/23-06:59:48.676663
            SID:2814856
            Source Port:49950
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949807193542033132 12/30/23-06:58:34.079878
            SID:2033132
            Source Port:49807
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850022193542814856 12/30/23-07:00:24.973826
            SID:2814856
            Source Port:50022
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850043193542814856 12/30/23-07:00:35.308067
            SID:2814856
            Source Port:50043
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749746193542033132 12/30/23-06:57:24.324942
            SID:2033132
            Source Port:49746
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749757193542814856 12/30/23-06:57:50.114659
            SID:2814856
            Source Port:49757
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749909193542814856 12/30/23-06:59:27.358945
            SID:2814856
            Source Port:49909
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749908193542814856 12/30/23-06:59:26.758826
            SID:2814856
            Source Port:49908
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749931193542033132 12/30/23-06:59:38.628084
            SID:2033132
            Source Port:49931
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749935193542033132 12/30/23-06:59:40.565444
            SID:2033132
            Source Port:49935
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949800193542814856 12/30/23-06:58:30.022010
            SID:2814856
            Source Port:49800
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749905193542814856 12/30/23-06:59:25.286864
            SID:2814856
            Source Port:49905
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949793193542033132 12/30/23-06:58:25.674401
            SID:2033132
            Source Port:49793
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749934193542033132 12/30/23-06:59:40.085126
            SID:2033132
            Source Port:49934
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949766193542814856 12/30/23-06:58:02.727133
            SID:2814856
            Source Port:49766
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850017193542033132 12/30/23-07:00:22.313219
            SID:2033132
            Source Port:50017
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949792193542033132 12/30/23-06:58:25.052320
            SID:2033132
            Source Port:49792
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949803193542814856 12/30/23-06:58:31.707862
            SID:2814856
            Source Port:49803
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949804193542814856 12/30/23-06:58:32.258279
            SID:2814856
            Source Port:49804
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749901193542814856 12/30/23-06:59:23.312951
            SID:2814856
            Source Port:49901
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850016193542033132 12/30/23-07:00:21.897628
            SID:2033132
            Source Port:50016
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749871193542814856 12/30/23-06:59:07.622024
            SID:2814856
            Source Port:49871
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949763193542814856 12/30/23-06:57:58.790672
            SID:2814856
            Source Port:49763
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749900193542814856 12/30/23-06:59:22.817240
            SID:2814856
            Source Port:49900
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749904193542814856 12/30/23-06:59:24.806589
            SID:2814856
            Source Port:49904
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749753193542814856 12/30/23-06:57:42.189827
            SID:2814856
            Source Port:49753
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850012193542033132 12/30/23-07:00:19.451840
            SID:2033132
            Source Port:50012
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550062193542033132 12/30/23-07:00:44.811642
            SID:2033132
            Source Port:50062
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749754193542814856 12/30/23-06:57:44.316818
            SID:2814856
            Source Port:49754
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749870193542814856 12/30/23-06:59:07.134679
            SID:2814856
            Source Port:49870
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749930193542033132 12/30/23-06:59:38.144940
            SID:2033132
            Source Port:49930
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949762193542814856 12/30/23-06:57:56.779496
            SID:2814856
            Source Port:49762
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850013193542033132 12/30/23-07:00:19.939025
            SID:2033132
            Source Port:50013
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550061193542033132 12/30/23-07:00:44.320331
            SID:2033132
            Source Port:50061
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949830193542033132 12/30/23-06:58:45.902361
            SID:2033132
            Source Port:49830
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749760193542814856 12/30/23-06:57:53.493964
            SID:2814856
            Source Port:49760
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749750193542814856 12/30/23-06:57:34.929638
            SID:2814856
            Source Port:49750
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949767193542814856 12/30/23-06:58:03.958715
            SID:2814856
            Source Port:49767
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749928193542033132 12/30/23-06:59:37.157075
            SID:2033132
            Source Port:49928
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949778193542814856 12/30/23-06:58:14.688767
            SID:2814856
            Source Port:49778
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749939193542033132 12/30/23-06:59:42.518313
            SID:2033132
            Source Port:49939
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949786193542033132 12/30/23-06:58:21.190683
            SID:2033132
            Source Port:49786
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949797193542033132 12/30/23-06:58:28.048530
            SID:2033132
            Source Port:49797
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749938193542033132 12/30/23-06:59:42.031161
            SID:2033132
            Source Port:49938
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749927193542033132 12/30/23-06:59:36.665802
            SID:2033132
            Source Port:49927
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949796193542033132 12/30/23-06:58:27.470586
            SID:2033132
            Source Port:49796
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749747193542814856 12/30/23-06:57:27.150655
            SID:2814856
            Source Port:49747
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949783193542033132 12/30/23-06:58:19.076238
            SID:2033132
            Source Port:49783
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749746193542814856 12/30/23-06:57:24.568832
            SID:2814856
            Source Port:49746
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949777193542814856 12/30/23-06:58:13.872631
            SID:2814856
            Source Port:49777
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850028193542033132 12/30/23-07:00:27.745382
            SID:2033132
            Source Port:50028
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949782193542033132 12/30/23-06:58:18.344993
            SID:2033132
            Source Port:49782
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850006193542033132 12/30/23-07:00:16.520244
            SID:2033132
            Source Port:50006
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850027193542033132 12/30/23-07:00:27.255013
            SID:2033132
            Source Port:50027
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850003193542033132 12/30/23-07:00:15.062948
            SID:2033132
            Source Port:50003
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749860193542814856 12/30/23-06:59:02.085316
            SID:2814856
            Source Port:49860
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949774193542814856 12/30/23-06:58:11.217163
            SID:2814856
            Source Port:49774
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749742193542814856 12/30/23-06:57:14.088663
            SID:2814856
            Source Port:49742
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550072193542033132 12/30/23-07:00:49.694789
            SID:2033132
            Source Port:50072
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749743193542814856 12/30/23-06:57:16.689114
            SID:2814856
            Source Port:49743
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749881193542814856 12/30/23-06:59:13.594722
            SID:2814856
            Source Port:49881
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949773193542814856 12/30/23-06:58:10.300191
            SID:2814856
            Source Port:49773
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850024193542033132 12/30/23-07:00:25.751103
            SID:2033132
            Source Port:50024
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550071193542033132 12/30/23-07:00:49.200940
            SID:2033132
            Source Port:50071
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850002193542033132 12/30/23-07:00:14.574938
            SID:2033132
            Source Port:50002
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850023193542033132 12/30/23-07:00:25.261896
            SID:2033132
            Source Port:50023
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749880193542814856 12/30/23-06:59:13.111628
            SID:2814856
            Source Port:49880
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949813193542033132 12/30/23-06:58:37.111513
            SID:2033132
            Source Port:49813
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949834193542033132 12/30/23-06:58:47.933226
            SID:2033132
            Source Port:49834
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749893193542033132 12/30/23-06:59:19.207463
            SID:2033132
            Source Port:49893
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949812193542033132 12/30/23-06:58:36.594044
            SID:2033132
            Source Port:49812
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949833193542033132 12/30/23-06:58:47.410751
            SID:2033132
            Source Port:49833
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749894193542033132 12/30/23-06:59:19.676849
            SID:2033132
            Source Port:49894
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550076193542033132 12/30/23-07:00:51.670271
            SID:2033132
            Source Port:50076
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749868193542814856 12/30/23-06:59:06.145562
            SID:2814856
            Source Port:49868
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949770193542814856 12/30/23-06:58:07.306224
            SID:2814856
            Source Port:49770
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949838193542033132 12/30/23-06:58:49.935180
            SID:2033132
            Source Port:49838
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749897193542033132 12/30/23-06:59:21.130355
            SID:2033132
            Source Port:49897
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949808193542814856 12/30/23-06:58:34.624993
            SID:2814856
            Source Port:49808
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949816193542033132 12/30/23-06:58:38.707245
            SID:2033132
            Source Port:49816
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949837193542033132 12/30/23-06:58:49.437993
            SID:2033132
            Source Port:49837
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749890193542033132 12/30/23-06:59:17.730882
            SID:2033132
            Source Port:49890
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749898193542033132 12/30/23-06:59:21.612585
            SID:2033132
            Source Port:49898
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850056193542814856 12/30/23-07:00:41.990891
            SID:2814856
            Source Port:50056
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749921193542814856 12/30/23-06:59:34.001695
            SID:2814856
            Source Port:49921
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850020193542033132 12/30/23-07:00:23.762339
            SID:2033132
            Source Port:50020
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850057193542814856 12/30/23-07:00:42.486869
            SID:2814856
            Source Port:50057
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550075193542033132 12/30/23-07:00:51.177057
            SID:2033132
            Source Port:50075
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749884193542814856 12/30/23-06:59:15.059251
            SID:2814856
            Source Port:49884
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749863193542814856 12/30/23-06:59:03.591806
            SID:2814856
            Source Port:49863
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850052193542814856 12/30/23-07:00:40.013512
            SID:2814856
            Source Port:50052
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749885193542814856 12/30/23-06:59:15.538707
            SID:2814856
            Source Port:49885
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749864193542814856 12/30/23-06:59:04.086040
            SID:2814856
            Source Port:49864
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749747193542814860 12/30/23-06:57:27.233979
            SID:2814860
            Source Port:49747
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949817193542033132 12/30/23-06:58:39.233276
            SID:2033132
            Source Port:49817
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749867193542814856 12/30/23-06:59:05.648160
            SID:2814856
            Source Port:49867
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749889193542814856 12/30/23-06:59:17.489613
            SID:2814856
            Source Port:49889
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550079193542033132 12/30/23-07:00:53.177189
            SID:2033132
            Source Port:50079
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850053193542814856 12/30/23-07:00:40.509000
            SID:2814856
            Source Port:50053
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749888193542814856 12/30/23-06:59:17.003077
            SID:2814856
            Source Port:49888
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749929193542814856 12/30/23-06:59:37.897152
            SID:2814856
            Source Port:49929
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849979193542033132 12/30/23-07:00:02.833960
            SID:2033132
            Source Port:49979
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749913193542033132 12/30/23-06:59:29.847668
            SID:2033132
            Source Port:49913
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949772193542033132 12/30/23-06:58:09.095731
            SID:2033132
            Source Port:49772
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949776193542033132 12/30/23-06:58:12.779493
            SID:2033132
            Source Port:49776
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949788193542814856 12/30/23-06:58:22.759732
            SID:2814856
            Source Port:49788
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749955193542033132 12/30/23-06:59:50.878260
            SID:2033132
            Source Port:49955
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850038193542033132 12/30/23-07:00:32.609416
            SID:2033132
            Source Port:50038
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949825193542814856 12/30/23-06:58:43.598734
            SID:2814856
            Source Port:49825
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849971193542033132 12/30/23-06:59:58.824501
            SID:2033132
            Source Port:49971
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949784193542814856 12/30/23-06:58:20.048612
            SID:2814856
            Source Port:49784
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749732193542814856 12/30/23-06:57:03.726887
            SID:2814856
            Source Port:49732
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949829193542814856 12/30/23-06:58:45.628952
            SID:2814856
            Source Port:49829
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849975193542033132 12/30/23-07:00:00.846778
            SID:2033132
            Source Port:49975
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749925193542814856 12/30/23-06:59:35.937314
            SID:2814856
            Source Port:49925
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749951193542033132 12/30/23-06:59:48.922026
            SID:2033132
            Source Port:49951
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850008193542814856 12/30/23-07:00:17.739937
            SID:2814856
            Source Port:50008
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550082193542033132 12/30/23-07:00:57.990897
            SID:2033132
            Source Port:50082
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749891193542814856 12/30/23-06:59:18.463462
            SID:2814856
            Source Port:49891
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850034193542033132 12/30/23-07:00:30.660872
            SID:2033132
            Source Port:50034
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849987193542814856 12/30/23-07:00:07.450556
            SID:2814856
            Source Port:49987
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949840193542033132 12/30/23-06:58:51.058204
            SID:2033132
            Source Port:49840
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849997193542814856 12/30/23-07:00:12.349998
            SID:2814856
            Source Port:49997
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849981193542033132 12/30/23-07:00:04.257676
            SID:2033132
            Source Port:49981
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749949193542033132 12/30/23-06:59:47.956084
            SID:2033132
            Source Port:49949
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749917193542033132 12/30/23-06:59:31.804979
            SID:2033132
            Source Port:49917
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749907193542033132 12/30/23-06:59:26.034167
            SID:2033132
            Source Port:49907
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949821193542814856 12/30/23-06:58:41.518023
            SID:2814856
            Source Port:49821
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949810193542814856 12/30/23-06:58:35.769712
            SID:2814856
            Source Port:49810
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749959193542033132 12/30/23-06:59:52.826362
            SID:2033132
            Source Port:49959
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849993193542814856 12/30/23-07:00:10.379084
            SID:2814856
            Source Port:49993
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849983193542814856 12/30/23-07:00:05.478752
            SID:2814856
            Source Port:49983
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849968193542033132 12/30/23-06:59:57.372313
            SID:2033132
            Source Port:49968
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749941193542033132 12/30/23-06:59:43.498607
            SID:2033132
            Source Port:49941
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949765193542033132 12/30/23-06:58:01.233628
            SID:2033132
            Source Port:49765
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749920193542033132 12/30/23-06:59:33.270015
            SID:2033132
            Source Port:49920
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749924193542033132 12/30/23-06:59:35.208692
            SID:2033132
            Source Port:49924
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749903193542033132 12/30/23-06:59:24.070627
            SID:2033132
            Source Port:49903
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749919193542814856 12/30/23-06:59:33.018377
            SID:2814856
            Source Port:49919
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749945193542033132 12/30/23-06:59:46.067668
            SID:2033132
            Source Port:49945
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849989193542033132 12/30/23-07:00:08.205585
            SID:2033132
            Source Port:49989
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949814193542814856 12/30/23-06:58:37.887301
            SID:2814856
            Source Port:49814
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949835193542814856 12/30/23-06:58:48.686724
            SID:2814856
            Source Port:49835
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749932193542814856 12/30/23-06:59:39.358213
            SID:2814856
            Source Port:49932
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949769193542033132 12/30/23-06:58:05.988000
            SID:2033132
            Source Port:49769
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749911193542814856 12/30/23-06:59:29.126763
            SID:2814856
            Source Port:49911
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749915193542814856 12/30/23-06:59:31.070055
            SID:2814856
            Source Port:49915
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749849193542033132 12/30/23-06:58:56.346466
            SID:2033132
            Source Port:49849
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949818193542814856 12/30/23-06:58:39.988518
            SID:2814856
            Source Port:49818
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949839193542814856 12/30/23-06:58:50.694196
            SID:2814856
            Source Port:49839
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749936193542814856 12/30/23-06:59:41.281512
            SID:2814856
            Source Port:49936
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749962193542033132 12/30/23-06:59:54.301440
            SID:2033132
            Source Port:49962
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749957193542814856 12/30/23-06:59:52.099962
            SID:2814856
            Source Port:49957
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1849985193542033132 12/30/23-07:00:06.216832
            SID:2033132
            Source Port:49985
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949802193542033132 12/30/23-06:58:30.906256
            SID:2033132
            Source Port:49802
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949823193542033132 12/30/23-06:58:42.341539
            SID:2033132
            Source Port:49823
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749862193542033132 12/30/23-06:59:02.844678
            SID:2033132
            Source Port:49862
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749883193542033132 12/30/23-06:59:14.334660
            SID:2033132
            Source Port:49883
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850051193542033132 12/30/23-07:00:39.525800
            SID:2033132
            Source Port:50051
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949844193542033132 12/30/23-06:58:53.721212
            SID:2033132
            Source Port:49844
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749749193542033132 12/30/23-06:57:32.111036
            SID:2033132
            Source Port:49749
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949827193542033132 12/30/23-06:58:44.367837
            SID:2033132
            Source Port:49827
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749866193542033132 12/30/23-06:59:04.846811
            SID:2033132
            Source Port:49866
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749887193542033132 12/30/23-06:59:16.275491
            SID:2033132
            Source Port:49887
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949780193542814856 12/30/23-06:58:17.081603
            SID:2814856
            Source Port:49780
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850004193542814856 12/30/23-07:00:15.787254
            SID:2814856
            Source Port:50004
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749953193542814856 12/30/23-06:59:50.142653
            SID:2814856
            Source Port:49953
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850046193542814856 12/30/23-07:00:36.764056
            SID:2814856
            Source Port:50046
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550065193542033132 12/30/23-07:00:46.284271
            SID:2033132
            Source Port:50065
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749895193542814856 12/30/23-06:59:20.392745
            SID:2814856
            Source Port:49895
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850025193542814856 12/30/23-07:00:26.469978
            SID:2814856
            Source Port:50025
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850030193542033132 12/30/23-07:00:28.712067
            SID:2033132
            Source Port:50030
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749745193542033132 12/30/23-06:57:21.641720
            SID:2033132
            Source Port:49745
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749853193542814856 12/30/23-06:58:58.560128
            SID:2814856
            Source Port:49853
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749874193542814856 12/30/23-06:59:09.083915
            SID:2814856
            Source Port:49874
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.156.13.20949806193542033132 12/30/23-06:58:33.167163
            SID:2033132
            Source Port:49806
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749857193542814856 12/30/23-06:59:00.592542
            SID:2814856
            Source Port:49857
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749878193542814856 12/30/23-06:59:12.145204
            SID:2814856
            Source Port:49878
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850000193542814856 12/30/23-07:00:13.841135
            SID:2814856
            Source Port:50000
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850042193542814856 12/30/23-07:00:34.818033
            SID:2814856
            Source Port:50042
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.418.197.239.550069193542033132 12/30/23-07:00:48.227392
            SID:2033132
            Source Port:50069
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.127.138.5749899193542814856 12/30/23-06:59:22.330011
            SID:2814856
            Source Port:49899
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.43.126.37.1850021193542814856 12/30/23-07:00:24.486098
            SID:2814856
            Source Port:50021
            Destination Port:19354
            Protocol:TCP
            Classtype:A Network Trojan was detected

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: tiodtk2cfy.exeAvira: detected
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeAvira: detection malicious, Label: TR/Dropper.Gen
            Source: C:\Umbrella.flv.exeAvira: detection malicious, Label: TR/Dropper.Gen
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeAvira: detection malicious, Label: TR/Dropper.Gen
            Source: C:\winhost.exeAvira: detection malicious, Label: TR/Dropper.Gen
            Source: C:\Users\user\AppData\Roaming\server.exeAvira: detection malicious, Label: TR/Dropper.Gen
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpackMalware Configuration Extractor: Njrat {"Campaign ID": "VicTim", "Version": "0.7d", "Install Name": "a1d56127836419435d08d7cc0808a629", "Install Dir": "system", "Registry Value": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Network Seprator": "|'|'|"}
            Source: 2.tcp.eu.ngrok.ioVirustotal: Detection: 12%Perma Link
            Source: C:\Umbrella.flv.exeReversingLabs: Detection: 83%
            Source: C:\Umbrella.flv.exeVirustotal: Detection: 81%Perma Link
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeReversingLabs: Detection: 83%
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeVirustotal: Detection: 81%Perma Link
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeReversingLabs: Detection: 83%
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeVirustotal: Detection: 81%Perma Link
            Source: C:\Users\user\AppData\Roaming\server.exeReversingLabs: Detection: 83%
            Source: C:\Users\user\AppData\Roaming\server.exeVirustotal: Detection: 81%Perma Link
            Source: C:\winhost.exeReversingLabs: Detection: 83%
            Source: C:\winhost.exeVirustotal: Detection: 81%Perma Link
            Source: tiodtk2cfy.exeReversingLabs: Detection: 83%
            Source: tiodtk2cfy.exeVirustotal: Detection: 81%Perma Link
            Source: Yara matchFile source: tiodtk2cfy.exe, type: SAMPLE
            Source: Yara matchFile source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: tiodtk2cfy.exe PID: 7508, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: server.exe PID: 7592, type: MEMORYSTR
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPED
            Source: Yara matchFile source: C:\Umbrella.flv.exe, type: DROPPED
            Source: Yara matchFile source: C:\winhost.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPED
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeJoe Sandbox ML: detected
            Source: C:\Umbrella.flv.exeJoe Sandbox ML: detected
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeJoe Sandbox ML: detected
            Source: C:\winhost.exeJoe Sandbox ML: detected
            Source: C:\Users\user\AppData\Roaming\server.exeJoe Sandbox ML: detected
            Source: tiodtk2cfy.exeJoe Sandbox ML: detected
            Source: tiodtk2cfy.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
            Source: tiodtk2cfy.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Spreading

            barindex
            Source: tiodtk2cfy.exe, Usb1.cs.Net Code: infect
            Source: server.exe.0.dr, Usb1.cs.Net Code: infect
            Source: Microsoft Corporation.exe.1.dr, Usb1.cs.Net Code: infect
            Source: a1d56127836419435d08d7cc0808a629Windows Update.exe.1.dr, Usb1.cs.Net Code: infect
            Source: Umbrella.flv.exe.1.dr, Usb1.cs.Net Code: infect
            Source: winhost.exe.1.dr, Usb1.cs.Net Code: infect
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\autorun.infJump to behavior
            Source: tiodtk2cfy.exe, 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: \autorun.inf
            Source: tiodtk2cfy.exe, 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: [autorun]
            Source: tiodtk2cfy.exe, 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: autorun.inf
            Source: tiodtk2cfy.exe, 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: \autorun.inf
            Source: tiodtk2cfy.exe, 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: [autorun]
            Source: tiodtk2cfy.exe, 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: autorun.inf
            Source: server.exe, 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: \autorun.inf
            Source: server.exe, 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: [autorun]
            Source: server.exe, 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: autorun.inf$OFk
            Source: tiodtk2cfy.exeBinary or memory string: \autorun.inf
            Source: tiodtk2cfy.exeBinary or memory string: [autorun]
            Source: tiodtk2cfy.exeBinary or memory string: autorun.inf
            Source: autorun.inf.1.drBinary or memory string: [autorun]
            Source: Microsoft Corporation.exe.1.drBinary or memory string: \autorun.inf
            Source: Microsoft Corporation.exe.1.drBinary or memory string: [autorun]
            Source: Microsoft Corporation.exe.1.drBinary or memory string: autorun.inf
            Source: Umbrella.flv.exe.1.drBinary or memory string: \autorun.inf
            Source: Umbrella.flv.exe.1.drBinary or memory string: [autorun]
            Source: Umbrella.flv.exe.1.drBinary or memory string: autorun.inf
            Source: a1d56127836419435d08d7cc0808a629Windows Update.exe.1.drBinary or memory string: \autorun.inf
            Source: a1d56127836419435d08d7cc0808a629Windows Update.exe.1.drBinary or memory string: [autorun]
            Source: a1d56127836419435d08d7cc0808a629Windows Update.exe.1.drBinary or memory string: autorun.inf
            Source: winhost.exe.1.drBinary or memory string: \autorun.inf
            Source: winhost.exe.1.drBinary or memory string: [autorun]
            Source: winhost.exe.1.drBinary or memory string: autorun.inf
            Source: server.exe.0.drBinary or memory string: \autorun.inf
            Source: server.exe.0.drBinary or memory string: [autorun]
            Source: server.exe.0.drBinary or memory string: autorun.inf

            Networking

            barindex
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49729 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49729 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49730 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49730 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49731 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49731 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49732 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49732 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49733 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49733 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49735 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49735 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49741 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49741 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49742 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49742 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49743 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49743 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49744 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49744 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49745 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49745 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49746 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49746 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49747 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49747 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814860 ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) 192.168.2.4:49747 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2825564 ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) 192.168.2.4:49747 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49748 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49748 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49749 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49749 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49750 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49750 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49751 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49751 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49752 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49752 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49753 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49753 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49754 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49754 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49755 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49755 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49756 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49756 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49757 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49757 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49759 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49759 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49760 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49760 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49761 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49761 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49762 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49762 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49763 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49763 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49764 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49764 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49765 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49765 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49766 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49766 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49767 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49767 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49768 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49768 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49769 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49769 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49770 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49770 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49771 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49771 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49772 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49772 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49773 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49773 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49774 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49774 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49775 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49775 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49776 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49776 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49777 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49777 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49778 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49778 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49779 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49779 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49780 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49780 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49781 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49781 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49782 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49782 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49783 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49783 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49784 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49784 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49785 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49785 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49786 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49786 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49787 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49787 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49788 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49788 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49789 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49789 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49790 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49790 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49791 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49791 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49792 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49792 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49793 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49793 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49794 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49794 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49795 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49795 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49796 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49796 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49797 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49797 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49798 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49798 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49799 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49799 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49800 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49800 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49801 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49801 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49802 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49802 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49803 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49803 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49804 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49804 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49805 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49805 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49806 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49806 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49807 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49808 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49808 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49809 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49809 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49810 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49810 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49811 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49811 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49812 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49812 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49813 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49813 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49814 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49814 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49815 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49815 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49816 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49816 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49817 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49817 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49818 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49818 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49819 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49819 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49820 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49820 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49821 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49821 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49822 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49822 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49823 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49823 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49824 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49824 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49825 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49825 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49826 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49826 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49827 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49827 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49828 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49828 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49829 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49829 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49830 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49830 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49831 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49831 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49832 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49832 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49833 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49833 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49834 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49834 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49835 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49835 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49836 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49836 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49837 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49837 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49838 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49838 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49839 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49839 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49840 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49840 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49841 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49842 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49843 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49843 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49844 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49844 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49845 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49845 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49846 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49846 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49847 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49847 -> 18.156.13.209:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49848 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49848 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49849 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49849 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49850 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49850 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49851 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49851 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49852 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49852 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49853 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49853 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49854 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49854 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49855 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49855 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49856 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49856 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49857 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49857 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49858 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49858 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49859 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49859 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49860 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49860 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49861 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49861 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49862 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49862 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49863 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49863 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49864 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49864 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49865 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49865 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49866 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49866 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49867 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49867 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49868 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49868 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49869 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49869 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49870 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49870 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49871 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49871 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49872 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49872 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49873 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49873 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49874 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49874 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49875 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49875 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49876 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49877 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49877 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49878 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49878 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49879 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49879 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49880 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49880 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49881 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49881 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49882 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49882 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49883 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49883 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49884 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49884 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49885 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49885 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49886 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49886 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49887 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49887 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49888 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49888 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49889 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49889 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49890 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49890 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49891 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49891 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49892 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49892 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49893 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49893 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49894 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49894 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49895 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49895 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49896 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49896 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49897 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49897 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49898 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49898 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49899 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49899 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49900 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49900 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49901 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49901 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49902 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49902 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49903 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49903 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49904 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49904 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49905 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49905 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49906 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49906 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49907 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49907 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49908 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49908 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49909 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49909 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49910 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49910 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49911 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49911 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49912 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49912 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49913 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49913 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49914 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49914 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49915 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49915 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49916 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49916 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49917 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49917 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49918 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49918 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49919 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49919 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49920 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49920 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49921 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49921 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49922 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49922 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49923 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49923 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49924 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49924 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49925 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49925 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49926 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49926 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49927 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49927 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49928 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49928 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49929 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49929 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49930 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49930 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49931 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49931 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49932 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49932 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49933 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49933 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49934 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49934 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49935 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49935 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49936 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49936 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49937 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49937 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49938 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49938 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49939 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49939 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49940 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49940 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49941 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49941 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49942 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49942 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49943 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49943 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49944 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49944 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49945 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49945 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49946 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49946 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49947 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49947 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49948 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49948 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49949 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49949 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49950 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49950 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49951 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49951 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49952 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49952 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49953 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49953 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49954 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49954 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49955 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49955 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49956 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49956 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49957 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49957 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49958 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49958 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49959 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49959 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49960 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49960 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49961 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49961 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49962 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49962 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49963 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49963 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49964 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49964 -> 3.127.138.57:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49965 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49965 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49966 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49966 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49967 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49967 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49968 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49968 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49969 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49969 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49970 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49970 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49971 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49971 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49972 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49972 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49973 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49973 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49974 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49974 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49975 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49975 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49976 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49976 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49977 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49977 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49978 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49978 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49979 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49979 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49980 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49980 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49981 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49981 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49982 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49982 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49983 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49983 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49984 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49984 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49985 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49985 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.4:49986 -> 3.126.37.18:19354
            Source: TrafficSnort IDS: 2814856 ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) 192.168.2.4:49986 -> 3.126.37.18:19354
            Source: global trafficTCP traffic: 3.127.138.57 ports 19354,1,3,4,5,9
            Source: global trafficTCP traffic: 18.156.13.209 ports 19354,1,3,4,5,9
            Source: global trafficTCP traffic: 3.126.37.18 ports 19354,1,3,4,5,9
            Source: global trafficTCP traffic: 18.197.239.5 ports 19354,1,3,4,5,9
            Source: global trafficTCP traffic: 192.168.2.4:49729 -> 3.127.138.57:19354
            Source: global trafficTCP traffic: 192.168.2.4:49762 -> 18.156.13.209:19354
            Source: global trafficTCP traffic: 192.168.2.4:49965 -> 3.126.37.18:19354
            Source: global trafficTCP traffic: 192.168.2.4:50060 -> 18.197.239.5:19354
            Source: Joe Sandbox ViewIP Address: 3.127.138.57 3.127.138.57
            Source: Joe Sandbox ViewIP Address: 18.156.13.209 18.156.13.209
            Source: Joe Sandbox ViewASN Name: AMAZON-02US AMAZON-02US
            Source: Joe Sandbox ViewASN Name: AMAZON-02US AMAZON-02US
            Source: Joe Sandbox ViewASN Name: AMAZON-02US AMAZON-02US
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownDNS traffic detected: queries for: 2.tcp.eu.ngrok.io
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior

            E-Banking Fraud

            barindex
            Source: Yara matchFile source: tiodtk2cfy.exe, type: SAMPLE
            Source: Yara matchFile source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: tiodtk2cfy.exe PID: 7508, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: server.exe PID: 7592, type: MEMORYSTR
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPED
            Source: Yara matchFile source: C:\Umbrella.flv.exe, type: DROPPED
            Source: Yara matchFile source: C:\winhost.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPED

            System Summary

            barindex
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: C:\winhost.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 Author: unknown
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: C:\winhost.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: C:\winhost.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: C:\winhost.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: Detects malware from disclosed CN malware set Author: Florian Roth
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: detect njRAT in memory Author: JPCERT/CC Incident Response Group
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: Detects NjRAT / Bladabindi Author: ditekSHen
            Source: C:\Users\user\AppData\Roaming\server.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_05090706 NtQuerySystemInformation,1_2_05090706
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_050906D5 NtQuerySystemInformation,1_2_050906D5
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_00A52BDB0_2_00A52BDB
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C442980_2_04C44298
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C445440_2_04C44544
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C447D40_2_04C447D4
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C4505D0_2_04C4505D
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C44B5B0_2_04C44B5B
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C450E30_2_04C450E3
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C4536F0_2_04C4536F
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C442690_2_04C44269
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C444F10_2_04C444F1
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C449F90_2_04C449F9
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C450000_2_04C45000
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C4470F0_2_04C4470F
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C44C8F0_2_04C44C8F
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C44F9D0_2_04C44F9D
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C4499D0_2_04C4499D
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C44F2F0_2_04C44F2F
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C449360_2_04C44936
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C446300_2_04C44630
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeCode function: 0_2_04C454590_2_04C45459
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_00942DB61_2_00942DB6
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048442981_2_04844298
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048475A81_2_048475A8
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_0484758E1_2_0484758E
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_0484499D1_2_0484499D
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048447D41_2_048447D4
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048444F11_2_048444F1
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048449F91_2_048449F9
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_0484470F1_2_0484470F
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048449361_2_04844936
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048446301_2_04844630
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048445441_2_04844544
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_04844B5B1_2_04844B5B
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048442691_2_04844269
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_04844C8F1_2_04844C8F
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_04844F9D1_2_04844F9D
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048450E31_2_048450E3
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048450001_2_04845000
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_04844F2F1_2_04844F2F
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_0484505D1_2_0484505D
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_048454591_2_04845459
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_0484536F1_2_0484536F
            Source: tiodtk2cfy.exe, 00000000.00000002.1629752992.0000000000A8E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemscorwks.dllT vs tiodtk2cfy.exe
            Source: tiodtk2cfy.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: tiodtk2cfy.exe, type: SAMPLEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: C:\winhost.exe, type: DROPPEDMatched rule: Windows_Trojan_Njrat_30f3c220 reference_sample = 741a0f3954499c11f9eddc8df7c31e7c59ca41f1a7005646735b8b1d53438c1b, os = windows, severity = x86, creation_date = 2021-06-13, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Njrat, fingerprint = d15e131bca6beddcaecb20fffaff1784ad8a33a25e7ce90f7450d1a362908cc4, id = 30f3c220-b8dc-45a1-bcf0-027c2f76fa63, last_modified = 2021-10-04
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: C:\Umbrella.flv.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: C:\winhost.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: C:\winhost.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: C:\winhost.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: CN_disclosed_20180208_c date = 2018-02-08, hash1 = 17475d25d40c877284e73890a9dd55fccedc6a5a071c351a8c342c8ef7f9cea7, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: Njrat hash1 = d5f63213ce11798879520b0e9b0d1b68d55f7727758ec8c120e370699a41379d, author = JPCERT/CC Incident Response Group, description = detect njRAT in memory, rule_usage = memory scan
            Source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPEDMatched rule: MALWARE_Win_NjRAT author = ditekSHen, description = Detects NjRAT / Bladabindi
            Source: classification engineClassification label: mal100.spre.phis.troj.adwa.evad.winEXE@7/10@5/4
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_0509058A AdjustTokenPrivileges,1_2_0509058A
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_05090553 AdjustTokenPrivileges,1_2_05090553
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile created: C:\Users\user\AppData\Roaming\appJump to behavior
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7652:120:WilError_03
            Source: C:\Users\user\AppData\Roaming\server.exeMutant created: \Sessions\1\BaseNamedObjects\a1d56127836419435d08d7cc0808a629
            Source: C:\Users\user\AppData\Roaming\server.exeMutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile created: C:\Users\user\AppData\Local\Temp\FransescoPast.txtJump to behavior
            Source: tiodtk2cfy.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: tiodtk2cfy.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\276d7f4a20a3c21c3bf6fc9bfc1915a2\mscorlib.ni.dllJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\276d7f4a20a3c21c3bf6fc9bfc1915a2\mscorlib.ni.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeSection loaded: C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\276d7f4a20a3c21c3bf6fc9bfc1915a2\mscorlib.ni.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeSection loaded: C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: tiodtk2cfy.exeReversingLabs: Detection: 83%
            Source: tiodtk2cfy.exeVirustotal: Detection: 81%
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile read: C:\Users\user\Desktop\tiodtk2cfy.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\tiodtk2cfy.exe C:\Users\user\Desktop\tiodtk2cfy.exe
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess created: C:\Users\user\AppData\Roaming\server.exe "C:\Users\user\AppData\Roaming\server.exe"
            Source: C:\Users\user\AppData\Roaming\server.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\server.exe" "server.exe" ENABLE
            Source: C:\Windows\SysWOW64\netsh.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: unknownProcess created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe"
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess created: C:\Users\user\AppData\Roaming\server.exe "C:\Users\user\AppData\Roaming\server.exe" Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\server.exe" "server.exe" ENABLEJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32Jump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dllJump to behavior
            Source: tiodtk2cfy.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
            Source: tiodtk2cfy.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Data Obfuscation

            barindex
            Source: tiodtk2cfy.exe, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
            Source: server.exe.0.dr, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
            Source: Microsoft Corporation.exe.1.dr, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
            Source: a1d56127836419435d08d7cc0808a629Windows Update.exe.1.dr, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
            Source: Umbrella.flv.exe.1.dr, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
            Source: winhost.exe.1.dr, Fransesco.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])
            Source: C:\Users\user\AppData\Roaming\server.exeCode function: 1_2_00AF1060 pushfd ; retf 0000h1_2_00AF1065
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeJump to dropped file
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeFile created: C:\Users\user\AppData\Roaming\server.exeJump to dropped file
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\winhost.exeJump to dropped file
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeJump to dropped file
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Umbrella.flv.exeJump to dropped file

            Boot Survival

            barindex
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeJump to dropped file
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeJump to dropped file
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exeJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeWindow / User API: threadDelayed 1995Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeWindow / User API: threadDelayed 2639Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeWindow / User API: foregroundWindowGot 682Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeWindow / User API: foregroundWindowGot 704Jump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exe TID: 7528Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exe TID: 7716Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exe TID: 7596Thread sleep time: -1995000s >= -30000sJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exe TID: 7596Thread sleep time: -2639000s >= -30000sJump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe TID: 8056Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: server.exe, 00000001.00000002.4063080190.0000000000769000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWdlImporters>
            Source: netsh.exe, 00000002.00000002.1646926055.0000000000EDA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllY
            Source: tiodtk2cfy.exe, 00000000.00000002.1629752992.0000000000B06000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
            Source: server.exe, 00000001.00000002.4063080190.0000000000769000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllss#SuspenderProcesss!RestarttProcesss!PermisaoStartUpp%ChamaFrmStartUpsss#EnviarStartupsssa]Software\Microsoft\Windows\CurrentVersion\Run\
            Source: tiodtk2cfy.exe, 00000000.00000002.1629752992.0000000000B06000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\=
            Source: C:\Users\user\AppData\Roaming\server.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeMemory allocated: page read and write | page guardJump to behavior
            Source: C:\Users\user\Desktop\tiodtk2cfy.exeProcess created: C:\Users\user\AppData\Roaming\server.exe "C:\Users\user\AppData\Roaming\server.exe" Jump to behavior
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 20:58:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:52:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 08:31:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:46:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:17:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:54:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 02:45:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:54:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:41:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:26:48 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 23:36:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:36:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:01:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:05:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:09:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:40:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:12:20 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:00:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 18:15:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:39:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:52:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:46:06 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 07:39:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 10:04:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 23:56:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:04:20 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 01:16:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 09:40:19 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 04:44:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 19:00:48 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:02:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:12:16 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:02:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:22:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:29:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 09:38:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 17:53:56 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:42:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:15:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 06:50:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:01:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/03 | 01:02:01 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:24:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:04:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:30:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:10:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:13:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:25:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:32:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:44:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 06:53:09 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:53:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:59:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:17:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:22:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:36:59 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 10:30:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:20:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 06:45:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:18:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:29:36 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:53:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:15:59 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:53:48 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:26:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 07:08:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:28:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:23:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:45:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:58:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:33:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:05:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:43:32 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:17:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:53:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:45:43 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 01:27:51 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:38:32 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:58:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:13:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:49:20 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:01:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 02:18:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:53:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:50:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:45:20 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 09:24:01 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:48:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:09:16 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:14:09 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 20:15:19 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:52:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:17:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:38:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:31:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:48:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:40:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 09:51:08 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:34:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:42:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:37:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:21:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:52:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:59:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:19:08 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 06:40:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 06:18:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:29:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 20:59:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 19:48:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:41:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/03 | 00:47:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:49:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:37:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 10:20:19 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 12:36:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:14:58 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:28:27 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:23:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:07:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 06:05:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:12:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:24:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:13:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:44:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:55:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:58:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:09:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:06:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:48:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:13:08 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:15:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:17:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:01:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:38:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:07:32 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:50:20 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:56:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 08:26:32 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:10:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:18:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 09:30:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/03 | 01:00:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:46:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:23:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 19:17:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:27:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 06:33:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 07:17:09 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:37:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:11:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:56:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 19:33:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:28:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:45:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:21:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 12:50:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:51:22 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 12:03:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:28:06 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:32:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:04:51 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:51:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:16:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:49:36 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:37:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:31:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:09:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:51:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:08:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 02:52:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:59:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:28:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:28:41 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:39:16 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:05:39 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002A33000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 23:51:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 01:27:51 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:19:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:38:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:53:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:36:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:40:52 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:21:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:31:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:43:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:59:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:24:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:43:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:28:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 10:40:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:03:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:50:01 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 18:46:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:25:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:35:22 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:43:59 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:31:04 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:23:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:06:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:53:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:21:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:08:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:41:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 20:33:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:33:27 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:07:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 09:49:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 19:53:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:23:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:04:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 06:49:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:38:09 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:19:51 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:02:41 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 10:36:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:54:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:46:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 01:53:56 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:33:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:05:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:16:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 07:22:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:30:41 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:57:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:12:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:08:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:54:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:06:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:59:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:12:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:29:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:47:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/03 | 00:12:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:40:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:27:16 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 17:10:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:19:22 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:00:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:47:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:39:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:53:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 02:34:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:54:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 06:13:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:27:06 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:10:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:21:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 13:28:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:55:09 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:00:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:01:47 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 02:37:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:46:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 17:52:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 02:03:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 07:35:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:09:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:34:01 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 06:51:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:23:48 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/03 | 01:03:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:46:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:38:51 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:24:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 01:03:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 18:52:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:11:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:33:59 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 20:14:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:35:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:27:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:55:32 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:28:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 09:29:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:43:41 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:12:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:29:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:17:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:03:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:04:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:51:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:51:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:01:56 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:02:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:19:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:28:43 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:49:41 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 07:13:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:59:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:51:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:53:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:02:27 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 13:00:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:58:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:49:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:27:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:59:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:23:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 01:41:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:13:41 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 06:14:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:54:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:40:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:33:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:21:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:10:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 02:51:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 04:39:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:26:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 20:37:25 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:25:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:04:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:14:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:00:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 01:46:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:00:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:04:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:41:36 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:29:48 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:32:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:14:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:42:06 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:10:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:35:43 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:17:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:12:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:08:19 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:47:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:20:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:40:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:06:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:36:01 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:15:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:42:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:48:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:43:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 06:43:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 07:41:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 05:52:09 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 06:49:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:18:19 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 01:55:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:24:05 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:27:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:04:01 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 05:44:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:54:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 01:24:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:06:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 08:38:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:08:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 19:37:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:37:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:07:01 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 07:27:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 12:38:00 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:04:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 02:31:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 13:26:10 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:04:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:44:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 17:29:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:53:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:58:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 01:08:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 07:16:16 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:38:43 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:17:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:19:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:47:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 16:58:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 06:59:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:21:17 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 07:05:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:38:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:40:05 - Program Manager
            Source: tiodtk2cfy.exe, Microsoft Corporation.exe.1.dr, Umbrella.flv.exe.1.dr, a1d56127836419435d08d7cc0808a629Windows Update.exe.1.dr, winhost.exe.1.dr, server.exe.0.drBinary or memory string: Shell_traywnd+MostrarBarraDeTarefas
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:41:08 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:26:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:08:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 12:02:56 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:05:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:29:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 05:32:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:03:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:34:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 02:10:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:30:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 08:14:50 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:51:01 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:16:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:14:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 18:33:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:18:52 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:24:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:33:22 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:58:54 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:26:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:59:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:42:06 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:02:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:16:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 13:05:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:13:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:15:44 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:25:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:58:02 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:40:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:13:56 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 08:54:21 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:17:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:34:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 19:58:05 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 23/12/30 | 06:57:17 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 18:41:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 13:43:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 05:01:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 21:55:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:12:08 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:52:58 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:39:43 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 05:02:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 08:41:57 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:51:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:03:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 09:36:59 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:13:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:30:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:57:48 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:54:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 17:32:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 09:18:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:40:32 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:54:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:19:16 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:52:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 11:48:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:57:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:48:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:27:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 05:43:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:23:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:57:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:16:23 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 15:00:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 05:49:12 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:10:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:23:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:23:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 09:23:02 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 20:13:55 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:07:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 21:10:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:59:30 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:24:25 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:29:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 10:34:22 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 02:00:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 23:16:27 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 17:23:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 13:14:08 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 04:55:40 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:19:36 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 11:02:49 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 21:22:39 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:03:03 - Program Manager
            Source: server.exe, 00000001.00000002.4063644018.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp, server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 08:15:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 17:05:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 22:32:42 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 06:35:38 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 04:23:35 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 17:41:37 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 07:11:29 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 01:47:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:23:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:29:45 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:26:36 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 20:25:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:18:15 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:36:18 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/05 | 10:30:46 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 14:51:14 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 16:08:47 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 22:27:28 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 12:01:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:26:33 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/07 | 19:26:05 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 10:51:31 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 11:23:34 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:41:03 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/12 | 18:52:24 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 12:14:07 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 09:11:59 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:10:53 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 00:50:11 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/13 | 03:59:26 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 03:02:04 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/10 | 04:45:13 - Program Manager
            Source: server.exe, 00000001.00000002.4064874288.00000000038F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 24/01/02 | 13:28:33 - Program Manager
            Source: C:\Windows\SysWOW64\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Lowering of HIPS / PFW / Operating System Security Settings

            barindex
            Source: tiodtk2cfy.exe, Fransesco.cs.Net Code: INS
            Source: server.exe.0.dr, Fransesco.cs.Net Code: INS
            Source: Microsoft Corporation.exe.1.dr, Fransesco.cs.Net Code: INS
            Source: a1d56127836419435d08d7cc0808a629Windows Update.exe.1.dr, Fransesco.cs.Net Code: INS
            Source: Umbrella.flv.exe.1.dr, Fransesco.cs.Net Code: INS
            Source: winhost.exe.1.dr, Fransesco.cs.Net Code: INS
            Source: C:\Users\user\AppData\Roaming\server.exeRegistry value created: HKEY_CURRENT_USER\Environment SEE_MASK_NOZONECHECKSJump to behavior
            Source: C:\Users\user\AppData\Roaming\server.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\server.exe" "server.exe" ENABLE
            Source: C:\Users\user\AppData\Roaming\server.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\server.exe" "server.exe" ENABLE

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: tiodtk2cfy.exe, type: SAMPLE
            Source: Yara matchFile source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: tiodtk2cfy.exe PID: 7508, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: server.exe PID: 7592, type: MEMORYSTR
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPED
            Source: Yara matchFile source: C:\Umbrella.flv.exe, type: DROPPED
            Source: Yara matchFile source: C:\winhost.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPED

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: tiodtk2cfy.exe, type: SAMPLE
            Source: Yara matchFile source: 0.0.tiodtk2cfy.exe.470000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: tiodtk2cfy.exe PID: 7508, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: server.exe PID: 7592, type: MEMORYSTR
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, type: DROPPED
            Source: Yara matchFile source: C:\Umbrella.flv.exe, type: DROPPED
            Source: Yara matchFile source: C:\winhost.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, type: DROPPED
            Source: Yara matchFile source: C:\Users\user\AppData\Roaming\server.exe, type: DROPPED
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
            21
            Replication Through Removable Media
            Windows Management Instrumentation12
            Registry Run Keys / Startup Folder
            1
            Access Token Manipulation
            1
            Masquerading
            OS Credential Dumping11
            Security Software Discovery
            21
            Replication Through Removable Media
            1
            Archive Collected Data
            Exfiltration Over Other Network Medium1
            Encrypted Channel
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
            Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts12
            Process Injection
            41
            Disable or Modify Tools
            LSASS Memory2
            Process Discovery
            Remote Desktop Protocol1
            Clipboard Data
            Exfiltration Over Bluetooth1
            Non-Standard Port
            SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
            Domain AccountsAtLogon Script (Windows)12
            Registry Run Keys / Startup Folder
            21
            Virtualization/Sandbox Evasion
            Security Account Manager21
            Virtualization/Sandbox Evasion
            SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
            Non-Application Layer Protocol
            Data Encrypted for ImpactDNS ServerEmail Addresses
            Local AccountsCronLogin HookLogin Hook1
            Access Token Manipulation
            NTDS1
            Application Window Discovery
            Distributed Component Object ModelInput CaptureTraffic Duplication1
            Application Layer Protocol
            Data DestructionVirtual Private ServerEmployee Names
            Cloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script12
            Process Injection
            LSA Secrets1
            Peripheral Device Discovery
            SSHKeyloggingScheduled TransferFallback ChannelsData Encrypted for ImpactServerGather Victim Network Information
            Replication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            Obfuscated Files or Information
            Cached Domain Credentials1
            File and Directory Discovery
            VNCGUI Input CaptureData Transfer Size LimitsMultiband CommunicationService StopBotnetDomain Properties
            External Remote ServicesSystemd TimersStartup ItemsStartup Items1
            Software Packing
            DCSync12
            System Information Discovery
            Windows Remote ManagementWeb Portal CaptureExfiltration Over C2 ChannelCommonly Used PortInhibit System RecoveryWeb ServicesDNS
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            tiodtk2cfy.exe84%ReversingLabsByteCode-MSIL.Backdoor.Bladabhindi
            tiodtk2cfy.exe82%VirustotalBrowse
            tiodtk2cfy.exe100%AviraTR/Dropper.Gen
            tiodtk2cfy.exe100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe100%AviraTR/Dropper.Gen
            C:\Umbrella.flv.exe100%AviraTR/Dropper.Gen
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe100%AviraTR/Dropper.Gen
            C:\winhost.exe100%AviraTR/Dropper.Gen
            C:\Users\user\AppData\Roaming\server.exe100%AviraTR/Dropper.Gen
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe100%Joe Sandbox ML
            C:\Umbrella.flv.exe100%Joe Sandbox ML
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe100%Joe Sandbox ML
            C:\winhost.exe100%Joe Sandbox ML
            C:\Users\user\AppData\Roaming\server.exe100%Joe Sandbox ML
            C:\Umbrella.flv.exe84%ReversingLabsByteCode-MSIL.Backdoor.Bladabhindi
            C:\Umbrella.flv.exe82%VirustotalBrowse
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe84%ReversingLabsByteCode-MSIL.Backdoor.Bladabhindi
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe82%VirustotalBrowse
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe84%ReversingLabsByteCode-MSIL.Backdoor.Bladabhindi
            C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe82%VirustotalBrowse
            C:\Users\user\AppData\Roaming\server.exe84%ReversingLabsByteCode-MSIL.Backdoor.Bladabhindi
            C:\Users\user\AppData\Roaming\server.exe82%VirustotalBrowse
            C:\winhost.exe84%ReversingLabsByteCode-MSIL.Backdoor.Bladabhindi
            C:\winhost.exe82%VirustotalBrowse
            No Antivirus matches
            SourceDetectionScannerLabelLink
            2.tcp.eu.ngrok.io12%VirustotalBrowse
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            2.tcp.eu.ngrok.io
            3.127.138.57
            truetrueunknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            3.127.138.57
            2.tcp.eu.ngrok.ioUnited States
            16509AMAZON-02UStrue
            18.156.13.209
            unknownUnited States
            16509AMAZON-02UStrue
            3.126.37.18
            unknownUnited States
            16509AMAZON-02UStrue
            18.197.239.5
            unknownUnited States
            16509AMAZON-02UStrue
            Joe Sandbox version:38.0.0 Ammolite
            Analysis ID:1368193
            Start date and time:2023-12-30 06:56:04 +01:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 7m 37s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:9
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:tiodtk2cfy.exe
            renamed because original name is a hash value
            Original Sample Name:b56be916b1ca250cd9fe04b283e0c3ee.exe
            Detection:MAL
            Classification:mal100.spre.phis.troj.adwa.evad.winEXE@7/10@5/4
            EGA Information:
            • Successful, ratio: 100%
            HCA Information:
            • Successful, ratio: 97%
            • Number of executed functions: 100
            • Number of non-executed functions: 17
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Override analysis time to 240000 for current running targets taking high CPU consumption
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
            • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size exceeded maximum capacity and may have missing behavior information.
            • Report size exceeded maximum capacity and may have missing disassembly code.
            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
            • Report size getting too big, too many NtDeviceIoControlFile calls found.
            • Report size getting too big, too many NtOpenKeyEx calls found.
            • Report size getting too big, too many NtQueryValueKey calls found.
            TimeTypeDescription
            05:56:55AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe
            05:57:06AutostartRun: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe
            06:57:26API Interceptor829850x Sleep call for process: server.exe modified
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            3.127.138.57QUuUm3J8x3.exeGet hashmaliciousNjratBrowse
              RWqHoCWEPI.exeGet hashmaliciousNjratBrowse
                OUXkIxeP6k.exeGet hashmaliciousNjratBrowse
                  eI43OwXSvq.exeGet hashmaliciousNjratBrowse
                    i9z1c1OtFb.exeGet hashmaliciousNjratBrowse
                      JYGc3o49WE.exeGet hashmaliciousNjratBrowse
                        J6VIiRgq3w.exeGet hashmaliciousNjratBrowse
                          7JdbeSrZ6s.exeGet hashmaliciousNjratBrowse
                            KcWQQO3nZP.exeGet hashmaliciousNjratBrowse
                              zep8vTa4sg.exeGet hashmaliciousNjratBrowse
                                umyExrpkSF.exeGet hashmaliciousNjratBrowse
                                  QBEgLAO40T.exeGet hashmaliciousNjratBrowse
                                    4KWKhZNy9w.exeGet hashmaliciousNjratBrowse
                                      yPGBUzqVE3.exeGet hashmaliciousNjratBrowse
                                        D02E3399D85D6B14B30F440181EF5B8FE6B55C403B8C7.exeGet hashmaliciousnjRatBrowse
                                          2dZGR4PTLu.exeGet hashmaliciousNjratBrowse
                                            LMva1J8Xkv.exeGet hashmaliciousNjratBrowse
                                              XlNjZS4E8x.exeGet hashmaliciousNjratBrowse
                                                1F3YBPagot.exeGet hashmaliciousNanocoreBrowse
                                                  H7mLbVb7Tm.exeGet hashmaliciousNjratBrowse
                                                    18.156.13.209http://www.sdrclm.cn/vendor/phpdocumentor/P800/P90GT_Invoice_Related_Property_Tax_P800.exeGet hashmaliciousRedLineBrowse
                                                    • 2.tcp.eu.ngrok.io:17685/
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    2.tcp.eu.ngrok.ioQUuUm3J8x3.exeGet hashmaliciousNjratBrowse
                                                    • 3.127.138.57
                                                    81Rz15POL6.exeGet hashmaliciousNjratBrowse
                                                    • 18.157.68.73
                                                    649DB66A36E095B16832637A31D3CCC75040C5A6C23F6.exeGet hashmaliciousNjratBrowse
                                                    • 18.156.13.209
                                                    pQBmVoyRnw.exeGet hashmaliciousNjratBrowse
                                                    • 18.156.13.209
                                                    RWqHoCWEPI.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    EB4B6878310B1E2843C964E02EC1782AACB518E32777A.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    NezbdhNgwG.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    xdPdkPMD8u.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    VBUXm77rfL.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    1UGdjTlX5v.exeGet hashmaliciousNjratBrowse
                                                    • 18.157.68.73
                                                    kXghM8bJcm.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    OUXkIxeP6k.exeGet hashmaliciousNjratBrowse
                                                    • 3.126.37.18
                                                    QzzmZiGinp.exeGet hashmaliciousNjratBrowse
                                                    • 18.156.13.209
                                                    eI43OwXSvq.exeGet hashmaliciousNjratBrowse
                                                    • 18.197.239.5
                                                    p0zYXkMETE.exeGet hashmaliciousNjratBrowse
                                                    • 18.157.68.73
                                                    i9z1c1OtFb.exeGet hashmaliciousNjratBrowse
                                                    • 18.157.68.73
                                                    aF73k2XwGj.exeGet hashmaliciousNjratBrowse
                                                    • 18.192.93.86
                                                    7XyFhq6BDj.exeGet hashmaliciousNjratBrowse
                                                    • 3.126.37.18
                                                    JYGc3o49WE.exeGet hashmaliciousNjratBrowse
                                                    • 18.157.68.73
                                                    J6VIiRgq3w.exeGet hashmaliciousNjratBrowse
                                                    • 3.126.37.18
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    AMAZON-02USsg4Mw15RpV.exeGet hashmaliciousNjratBrowse
                                                    • 3.67.161.133
                                                    https://www.americanexpressseguros.com/Get hashmaliciousUnknownBrowse
                                                    • 13.225.47.89
                                                    https://www.direct.smbc.shengmabxg.com/ibg/client/home.phpGet hashmaliciousUnknownBrowse
                                                    • 54.150.240.172
                                                    https://www.smbc.link.lekeogroup.com/Get hashmaliciousUnknownBrowse
                                                    • 13.113.75.209
                                                    https://www.pay.screnlefu.com/ibg/client/home.phpGet hashmaliciousUnknownBrowse
                                                    • 13.113.75.209
                                                    https://p.feedblitz.com/t3.asp?/1081591/102442729/7821567_/~feeds.feedblitz.com/~/t/0/0/sethsblog/posts/~//haulitalldmv.com/fixeddoc/mainline/adbdoc/gjhfkghfgfghfhjfghfjghjfghfhgfhghfjhdfjhjdfdf/fjghfjhguhurhgjghjfgjdhjdhghfghkfgjkdghjgljklhjkykutukhkfhgjfghdhghdgfhgegdghjdfghjhgjdgh/iiojbtvqupszfgguzwpwymkdccitcssrkvurbazqqostwbjutwgnijdiregmzhvwdwemqwhluxzlckcmtuaruhbdntcimlqxwfmn/bWF0dGhldy5tY2RvbmFsZEBkb3QuZ292Get hashmaliciousUnknownBrowse
                                                    • 13.225.47.24
                                                    6101XOxMbY.exeGet hashmaliciousGlupteba, LummaC Stealer, Petite Virus, RedLine, SmokeLoader, Stealc, zgRATBrowse
                                                    • 104.192.141.1
                                                    https://vqrvoca8x6h374fj71x.blob.core.windows.net/vqrvoca8x6h374fj71x/url.html#cl/7671_md/12/613/2075/415/1157811Get hashmaliciousPhisherBrowse
                                                    • 18.245.113.73
                                                    Sz8KLg559F.exeGet hashmaliciousGlupteba, LummaC Stealer, Petite Virus, RedLine, SmokeLoader, Stealc, zgRATBrowse
                                                    • 52.217.200.137
                                                    SqhpdzwbpB.exeGet hashmaliciousGurcu StealerBrowse
                                                    • 18.218.18.183
                                                    IsJb5hB84q.exeGet hashmaliciousNjratBrowse
                                                    • 3.69.115.178
                                                    DG8gGqfke1.exeGet hashmaliciousUnknownBrowse
                                                    • 18.154.242.89
                                                    https://www.msn.com/fr-frGet hashmaliciousUnknownBrowse
                                                    • 44.225.83.80
                                                    https://pub-5e1216f7ac0c4c66ad3357156574b076.r2.dev/American_Express_card_protection.htmGet hashmaliciousHTMLPhisherBrowse
                                                    • 35.166.198.201
                                                    https://pub-deefeb5d00534e3992bcd5b787c594a8.r2.dev/jsnew.htmlGet hashmaliciousHTMLPhisherBrowse
                                                    • 18.245.113.72
                                                    Patch_MB 4.6.x.exeGet hashmaliciousUnknownBrowse
                                                    • 52.27.99.226
                                                    https://www.fortinet.com/blog/threat-research/teamcity-intrusion-saga-apt29-suspected-exploiting-cve-2023-42793Get hashmaliciousUnknownBrowse
                                                    • 35.161.163.45
                                                    https://ipfs.io/ipfs/QmXTmcbaHxbnpYGmiteZq5F2DK46p6iMTdvnpd5iSnnYLo/index.htmlGet hashmaliciousUnknownBrowse
                                                    • 65.8.228.116
                                                    s8M01kYpwz.elfGet hashmaliciousMiraiBrowse
                                                    • 13.208.205.138
                                                    file.exeGet hashmaliciousGlupteba, Petite Virus, SmokeLoader, Socks5Systemz, StealcBrowse
                                                    • 44.236.177.54
                                                    AMAZON-02USsg4Mw15RpV.exeGet hashmaliciousNjratBrowse
                                                    • 3.67.161.133
                                                    https://www.americanexpressseguros.com/Get hashmaliciousUnknownBrowse
                                                    • 13.225.47.89
                                                    https://www.direct.smbc.shengmabxg.com/ibg/client/home.phpGet hashmaliciousUnknownBrowse
                                                    • 54.150.240.172
                                                    https://www.smbc.link.lekeogroup.com/Get hashmaliciousUnknownBrowse
                                                    • 13.113.75.209
                                                    https://www.pay.screnlefu.com/ibg/client/home.phpGet hashmaliciousUnknownBrowse
                                                    • 13.113.75.209
                                                    https://p.feedblitz.com/t3.asp?/1081591/102442729/7821567_/~feeds.feedblitz.com/~/t/0/0/sethsblog/posts/~//haulitalldmv.com/fixeddoc/mainline/adbdoc/gjhfkghfgfghfhjfghfjghjfghfhgfhghfjhdfjhjdfdf/fjghfjhguhurhgjghjfgjdhjdhghfghkfgjkdghjgljklhjkykutukhkfhgjfghdhghdgfhgegdghjdfghjhgjdgh/iiojbtvqupszfgguzwpwymkdccitcssrkvurbazqqostwbjutwgnijdiregmzhvwdwemqwhluxzlckcmtuaruhbdntcimlqxwfmn/bWF0dGhldy5tY2RvbmFsZEBkb3QuZ292Get hashmaliciousUnknownBrowse
                                                    • 13.225.47.24
                                                    6101XOxMbY.exeGet hashmaliciousGlupteba, LummaC Stealer, Petite Virus, RedLine, SmokeLoader, Stealc, zgRATBrowse
                                                    • 104.192.141.1
                                                    https://vqrvoca8x6h374fj71x.blob.core.windows.net/vqrvoca8x6h374fj71x/url.html#cl/7671_md/12/613/2075/415/1157811Get hashmaliciousPhisherBrowse
                                                    • 18.245.113.73
                                                    Sz8KLg559F.exeGet hashmaliciousGlupteba, LummaC Stealer, Petite Virus, RedLine, SmokeLoader, Stealc, zgRATBrowse
                                                    • 52.217.200.137
                                                    SqhpdzwbpB.exeGet hashmaliciousGurcu StealerBrowse
                                                    • 18.218.18.183
                                                    IsJb5hB84q.exeGet hashmaliciousNjratBrowse
                                                    • 3.69.115.178
                                                    DG8gGqfke1.exeGet hashmaliciousUnknownBrowse
                                                    • 18.154.242.89
                                                    https://www.msn.com/fr-frGet hashmaliciousUnknownBrowse
                                                    • 44.225.83.80
                                                    https://pub-5e1216f7ac0c4c66ad3357156574b076.r2.dev/American_Express_card_protection.htmGet hashmaliciousHTMLPhisherBrowse
                                                    • 35.166.198.201
                                                    https://pub-deefeb5d00534e3992bcd5b787c594a8.r2.dev/jsnew.htmlGet hashmaliciousHTMLPhisherBrowse
                                                    • 18.245.113.72
                                                    Patch_MB 4.6.x.exeGet hashmaliciousUnknownBrowse
                                                    • 52.27.99.226
                                                    https://www.fortinet.com/blog/threat-research/teamcity-intrusion-saga-apt29-suspected-exploiting-cve-2023-42793Get hashmaliciousUnknownBrowse
                                                    • 35.161.163.45
                                                    https://ipfs.io/ipfs/QmXTmcbaHxbnpYGmiteZq5F2DK46p6iMTdvnpd5iSnnYLo/index.htmlGet hashmaliciousUnknownBrowse
                                                    • 65.8.228.116
                                                    s8M01kYpwz.elfGet hashmaliciousMiraiBrowse
                                                    • 13.208.205.138
                                                    file.exeGet hashmaliciousGlupteba, Petite Virus, SmokeLoader, Socks5Systemz, StealcBrowse
                                                    • 44.236.177.54
                                                    AMAZON-02USsg4Mw15RpV.exeGet hashmaliciousNjratBrowse
                                                    • 3.67.161.133
                                                    https://www.americanexpressseguros.com/Get hashmaliciousUnknownBrowse
                                                    • 13.225.47.89
                                                    https://www.direct.smbc.shengmabxg.com/ibg/client/home.phpGet hashmaliciousUnknownBrowse
                                                    • 54.150.240.172
                                                    https://www.smbc.link.lekeogroup.com/Get hashmaliciousUnknownBrowse
                                                    • 13.113.75.209
                                                    https://www.pay.screnlefu.com/ibg/client/home.phpGet hashmaliciousUnknownBrowse
                                                    • 13.113.75.209
                                                    https://p.feedblitz.com/t3.asp?/1081591/102442729/7821567_/~feeds.feedblitz.com/~/t/0/0/sethsblog/posts/~//haulitalldmv.com/fixeddoc/mainline/adbdoc/gjhfkghfgfghfhjfghfjghjfghfhgfhghfjhdfjhjdfdf/fjghfjhguhurhgjghjfgjdhjdhghfghkfgjkdghjgljklhjkykutukhkfhgjfghdhghdgfhgegdghjdfghjhgjdgh/iiojbtvqupszfgguzwpwymkdccitcssrkvurbazqqostwbjutwgnijdiregmzhvwdwemqwhluxzlckcmtuaruhbdntcimlqxwfmn/bWF0dGhldy5tY2RvbmFsZEBkb3QuZ292Get hashmaliciousUnknownBrowse
                                                    • 13.225.47.24
                                                    6101XOxMbY.exeGet hashmaliciousGlupteba, LummaC Stealer, Petite Virus, RedLine, SmokeLoader, Stealc, zgRATBrowse
                                                    • 104.192.141.1
                                                    https://vqrvoca8x6h374fj71x.blob.core.windows.net/vqrvoca8x6h374fj71x/url.html#cl/7671_md/12/613/2075/415/1157811Get hashmaliciousPhisherBrowse
                                                    • 18.245.113.73
                                                    Sz8KLg559F.exeGet hashmaliciousGlupteba, LummaC Stealer, Petite Virus, RedLine, SmokeLoader, Stealc, zgRATBrowse
                                                    • 52.217.200.137
                                                    SqhpdzwbpB.exeGet hashmaliciousGurcu StealerBrowse
                                                    • 18.218.18.183
                                                    IsJb5hB84q.exeGet hashmaliciousNjratBrowse
                                                    • 3.69.115.178
                                                    DG8gGqfke1.exeGet hashmaliciousUnknownBrowse
                                                    • 18.154.242.89
                                                    https://www.msn.com/fr-frGet hashmaliciousUnknownBrowse
                                                    • 44.225.83.80
                                                    https://pub-5e1216f7ac0c4c66ad3357156574b076.r2.dev/American_Express_card_protection.htmGet hashmaliciousHTMLPhisherBrowse
                                                    • 35.166.198.201
                                                    https://pub-deefeb5d00534e3992bcd5b787c594a8.r2.dev/jsnew.htmlGet hashmaliciousHTMLPhisherBrowse
                                                    • 18.245.113.72
                                                    Patch_MB 4.6.x.exeGet hashmaliciousUnknownBrowse
                                                    • 52.27.99.226
                                                    https://www.fortinet.com/blog/threat-research/teamcity-intrusion-saga-apt29-suspected-exploiting-cve-2023-42793Get hashmaliciousUnknownBrowse
                                                    • 35.161.163.45
                                                    https://ipfs.io/ipfs/QmXTmcbaHxbnpYGmiteZq5F2DK46p6iMTdvnpd5iSnnYLo/index.htmlGet hashmaliciousUnknownBrowse
                                                    • 65.8.228.116
                                                    s8M01kYpwz.elfGet hashmaliciousMiraiBrowse
                                                    • 13.208.205.138
                                                    file.exeGet hashmaliciousGlupteba, Petite Virus, SmokeLoader, Socks5Systemz, StealcBrowse
                                                    • 44.236.177.54
                                                    No context
                                                    No context
                                                    Process:C:\Users\user\AppData\Roaming\server.exe
                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):95232
                                                    Entropy (8bit):5.564110245087195
                                                    Encrypted:false
                                                    SSDEEP:768:oY30wb30YTXspgM0m2zGjpyDtdXWuhtXYLWhyXxrjEtCdnl2pi1Rz4Rk3hsGdpP3:EwT0AA0mT1mrWxL5jEwzGi1dDxDPgS
                                                    MD5:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    SHA1:8F10D4274FB142A1B296702D5A430E95D3225E9B
                                                    SHA-256:A1586D89FCBDA8B94C59634A7D68BA4B6E884C68A92355C6487068D2212B6043
                                                    SHA-512:9DCE2944F564342862816EE023E1BCF25705CBAF86F282B88FF7B2D76E4946B8531F42F467ED31B11A6F0FF44A81C2FB2AD66206A1178B6A3CF3266990AD0438
                                                    Malicious:true
                                                    Yara Hits:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Umbrella.flv.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Umbrella.flv.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Umbrella.flv.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Umbrella.flv.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Umbrella.flv.exe, Author: ditekSHen
                                                    Antivirus:
                                                    • Antivirus: Avira, Detection: 100%
                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                    • Antivirus: ReversingLabs, Detection: 84%
                                                    • Antivirus: Virustotal, Detection: 82%, Browse
                                                    Reputation:low
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...fQ.e.................p............... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text....o... ...p.................. ..`.reloc...............r..............@..B................................................................H.......................................................................&.(......**..(......*.s.........s ........s!........s".........*.0...........~....o#....+..*.0...........~....o$....+..*.0...........~....o%....+..*.0...........~....o&....+..*.0.............(....(.....+..*...0............(.....+..*.0................(.....+..*.0............(.....+..*.0.. ...................,.(...+.+.+....+...*.0...........................**..(......*....0..&........~..............,.(...+.
                                                    Process:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):525
                                                    Entropy (8bit):5.259753436570609
                                                    Encrypted:false
                                                    SSDEEP:12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve
                                                    MD5:260E01CC001F9C4643CA7A62F395D747
                                                    SHA1:492AD0ACE3A9C8736909866EEA168962D418BE5A
                                                    SHA-256:4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030
                                                    SHA-512:01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4
                                                    Malicious:false
                                                    Reputation:moderate, very likely benign file
                                                    Preview:1,"fusion","GAC",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System\bec14584c93014efbc76285c35d1e891\System.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7d443c6c007fe8696f9aa6ff1da53ef7\Microsoft.VisualBasic.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2cdaeaf53e3d49038cf7cb0ce9d805d3\System.Drawing.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d0e5535854cce87ea7f2d69d0594b7a8\System.Windows.Forms.ni.dll",0..
                                                    Process:C:\Users\user\Desktop\tiodtk2cfy.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):525
                                                    Entropy (8bit):5.259753436570609
                                                    Encrypted:false
                                                    SSDEEP:12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve
                                                    MD5:260E01CC001F9C4643CA7A62F395D747
                                                    SHA1:492AD0ACE3A9C8736909866EEA168962D418BE5A
                                                    SHA-256:4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030
                                                    SHA-512:01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4
                                                    Malicious:false
                                                    Reputation:moderate, very likely benign file
                                                    Preview:1,"fusion","GAC",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System\bec14584c93014efbc76285c35d1e891\System.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7d443c6c007fe8696f9aa6ff1da53ef7\Microsoft.VisualBasic.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2cdaeaf53e3d49038cf7cb0ce9d805d3\System.Drawing.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d0e5535854cce87ea7f2d69d0594b7a8\System.Windows.Forms.ni.dll",0..
                                                    Process:C:\Users\user\AppData\Roaming\server.exe
                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):95232
                                                    Entropy (8bit):5.564110245087195
                                                    Encrypted:false
                                                    SSDEEP:768:oY30wb30YTXspgM0m2zGjpyDtdXWuhtXYLWhyXxrjEtCdnl2pi1Rz4Rk3hsGdpP3:EwT0AA0mT1mrWxL5jEwzGi1dDxDPgS
                                                    MD5:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    SHA1:8F10D4274FB142A1B296702D5A430E95D3225E9B
                                                    SHA-256:A1586D89FCBDA8B94C59634A7D68BA4B6E884C68A92355C6487068D2212B6043
                                                    SHA-512:9DCE2944F564342862816EE023E1BCF25705CBAF86F282B88FF7B2D76E4946B8531F42F467ED31B11A6F0FF44A81C2FB2AD66206A1178B6A3CF3266990AD0438
                                                    Malicious:true
                                                    Yara Hits:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: ditekSHen
                                                    Antivirus:
                                                    • Antivirus: Avira, Detection: 100%
                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                    • Antivirus: ReversingLabs, Detection: 84%
                                                    • Antivirus: Virustotal, Detection: 82%, Browse
                                                    Reputation:low
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...fQ.e.................p............... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text....o... ...p.................. ..`.reloc...............r..............@..B................................................................H.......................................................................&.(......**..(......*.s.........s ........s!........s".........*.0...........~....o#....+..*.0...........~....o$....+..*.0...........~....o%....+..*.0...........~....o&....+..*.0.............(....(.....+..*...0............(.....+..*.0................(.....+..*.0............(.....+..*.0.. ...................,.(...+.+.+....+...*.0...........................**..(......*....0..&........~..............,.(...+.
                                                    Process:C:\Users\user\AppData\Roaming\server.exe
                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):95232
                                                    Entropy (8bit):5.564110245087195
                                                    Encrypted:false
                                                    SSDEEP:768:oY30wb30YTXspgM0m2zGjpyDtdXWuhtXYLWhyXxrjEtCdnl2pi1Rz4Rk3hsGdpP3:EwT0AA0mT1mrWxL5jEwzGi1dDxDPgS
                                                    MD5:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    SHA1:8F10D4274FB142A1B296702D5A430E95D3225E9B
                                                    SHA-256:A1586D89FCBDA8B94C59634A7D68BA4B6E884C68A92355C6487068D2212B6043
                                                    SHA-512:9DCE2944F564342862816EE023E1BCF25705CBAF86F282B88FF7B2D76E4946B8531F42F467ED31B11A6F0FF44A81C2FB2AD66206A1178B6A3CF3266990AD0438
                                                    Malicious:true
                                                    Yara Hits:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a1d56127836419435d08d7cc0808a629Windows Update.exe, Author: ditekSHen
                                                    Antivirus:
                                                    • Antivirus: Avira, Detection: 100%
                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                    • Antivirus: ReversingLabs, Detection: 84%
                                                    • Antivirus: Virustotal, Detection: 82%, Browse
                                                    Reputation:low
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...fQ.e.................p............... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text....o... ...p.................. ..`.reloc...............r..............@..B................................................................H.......................................................................&.(......**..(......*.s.........s ........s!........s".........*.0...........~....o#....+..*.0...........~....o$....+..*.0...........~....o%....+..*.0...........~....o&....+..*.0.............(....(.....+..*...0............(.....+..*.0................(.....+..*.0............(.....+..*.0.. ...................,.(...+.+.+....+...*.0...........................**..(......*....0..&........~..............,.(...+.
                                                    Process:C:\Users\user\Desktop\tiodtk2cfy.exe
                                                    File Type:Unicode text, UTF-8 (with BOM) text, with no line terminators
                                                    Category:dropped
                                                    Size (bytes):5
                                                    Entropy (8bit):2.321928094887362
                                                    Encrypted:false
                                                    SSDEEP:3:Zn:Z
                                                    MD5:B66E20886F9675FE4DBF430EA2D0BF8D
                                                    SHA1:2E676DA72201E6E4482E00B300511900C6AEE5A0
                                                    SHA-256:899A421C56C18058CBDD16DD7FB313A57D36C1189CA0F442070ED01D17241414
                                                    SHA-512:F431616522F775DE27CCDE420F0DE6F8B3477FBE97CFD8001864B8289A570916A6DD32C84FCF8AF6083D8C1B47C61AA5C73ED1E7CC75213D3F24BD94A93CB870
                                                    Malicious:false
                                                    Reputation:moderate, very likely benign file
                                                    Preview:.30
                                                    Process:C:\Users\user\Desktop\tiodtk2cfy.exe
                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):95232
                                                    Entropy (8bit):5.564110245087195
                                                    Encrypted:false
                                                    SSDEEP:768:oY30wb30YTXspgM0m2zGjpyDtdXWuhtXYLWhyXxrjEtCdnl2pi1Rz4Rk3hsGdpP3:EwT0AA0mT1mrWxL5jEwzGi1dDxDPgS
                                                    MD5:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    SHA1:8F10D4274FB142A1B296702D5A430E95D3225E9B
                                                    SHA-256:A1586D89FCBDA8B94C59634A7D68BA4B6E884C68A92355C6487068D2212B6043
                                                    SHA-512:9DCE2944F564342862816EE023E1BCF25705CBAF86F282B88FF7B2D76E4946B8531F42F467ED31B11A6F0FF44A81C2FB2AD66206A1178B6A3CF3266990AD0438
                                                    Malicious:true
                                                    Yara Hits:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\server.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\server.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\server.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\server.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\server.exe, Author: ditekSHen
                                                    Antivirus:
                                                    • Antivirus: Avira, Detection: 100%
                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                    • Antivirus: ReversingLabs, Detection: 84%
                                                    • Antivirus: Virustotal, Detection: 82%, Browse
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...fQ.e.................p............... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text....o... ...p.................. ..`.reloc...............r..............@..B................................................................H.......................................................................&.(......**..(......*.s.........s ........s!........s".........*.0...........~....o#....+..*.0...........~....o$....+..*.0...........~....o%....+..*.0...........~....o&....+..*.0.............(....(.....+..*...0............(.....+..*.0................(.....+..*.0............(.....+..*.0.. ...................,.(...+.+.+....+...*.0...........................**..(......*....0..&........~..............,.(...+.
                                                    Process:C:\Users\user\AppData\Roaming\server.exe
                                                    File Type:Microsoft Windows Autorun file
                                                    Category:dropped
                                                    Size (bytes):55
                                                    Entropy (8bit):4.474554204780528
                                                    Encrypted:false
                                                    SSDEEP:3:It1KV2PHQCyK0x:e1KAwCyD
                                                    MD5:40B1630BE21F39CB17BD1963CAE5A207
                                                    SHA1:63C14BD151D42820DD45C033363FA5B9E1D34124
                                                    SHA-256:F87E55F1A423B65FD639146F71F6027DBD4D6E69B65D9A17F1744774AA6589E1
                                                    SHA-512:833112ED4A9A3C621D2FFFC78F83502B2937B82A2CF9BC692D75D907CE2AA46C2D97CFE23C402DB3292B2DD2655FF8692C3CD00D5BA4D792C3D8AF24958E1926
                                                    Malicious:true
                                                    Preview:[autorun]..open=C:\Umbrella.flv.exe..shellexecute=C:\..
                                                    Process:C:\Users\user\AppData\Roaming\server.exe
                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):95232
                                                    Entropy (8bit):5.564110245087195
                                                    Encrypted:false
                                                    SSDEEP:768:oY30wb30YTXspgM0m2zGjpyDtdXWuhtXYLWhyXxrjEtCdnl2pi1Rz4Rk3hsGdpP3:EwT0AA0mT1mrWxL5jEwzGi1dDxDPgS
                                                    MD5:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    SHA1:8F10D4274FB142A1B296702D5A430E95D3225E9B
                                                    SHA-256:A1586D89FCBDA8B94C59634A7D68BA4B6E884C68A92355C6487068D2212B6043
                                                    SHA-512:9DCE2944F564342862816EE023E1BCF25705CBAF86F282B88FF7B2D76E4946B8531F42F467ED31B11A6F0FF44A81C2FB2AD66206A1178B6A3CF3266990AD0438
                                                    Malicious:true
                                                    Yara Hits:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\winhost.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\winhost.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\winhost.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\winhost.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\winhost.exe, Author: ditekSHen
                                                    Antivirus:
                                                    • Antivirus: Avira, Detection: 100%
                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                    • Antivirus: ReversingLabs, Detection: 84%
                                                    • Antivirus: Virustotal, Detection: 82%, Browse
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...fQ.e.................p............... ........@.. ....................................@.....................................O.................................................................................... ............... ..H............text....o... ...p.................. ..`.reloc...............r..............@..B................................................................H.......................................................................&.(......**..(......*.s.........s ........s!........s".........*.0...........~....o#....+..*.0...........~....o$....+..*.0...........~....o%....+..*.0...........~....o&....+..*.0.............(....(.....+..*...0............(.....+..*.0................(.....+..*.0............(.....+..*.0.. ...................,.(...+.+.+....+...*.0...........................**..(......*....0..&........~..............,.(...+.
                                                    Process:C:\Windows\SysWOW64\netsh.exe
                                                    File Type:ASCII text, with CRLF line terminators
                                                    Category:dropped
                                                    Size (bytes):313
                                                    Entropy (8bit):4.971939296804078
                                                    Encrypted:false
                                                    SSDEEP:6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha
                                                    MD5:689E2126A85BF55121488295EE068FA1
                                                    SHA1:09BAAA253A49D80C18326DFBCA106551EBF22DD6
                                                    SHA-256:D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25
                                                    SHA-512:C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C
                                                    Malicious:false
                                                    Preview:..IMPORTANT: Command executed successfully...However, "netsh firewall" is deprecated;..use "netsh advfirewall firewall" instead...For more information on using "netsh advfirewall firewall" commands..instead of "netsh firewall", see KB article 947709..at https://go.microsoft.com/fwlink/?linkid=121488 .....Ok.....
                                                    File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                    Entropy (8bit):5.564110245087195
                                                    TrID:
                                                    • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                                                    • Win32 Executable (generic) a (10002005/4) 49.75%
                                                    • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                                    • Windows Screen Saver (13104/52) 0.07%
                                                    • Generic Win/DOS Executable (2004/3) 0.01%
                                                    File name:tiodtk2cfy.exe
                                                    File size:95'232 bytes
                                                    MD5:b56be916b1ca250cd9fe04b283e0c3ee
                                                    SHA1:8f10d4274fb142a1b296702d5a430e95d3225e9b
                                                    SHA256:a1586d89fcbda8b94c59634a7d68ba4b6e884c68a92355c6487068d2212b6043
                                                    SHA512:9dce2944f564342862816ee023e1bcf25705cbaf86f282b88ff7b2d76e4946b8531f42f467ed31b11a6f0ff44a81c2fb2ad66206a1178b6a3cf3266990ad0438
                                                    SSDEEP:768:oY30wb30YTXspgM0m2zGjpyDtdXWuhtXYLWhyXxrjEtCdnl2pi1Rz4Rk3hsGdpP3:EwT0AA0mT1mrWxL5jEwzGi1dDxDPgS
                                                    TLSH:1B93D88977E56524E4BF5AF75472F2004F74B54B1602E39D48F218AA0B33AC44F89FEA
                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...fQ.e.................p............... ........@.. ....................................@................................
                                                    Icon Hash:90cececece8e8eb0
                                                    Entrypoint:0x418f0e
                                                    Entrypoint Section:.text
                                                    Digitally signed:false
                                                    Imagebase:0x400000
                                                    Subsystem:windows gui
                                                    Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                    Time Stamp:0x658C5166 [Wed Dec 27 16:31:34 2023 UTC]
                                                    TLS Callbacks:
                                                    CLR (.Net) Version:
                                                    OS Version Major:4
                                                    OS Version Minor:0
                                                    File Version Major:4
                                                    File Version Minor:0
                                                    Subsystem Version Major:4
                                                    Subsystem Version Minor:0
                                                    Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                    Instruction
                                                    jmp dword ptr [00402000h]
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    add byte ptr [eax], al
                                                    NameVirtual AddressVirtual Size Is in Section
                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0x18ebc0x4f.text
                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x1a0000xc.reloc
                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                    NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                    .text0x20000x16f140x17000False0.36806852921195654data5.5958167320938665IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                    .reloc0x1a0000xc0x200False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                    DLLImport
                                                    mscoree.dll_CorExeMain
                                                    TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                    192.168.2.418.197.239.550070193542814856 12/30/23-07:00:48.954923TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007019354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550072193542814856 12/30/23-07:00:49.937293TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007219354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550071193542814856 12/30/23-07:00:49.443578TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007119354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550074193542814856 12/30/23-07:00:50.928621TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007419354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949844193542814856 12/30/23-06:58:53.964218TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949845193542814856 12/30/23-06:58:54.461893TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984519354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550073193542814856 12/30/23-07:00:50.430940TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007319354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949846193542814856 12/30/23-06:58:54.962969TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984619354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550078193542814856 12/30/23-07:00:52.921914TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007819354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949847193542814856 12/30/23-06:58:55.462477TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984719354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550075193542814856 12/30/23-07:00:51.423156TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007519354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550079193542814856 12/30/23-07:00:53.417118TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007919354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550076193542814856 12/30/23-07:00:51.914234TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007619354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550077193542814856 12/30/23-07:00:52.429766TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5007719354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949843193542814856 12/30/23-06:58:53.458642TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984319354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949832193542814856 12/30/23-06:58:47.148856TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949831193542814856 12/30/23-06:58:46.651530TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949840193542814856 12/30/23-06:58:51.198140TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984019354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949830193542814856 12/30/23-06:58:46.139598TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983019354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550080193542814856 12/30/23-07:00:53.911195TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5008019354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949763193542033132 12/30/23-06:57:58.658795TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976319354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550060193542814856 12/30/23-07:00:44.073546TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006019354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550061193542814856 12/30/23-07:00:44.563845TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006119354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550081193542814856 12/30/23-07:00:54.395316TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5008119354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949762193542033132 12/30/23-06:57:56.539963TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976219354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550082193542814856 12/30/23-07:00:58.229074TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5008219354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550064193542814856 12/30/23-07:00:46.036167TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006419354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550063193542814856 12/30/23-07:00:45.540599TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006319354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550062193542814856 12/30/23-07:00:45.053977TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006219354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550068193542814856 12/30/23-07:00:47.982577TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006819354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550067193542814856 12/30/23-07:00:47.495787TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006719354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550069193542814856 12/30/23-07:00:48.469821TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006919354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550065193542814856 12/30/23-07:00:46.523306TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006519354192.168.2.418.197.239.5
                                                    192.168.2.418.197.239.550066193542814856 12/30/23-07:00:47.015523TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5006619354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949773193542033132 12/30/23-06:58:10.061344TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749910193542033132 12/30/23-06:59:28.395113TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949777193542033132 12/30/23-06:58:13.628186TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977719354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949822193542814856 12/30/23-06:58:42.080105TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949771193542033132 12/30/23-06:58:08.096308TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949779193542033132 12/30/23-06:58:15.550531TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749912193542033132 12/30/23-06:59:29.368484TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749894193542814856 12/30/23-06:59:19.912088TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989419354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949824193542814856 12/30/23-06:58:43.090902TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949826193542814856 12/30/23-06:58:44.099384TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982619354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550081193542033132 12/30/23-07:00:54.154302TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5008119354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949828193542814856 12/30/23-06:58:45.123472TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749890193542814856 12/30/23-06:59:17.969044TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749892193542814856 12/30/23-06:59:18.951027TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989219354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949841193542033132 12/30/23-06:58:52.214516TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749908193542033132 12/30/23-06:59:26.520668TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749918193542033132 12/30/23-06:59:32.288100TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749906193542033132 12/30/23-06:59:25.530242TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850007193542033132 12/30/23-07:00:17.003332TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000719354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749904193542033132 12/30/23-06:59:24.562802TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749914193542033132 12/30/23-06:59:30.329855TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850009193542033132 12/30/23-07:00:17.992635TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000919354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949820193542814856 12/30/23-06:58:41.006653TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982019354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949775193542033132 12/30/23-06:58:11.898804TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749916193542033132 12/30/23-06:59:31.315995TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991619354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949764193542033132 12/30/23-06:57:59.930348TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749900193542033132 12/30/23-06:59:22.575675TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749921193542033132 12/30/23-06:59:33.759908TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749902193542033132 12/30/23-06:59:23.554900TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990219354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949766193542033132 12/30/23-06:58:02.485767TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949787193542033132 12/30/23-06:58:21.859503TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978719354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949811193542814856 12/30/23-06:58:36.302287TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749923193542033132 12/30/23-06:59:34.726286TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992319354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949768193542033132 12/30/23-06:58:04.876943TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949789193542033132 12/30/23-06:58:23.169791TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978919354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949834193542814856 12/30/23-06:58:48.171147TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949813193542814856 12/30/23-06:58:37.354950TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981319354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949815193542814856 12/30/23-06:58:38.422230TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981519354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949836193542814856 12/30/23-06:58:49.179643TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949817193542814856 12/30/23-06:58:39.473534TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981719354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949838193542814856 12/30/23-06:58:50.173808TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949843193542033132 12/30/23-06:58:53.218383TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984319354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550066193542033132 12/30/23-07:00:46.770843TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006619354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749879193542814856 12/30/23-06:59:12.631314TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850010193542033132 12/30/23-07:00:18.477026TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001019354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949845193542033132 12/30/23-06:58:54.222789TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984519354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949819193542814856 12/30/23-06:58:40.501000TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981919354192.168.2.418.156.13.209
                                                    192.168.2.418.197.239.550064193542033132 12/30/23-07:00:45.792625TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006419354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949847193542033132 12/30/23-06:58:55.219909TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749875193542814856 12/30/23-06:59:09.576470TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749896193542814856 12/30/23-06:59:20.882239TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749877193542814856 12/30/23-06:59:11.657337TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749898193542814856 12/30/23-06:59:21.850035TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989819354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550068193542033132 12/30/23-07:00:47.740606TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006819354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949795193542033132 12/30/23-06:58:26.878298TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749932193542033132 12/30/23-06:59:39.117147TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749756193542814856 12/30/23-06:57:48.292899TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975619354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949794193542033132 12/30/23-06:58:26.283659TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949798193542033132 12/30/23-06:58:28.628830TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949791193542033132 12/30/23-06:58:24.422556TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949799193542033132 12/30/23-06:58:29.212613TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749906193542814856 12/30/23-06:59:25.770785TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749752193542814856 12/30/23-06:57:39.966123TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749751193542814856 12/30/23-06:57:37.519223TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749759193542814856 12/30/23-06:57:51.839689TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975919354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949801193542814856 12/30/23-06:58:30.584406TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949802193542814856 12/30/23-06:58:31.147560TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980219354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749907193542814856 12/30/23-06:59:26.275930TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749933193542033132 12/30/23-06:59:39.601760TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749873193542814856 12/30/23-06:59:08.594471TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987319354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949764193542814856 12/30/23-06:58:00.172622TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949765193542814856 12/30/23-06:58:01.473265TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749902193542814856 12/30/23-06:59:23.793402TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850015193542033132 12/30/23-07:00:21.543091TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001519354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749872193542814856 12/30/23-06:59:08.108252TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850014193542033132 12/30/23-07:00:20.575513TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001419354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949790193542033132 12/30/23-06:58:23.797823TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749899193542033132 12/30/23-06:59:22.091446TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850011193542033132 12/30/23-07:00:18.962037TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001119354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949831193542033132 12/30/23-06:58:46.408297TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749755193542814856 12/30/23-06:57:46.372600TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975519354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949832193542033132 12/30/23-06:58:46.906902TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949805193542814856 12/30/23-06:58:32.805845TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980519354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949806193542814856 12/30/23-06:58:33.355460TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980619354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749903193542814856 12/30/23-06:59:24.315420TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990319354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550060193542033132 12/30/23-07:00:43.834106TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006019354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749929193542033132 12/30/23-06:59:37.653403TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850018193542033132 12/30/23-07:00:22.786929TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001819354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850029193542033132 12/30/23-07:00:28.229769TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002919354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949779193542814856 12/30/23-06:58:15.792812TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749936193542033132 12/30/23-06:59:41.043152TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993619354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949768193542814856 12/30/23-06:58:05.118313TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949769193542814856 12/30/23-06:58:06.230283TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749925193542033132 12/30/23-06:59:35.700120TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749926193542033132 12/30/23-06:59:36.181869TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850019193542033132 12/30/23-07:00:23.274007TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001919354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949785193542033132 12/30/23-06:58:20.502867TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749937193542033132 12/30/23-06:59:41.527798TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949784193542033132 12/30/23-06:58:19.803732TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749745193542814856 12/30/23-06:57:21.884586TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974519354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949780193542033132 12/30/23-06:58:16.840242TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978019354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949781193542033132 12/30/23-06:58:17.605537TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749741193542814856 12/30/23-06:57:11.514602TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749749193542814856 12/30/23-06:57:32.353860TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749761193542814856 12/30/23-06:57:55.069798TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949776193542814856 12/30/23-06:58:13.018301TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977619354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749748193542814856 12/30/23-06:57:29.753082TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974819354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949775193542814856 12/30/23-06:58:12.140545TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977519354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850005193542033132 12/30/23-07:00:16.032843TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850026193542033132 12/30/23-07:00:26.716616TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749862193542814856 12/30/23-06:59:03.086640TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986219354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550070193542033132 12/30/23-07:00:48.719328TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007019354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749883193542814856 12/30/23-06:59:14.575085TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749861193542814856 12/30/23-06:59:02.584434TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850004193542033132 12/30/23-07:00:15.549435TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850025193542033132 12/30/23-07:00:26.230594TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002519354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749882193542814856 12/30/23-06:59:14.082439TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988219354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949771193542814856 12/30/23-06:58:08.334196TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977119354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850001193542033132 12/30/23-07:00:14.107818TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850022193542033132 12/30/23-07:00:24.731564TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002219354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550073193542033132 12/30/23-07:00:50.186982TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007319354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949772193542814856 12/30/23-06:58:09.337276TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977219354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749744193542814856 12/30/23-06:57:19.294692TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850059193542814856 12/30/23-07:00:43.466411TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005919354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550077193542033132 12/30/23-07:00:52.186665TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007719354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949814193542033132 12/30/23-06:58:37.646709TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949835193542033132 12/30/23-06:58:48.442153TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749892193542033132 12/30/23-06:59:18.710203TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850058193542814856 12/30/23-07:00:42.973648TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005819354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550078193542033132 12/30/23-07:00:52.683987TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007819354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749891193542033132 12/30/23-06:59:18.218918TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749895193542033132 12/30/23-06:59:20.153537TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749869193542814856 12/30/23-06:59:06.630731TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850000193542033132 12/30/23-07:00:13.595230TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850021193542033132 12/30/23-07:00:24.247127TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002119354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749896193542033132 12/30/23-06:59:20.640929TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989619354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550074193542033132 12/30/23-07:00:50.682277TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007419354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949815193542033132 12/30/23-06:58:38.185220TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981519354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949836193542033132 12/30/23-06:58:48.938117TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949809193542814856 12/30/23-06:58:35.250061TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749920193542814856 12/30/23-06:59:33.515224TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749865193542814856 12/30/23-06:59:04.588452TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749886193542814856 12/30/23-06:59:16.032780TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749866193542814856 12/30/23-06:59:05.087576TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850055193542814856 12/30/23-07:00:41.504089TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005519354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949839193542033132 12/30/23-06:58:50.449348TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749887193542814856 12/30/23-06:59:16.514863TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949818193542033132 12/30/23-06:58:39.751349TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949819193542033132 12/30/23-06:58:40.262690TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981919354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850054193542814856 12/30/23-07:00:41.016431TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749911193542033132 12/30/23-06:59:28.906034TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749953193542033132 12/30/23-06:59:49.899296TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995319354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949774193542033132 12/30/23-06:58:10.980764TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949770193542033132 12/30/23-06:58:07.067339TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977019354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949778193542033132 12/30/23-06:58:14.453525TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749927193542814856 12/30/23-06:59:36.906209TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992719354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849977193542033132 12/30/23-07:00:01.827518TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997719354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749730193542814856 12/30/23-06:56:58.554147TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4973019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949823193542814856 12/30/23-06:58:42.580546TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749923193542814856 12/30/23-06:59:34.964003TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992319354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550080193542033132 12/30/23-07:00:53.665144TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5008019354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749851193542814856 12/30/23-06:58:57.593735TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949786193542814856 12/30/23-06:58:21.432065TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978619354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849973193542033132 12/30/23-06:59:59.823165TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749878193542033132 12/30/23-06:59:11.903318TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849989193542814856 12/30/23-07:00:08.436279TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749893193542814856 12/30/23-06:59:19.436193TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850036193542033132 12/30/23-07:00:31.626776TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003619354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949782193542814856 12/30/23-06:58:18.587636TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978219354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749760193542033132 12/30/23-06:57:53.252164TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949811193542033132 12/30/23-06:58:36.061798TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949827193542814856 12/30/23-06:58:44.610808TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982719354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849995193542814856 12/30/23-07:00:11.352583TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849985193542814856 12/30/23-07:00:06.458086TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849981193542814856 12/30/23-07:00:04.500208TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849991193542814856 12/30/23-07:00:09.404969TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849999193542814856 12/30/23-07:00:13.331950TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749909193542033132 12/30/23-06:59:27.121367TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749919193542033132 12/30/23-06:59:32.776505TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850008193542033132 12/30/23-07:00:17.503665TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749957193542033132 12/30/23-06:59:51.858230TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749915193542033132 12/30/23-06:59:30.824594TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749947193542033132 12/30/23-06:59:46.987477TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749905193542033132 12/30/23-06:59:25.049008TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749964193542033132 12/30/23-06:59:55.271906TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749922193542033132 12/30/23-06:59:34.244220TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749943193542033132 12/30/23-06:59:44.719248TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849987193542033132 12/30/23-07:00:07.206315TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998719354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949767193542033132 12/30/23-06:58:03.713667TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976719354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949788193542033132 12/30/23-06:58:22.517327TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749959193542814856 12/30/23-06:59:53.069861TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849966193542033132 12/30/23-06:59:56.364852TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996619354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949833193542814856 12/30/23-06:58:47.656166TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749938193542814856 12/30/23-06:59:42.272685TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993819354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949812193542814856 12/30/23-06:58:36.835456TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981219354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749901193542033132 12/30/23-06:59:23.075689TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749917193542814856 12/30/23-06:59:32.043952TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749955193542814856 12/30/23-06:59:51.120533TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749868193542033132 12/30/23-06:59:05.905389TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749889193542033132 12/30/23-06:59:17.247936TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988919354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949837193542814856 12/30/23-06:58:49.679623TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749934193542814856 12/30/23-06:59:40.323985TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849978193542814856 12/30/23-07:00:02.576014TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997819354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849983193542033132 12/30/23-07:00:05.234340TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749960193542033132 12/30/23-06:59:53.321128TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949842193542033132 12/30/23-06:58:52.917769TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949800193542033132 12/30/23-06:58:29.782591TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980019354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949816193542814856 12/30/23-06:58:38.952892TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949821193542033132 12/30/23-06:58:41.279188TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749913193542814856 12/30/23-06:59:30.084234TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850006193542814856 12/30/23-07:00:16.760624TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749859193542814856 12/30/23-06:59:01.585982TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850048193542814856 12/30/23-07:00:37.736713TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004819354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550067193542033132 12/30/23-07:00:47.256829TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006719354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749860193542033132 12/30/23-06:59:01.845457TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749881193542033132 12/30/23-06:59:13.355381TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949846193542033132 12/30/23-06:58:54.722012TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984619354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850027193542814856 12/30/23-07:00:27.496245TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850032193542033132 12/30/23-07:00:29.691730TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749951193542814856 12/30/23-06:59:49.163586TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850002193542814856 12/30/23-07:00:14.817994TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000219354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550063193542033132 12/30/23-07:00:45.301340TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006319354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749864193542033132 12/30/23-06:59:03.844410TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749885193542033132 12/30/23-06:59:15.300659TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850053193542033132 12/30/23-07:00:40.266642TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749930193542814856 12/30/23-06:59:38.383930TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949804193542033132 12/30/23-06:58:32.016402TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949825193542033132 12/30/23-06:58:43.358709TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982519354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850040193542814856 12/30/23-07:00:33.829919TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004019354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749897193542814856 12/30/23-06:59:21.371867TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989719354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850023193542814856 12/30/23-07:00:25.504623TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850044193542814856 12/30/23-07:00:35.791284TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749855193542814856 12/30/23-06:58:59.561215TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749747193542033132 12/30/23-06:57:26.909123TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949808193542033132 12/30/23-06:58:34.389036TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949829193542033132 12/30/23-06:58:45.412490TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982919354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849998193542033132 12/30/23-07:00:12.595313TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749741193542033132 12/30/23-06:57:11.270022TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749948193542814856 12/30/23-06:59:47.711739TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749949193542814856 12/30/23-06:59:48.194602TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749743193542033132 12/30/23-06:57:16.443459TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849999193542033132 12/30/23-07:00:13.088344TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749742193542033132 12/30/23-06:57:13.847951TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749944193542814856 12/30/23-06:59:45.216851TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849993193542033132 12/30/23-07:00:10.142760TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850058193542033132 12/30/23-07:00:42.731334TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749943193542814856 12/30/23-06:59:44.723176TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749945193542814856 12/30/23-06:59:46.180591TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850057193542033132 12/30/23-07:00:42.242902TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850059193542033132 12/30/23-07:00:43.221744TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749857193542033132 12/30/23-06:59:00.347550TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749859193542033132 12/30/23-06:59:01.345120TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849994193542033132 12/30/23-07:00:10.626827TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749856193542033132 12/30/23-06:58:59.842821TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849967193542814856 12/30/23-06:59:57.092698TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849997193542033132 12/30/23-07:00:12.105095TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850054193542033132 12/30/23-07:00:40.775184TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749947193542814856 12/30/23-06:59:47.226861TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994719354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850055193542033132 12/30/23-07:00:41.261760TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849968193542814856 12/30/23-06:59:57.609467TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749946193542814856 12/30/23-06:59:46.733187TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849995193542033132 12/30/23-07:00:11.110412TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850056193542033132 12/30/23-07:00:41.748672TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849996193542033132 12/30/23-07:00:11.636031TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749858193542033132 12/30/23-06:59:00.844263TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849969193542814856 12/30/23-06:59:58.095277TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996919354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850029193542814856 12/30/23-07:00:28.466902TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002919354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849973193542814856 12/30/23-07:00:00.069190TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849970193542814856 12/30/23-06:59:58.576787TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849974193542814856 12/30/23-07:00:00.562308TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849977193542814856 12/30/23-07:00:02.069880TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997719354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749747193542825564 12/30/23-06:57:27.233979TCP2825564ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act)4974719354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849966193542814856 12/30/23-06:59:56.605198TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849975193542814856 12/30/23-07:00:01.086540TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849991193542033132 12/30/23-07:00:09.163787TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849976193542814856 12/30/23-07:00:01.573004TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849992193542033132 12/30/23-07:00:09.652740TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999219354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849965193542814856 12/30/23-06:59:56.116605TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849990193542033132 12/30/23-07:00:08.679646TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4999019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849971193542814856 12/30/23-06:59:59.069362TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849972193542814856 12/30/23-06:59:59.556918TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749751193542033132 12/30/23-06:57:37.279473TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749730193542033132 12/30/23-06:56:58.314971TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4973019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749731193542033132 12/30/23-06:57:00.892532TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4973119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949799193542814856 12/30/23-06:58:29.449482TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749752193542033132 12/30/23-06:57:39.791208TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975219354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949798193542814856 12/30/23-06:58:28.873869TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979819354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850049193542033132 12/30/23-07:00:38.002839TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749732193542033132 12/30/23-06:57:03.485136TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4973219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749753193542033132 12/30/23-06:57:41.950785TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975319354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949796193542814856 12/30/23-06:58:27.711457TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979619354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850047193542033132 12/30/23-07:00:37.016103TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004719354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949797193542814856 12/30/23-06:58:28.289196TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979719354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850046193542033132 12/30/23-07:00:36.524654TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850048193542033132 12/30/23-07:00:37.496687TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004819354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949795193542814856 12/30/23-06:58:27.120834TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979519354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850043193542033132 12/30/23-07:00:35.064965TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850044193542033132 12/30/23-07:00:35.550765TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749750193542033132 12/30/23-06:57:34.687734TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949793193542814856 12/30/23-06:58:25.915869TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979319354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850019193542814856 12/30/23-07:00:23.516431TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001919354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850045193542033132 12/30/23-07:00:36.039234TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850018193542814856 12/30/23-07:00:23.027394TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001819354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949794193542814856 12/30/23-06:58:26.526085TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749849193542814856 12/30/23-06:58:56.589692TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850017193542814856 12/30/23-07:00:22.536265TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850038193542814856 12/30/23-07:00:32.847377TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749871193542033132 12/30/23-06:59:07.380827TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749872193542033132 12/30/23-06:59:07.866667TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749848193542814856 12/30/23-06:58:56.080050TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4984819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850037193542814856 12/30/23-07:00:32.357774TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850039193542814856 12/30/23-07:00:33.338541TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749851193542033132 12/30/23-06:58:57.350136TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850040193542033132 12/30/23-07:00:33.587063TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004019354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749870193542033132 12/30/23-06:59:06.892440TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749873193542033132 12/30/23-06:59:08.354127TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749874193542033132 12/30/23-06:59:08.860526TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850016193542814856 12/30/23-07:00:22.047418TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001619354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949792193542814856 12/30/23-06:58:25.292661TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979219354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749852193542033132 12/30/23-06:58:57.840227TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749940193542814856 12/30/23-06:59:43.253908TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994019354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850013193542814856 12/30/23-07:00:20.180218TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850034193542814856 12/30/23-07:00:30.897052TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749875193542033132 12/30/23-06:59:09.335661TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749876193542033132 12/30/23-06:59:11.164509TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749941193542814856 12/30/23-06:59:43.737971TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749962193542814856 12/30/23-06:59:54.541480TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850035193542814856 12/30/23-07:00:31.380008TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003519354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949791193542814856 12/30/23-06:58:24.664666TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749853193542033132 12/30/23-06:58:58.326027TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749855193542033132 12/30/23-06:58:59.316698TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850042193542033132 12/30/23-07:00:34.574205TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749942193542814856 12/30/23-06:59:44.234619TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4994219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749963193542814856 12/30/23-06:59:55.027646TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850036193542814856 12/30/23-07:00:31.869023TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850014193542814856 12/30/23-07:00:20.683832TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001419354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949790193542814856 12/30/23-06:58:24.039838TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4979019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749854193542033132 12/30/23-06:58:58.817855TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850041193542033132 12/30/23-07:00:34.083405TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5004119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850030193542814856 12/30/23-07:00:28.954437TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003019354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749735193542033132 12/30/23-06:57:08.663103TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4973519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850031193542814856 12/30/23-07:00:29.445787TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003119354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749754193542033132 12/30/23-06:57:44.074834TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749756193542033132 12/30/23-06:57:48.050572TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749733193542033132 12/30/23-06:57:06.081901TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4973319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850012193542814856 12/30/23-07:00:19.695001TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749755193542033132 12/30/23-06:57:46.129320TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749759193542033132 12/30/23-06:57:51.599816TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749729193542814856 12/30/23-06:56:56.048636TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4972919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749961193542814856 12/30/23-06:59:54.054177TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850033193542814856 12/30/23-07:00:30.416672TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850011193542814856 12/30/23-07:00:19.203057TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001119354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850032193542814856 12/30/23-07:00:29.928847TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5003219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749960193542814856 12/30/23-06:59:53.565099TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996019354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850010193542814856 12/30/23-07:00:18.717437TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5001019354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749757193542033132 12/30/23-06:57:49.875086TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4975719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749850193542033132 12/30/23-06:58:56.842955TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4985019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749952193542033132 12/30/23-06:59:49.412198TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749954193542033132 12/30/23-06:59:50.385891TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749735193542814856 12/30/23-06:57:08.903912TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4973519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849976193542033132 12/30/23-07:00:01.334423TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749956193542033132 12/30/23-06:59:51.364436TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850039193542033132 12/30/23-07:00:33.093585TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003919354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850050193542814856 12/30/23-07:00:38.709977TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005019354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949787193542814856 12/30/23-06:58:22.099907TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749928193542814856 12/30/23-06:59:37.398460TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849978193542033132 12/30/23-07:00:02.331532TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749879193542033132 12/30/23-06:59:12.389730TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749964193542814856 12/30/23-06:59:55.513903TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4996419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850035193542033132 12/30/23-07:00:31.140226TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850037193542033132 12/30/23-07:00:32.119237TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003719354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749850193542814856 12/30/23-06:58:57.083342TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749877193542033132 12/30/23-06:59:11.416435TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4987719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749731193542814856 12/30/23-06:57:01.133659TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4973119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749922193542814856 12/30/23-06:59:34.483645TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749926193542814856 12/30/23-06:59:36.421423TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992619354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949785193542814856 12/30/23-06:58:20.746863TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978519354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849972193542033132 12/30/23-06:59:59.314289TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749761193542033132 12/30/23-06:57:54.828622TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949810193542033132 12/30/23-06:58:35.529677TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749950193542033132 12/30/23-06:59:48.439896TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995019354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850033193542033132 12/30/23-07:00:30.175204TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749733193542814856 12/30/23-06:57:06.321693TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4973319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749924193542814856 12/30/23-06:59:35.446750TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850007193542814856 12/30/23-07:00:17.242018TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000719354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949783193542814856 12/30/23-06:58:19.316332TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978319354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849974193542033132 12/30/23-07:00:00.317197TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849984193542814856 12/30/23-07:00:05.970954TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849994193542814856 12/30/23-07:00:10.865713TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849992193542814856 12/30/23-07:00:09.897175TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999219354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849996193542814856 12/30/23-07:00:11.851716TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850009193542814856 12/30/23-07:00:18.231993TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000919354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849980193542814856 12/30/23-07:00:04.012515TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849988193542814856 12/30/23-07:00:07.946788TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998819354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849990193542814856 12/30/23-07:00:08.920614TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849998193542814856 12/30/23-07:00:12.837253TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999819354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849980193542033132 12/30/23-07:00:03.827429TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849970193542033132 12/30/23-06:59:58.337721TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849986193542814856 12/30/23-07:00:06.958269TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998619354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949789193542814856 12/30/23-06:58:23.407334TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749958193542033132 12/30/23-06:59:52.342235TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849982193542814856 12/30/23-07:00:04.987660TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749948193542033132 12/30/23-06:59:47.472154TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849969193542033132 12/30/23-06:59:57.853566TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749963193542033132 12/30/23-06:59:54.785800TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749942193542033132 12/30/23-06:59:43.992910TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749946193542033132 12/30/23-06:59:46.488338TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749916193542814856 12/30/23-06:59:31.555556TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849988193542033132 12/30/23-07:00:07.700870TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749918193542814856 12/30/23-06:59:32.529835TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849967193542033132 12/30/23-06:59:56.850603TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996719354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749939193542814856 12/30/23-06:59:42.759589TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749944193542033132 12/30/23-06:59:44.971902TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749869193542033132 12/30/23-06:59:06.391520TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749912193542814856 12/30/23-06:59:29.607772TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749954193542814856 12/30/23-06:59:50.627454TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749848193542033132 12/30/23-06:58:55.841355TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849982193542033132 12/30/23-07:00:04.772515TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998219354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849984193542033132 12/30/23-07:00:05.732245TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749867193542033132 12/30/23-06:59:05.403704TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749888193542033132 12/30/23-06:59:16.761193TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749933193542814856 12/30/23-06:59:39.842196TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749937193542814856 12/30/23-06:59:41.768490TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993719354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849965193542033132 12/30/23-06:59:55.878341TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996519354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949820193542033132 12/30/23-06:58:40.765520TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749958193542814856 12/30/23-06:59:52.581860TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749961193542033132 12/30/23-06:59:53.811310TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849986193542033132 12/30/23-07:00:06.716982TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749914193542814856 12/30/23-06:59:30.573264TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849979193542814856 12/30/23-07:00:03.071228TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4997919354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949822193542033132 12/30/23-06:58:41.834391TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982219354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749956193542814856 12/30/23-06:59:51.605514TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749935193542814856 12/30/23-06:59:40.802367TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749940193542033132 12/30/23-06:59:43.008933TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749861193542033132 12/30/23-06:59:02.343732TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749882193542033132 12/30/23-06:59:13.841892TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850050193542033132 12/30/23-07:00:38.576098TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005019354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949824193542033132 12/30/23-06:58:42.848389TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982419354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850049193542814856 12/30/23-07:00:38.223716TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004919354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949801193542033132 12/30/23-06:58:30.343483TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949803193542033132 12/30/23-06:58:31.468455TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980319354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850026193542814856 12/30/23-07:00:26.960595TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850028193542814856 12/30/23-07:00:27.990273TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749858193542814856 12/30/23-06:59:01.085903TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749863193542033132 12/30/23-06:59:03.347715TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749884193542033132 12/30/23-06:59:14.818821TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749880193542033132 12/30/23-06:59:12.872848TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988019354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850005193542814856 12/30/23-07:00:16.273723TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000519354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949781193542814856 12/30/23-06:58:17.843270TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978119354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749865193542033132 12/30/23-06:59:04.346123TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749886193542033132 12/30/23-06:59:15.787605TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988619354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850045193542814856 12/30/23-07:00:36.282306TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004519354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949805193542033132 12/30/23-06:58:32.563530TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980519354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850024193542814856 12/30/23-07:00:25.988529TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850031193542033132 12/30/23-07:00:29.206057TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003119354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749910193542814856 12/30/23-06:59:28.641541TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991019354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850052193542033132 12/30/23-07:00:39.896763TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749729193542033132 12/30/23-06:56:55.865512TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4972919354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949826193542033132 12/30/23-06:58:43.862219TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982619354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749952193542814856 12/30/23-06:59:49.653812TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850047193542814856 12/30/23-07:00:37.254319TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850003193542814856 12/30/23-07:00:15.304449TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749931193542814856 12/30/23-06:59:38.869094TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749852193542814856 12/30/23-06:58:58.076573TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985219354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850041193542814856 12/30/23-07:00:34.323025TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004119354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949809193542033132 12/30/23-06:58:35.007968TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980919354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850020193542814856 12/30/23-07:00:24.001117TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002019354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749854193542814856 12/30/23-06:58:59.057474TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985419354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850001193542814856 12/30/23-07:00:14.328187TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000119354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749744193542033132 12/30/23-06:57:19.050041TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749748193542033132 12/30/23-06:57:29.511857TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749856193542814856 12/30/23-06:59:00.087695TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985619354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949828193542033132 12/30/23-06:58:44.882263TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749950193542814856 12/30/23-06:59:48.676663TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949807193542033132 12/30/23-06:58:34.079878TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980719354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850022193542814856 12/30/23-07:00:24.973826TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002219354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850043193542814856 12/30/23-07:00:35.308067TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749746193542033132 12/30/23-06:57:24.324942TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749757193542814856 12/30/23-06:57:50.114659TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749909193542814856 12/30/23-06:59:27.358945TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749908193542814856 12/30/23-06:59:26.758826TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749931193542033132 12/30/23-06:59:38.628084TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749935193542033132 12/30/23-06:59:40.565444TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993519354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949800193542814856 12/30/23-06:58:30.022010TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749905193542814856 12/30/23-06:59:25.286864TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990519354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949793193542033132 12/30/23-06:58:25.674401TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749934193542033132 12/30/23-06:59:40.085126TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993419354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949766193542814856 12/30/23-06:58:02.727133TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976619354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850017193542033132 12/30/23-07:00:22.313219TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001719354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949792193542033132 12/30/23-06:58:25.052320TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949803193542814856 12/30/23-06:58:31.707862TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980319354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949804193542814856 12/30/23-06:58:32.258279TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749901193542814856 12/30/23-06:59:23.312951TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850016193542033132 12/30/23-07:00:21.897628TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749871193542814856 12/30/23-06:59:07.622024TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949763193542814856 12/30/23-06:57:58.790672TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749900193542814856 12/30/23-06:59:22.817240TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749904193542814856 12/30/23-06:59:24.806589TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4990419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749753193542814856 12/30/23-06:57:42.189827TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850012193542033132 12/30/23-07:00:19.451840TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001219354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550062193542033132 12/30/23-07:00:44.811642TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006219354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749754193542814856 12/30/23-06:57:44.316818TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749870193542814856 12/30/23-06:59:07.134679TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749930193542033132 12/30/23-06:59:38.144940TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949762193542814856 12/30/23-06:57:56.779496TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976219354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850013193542033132 12/30/23-07:00:19.939025TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5001319354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550061193542033132 12/30/23-07:00:44.320331TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006119354192.168.2.418.197.239.5
                                                    192.168.2.418.156.13.20949830193542033132 12/30/23-06:58:45.902361TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749760193542814856 12/30/23-06:57:53.493964TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749750193542814856 12/30/23-06:57:34.929638TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4975019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949767193542814856 12/30/23-06:58:03.958715TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4976719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749928193542033132 12/30/23-06:59:37.157075TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992819354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949778193542814856 12/30/23-06:58:14.688767TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749939193542033132 12/30/23-06:59:42.518313TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993919354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949786193542033132 12/30/23-06:58:21.190683TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949797193542033132 12/30/23-06:58:28.048530TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749938193542033132 12/30/23-06:59:42.031161TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4993819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749927193542033132 12/30/23-06:59:36.665802TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949796193542033132 12/30/23-06:58:27.470586TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4979619354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749747193542814856 12/30/23-06:57:27.150655TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949783193542033132 12/30/23-06:58:19.076238TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749746193542814856 12/30/23-06:57:24.568832TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974619354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949777193542814856 12/30/23-06:58:13.872631TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977719354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850028193542033132 12/30/23-07:00:27.745382TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002819354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949782193542033132 12/30/23-06:58:18.344993TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4978219354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850006193542033132 12/30/23-07:00:16.520244TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000619354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850027193542033132 12/30/23-07:00:27.255013TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850003193542033132 12/30/23-07:00:15.062948TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749860193542814856 12/30/23-06:59:02.085316TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949774193542814856 12/30/23-06:58:11.217163TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749742193542814856 12/30/23-06:57:14.088663TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974219354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550072193542033132 12/30/23-07:00:49.694789TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007219354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749743193542814856 12/30/23-06:57:16.689114TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4974319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749881193542814856 12/30/23-06:59:13.594722TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949773193542814856 12/30/23-06:58:10.300191TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977319354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850024193542033132 12/30/23-07:00:25.751103TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002419354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550071193542033132 12/30/23-07:00:49.200940TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007119354192.168.2.418.197.239.5
                                                    192.168.2.43.126.37.1850002193542033132 12/30/23-07:00:14.574938TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5000219354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850023193542033132 12/30/23-07:00:25.261896TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749880193542814856 12/30/23-06:59:13.111628TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988019354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949813193542033132 12/30/23-06:58:37.111513TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981319354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949834193542033132 12/30/23-06:58:47.933226TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749893193542033132 12/30/23-06:59:19.207463TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989319354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949812193542033132 12/30/23-06:58:36.594044TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949833193542033132 12/30/23-06:58:47.410751TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749894193542033132 12/30/23-06:59:19.676849TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989419354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550076193542033132 12/30/23-07:00:51.670271TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007619354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749868193542814856 12/30/23-06:59:06.145562TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986819354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949770193542814856 12/30/23-06:58:07.306224TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4977019354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949838193542033132 12/30/23-06:58:49.935180TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749897193542033132 12/30/23-06:59:21.130355TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949808193542814856 12/30/23-06:58:34.624993TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4980819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949816193542033132 12/30/23-06:58:38.707245TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949837193542033132 12/30/23-06:58:49.437993TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4983719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749890193542033132 12/30/23-06:59:17.730882TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749898193542033132 12/30/23-06:59:21.612585TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4989819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850056193542814856 12/30/23-07:00:41.990891TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005619354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749921193542814856 12/30/23-06:59:34.001695TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850020193542033132 12/30/23-07:00:23.762339TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5002019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850057193542814856 12/30/23-07:00:42.486869TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005719354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550075193542033132 12/30/23-07:00:51.177057TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007519354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749884193542814856 12/30/23-06:59:15.059251TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749863193542814856 12/30/23-06:59:03.591806TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850052193542814856 12/30/23-07:00:40.013512TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005219354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749885193542814856 12/30/23-06:59:15.538707TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749864193542814856 12/30/23-06:59:04.086040TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749747193542814860 12/30/23-06:57:27.233979TCP2814860ETPRO TROJAN njRAT/Bladabindi CnC Callback (act)4974719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949817193542033132 12/30/23-06:58:39.233276TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4981719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749867193542814856 12/30/23-06:59:05.648160TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4986719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749889193542814856 12/30/23-06:59:17.489613TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988919354192.168.2.43.127.138.57
                                                    192.168.2.418.197.239.550079193542033132 12/30/23-07:00:53.177189TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5007919354192.168.2.418.197.239.5
                                                    192.168.2.43.126.37.1850053193542814856 12/30/23-07:00:40.509000TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5005319354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749888193542814856 12/30/23-06:59:17.003077TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4988819354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749929193542814856 12/30/23-06:59:37.897152TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849979193542033132 12/30/23-07:00:02.833960TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997919354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749913193542033132 12/30/23-06:59:29.847668TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991319354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949772193542033132 12/30/23-06:58:09.095731TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949776193542033132 12/30/23-06:58:12.779493TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4977619354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949788193542814856 12/30/23-06:58:22.759732TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978819354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749955193542033132 12/30/23-06:59:50.878260TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850038193542033132 12/30/23-07:00:32.609416TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003819354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949825193542814856 12/30/23-06:58:43.598734TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982519354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849971193542033132 12/30/23-06:59:58.824501TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997119354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949784193542814856 12/30/23-06:58:20.048612TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749732193542814856 12/30/23-06:57:03.726887TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4973219354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949829193542814856 12/30/23-06:58:45.628952TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982919354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849975193542033132 12/30/23-07:00:00.846778TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4997519354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749925193542814856 12/30/23-06:59:35.937314TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4992519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749951193542033132 12/30/23-06:59:48.922026TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850008193542814856 12/30/23-07:00:17.739937TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000819354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550082193542033132 12/30/23-07:00:57.990897TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5008219354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749891193542814856 12/30/23-06:59:18.463462TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989119354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850034193542033132 12/30/23-07:00:30.660872TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003419354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849987193542814856 12/30/23-07:00:07.450556TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998719354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949840193542033132 12/30/23-06:58:51.058204TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984019354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1849997193542814856 12/30/23-07:00:12.349998TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999719354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849981193542033132 12/30/23-07:00:04.257676TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998119354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749949193542033132 12/30/23-06:59:47.956084TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749917193542033132 12/30/23-06:59:31.804979TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4991719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749907193542033132 12/30/23-06:59:26.034167TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949821193542814856 12/30/23-06:58:41.518023TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4982119354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949810193542814856 12/30/23-06:58:35.769712TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981019354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749959193542033132 12/30/23-06:59:52.826362TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4995919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849993193542814856 12/30/23-07:00:10.379084TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4999319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849983193542814856 12/30/23-07:00:05.478752TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4998319354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1849968193542033132 12/30/23-06:59:57.372313TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996819354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749941193542033132 12/30/23-06:59:43.498607TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994119354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949765193542033132 12/30/23-06:58:01.233628TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749920193542033132 12/30/23-06:59:33.270015TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992019354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749924193542033132 12/30/23-06:59:35.208692TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4992419354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749903193542033132 12/30/23-06:59:24.070627TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4990319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749919193542814856 12/30/23-06:59:33.018377TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991919354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749945193542033132 12/30/23-06:59:46.067668TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4994519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849989193542033132 12/30/23-07:00:08.205585TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998919354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949814193542814856 12/30/23-06:58:37.887301TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981419354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949835193542814856 12/30/23-06:58:48.686724TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983519354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749932193542814856 12/30/23-06:59:39.358213TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993219354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949769193542033132 12/30/23-06:58:05.988000TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4976919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749911193542814856 12/30/23-06:59:29.126763TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991119354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749915193542814856 12/30/23-06:59:31.070055TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4991519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749849193542033132 12/30/23-06:58:56.346466TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984919354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949818193542814856 12/30/23-06:58:39.988518TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4981819354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949839193542814856 12/30/23-06:58:50.694196TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4983919354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749936193542814856 12/30/23-06:59:41.281512TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4993619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749962193542033132 12/30/23-06:59:54.301440TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4996219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749957193542814856 12/30/23-06:59:52.099962TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995719354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1849985193542033132 12/30/23-07:00:06.216832TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4998519354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949802193542033132 12/30/23-06:58:30.906256TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980219354192.168.2.418.156.13.209
                                                    192.168.2.418.156.13.20949823193542033132 12/30/23-06:58:42.341539TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982319354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749862193542033132 12/30/23-06:59:02.844678TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986219354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749883193542033132 12/30/23-06:59:14.334660TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850051193542033132 12/30/23-07:00:39.525800TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5005119354192.168.2.43.126.37.18
                                                    192.168.2.418.156.13.20949844193542033132 12/30/23-06:58:53.721212TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4984419354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749749193542033132 12/30/23-06:57:32.111036TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974919354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949827193542033132 12/30/23-06:58:44.367837TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4982719354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749866193542033132 12/30/23-06:59:04.846811TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4986619354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749887193542033132 12/30/23-06:59:16.275491TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4988719354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949780193542814856 12/30/23-06:58:17.081603TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4978019354192.168.2.418.156.13.209
                                                    192.168.2.43.126.37.1850004193542814856 12/30/23-07:00:15.787254TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000419354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749953193542814856 12/30/23-06:59:50.142653TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4995319354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850046193542814856 12/30/23-07:00:36.764056TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004619354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550065193542033132 12/30/23-07:00:46.284271TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006519354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749895193542814856 12/30/23-06:59:20.392745TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989519354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850025193542814856 12/30/23-07:00:26.469978TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002519354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850030193542033132 12/30/23-07:00:28.712067TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5003019354192.168.2.43.126.37.18
                                                    192.168.2.43.127.138.5749745193542033132 12/30/23-06:57:21.641720TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4974519354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749853193542814856 12/30/23-06:58:58.560128TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985319354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749874193542814856 12/30/23-06:59:09.083915TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987419354192.168.2.43.127.138.57
                                                    192.168.2.418.156.13.20949806193542033132 12/30/23-06:58:33.167163TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)4980619354192.168.2.418.156.13.209
                                                    192.168.2.43.127.138.5749857193542814856 12/30/23-06:59:00.592542TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4985719354192.168.2.43.127.138.57
                                                    192.168.2.43.127.138.5749878193542814856 12/30/23-06:59:12.145204TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4987819354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850000193542814856 12/30/23-07:00:13.841135TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5000019354192.168.2.43.126.37.18
                                                    192.168.2.43.126.37.1850042193542814856 12/30/23-07:00:34.818033TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5004219354192.168.2.43.126.37.18
                                                    192.168.2.418.197.239.550069193542033132 12/30/23-07:00:48.227392TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)5006919354192.168.2.418.197.239.5
                                                    192.168.2.43.127.138.5749899193542814856 12/30/23-06:59:22.330011TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)4989919354192.168.2.43.127.138.57
                                                    192.168.2.43.126.37.1850021193542814856 12/30/23-07:00:24.486098TCP2814856ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf)5002119354192.168.2.43.126.37.18
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Dec 30, 2023 06:56:55.469639063 CET4972919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:55.712502003 CET19354497293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:55.712625980 CET4972919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:55.865511894 CET4972919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:56.048576117 CET19354497293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:56.048635960 CET4972919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:56.108165026 CET19354497293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:56.291342020 CET19354497293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:56.327167988 CET19354497293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:56.327183008 CET19354497293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:56.327256918 CET4972919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.073153019 CET4972919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.074419975 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.313826084 CET19354497303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:58.313930035 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.314970970 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.554075956 CET19354497303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:58.554147005 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.641149998 CET19354497303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:58.694055080 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:56:58.793492079 CET19354497303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:58.828941107 CET19354497303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:58.829019070 CET19354497303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:56:58.829099894 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:00.648231030 CET4973019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:00.650451899 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:00.891793013 CET19354497313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:00.891927004 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:00.892532110 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:01.133577108 CET19354497313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:01.133658886 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:01.235593081 CET19354497313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:01.287942886 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:01.374927044 CET19354497313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:01.407370090 CET19354497313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:01.407386065 CET19354497313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:01.407542944 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.241113901 CET4973119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.242218018 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.484025955 CET19354497323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:03.484100103 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.485136032 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.726814985 CET19354497323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:03.726886988 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.814831018 CET19354497323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:03.866045952 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:03.968732119 CET19354497323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:03.999703884 CET19354497323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:03.999720097 CET19354497323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:03.999783993 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:05.840255022 CET4973219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:05.841445923 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:06.081151009 CET19354497333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:06.081355095 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:06.081901073 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:06.321582079 CET19354497333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:06.321692944 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:06.409636021 CET19354497333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:06.561436892 CET19354497333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:06.569060087 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:06.594801903 CET19354497333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:06.594818115 CET19354497333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:06.594871998 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:08.413548946 CET4973319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:08.421092033 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:08.661777973 CET19354497353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:08.661849022 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:08.663103104 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:08.903800964 CET19354497353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:08.903912067 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:09.012130022 CET19354497353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:09.144530058 CET19354497353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:09.170716047 CET19354497353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:09.170902967 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:09.171422005 CET19354497353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:09.171493053 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.022619963 CET4973519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.023657084 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.266801119 CET19354497413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:11.267137051 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.270021915 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.513315916 CET19354497413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:11.514601946 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.594841003 CET19354497413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:11.662825108 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:11.757683039 CET19354497413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:11.785778046 CET19354497413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:11.785835028 CET19354497413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:11.785921097 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:13.600963116 CET4974119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:13.605890989 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:13.846651077 CET19354497423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:13.846934080 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:13.847950935 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:14.088594913 CET19354497423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:14.088663101 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:14.181797981 CET19354497423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:14.272203922 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:14.329301119 CET19354497423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:14.359915018 CET19354497423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:14.360059977 CET19354497423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:14.360112906 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.194334984 CET4974219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.195732117 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.441185951 CET19354497433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:16.441327095 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.443459034 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.688981056 CET19354497433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:16.689114094 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.797094107 CET19354497433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:16.850425959 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:16.934520960 CET19354497433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:16.965940952 CET19354497433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:16.974797964 CET19354497433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:16.974967957 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:18.803529978 CET4974319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:18.804729939 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:19.049343109 CET19354497443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:19.049530029 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:19.050040960 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:19.294501066 CET19354497443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:19.294692039 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:19.392755032 CET19354497443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:19.444128990 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:19.539094925 CET19354497443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:19.573976040 CET19354497443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:19.573988914 CET19354497443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:19.574048996 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:21.397290945 CET4974419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:21.398519993 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:21.640994072 CET19354497453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:21.641103029 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:21.641720057 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:21.884291887 CET19354497453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:21.884586096 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:22.005055904 CET19354497453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:22.069222927 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:22.127147913 CET19354497453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:22.155880928 CET19354497453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:22.155936003 CET19354497453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:22.156177998 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.061997890 CET4974519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.080318928 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.323915005 CET19354497463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:24.324049950 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.324942112 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.568738937 CET19354497463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:24.568831921 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.652942896 CET19354497463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:24.739059925 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:24.812693119 CET19354497463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:24.838845968 CET19354497463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:24.852193117 CET19354497463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:24.852261066 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:26.663192034 CET4974619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:26.666383028 CET4974719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:26.908193111 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:26.908567905 CET4974719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:26.909122944 CET4974719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:27.150551081 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:27.150655031 CET4974719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:27.233905077 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:27.233978987 CET4974719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:27.392143011 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:27.423588037 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:27.423638105 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:27.423718929 CET4974719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:27.475579977 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:27.665219069 CET19354497473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:29.269331932 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:29.509983063 CET19354497483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:29.510155916 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:29.511857033 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:29.752959013 CET19354497483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:29.753082037 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:29.858458996 CET19354497483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:29.993510008 CET19354497483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:30.022701979 CET19354497483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:30.022735119 CET19354497483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:30.022757053 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:30.022804976 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:31.866151094 CET4974819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:31.867369890 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:32.110030890 CET19354497493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:32.110120058 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:32.111036062 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:32.353615999 CET19354497493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:32.353859901 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:32.436157942 CET19354497493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:32.490957975 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:32.608221054 CET19354497493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:32.624315023 CET19354497493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:32.624331951 CET19354497493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:32.624413967 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:34.444252968 CET4974919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:34.445239067 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:34.687108040 CET19354497503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:34.687323093 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:34.687733889 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:34.929590940 CET19354497503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:34.929637909 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:35.032809019 CET19354497503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:35.084790945 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:35.171435118 CET19354497503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:35.201462984 CET19354497503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:35.201478958 CET19354497503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:35.201652050 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.037993908 CET4975019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.039066076 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.278801918 CET19354497513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:37.279035091 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.279473066 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.519175053 CET19354497513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:37.519222975 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.604433060 CET19354497513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:37.647273064 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:37.758863926 CET19354497513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:37.787389994 CET19354497513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:37.787451029 CET19354497513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:37.787514925 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:39.475552082 CET4975119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:39.484791040 CET4975219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:39.725323915 CET19354497523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:39.725442886 CET4975219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:39.791208029 CET4975219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:39.966010094 CET19354497523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:39.966123104 CET4975219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:39.966161013 CET19354497523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:39.966211081 CET4975219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:40.031846046 CET19354497523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:40.206614017 CET19354497523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:40.206629038 CET19354497523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:41.710866928 CET4975319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:41.950124979 CET19354497533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:41.950222969 CET4975319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:41.950784922 CET4975319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:42.189599991 CET19354497533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:42.189749956 CET19354497533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:42.189826965 CET4975319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:42.189826965 CET4975319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:42.189971924 CET19354497533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:42.429240942 CET19354497533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:42.429254055 CET19354497533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:43.831419945 CET4975419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:44.073935986 CET19354497543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:44.074026108 CET4975419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:44.074834108 CET4975419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:44.316701889 CET19354497543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:44.316716909 CET19354497543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:44.316817999 CET4975419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:44.317152977 CET19354497543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:44.559246063 CET19354497543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:45.885195971 CET4975519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:46.128730059 CET19354497553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:46.128828049 CET4975519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:46.129319906 CET4975519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:46.372411966 CET19354497553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:46.372576952 CET19354497553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:46.372600079 CET4975519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:46.372653961 CET4975519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:46.372809887 CET19354497553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:46.615991116 CET19354497553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:46.616020918 CET19354497553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:47.806771040 CET4975619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:48.049669981 CET19354497563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:48.049787045 CET4975619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:48.050571918 CET4975619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:48.292825937 CET19354497563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:48.292840004 CET19354497563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:48.292898893 CET4975619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:48.293452024 CET19354497563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:48.535660982 CET19354497563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:49.634615898 CET4975719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:49.874525070 CET19354497573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:49.874598980 CET4975719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:49.875086069 CET4975719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:50.114594936 CET19354497573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:50.114636898 CET19354497573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:50.114659071 CET4975719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:50.114698887 CET4975719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:50.114908934 CET19354497573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:50.354707956 CET19354497573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:50.354873896 CET19354497573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:51.356833935 CET4975919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:51.597254038 CET19354497593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:51.599073887 CET4975919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:51.599816084 CET4975919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:51.839597940 CET19354497593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:51.839616060 CET19354497593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:51.839689016 CET4975919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:51.840080023 CET19354497593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:52.080039978 CET19354497593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:53.008819103 CET4976019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:53.251128912 CET19354497603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:53.251445055 CET4976019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:53.252163887 CET4976019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:53.493859053 CET19354497603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:53.493877888 CET19354497603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:53.493963957 CET4976019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:53.494110107 CET4976019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:53.494343996 CET19354497603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:53.736330032 CET19354497603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:53.736406088 CET19354497603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:54.586138964 CET4976119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:54.827773094 CET19354497613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:54.827852011 CET4976119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:54.828622103 CET4976119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:55.069709063 CET19354497613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:55.069722891 CET19354497613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:55.069797993 CET4976119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:57:55.070066929 CET19354497613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:55.311407089 CET19354497613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:57:56.298998117 CET4976219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:56.539036989 CET193544976218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:56.539139986 CET4976219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:56.539963007 CET4976219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:56.779381990 CET193544976218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:56.779398918 CET193544976218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:56.779495955 CET4976219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:56.779906988 CET193544976218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:57.019632101 CET193544976218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:58.310801029 CET4976319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:58.550436974 CET193544976318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:58.550637960 CET4976319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:58.658795118 CET4976319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:58.790417910 CET193544976318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:58.790433884 CET193544976318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:58.790672064 CET4976319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:58.898622990 CET193544976318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:59.030297995 CET193544976318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:59.686278105 CET4976419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:59.929301977 CET193544976418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:57:59.929392099 CET4976419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:57:59.930347919 CET4976419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:00.172513008 CET193544976418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:00.172621965 CET4976419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:00.172861099 CET193544976418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:00.172991037 CET4976419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:00.173341990 CET193544976418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:00.415615082 CET193544976418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:00.415857077 CET193544976418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:00.992511034 CET4976519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:01.232672930 CET193544976518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:01.232888937 CET4976519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:01.233628035 CET4976519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:01.473098993 CET193544976518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:01.473112106 CET193544976518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:01.473264933 CET4976519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:01.473514080 CET193544976518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:01.713239908 CET193544976518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:02.242513895 CET4976619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:02.484847069 CET193544976618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:02.484931946 CET4976619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:02.485766888 CET4976619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:02.727041006 CET193544976618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:02.727061033 CET193544976618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:02.727133036 CET4976619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:02.727567911 CET193544976618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:02.968995094 CET193544976618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:03.466685057 CET4976719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:03.712558985 CET193544976718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:03.712667942 CET4976719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:03.713666916 CET4976719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:03.958637953 CET193544976718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:03.958652973 CET193544976718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:03.958714962 CET4976719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:03.958750010 CET4976719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:03.959395885 CET193544976718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:04.204499960 CET193544976718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:04.204637051 CET193544976718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:04.633238077 CET4976819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:04.875629902 CET193544976818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:04.875732899 CET4976819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:04.876943111 CET4976819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:05.118236065 CET193544976818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:05.118249893 CET193544976818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:05.118313074 CET4976819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:05.118354082 CET4976819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:05.119173050 CET193544976818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:05.360723972 CET193544976818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:05.360738993 CET193544976818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:05.743041992 CET4976919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:05.986917019 CET193544976918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:05.987031937 CET4976919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:05.987999916 CET4976919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:06.230175018 CET193544976918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:06.230189085 CET193544976918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:06.230283022 CET4976919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:06.230813980 CET193544976918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:06.473305941 CET193544976918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:06.826179028 CET4977019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:07.066178083 CET193544977018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:07.066287041 CET4977019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:07.067338943 CET4977019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:07.306039095 CET193544977018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:07.306056023 CET193544977018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:07.306224108 CET4977019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:07.306224108 CET4977019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:07.306979895 CET193544977018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:07.546003103 CET193544977018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:07.546015978 CET193544977018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:07.856683016 CET4977119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:08.095185041 CET193544977118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:08.095284939 CET4977119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:08.096307993 CET4977119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:08.334018946 CET193544977118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:08.334032059 CET193544977118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:08.334196091 CET4977119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:08.334676027 CET193544977118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:08.572686911 CET193544977118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:08.852111101 CET4977219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:09.094588995 CET193544977218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:09.094680071 CET4977219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:09.095731020 CET4977219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:09.337173939 CET193544977218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:09.337203026 CET193544977218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:09.337275982 CET4977219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:09.337819099 CET193544977218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:09.579693079 CET193544977218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:09.820400953 CET4977319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:10.060245991 CET193544977318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:10.060367107 CET4977319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:10.061343908 CET4977319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:10.300115108 CET193544977318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:10.300117016 CET193544977318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:10.300190926 CET4977319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:10.300797939 CET193544977318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:10.539756060 CET193544977318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:10.742480040 CET4977419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:10.979680061 CET193544977418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:10.979772091 CET4977419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:10.980763912 CET4977419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:11.216897011 CET193544977418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:11.216931105 CET193544977418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:11.217163086 CET4977419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:11.217597961 CET193544977418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:11.454109907 CET193544977418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:11.655291080 CET4977519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:11.897640944 CET193544977518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:11.897865057 CET4977519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:11.898803949 CET4977519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:12.140439034 CET193544977518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:12.140475988 CET193544977518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:12.140544891 CET4977519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:12.140566111 CET4977519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:12.141031027 CET193544977518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:12.383076906 CET193544977518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:12.383104086 CET193544977518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:12.539172888 CET4977619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:12.778510094 CET193544977618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:12.778629065 CET4977619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:12.779493093 CET4977619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.018224001 CET193544977618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.018254995 CET193544977618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.018301010 CET4977619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.018321037 CET4977619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.018587112 CET193544977618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.259902000 CET193544977618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.259913921 CET193544977618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.382709980 CET4977719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.627516985 CET193544977718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.627597094 CET4977719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.628185987 CET4977719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.872520924 CET193544977718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.872553110 CET193544977718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:13.872631073 CET4977719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:13.872889042 CET193544977718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:14.117446899 CET193544977718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:14.210779905 CET4977819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:14.449465990 CET193544977818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:14.449559927 CET4977819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:14.453525066 CET4977819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:14.688656092 CET193544977818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:14.688671112 CET193544977818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:14.688766956 CET4977819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:14.692053080 CET193544977818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:14.927287102 CET193544977818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:15.307110071 CET4977919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:15.549776077 CET193544977918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:15.549916983 CET4977919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:15.550530910 CET4977919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:15.792695999 CET193544977918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:15.792812109 CET4977919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:15.792849064 CET193544977918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:15.792920113 CET4977919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:15.793061972 CET193544977918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:16.036072969 CET193544977918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:16.036108971 CET193544977918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:16.597455025 CET4978019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:16.839514971 CET193544978018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:16.839610100 CET4978019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:16.840241909 CET4978019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:17.081511974 CET193544978018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.081541061 CET193544978018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.081603050 CET4978019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:17.081620932 CET4978019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:17.081878901 CET193544978018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.323290110 CET193544978018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.323319912 CET193544978018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.367172003 CET4978119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:17.604918003 CET193544978118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.605129957 CET4978119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:17.605536938 CET4978119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:17.843152046 CET193544978118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.843184948 CET193544978118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.843194962 CET193544978118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:17.843270063 CET4978119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:18.081218004 CET193544978118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.101429939 CET4978219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:18.344285965 CET193544978218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.344388008 CET4978219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:18.344993114 CET4978219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:18.587568045 CET193544978218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.587634087 CET193544978218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.587635994 CET4978219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:18.587661982 CET193544978218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.587680101 CET4978219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:18.830452919 CET193544978218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.830496073 CET193544978218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:18.835980892 CET4978319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.075556993 CET193544978318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:19.075786114 CET4978319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.076237917 CET4978319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.316078901 CET193544978318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:19.316106081 CET193544978318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:19.316112041 CET193544978318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:19.316332102 CET4978319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.550966978 CET4978319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.552352905 CET4978419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.555958033 CET193544978318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:19.797579050 CET193544978418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:19.803090096 CET4978419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:19.803731918 CET4978419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.048382998 CET193544978418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.048420906 CET193544978418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.048612118 CET4978419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.048707008 CET193544978418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.256684065 CET4978419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.257739067 CET4978519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.293905020 CET193544978418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.502135038 CET193544978518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.502245903 CET4978519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.502866983 CET4978519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.746783018 CET193544978518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.746798992 CET193544978518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.746862888 CET4978519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.746997118 CET193544978518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:20.944242001 CET4978519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.945406914 CET4978619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:20.991242886 CET193544978518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.187278986 CET193544978618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.189857960 CET4978619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:21.190682888 CET4978619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:21.431865931 CET193544978618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.431894064 CET193544978618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.432065010 CET4978619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:21.432614088 CET193544978618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.616522074 CET4978619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:21.617552042 CET4978719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:21.673980951 CET193544978618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.858721972 CET193544978718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:21.858798981 CET4978719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:21.859503031 CET4978719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.099843979 CET193544978718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.099862099 CET193544978718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.099906921 CET4978719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.099948883 CET4978719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.100285053 CET193544978718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.272299051 CET4978719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.273454905 CET4978819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.340893030 CET193544978718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.340913057 CET193544978718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.516402006 CET193544978818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.516474962 CET4978819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.517327070 CET4978819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.759617090 CET193544978818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.759649038 CET193544978818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.759732008 CET4978819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.760241985 CET193544978818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:22.928529978 CET4978819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:22.929572105 CET4978919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.002851963 CET193544978818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.168359041 CET193544978918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.168443918 CET4978919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.169790983 CET4978919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.407259941 CET193544978918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.407274961 CET193544978918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.407334089 CET4978919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.408323050 CET193544978918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.553642035 CET4978919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.554681063 CET4979019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.646004915 CET193544978918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.797100067 CET193544979018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:23.797205925 CET4979019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:23.797822952 CET4979019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.039774895 CET193544979018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.039791107 CET193544979018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.039838076 CET4979019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.039882898 CET4979019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.039902925 CET193544979018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.178569078 CET4979019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.179522991 CET4979119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.282085896 CET193544979018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.282099962 CET193544979018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.421844006 CET193544979118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.421943903 CET4979119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.422555923 CET4979119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.664598942 CET193544979118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.664618969 CET193544979118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.664665937 CET4979119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.664705992 CET4979119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.664767981 CET193544979118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.803643942 CET4979119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.804748058 CET4979219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:24.907155037 CET193544979118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:24.907167912 CET193544979118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.048531055 CET193544979218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.048612118 CET4979219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.052320004 CET4979219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.292591095 CET193544979218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.292603970 CET193544979218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.292660952 CET4979219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.295943022 CET193544979218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.430929899 CET4979219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.432034016 CET4979319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.536312103 CET193544979218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.673746109 CET193544979318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.673851013 CET4979319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.674401045 CET4979319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.915761948 CET193544979318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.915790081 CET193544979318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:25.915868998 CET4979319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:25.916273117 CET193544979318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.037954092 CET4979319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.040007114 CET4979419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.157805920 CET193544979318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.282926083 CET193544979418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.283005953 CET4979419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.283658981 CET4979419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.526029110 CET193544979418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.526047945 CET193544979418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.526084900 CET4979419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.526113033 CET4979419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.526457071 CET193544979418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.631653070 CET4979419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.632620096 CET4979519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.769078970 CET193544979418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.769089937 CET193544979418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.876574993 CET193544979518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:26.876708984 CET4979519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:26.878298044 CET4979519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.120683908 CET193544979518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.120711088 CET193544979518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.120834112 CET4979519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.122190952 CET193544979518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.225418091 CET4979519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.226392984 CET4979619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.364667892 CET193544979518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.468835115 CET193544979618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.468950987 CET4979619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.470586061 CET4979619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.711349964 CET193544979618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.711380005 CET193544979618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.711457014 CET4979619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.711477041 CET4979619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.712718010 CET193544979618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.803529024 CET4979619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.804554939 CET4979719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:27.953979969 CET193544979618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:27.953991890 CET193544979618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.046653986 CET193544979718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.046778917 CET4979719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.048530102 CET4979719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.289083004 CET193544979718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.289117098 CET193544979718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.289196014 CET4979719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.289232969 CET4979719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.290546894 CET193544979718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.381668091 CET4979719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.382591009 CET4979819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.531244993 CET193544979718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.531276941 CET193544979718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.628097057 CET193544979818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.628212929 CET4979819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.628829956 CET4979819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.873769045 CET193544979818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.873806000 CET193544979818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.873868942 CET4979819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.873904943 CET4979819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.874051094 CET193544979818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:28.960310936 CET4979819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:28.974420071 CET4979919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.119342089 CET193544979818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.119369984 CET193544979818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.211638927 CET193544979918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.211745977 CET4979919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.212613106 CET4979919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.449337006 CET193544979918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.449385881 CET193544979918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.449481964 CET4979919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.449696064 CET193544979918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.449733019 CET4979919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.538038015 CET4979919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.539139986 CET4980019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.686760902 CET193544979918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.686808109 CET193544979918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.780451059 CET193544980018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:29.780654907 CET4980019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:29.782591105 CET4980019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.021934032 CET193544980018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.021948099 CET193544980018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.022010088 CET4980019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.023519039 CET193544980018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.100474119 CET4980019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.101500034 CET4980119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.263041973 CET193544980018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.342762947 CET193544980118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.342885017 CET4980119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.343482971 CET4980119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.584295988 CET193544980118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.584330082 CET193544980118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.584405899 CET4980119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.584635019 CET4980119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.584881067 CET193544980118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.662919044 CET4980119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.664108038 CET4980219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.825658083 CET193544980118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.825742006 CET193544980118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.905564070 CET193544980218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:30.905781031 CET4980219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:30.906255960 CET4980219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.147478104 CET193544980218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.147480011 CET193544980218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.147530079 CET193544980218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.147559881 CET4980219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.220212936 CET4980219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.221117020 CET4980319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.389095068 CET193544980218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.464378119 CET193544980318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.464520931 CET4980319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.468455076 CET4980319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.707746029 CET193544980318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.707776070 CET193544980318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.707861900 CET4980319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.707895994 CET4980319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.711489916 CET193544980318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.772326946 CET4980319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.773396969 CET4980419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:31.951678991 CET193544980318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:31.951689959 CET193544980318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.015662909 CET193544980418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.015746117 CET4980419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.016402006 CET4980419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.258167028 CET193544980418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.258177996 CET193544980418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.258279085 CET4980419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.258677959 CET193544980418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.319166899 CET4980419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.320183992 CET4980519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.500633001 CET193544980418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.562853098 CET193544980518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.562922001 CET4980519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.563529968 CET4980519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.805737019 CET193544980518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.805768013 CET193544980518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.805845022 CET4980519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.805845976 CET4980519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.805881977 CET193544980518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:32.866051912 CET4980519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:32.867043972 CET4980619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.048394918 CET193544980518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.048408985 CET193544980518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.111119032 CET193544980618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.111248970 CET4980619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.167162895 CET4980619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.355370045 CET193544980618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.355400085 CET193544980618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.355459929 CET4980619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.411066055 CET193544980618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.412931919 CET4980619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.414015055 CET4980719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.599477053 CET193544980618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.653493881 CET193544980718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.653589010 CET4980719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:33.893107891 CET193544980718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.893135071 CET193544980718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:33.893208981 CET4980719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.079878092 CET4980719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.131653070 CET4980719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.132632971 CET4980819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.319220066 CET193544980718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:34.378563881 CET193544980818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:34.378798008 CET4980819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.389035940 CET4980819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.624906063 CET193544980818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:34.624936104 CET193544980818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:34.624993086 CET4980819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.625010014 CET4980819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.634984016 CET193544980818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:34.764055967 CET4980819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.765091896 CET4980919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:34.870866060 CET193544980818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:34.870915890 CET193544980818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.007375002 CET193544980918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.007458925 CET4980919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.007967949 CET4980919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.249974966 CET193544980918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.250008106 CET193544980918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.250061035 CET4980919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.250107050 CET4980919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.250170946 CET193544980918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.288853884 CET4980919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.289756060 CET4981019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.492583990 CET193544980918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.492613077 CET193544980918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.529040098 CET193544981018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.529248953 CET4981019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.529676914 CET4981019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.769632101 CET193544981018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.769644976 CET193544981018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.769711971 CET4981019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.769892931 CET193544981018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:35.819185972 CET4981019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:35.820188046 CET4981119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.008879900 CET193544981018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.061103106 CET193544981118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.061211109 CET4981119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.061798096 CET4981119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.302227974 CET193544981118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.302287102 CET4981119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.302578926 CET193544981118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.302588940 CET193544981118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.302632093 CET4981119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.350667953 CET4981119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.351701021 CET4981219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.543267965 CET193544981118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.543395042 CET193544981118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.593422890 CET193544981218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.593492031 CET4981219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.594043970 CET4981219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.835263968 CET193544981218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.835455894 CET4981219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.835475922 CET193544981218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.835524082 CET4981219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.835604906 CET193544981218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:36.866033077 CET4981219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:36.867039919 CET4981319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.077826023 CET193544981218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.077853918 CET193544981218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.110816002 CET193544981318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.110877037 CET4981319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.111512899 CET4981319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.354887962 CET193544981318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.354949951 CET4981319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.355366945 CET193544981318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.355376959 CET193544981318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.355418921 CET4981319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.397600889 CET4981319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.404426098 CET4981419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.598769903 CET193544981318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.599061012 CET193544981318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.645752907 CET193544981418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.645883083 CET4981419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.646708965 CET4981419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.887207985 CET193544981418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.887236118 CET193544981418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.887300968 CET4981419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.887835026 CET193544981418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:37.929512978 CET4981419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:37.938266039 CET4981519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.128437042 CET193544981418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.180172920 CET193544981518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.180330038 CET4981519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.185220003 CET4981519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.422117949 CET193544981518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.422144890 CET193544981518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.422230005 CET4981519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.426739931 CET193544981518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.459767103 CET4981519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.460742950 CET4981619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.664048910 CET193544981518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.706485033 CET193544981618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.706610918 CET4981619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.707245111 CET4981619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.952754974 CET193544981618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.952781916 CET193544981618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.952892065 CET4981619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.953598976 CET193544981618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:38.991147041 CET4981619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:38.992177010 CET4981719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.198976040 CET193544981618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.232516050 CET193544981718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.232764006 CET4981719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.233275890 CET4981719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.473288059 CET193544981718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.473534107 CET4981719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.473542929 CET193544981718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.473556042 CET193544981718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.473592997 CET4981719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.509887934 CET4981719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.510932922 CET4981819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.713917017 CET193544981718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.713929892 CET193544981718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.749478102 CET193544981818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.749607086 CET4981819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.751348972 CET4981819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.988311052 CET193544981818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.988344908 CET193544981818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:39.988518000 CET4981819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.988518953 CET4981819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:39.989804983 CET193544981818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.022301912 CET4981819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.023286104 CET4981919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.227093935 CET193544981818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.227107048 CET193544981818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.262006998 CET193544981918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.262073994 CET4981919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.262690067 CET4981919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.500937939 CET193544981918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.500952005 CET193544981918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.500999928 CET4981919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.501013041 CET4981919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.501234055 CET193544981918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.522279024 CET4981919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.523272991 CET4982019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.739631891 CET193544981918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.739645004 CET193544981918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.764806986 CET193544982018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:40.764899015 CET4982019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:40.765520096 CET4982019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.006557941 CET193544982018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.006653070 CET4982019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.006706953 CET193544982018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.006773949 CET4982019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.007035017 CET193544982018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.038014889 CET4982019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.039110899 CET4982119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.248321056 CET193544982018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.248333931 CET193544982018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.278459072 CET193544982118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.278547049 CET4982119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.279187918 CET4982119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.517972946 CET193544982118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.518023014 CET4982119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.518126011 CET193544982118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.518172026 CET4982119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.518274069 CET193544982118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.586462021 CET4982119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.587506056 CET4982219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.757452965 CET193544982118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.757464886 CET193544982118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.833708048 CET193544982218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:41.833811045 CET4982219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:41.834391117 CET4982219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.079993963 CET193544982218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.080008984 CET193544982218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.080105066 CET4982219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.080341101 CET193544982218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.100537062 CET4982219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.101499081 CET4982319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.326153994 CET193544982218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.340836048 CET193544982318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.340910912 CET4982319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.341538906 CET4982319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.580466986 CET193544982318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.580480099 CET193544982318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.580545902 CET4982319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.580807924 CET193544982318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.603815079 CET4982319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.604780912 CET4982419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.819755077 CET193544982318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.847682953 CET193544982418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:42.847779989 CET4982419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:42.848388910 CET4982419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.090810061 CET193544982418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.090827942 CET193544982418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.090902090 CET4982419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.091136932 CET193544982418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.116516113 CET4982419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.117674112 CET4982519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.333781958 CET193544982418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.358016968 CET193544982518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.358128071 CET4982519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.358709097 CET4982519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.598654985 CET193544982518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.598669052 CET193544982518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.598733902 CET4982519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.598998070 CET193544982518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.618050098 CET4982519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.619998932 CET4982619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.840214014 CET193544982518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.860378027 CET193544982618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:43.860469103 CET4982619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:43.862219095 CET4982619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.099289894 CET193544982618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.099309921 CET193544982618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.099384069 CET4982619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.099415064 CET4982619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.100776911 CET193544982618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.116338968 CET4982619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.123684883 CET4982719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.337989092 CET193544982618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.338217020 CET193544982618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.367098093 CET193544982718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.367202044 CET4982719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.367836952 CET4982719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.610699892 CET193544982718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.610728979 CET193544982718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.610807896 CET4982719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.610972881 CET193544982718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.631869078 CET4982719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.639857054 CET4982819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.854114056 CET193544982718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.881496906 CET193544982818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:44.881601095 CET4982819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:44.882262945 CET4982819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.123395920 CET193544982818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.123409033 CET193544982818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.123471975 CET4982819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.123835087 CET193544982818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.147468090 CET4982819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.148526907 CET4982919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.365080118 CET193544982818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.389058113 CET193544982918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.389152050 CET4982919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.412489891 CET4982919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.628849030 CET193544982918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.628861904 CET193544982918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.628952026 CET4982919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.651055098 CET4982919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.652029991 CET193544982918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.652633905 CET4983019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.868932009 CET193544982918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.896928072 CET193544983018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:45.897021055 CET4983019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:45.902360916 CET4983019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.139512062 CET193544983018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.139525890 CET193544983018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.139597893 CET4983019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.144648075 CET193544983018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.162935019 CET4983019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.164000034 CET4983119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.381970882 CET193544983018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.407582045 CET193544983118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.407702923 CET4983119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.408297062 CET4983119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.651432991 CET193544983118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.651447058 CET193544983118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.651530027 CET4983119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.651721001 CET193544983118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.662910938 CET4983119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.663947105 CET4983219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.895066023 CET193544983118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.906238079 CET193544983218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:46.906315088 CET4983219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:46.906902075 CET4983219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.148757935 CET193544983218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.148855925 CET4983219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.148911953 CET193544983218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.149033070 CET4983219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.149216890 CET193544983218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.162978888 CET4983219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.164016962 CET4983319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.391478062 CET193544983218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.391490936 CET193544983218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.410056114 CET193544983318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.410123110 CET4983319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.410751104 CET4983319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.656096935 CET193544983318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.656114101 CET193544983318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.656166077 CET4983319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.656179905 CET4983319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.656536102 CET193544983318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.679135084 CET4983319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.691179991 CET4983419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.902100086 CET193544983318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.902115107 CET193544983318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.930996895 CET193544983418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:47.931102991 CET4983419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:47.933226109 CET4983419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.171086073 CET193544983418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.171099901 CET193544983418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.171147108 CET4983419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.172965050 CET193544983418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.195456982 CET4983419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.196516991 CET4983519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.411072969 CET193544983418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.441427946 CET193544983518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.441541910 CET4983519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.442152977 CET4983519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.686575890 CET193544983518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.686605930 CET193544983518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.686723948 CET4983519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.687217951 CET193544983518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.694240093 CET4983519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.695600986 CET4983619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.931741953 CET193544983518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.937390089 CET193544983618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:48.937493086 CET4983619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:48.938117027 CET4983619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.179534912 CET193544983618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.179564953 CET193544983618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.179642916 CET4983619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.180133104 CET193544983618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.194241047 CET4983619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.195348024 CET4983719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.421494961 CET193544983618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.437321901 CET193544983718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.437392950 CET4983719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.437993050 CET4983719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.679553986 CET193544983718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.679570913 CET193544983718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.679622889 CET4983719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.679651976 CET4983719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.679913044 CET193544983718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.694206953 CET4983719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.695189953 CET4983819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.921535015 CET193544983718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.921547890 CET193544983718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.934273958 CET193544983818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:49.934492111 CET4983819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:49.935179949 CET4983819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.173677921 CET193544983818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.173692942 CET193544983818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.173808098 CET4983819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.174057007 CET193544983818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.202183962 CET4983819354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.203181028 CET4983919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.412724972 CET193544983818.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.448662043 CET193544983918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.448744059 CET4983919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.449347973 CET4983919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.694092989 CET193544983918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.694124937 CET193544983918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.694195986 CET4983919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.694433928 CET193544983918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.709846020 CET4983919354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.710866928 CET4984019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:50.939620972 CET193544983918.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.954410076 CET193544984018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:50.954520941 CET4984019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.058203936 CET4984019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.197916985 CET193544984018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.198139906 CET4984019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.198184967 CET193544984018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.198230028 CET4984019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.233712912 CET4984019354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.234798908 CET4984119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.301484108 CET193544984018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.441576004 CET193544984018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.441611052 CET193544984018.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.477864981 CET193544984118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.477967978 CET4984119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:51.721400976 CET193544984118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.721434116 CET193544984118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:51.721534967 CET4984119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.214515924 CET4984119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.245666027 CET4984119354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.248600006 CET4984219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.457748890 CET193544984118.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:52.490494967 CET193544984218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:52.490613937 CET4984219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.732789040 CET193544984218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:52.732803106 CET193544984218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:52.732884884 CET4984219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.917768955 CET4984219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.976128101 CET4984219354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:52.977045059 CET4984319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.159737110 CET193544984218.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.217747927 CET193544984318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.217942953 CET4984319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.218383074 CET4984319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.458527088 CET193544984318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.458543062 CET193544984318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.458642006 CET4984319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.458784103 CET193544984318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.475687981 CET4984319354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.476679087 CET4984419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.699074984 CET193544984318.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.720247030 CET193544984418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.720354080 CET4984419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.721211910 CET4984419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.964123964 CET193544984418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.964139938 CET193544984418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.964217901 CET4984419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.964801073 CET193544984418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:53.975641966 CET4984419354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:53.982872009 CET4984519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.207890987 CET193544984418.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.222090960 CET193544984518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.222152948 CET4984519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.222789049 CET4984519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.461831093 CET193544984518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.461844921 CET193544984518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.461893082 CET4984519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.461913109 CET4984519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.462018013 CET193544984518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.476083994 CET4984519354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.477946997 CET4984619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.701030970 CET193544984518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.701071024 CET193544984518.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.720082998 CET193544984618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.720187902 CET4984619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.722012043 CET4984619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.962855101 CET193544984618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.962883949 CET193544984618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.962969065 CET4984619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.963007927 CET4984619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.964071035 CET193544984618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:54.975444078 CET4984619354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:54.976466894 CET4984719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:55.205110073 CET193544984618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.205123901 CET193544984618.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.219196081 CET193544984718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.219316006 CET4984719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:55.219908953 CET4984719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:55.462378979 CET193544984718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.462413073 CET193544984718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.462476969 CET4984719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:55.462512970 CET4984719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:55.462620020 CET193544984718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.475423098 CET4984719354192.168.2.418.156.13.209
                                                    Dec 30, 2023 06:58:55.601169109 CET4984819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:55.705246925 CET193544984718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.705260038 CET193544984718.156.13.209192.168.2.4
                                                    Dec 30, 2023 06:58:55.840503931 CET19354498483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:55.840629101 CET4984819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:55.841355085 CET4984819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.079993010 CET19354498483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.080007076 CET19354498483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.080049992 CET4984819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.080065012 CET4984819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.080507040 CET19354498483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.101556063 CET4984819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.102540016 CET4984919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.319482088 CET19354498483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.319494963 CET19354498483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.345535994 CET19354498493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.345841885 CET4984919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.346466064 CET4984919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.589584112 CET19354498493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.589692116 CET4984919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.592210054 CET19354498493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.592222929 CET19354498493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.601435900 CET4985019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.832658052 CET19354498493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.842210054 CET19354498503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:56.842308998 CET4985019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:56.842955112 CET4985019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.083234072 CET19354498503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.083249092 CET19354498503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.083342075 CET4985019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.083647013 CET19354498503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.100441933 CET4985019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.105731010 CET4985119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.324182034 CET19354498503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.349494934 CET19354498513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.349596024 CET4985119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.350136042 CET4985119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.593537092 CET19354498513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.593550920 CET19354498513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.593734980 CET4985119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.593811989 CET19354498513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.600425959 CET4985119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.601495028 CET4985219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.837544918 CET19354498513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.839301109 CET19354498523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:57.839375973 CET4985219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:57.840226889 CET4985219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.076363087 CET19354498523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.076426029 CET19354498523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.076572895 CET4985219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.076908112 CET19354498523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.084783077 CET4985219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.085808992 CET4985319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.313343048 CET19354498523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.322787046 CET19354498533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.322854042 CET4985319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.326026917 CET4985319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.559971094 CET19354498533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.559983969 CET19354498533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.560127974 CET4985319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.562941074 CET19354498533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.569856882 CET4985319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.577073097 CET4985419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.797218084 CET19354498533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.817059994 CET19354498543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:58.817277908 CET4985419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:58.817854881 CET4985419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.057389975 CET19354498543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.057404041 CET19354498543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.057473898 CET4985419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.057501078 CET4985419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.057763100 CET19354498543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.069257975 CET4985419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.070580006 CET4985519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.297760963 CET19354498543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.297771931 CET19354498543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.315713882 CET19354498553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.315831900 CET4985519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.316698074 CET4985519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.561113119 CET19354498553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.561129093 CET19354498553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.561214924 CET4985519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.561248064 CET4985519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.561738968 CET19354498553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.595700026 CET4985519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.596827984 CET4985619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.806370020 CET19354498553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.806384087 CET19354498553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.842068911 CET19354498563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:58:59.842209101 CET4985619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:58:59.842820883 CET4985619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.087599039 CET19354498563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.087610960 CET19354498563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.087694883 CET4985619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.087739944 CET19354498563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.100464106 CET4985619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.101485968 CET4985719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.332602978 CET19354498563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.346801996 CET19354498573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.346903086 CET4985719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.347549915 CET4985719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.592336893 CET19354498573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.592351913 CET19354498573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.592541933 CET4985719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.592745066 CET19354498573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.600569963 CET4985719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.601628065 CET4985819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.838017941 CET19354498573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.843544960 CET19354498583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:00.843638897 CET4985819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:00.844263077 CET4985819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.085702896 CET19354498583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.085716963 CET19354498583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.085902929 CET4985819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.086318970 CET19354498583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.100410938 CET4985819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.101489067 CET4985919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.327769041 CET19354498583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.343554020 CET19354498593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.343622923 CET4985919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.345119953 CET4985919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.585926056 CET19354498593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.585939884 CET19354498593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.585982084 CET4985919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.586004972 CET4985919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.587583065 CET19354498593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.600455046 CET4985919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.601461887 CET4986019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.828130007 CET19354498593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.828159094 CET19354498593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.843187094 CET19354498603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:01.843322039 CET4986019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:01.845457077 CET4986019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.085169077 CET19354498603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.085182905 CET19354498603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.085315943 CET4986019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.087014914 CET19354498603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.100492001 CET4986019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.101583958 CET4986119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.327120066 CET19354498603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.342772007 CET19354498613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.342987061 CET4986119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.343732119 CET4986119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.584198952 CET19354498613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.584225893 CET19354498613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.584434032 CET4986119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.584613085 CET19354498613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.600754023 CET4986119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.601752043 CET4986219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.825642109 CET19354498613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.843916893 CET19354498623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:02.844047070 CET4986219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:02.844677925 CET4986219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.086561918 CET19354498623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.086584091 CET19354498623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.086639881 CET4986219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.086661100 CET4986219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.086884975 CET19354498623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.100452900 CET4986219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.101730108 CET4986319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.328772068 CET19354498623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.328787088 CET19354498623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.346587896 CET19354498633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.346653938 CET4986319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.347714901 CET4986319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.591677904 CET19354498633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.591691017 CET19354498633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.591805935 CET4986319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.592495918 CET19354498633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.600438118 CET4986319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.601615906 CET4986419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.836857080 CET19354498633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.843678951 CET19354498643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:03.843791962 CET4986419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:03.844409943 CET4986419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.085916996 CET19354498643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.086040020 CET4986419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.086065054 CET19354498643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.086116076 CET4986419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.086286068 CET19354498643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.100996017 CET4986419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.102850914 CET4986519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.328171968 CET19354498643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.328486919 CET19354498643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.345488071 CET19354498653.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.345555067 CET4986519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.346122980 CET4986519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.588386059 CET19354498653.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.588404894 CET19354498653.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.588452101 CET4986519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.588502884 CET4986519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.588675976 CET19354498653.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.600413084 CET4986519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.601654053 CET4986619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.831231117 CET19354498653.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.831243992 CET19354498653.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.844208002 CET19354498663.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:04.844307899 CET4986619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:04.846811056 CET4986619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.087012053 CET19354498663.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.087024927 CET19354498663.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.087575912 CET4986619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.089574099 CET19354498663.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.100851059 CET4986619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.157993078 CET4986719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.330287933 CET19354498663.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.402930021 CET19354498673.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.403013945 CET4986719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.403703928 CET4986719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.648044109 CET19354498673.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.648058891 CET19354498673.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.648159981 CET4986719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.648427963 CET19354498673.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.662952900 CET4986719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.663965940 CET4986819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.893013954 CET19354498673.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.904314041 CET19354498683.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:05.904419899 CET4986819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:05.905389071 CET4986819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.145457983 CET19354498683.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.145561934 CET4986819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.145716906 CET19354498683.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.145734072 CET19354498683.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.148644924 CET4986919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.385713100 CET19354498683.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.389420986 CET19354498693.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.389602900 CET4986919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.391520023 CET4986919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.630536079 CET19354498693.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.630567074 CET19354498693.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.630731106 CET4986919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.630732059 CET4986919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.632200956 CET19354498693.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.648089886 CET4986919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.649007082 CET4987019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.871577024 CET19354498693.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.871591091 CET19354498693.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.891726017 CET19354498703.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:06.891799927 CET4987019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:06.892440081 CET4987019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.134568930 CET19354498703.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.134596109 CET19354498703.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.134679079 CET4987019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.135099888 CET19354498703.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.137835979 CET4987019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.138833046 CET4987119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.377357960 CET19354498703.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.380153894 CET19354498713.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.380342960 CET4987119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.380826950 CET4987119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.621918917 CET19354498713.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.622024059 CET4987119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.622056961 CET19354498713.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.622133017 CET19354498713.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.622196913 CET4987119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.622816086 CET4987119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.623778105 CET4987219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.863399982 CET19354498713.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.863668919 CET19354498713.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.865916014 CET19354498723.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:07.866038084 CET4987219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:07.866667032 CET4987219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.108186007 CET19354498723.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.108252048 CET4987219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.108459949 CET19354498723.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.108499050 CET4987219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.108675957 CET19354498723.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.111504078 CET4987219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.112500906 CET4987319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.350435019 CET19354498723.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.350565910 CET19354498723.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.353104115 CET19354498733.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.353205919 CET4987319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.354126930 CET4987319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.594233036 CET19354498733.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.594244957 CET19354498733.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.594470978 CET4987319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.594830036 CET4987319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.594887972 CET19354498733.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.596034050 CET4987419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.835392952 CET19354498733.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.839776039 CET19354498743.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:08.839873075 CET4987419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:08.860526085 CET4987419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.083695889 CET19354498743.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.083914995 CET4987419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.083945990 CET19354498743.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.084089994 CET4987419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.084774017 CET4987419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.085805893 CET4987519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.104196072 CET19354498743.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.327788115 CET19354498743.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.327908039 CET19354498743.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.330935001 CET19354498753.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.331136942 CET4987519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.335660934 CET4987519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.576251030 CET19354498753.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.576394081 CET19354498753.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.576469898 CET4987519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.579016924 CET4987519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.580585003 CET19354498753.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.584830046 CET4987519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.585922956 CET4987619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:09.821598053 CET19354498753.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.823901892 CET19354498753.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.824861050 CET19354498763.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:09.824944973 CET4987619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:10.064209938 CET19354498763.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:10.064229012 CET19354498763.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:10.064307928 CET4987619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.164509058 CET4987619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.173593998 CET4987619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.174559116 CET4987719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.403527021 CET19354498763.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.415786982 CET19354498773.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.415895939 CET4987719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.416435003 CET4987719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.657162905 CET19354498773.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.657182932 CET19354498773.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.657336950 CET4987719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.657336950 CET4987719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.657448053 CET19354498773.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.658480883 CET4987719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.659667969 CET4987819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.898489952 CET19354498773.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.898504019 CET19354498773.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.902357101 CET19354498783.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:11.902466059 CET4987819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:11.903317928 CET4987819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.145150900 CET19354498783.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.145204067 CET4987819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.145302057 CET19354498783.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.145349979 CET4987819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.145694017 CET4987819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.145807981 CET19354498783.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.146806955 CET4987919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.387794018 CET19354498783.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.387945890 CET19354498783.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.389004946 CET19354498793.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.389092922 CET4987919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.389729977 CET4987919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.631191015 CET19354498793.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.631221056 CET19354498793.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.631314039 CET4987919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.631776094 CET4987919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.631961107 CET19354498793.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.632822990 CET4988019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.872021914 CET19354498803.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:12.872111082 CET4988019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.872848034 CET4988019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:12.873217106 CET19354498793.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.111409903 CET19354498803.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.111628056 CET4988019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.111691952 CET19354498803.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.111701965 CET19354498803.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.111742973 CET4988019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.112974882 CET4988019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.114247084 CET4988119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.350646973 CET19354498803.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.350661039 CET19354498803.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.354388952 CET19354498813.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.354485989 CET4988119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.355381012 CET4988119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.594638109 CET19354498813.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.594671965 CET19354498813.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.594722033 CET4988119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.594882965 CET4988119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.595361948 CET19354498813.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.595581055 CET4988119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.596605062 CET4988219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.834805965 CET19354498813.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.834973097 CET19354498813.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.839142084 CET19354498823.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:13.839348078 CET4988219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:13.841892004 CET4988219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.082170963 CET19354498823.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.082204103 CET19354498823.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.082438946 CET4988219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.084367037 CET19354498823.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.091613054 CET4988219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.092966080 CET4988319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.324959993 CET19354498823.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.333758116 CET19354498833.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.333863974 CET4988319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.334660053 CET4988319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.574954033 CET19354498833.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.574984074 CET19354498833.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.575084925 CET4988319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.575352907 CET19354498833.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.575464010 CET4988319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.576396942 CET4988419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.817833900 CET19354498833.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.817989111 CET19354498843.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:14.818084955 CET4988419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:14.818820953 CET4988419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.059156895 CET19354498843.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.059211969 CET19354498843.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.059221983 CET19354498843.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.059251070 CET4988419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.059267998 CET4988419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.059801102 CET4988419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.060992956 CET4988519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.299524069 CET19354498843.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.299540997 CET19354498843.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.299698114 CET19354498853.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.299806118 CET4988519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.300658941 CET4988519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.538606882 CET19354498853.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.538619995 CET19354498853.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.538707018 CET4988519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.539098024 CET4988519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.539329052 CET19354498853.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.540044069 CET4988619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.777340889 CET19354498853.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.784933090 CET19354498863.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:15.785168886 CET4988619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:15.787605047 CET4988619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.032563925 CET19354498863.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.032779932 CET4988619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.033802986 CET19354498863.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.033814907 CET19354498863.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.034917116 CET4988719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.274789095 CET19354498873.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.274872065 CET4988719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.275490999 CET4988719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.277467012 CET19354498863.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.514812946 CET19354498873.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.514852047 CET19354498873.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.514863014 CET4988719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.514889956 CET4988719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.515400887 CET19354498873.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.516911983 CET4988719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.518111944 CET4988819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.754740953 CET19354498873.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.754765987 CET19354498873.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.760481119 CET19354498883.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:16.760653973 CET4988819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:16.761193037 CET4988819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.002888918 CET19354498883.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.002918959 CET19354498883.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.003077030 CET4988819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.003077030 CET4988819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.003202915 CET19354498883.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.003878117 CET4988819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.004878044 CET4988919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.245440006 CET19354498883.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.245455980 CET19354498883.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.247199059 CET19354498893.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.247283936 CET4988919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.247936010 CET4988919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.489506960 CET19354498893.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.489521027 CET19354498893.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.489613056 CET4988919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.489862919 CET19354498893.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.489983082 CET4988919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.490834951 CET4989019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.729840040 CET19354498903.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.729908943 CET4989019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.730881929 CET4989019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.731641054 CET19354498893.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.968944073 CET19354498903.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.968974113 CET19354498903.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.969043970 CET4989019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.969640970 CET19354498903.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:17.971303940 CET4989019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:17.972367048 CET4989119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.207885981 CET19354498903.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.217685938 CET19354498913.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.217812061 CET4989119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.218918085 CET4989119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.463402987 CET19354498913.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.463462114 CET4989119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.463551998 CET19354498913.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.463599920 CET4989119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.464215040 CET19354498913.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.467624903 CET4989119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.468641996 CET4989219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.708811998 CET19354498913.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.709148884 CET19354498913.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.709455013 CET19354498923.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.709625006 CET4989219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.710202932 CET4989219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.950949907 CET19354498923.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.950962067 CET19354498923.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.950975895 CET19354498923.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:18.951026917 CET4989219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.951430082 CET4989219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:18.952469110 CET4989319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.191690922 CET19354498923.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.194046974 CET19354498933.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.194159031 CET4989319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.207463026 CET4989319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.436122894 CET19354498933.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.436140060 CET19354498933.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.436192989 CET4989319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.436244965 CET4989319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.437010050 CET4989319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.438045979 CET4989419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.448993921 CET19354498933.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.674865961 CET19354498943.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.674969912 CET4989419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.676848888 CET4989419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.677746058 CET19354498933.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.678020954 CET19354498933.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.911871910 CET19354498943.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.911904097 CET19354498943.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:19.912087917 CET4989419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.912436962 CET4989419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.913486004 CET4989519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:19.913552046 CET19354498943.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.148991108 CET19354498943.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.152940035 CET19354498953.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.153018951 CET4989519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.153537035 CET4989519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.392653942 CET19354498953.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.392688990 CET19354498953.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.392745018 CET4989519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.392770052 CET4989519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.393430948 CET19354498953.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.397279978 CET4989519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.398325920 CET4989619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.632333040 CET19354498953.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.632590055 CET19354498953.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.640161037 CET19354498963.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.640253067 CET4989619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.640928984 CET4989619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.882162094 CET19354498963.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.882180929 CET19354498963.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.882239103 CET4989619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.882272005 CET4989619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.882572889 CET19354498963.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:20.886425972 CET4989619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:20.887332916 CET4989719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.124298096 CET19354498963.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.124310017 CET19354498963.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.129694939 CET19354498973.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.129759073 CET4989719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.130354881 CET4989719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.371808052 CET19354498973.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.371823072 CET19354498973.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.371866941 CET4989719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.371896029 CET4989719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.372186899 CET19354498973.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.372487068 CET4989719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.374423027 CET4989819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.611987114 CET19354498983.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.612104893 CET4989819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.612585068 CET4989819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.613822937 CET19354498973.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.613833904 CET19354498973.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.849919081 CET19354498983.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.849948883 CET19354498983.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.850034952 CET4989819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.850207090 CET19354498983.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:21.850687027 CET4989819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:21.851819992 CET4989919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.087678909 CET19354498983.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.090774059 CET19354498993.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.090878010 CET4989919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.091445923 CET4989919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.329920053 CET19354498993.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.329935074 CET19354498993.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.330010891 CET4989919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.330429077 CET19354498993.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.331496000 CET4989919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.332475901 CET4990019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.568813086 CET19354498993.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.574275017 CET19354499003.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.575066090 CET4990019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.575675011 CET4990019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.817137003 CET19354499003.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.817174911 CET19354499003.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.817240000 CET4990019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.817260027 CET4990019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.817267895 CET19354499003.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:22.818811893 CET4990019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:22.825011015 CET4990119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.058875084 CET19354499003.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.059142113 CET19354499003.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.068875074 CET19354499013.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.068970919 CET4990119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.075689077 CET4990119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.312835932 CET19354499013.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.312865973 CET19354499013.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.312951088 CET4990119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.313941956 CET4990119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.314944029 CET4990219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.319322109 CET19354499013.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.554207087 CET19354499023.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.554328918 CET4990219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.554899931 CET4990219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.556590080 CET19354499013.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.793339014 CET19354499023.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.793354034 CET19354499023.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.793401957 CET4990219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.793433905 CET4990219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.793884039 CET19354499023.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:23.818056107 CET4990219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:23.824942112 CET4990319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.032529116 CET19354499023.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.032546043 CET19354499023.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.069889069 CET19354499033.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.069998026 CET4990319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.070626974 CET4990319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.315324068 CET19354499033.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.315354109 CET19354499033.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.315363884 CET19354499033.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.315419912 CET4990319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.317318916 CET4990319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.318305016 CET4990419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.560240984 CET19354499033.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.562252998 CET19354499043.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.562325954 CET4990419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.562802076 CET4990419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.806526899 CET19354499043.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.806588888 CET4990419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.806672096 CET19354499043.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.806715012 CET4990419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.806834936 CET19354499043.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:24.808693886 CET4990419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:24.809742928 CET4990519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.048332930 CET19354499053.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.048403978 CET4990519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.049007893 CET4990519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.050616026 CET19354499043.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.050751925 CET19354499043.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.286761045 CET19354499053.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.286789894 CET19354499053.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.286864042 CET4990519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.287281990 CET19354499053.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.287719011 CET4990519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.288741112 CET4990619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.525140047 CET19354499053.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.529603958 CET19354499063.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.529670000 CET4990619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.530241966 CET4990619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.770668030 CET19354499063.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.770785093 CET4990619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.770792961 CET19354499063.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.770860910 CET4990619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.771182060 CET19354499063.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:25.789885044 CET4990619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:25.791054964 CET4990719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.011781931 CET19354499063.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.011810064 CET19354499063.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.033204079 CET19354499073.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.033304930 CET4990719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.034167051 CET4990719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.275854111 CET19354499073.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.275866985 CET19354499073.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.275929928 CET4990719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.276933908 CET19354499073.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.280822992 CET4990719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.281846046 CET4990819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.518055916 CET19354499073.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.520040989 CET19354499083.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.520126104 CET4990819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.520668030 CET4990819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.758749008 CET19354499083.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.758764029 CET19354499083.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.758826017 CET4990819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.758872032 CET19354499083.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:26.881875038 CET4990819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.882935047 CET4990919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:26.997090101 CET19354499083.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:27.120764971 CET19354499093.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:27.120856047 CET4990919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:27.121366978 CET4990919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:27.358840942 CET19354499093.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:27.358859062 CET19354499093.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:27.358944893 CET4990919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:27.359477043 CET19354499093.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:27.596744061 CET19354499093.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.149235010 CET4991019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:28.394499063 CET19354499103.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.394592047 CET4991019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:28.395112991 CET4991019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:28.641465902 CET19354499103.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.641541004 CET4991019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:28.641642094 CET19354499103.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.641654968 CET19354499103.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.642977953 CET4991119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:28.884763956 CET19354499113.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.884860992 CET4991119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:28.886652946 CET19354499103.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:28.906033993 CET4991119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.126679897 CET19354499113.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.126693964 CET19354499113.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.126763105 CET4991119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.126796007 CET4991119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.127468109 CET4991119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.128417969 CET4991219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.147785902 CET19354499113.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.367847919 CET19354499123.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.367940903 CET4991219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.368484020 CET4991219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.368525028 CET19354499113.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.368558884 CET19354499113.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.607717037 CET19354499123.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.607731104 CET19354499123.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.607772112 CET4991219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.607783079 CET4991219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.607906103 CET19354499123.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.609123945 CET4991219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.610162020 CET4991319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.846942902 CET19354499133.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.847039938 CET4991319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:29.847089052 CET19354499123.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.847115993 CET19354499123.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:29.847667933 CET4991319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.084136963 CET19354499133.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.084167957 CET19354499133.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.084233999 CET4991319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.084369898 CET19354499133.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.084937096 CET4991319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.085985899 CET4991419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.321260929 CET19354499133.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.329240084 CET19354499143.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.329405069 CET4991419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.329854965 CET4991419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.573014975 CET19354499143.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.573045969 CET19354499143.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.573056936 CET19354499143.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.573263884 CET4991419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.575620890 CET4991419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.578362942 CET4991519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.816834927 CET19354499143.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.823929071 CET19354499153.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:30.824013948 CET4991519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:30.824594021 CET4991519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.069957972 CET19354499153.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.069988966 CET19354499153.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.070003986 CET19354499153.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.070055008 CET4991519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.070086002 CET4991519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.074744940 CET4991519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.075733900 CET4991619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.315239906 CET19354499163.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.315320015 CET4991619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.315709114 CET19354499153.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.315721035 CET19354499153.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.315994978 CET4991619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.555347919 CET19354499163.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.555387020 CET19354499163.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.555531025 CET19354499163.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.555556059 CET4991619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.558490992 CET4991619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.564891100 CET4991719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.795111895 CET19354499163.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.804136992 CET19354499173.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:31.804239035 CET4991719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:31.804979086 CET4991719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.043890953 CET19354499173.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.043910980 CET19354499173.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.043951988 CET4991719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.043978930 CET4991719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.044162035 CET19354499173.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.044279099 CET4991719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.045341969 CET4991819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.283272982 CET19354499173.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.283307076 CET19354499173.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.287147045 CET19354499183.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.287466049 CET4991819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.288100004 CET4991819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.529608011 CET19354499183.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.529638052 CET19354499183.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.529783964 CET19354499183.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.529834986 CET4991819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.532557011 CET4991819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.533617973 CET4991919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.771634102 CET19354499183.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.775784969 CET19354499193.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:32.775870085 CET4991919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:32.776504993 CET4991919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.018125057 CET19354499193.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.018232107 CET19354499193.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.018377066 CET4991919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.018696070 CET19354499193.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.022859097 CET4991919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.023933887 CET4992019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.260523081 CET19354499193.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.269330025 CET19354499203.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.269412994 CET4992019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.270015001 CET4992019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.515130043 CET19354499203.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.515158892 CET19354499203.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.515223980 CET4992019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.515513897 CET19354499203.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.515614986 CET4992019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.516644955 CET4992119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.759016037 CET19354499213.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:33.759085894 CET4992119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.759907961 CET4992119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:33.760592937 CET19354499203.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.001640081 CET19354499213.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.001657009 CET19354499213.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.001694918 CET4992119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.001713991 CET4992119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.002130032 CET19354499213.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.002414942 CET4992119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.003412962 CET4992219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.243258953 CET19354499223.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.243379116 CET4992219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.244031906 CET19354499213.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.244044065 CET19354499213.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.244220018 CET4992219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.483573914 CET19354499223.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.483586073 CET19354499223.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.483644962 CET4992219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.484023094 CET19354499223.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.485739946 CET4992219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.486963987 CET4992319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.723577976 CET19354499223.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.725251913 CET19354499233.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.725446939 CET4992319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.726285934 CET4992319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.963923931 CET19354499233.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.963938951 CET19354499233.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.964003086 CET4992319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.964481115 CET19354499233.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:34.965643883 CET4992319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:34.966983080 CET4992419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.202204943 CET19354499233.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.206636906 CET19354499243.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.206840038 CET4992419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.208692074 CET4992419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.446645021 CET19354499243.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.446660995 CET19354499243.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.446749926 CET4992419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.446763992 CET4992419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.448369026 CET19354499243.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.450777054 CET4992419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.451937914 CET4992519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.686428070 CET19354499243.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.686444044 CET19354499243.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.694356918 CET19354499253.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.694566965 CET4992519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.700119972 CET4992519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.937163115 CET19354499253.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.937176943 CET19354499253.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:35.937314034 CET4992519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.940340996 CET4992519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.941327095 CET4992619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:35.942847013 CET19354499253.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.180068016 CET19354499253.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.181183100 CET19354499263.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.181257010 CET4992619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.181869030 CET4992619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.421319962 CET19354499263.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.421334028 CET19354499263.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.421422958 CET4992619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.421602964 CET19354499263.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.423497915 CET4992619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.424434900 CET4992719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.661418915 CET19354499263.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.665074110 CET19354499273.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.665158987 CET4992719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.665802002 CET4992719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.906011105 CET19354499273.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.906040907 CET19354499273.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.906208992 CET4992719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.906511068 CET19354499273.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:36.913603067 CET4992719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:36.914617062 CET4992819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.147092104 CET19354499273.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.156224966 CET19354499283.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.156461000 CET4992819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.157074928 CET4992819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.398397923 CET19354499283.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.398427010 CET19354499283.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.398459911 CET4992819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.398478985 CET4992819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.398658037 CET19354499283.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.402699947 CET4992819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.408833027 CET4992919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.640117884 CET19354499283.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.640151024 CET19354499283.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.652648926 CET19354499293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.652751923 CET4992919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.653403044 CET4992919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.896857023 CET19354499293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.896872044 CET19354499293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.897118092 CET19354499293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:37.897151947 CET4992919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.904026985 CET4992919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:37.904911995 CET4993019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.140923977 CET19354499293.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.144252062 CET19354499303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.144328117 CET4993019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.144939899 CET4993019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.383876085 CET19354499303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.383888006 CET19354499303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.383929968 CET4993019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.383949995 CET4993019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.384054899 CET19354499303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.384315968 CET4993019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.385919094 CET4993119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.623281002 CET19354499303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.623294115 CET19354499303.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.627387047 CET19354499313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.627459049 CET4993119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.628083944 CET4993119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.868874073 CET19354499313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.868887901 CET19354499313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.869093895 CET4993119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.869370937 CET19354499313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:38.874104977 CET4993119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:38.875235081 CET4993219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.110445023 CET19354499313.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.116451025 CET19354499323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.116652012 CET4993219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.117146969 CET4993219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.357981920 CET19354499323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.357995987 CET19354499323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.358194113 CET19354499323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.358212948 CET4993219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.358894110 CET4993219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.359874010 CET4993319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.599930048 CET19354499323.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.600874901 CET19354499333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.600970984 CET4993319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.601759911 CET4993319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.842132092 CET19354499333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.842148066 CET19354499333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.842195988 CET4993319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.842211962 CET4993319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.842735052 CET19354499333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:39.844507933 CET4993319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:39.845573902 CET4993419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.083193064 CET19354499333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.083204985 CET19354499333.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.084427118 CET19354499343.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.084595919 CET4993419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.085125923 CET4993419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.323785067 CET19354499343.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.323813915 CET19354499343.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.323913097 CET19354499343.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.323985100 CET4993419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.324261904 CET4993419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.325246096 CET4993519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.563108921 CET19354499343.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.563627005 CET19354499353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.563690901 CET4993519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.565443993 CET4993519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.802253962 CET19354499353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.802287102 CET19354499353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:40.802366972 CET4993519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.802519083 CET4993519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.802669048 CET4993519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.803649902 CET4993619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:40.803776026 CET19354499353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.040888071 CET19354499353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.040901899 CET19354499353.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.042419910 CET19354499363.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.042488098 CET4993619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.043152094 CET4993619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.281435013 CET19354499363.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.281447887 CET19354499363.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.281512022 CET4993619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.281527042 CET4993619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.281981945 CET19354499363.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.286573887 CET4993619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.287642002 CET4993719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.520378113 CET19354499363.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.520394087 CET19354499363.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.527050018 CET19354499373.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.527242899 CET4993719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.527797937 CET4993719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.768418074 CET19354499373.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.768435001 CET19354499373.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.768490076 CET4993719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.768507004 CET4993719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.768765926 CET19354499373.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:41.786653996 CET4993719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:41.787883997 CET4993819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.007947922 CET19354499373.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.008009911 CET19354499373.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.029975891 CET19354499383.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.030061007 CET4993819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.031161070 CET4993819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.272367001 CET19354499383.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.272397995 CET19354499383.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.272685051 CET4993819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.273191929 CET19354499383.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.274019003 CET4993819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.275996923 CET4993919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.514861107 CET19354499383.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.517302036 CET19354499393.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.517493963 CET4993919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.518312931 CET4993919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.759373903 CET19354499393.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.759387970 CET19354499393.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.759460926 CET19354499393.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:42.759588957 CET4993919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.762291908 CET4993919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:42.763425112 CET4994019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.000885010 CET19354499393.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.008304119 CET19354499403.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.008485079 CET4994019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.008933067 CET4994019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.253573895 CET19354499403.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.253602982 CET19354499403.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.253618956 CET19354499403.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.253907919 CET4994019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.257479906 CET4994019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.258495092 CET4994119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.497854948 CET19354499413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.498111963 CET4994119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.498606920 CET4994119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.498866081 CET19354499403.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.737835884 CET19354499413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.737867117 CET19354499413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.737895012 CET19354499413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.737971067 CET4994119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.749345064 CET4994119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.750307083 CET4994219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.977339029 CET19354499413.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.992221117 CET19354499423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:43.992300034 CET4994219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:43.992909908 CET4994219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.234534979 CET19354499423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.234586000 CET19354499423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.234618902 CET4994219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.234654903 CET4994219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.234802008 CET19354499423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.241051912 CET4994219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.242070913 CET4994319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.476713896 CET19354499423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.476752043 CET19354499423.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.482570887 CET19354499433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.482649088 CET4994319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.719248056 CET4994319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.723102093 CET19354499433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.723117113 CET19354499433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.723176003 CET4994319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.725137949 CET4994319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.726350069 CET4994419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.959578991 CET19354499433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.963910103 CET19354499433.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.971302986 CET19354499443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:44.971385956 CET4994419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:44.971901894 CET4994419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:45.216753960 CET19354499443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:45.216768980 CET19354499443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:45.216850996 CET4994419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:45.216932058 CET19354499443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:45.461961985 CET19354499443.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:45.700562954 CET4994519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:45.941350937 CET19354499453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:45.941459894 CET4994519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.067667961 CET4994519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.180527925 CET19354499453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.180541992 CET19354499453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.180591106 CET4994519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.241590023 CET4994519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.242542028 CET4994619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.306567907 CET19354499453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.420665979 CET19354499453.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.487689018 CET19354499463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.487783909 CET4994619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.488337994 CET4994619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.733109951 CET19354499463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.733125925 CET19354499463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.733186960 CET4994619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.733326912 CET19354499463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.741055012 CET4994619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.742060900 CET4994719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.979406118 CET19354499463.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.984344006 CET19354499473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:46.984422922 CET4994719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:46.987477064 CET4994719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.226777077 CET19354499473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.226790905 CET19354499473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.226861000 CET4994719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.229156971 CET19354499473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.231462955 CET4994719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.232496977 CET4994819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.468615055 CET19354499473.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.471496105 CET19354499483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.471555948 CET4994819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.472153902 CET4994819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.711620092 CET19354499483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.711658001 CET19354499483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.711739063 CET4994819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.711997986 CET19354499483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.714875937 CET4994819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.716499090 CET4994919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.950674057 CET19354499483.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.955391884 CET19354499493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:47.955466032 CET4994919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:47.956084013 CET4994919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.194494009 CET19354499493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.194545031 CET19354499493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.194602013 CET4994919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.194633961 CET4994919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.194894075 CET4994919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.195159912 CET19354499493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.195883036 CET4995019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.433723927 CET19354499493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.433736086 CET19354499493.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.436058998 CET19354499503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.436136961 CET4995019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.439896107 CET4995019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.676570892 CET19354499503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.676584959 CET19354499503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.676662922 CET4995019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.678436041 CET4995019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.679470062 CET4995119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.680088997 CET19354499503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.917038918 CET19354499503.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.921293974 CET19354499513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:48.921498060 CET4995119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:48.922025919 CET4995119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.163520098 CET19354499513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.163535118 CET19354499513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.163583994 CET19354499513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.163585901 CET4995119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.163606882 CET4995119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.168627977 CET4995119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.169575930 CET4995219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.405949116 CET19354499513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.405983925 CET19354499513.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.411510944 CET19354499523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.411617041 CET4995219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.412198067 CET4995219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.653701067 CET19354499523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.653738976 CET19354499523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.653811932 CET4995219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.653832912 CET4995219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.654095888 CET19354499523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.654230118 CET4995219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.655230999 CET4995319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.895884991 CET19354499523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.895921946 CET19354499523.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.898601055 CET19354499533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:49.898705006 CET4995319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:49.899296045 CET4995319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.142419100 CET19354499533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.142447948 CET19354499533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.142455101 CET19354499533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.142652988 CET4995319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.142919064 CET4995319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.143873930 CET4995419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.385216951 CET19354499543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.385283947 CET4995419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.385871887 CET19354499533.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.385890961 CET4995419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.627233982 CET19354499543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.627266884 CET19354499543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.627273083 CET19354499543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.627454042 CET4995419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.627799034 CET4995419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.628846884 CET4995519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.868824959 CET19354499543.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.874373913 CET19354499553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:50.874497890 CET4995519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:50.878259897 CET4995519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.120467901 CET19354499553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.120487928 CET19354499553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.120532990 CET4995519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.120556116 CET4995519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.121081114 CET4995519354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.122394085 CET4995619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.123806953 CET19354499553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.363816023 CET19354499563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.363938093 CET4995619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.364435911 CET4995619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.366056919 CET19354499553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.366067886 CET19354499553.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.605427980 CET19354499563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.605442047 CET19354499563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.605514050 CET4995619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.605724096 CET19354499563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.611260891 CET4995619354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.615154982 CET4995719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.846858978 CET19354499563.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.857522011 CET19354499573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:51.857601881 CET4995719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:51.858230114 CET4995719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.099788904 CET19354499573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.099807024 CET19354499573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.099961996 CET4995719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.100105047 CET19354499573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.100433111 CET4995719354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.101391077 CET4995819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.341461897 CET19354499583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.341581106 CET4995819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.341912985 CET19354499573.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.342235088 CET4995819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.581765890 CET19354499583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.581784010 CET19354499583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.581860065 CET4995819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.582112074 CET19354499583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.582168102 CET4995819354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.583132029 CET4995919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.821738958 CET19354499583.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.825690031 CET19354499593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:52.825754881 CET4995919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:52.826361895 CET4995919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.069658995 CET19354499593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.069677114 CET19354499593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.069746971 CET19354499593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.069860935 CET4995919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.074568987 CET4995919354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.076632023 CET4996019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.312629938 CET19354499593.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.320553064 CET19354499603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.320628881 CET4996019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.321127892 CET4996019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.564986944 CET19354499603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.565004110 CET19354499603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.565099001 CET4996019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.565120935 CET19354499603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.566457033 CET4996019354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.567334890 CET4996119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.809132099 CET19354499603.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.810590029 CET19354499613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:53.810693979 CET4996119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:53.811310053 CET4996119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.054114103 CET19354499613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.054127932 CET19354499613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.054177046 CET4996119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.054207087 CET4996119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.054480076 CET19354499613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.059052944 CET4996119354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.060163975 CET4996219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.298388004 CET19354499613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.298408031 CET19354499613.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.300668955 CET19354499623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.300786972 CET4996219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.301440001 CET4996219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.541383982 CET19354499623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.541400909 CET19354499623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.541480064 CET4996219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.541743994 CET19354499623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.543427944 CET4996219354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.544425964 CET4996319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.781980038 CET19354499623.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.785084009 CET19354499633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:54.785188913 CET4996319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:54.785799980 CET4996319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.027542114 CET19354499633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.027559042 CET19354499633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.027569056 CET19354499633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.027646065 CET4996319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.027671099 CET4996319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.028031111 CET4996319354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.029056072 CET4996419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.268513918 CET19354499633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.268548012 CET19354499633.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.271220922 CET19354499643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.271317959 CET4996419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.271905899 CET4996419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.513848066 CET19354499643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.513864040 CET19354499643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.513902903 CET4996419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.513917923 CET19354499643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.513926029 CET4996419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.515176058 CET4996419354192.168.2.43.127.138.57
                                                    Dec 30, 2023 06:59:55.639142036 CET4996519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:55.756006956 CET19354499643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.756020069 CET19354499643.127.138.57192.168.2.4
                                                    Dec 30, 2023 06:59:55.877717018 CET19354499653.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:55.877825022 CET4996519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:55.878340960 CET4996519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.116473913 CET19354499653.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.116496086 CET19354499653.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.116605043 CET4996519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.116811037 CET19354499653.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.121431112 CET4996519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.123465061 CET4996619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.355154037 CET19354499653.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.364146948 CET19354499663.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.364238977 CET4996619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.364851952 CET4996619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.605109930 CET19354499663.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.605127096 CET19354499663.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.605197906 CET4996619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.605509043 CET19354499663.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.606209040 CET4996619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.607172966 CET4996719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.845921040 CET19354499663.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.849745989 CET19354499673.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:56.849853992 CET4996719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:56.850603104 CET4996719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.092624903 CET19354499673.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.092641115 CET19354499673.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.092698097 CET4996719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.092715025 CET4996719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.093153954 CET19354499673.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.127203941 CET4996719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.128597021 CET4996819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.335257053 CET19354499673.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.335273027 CET19354499673.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.368777037 CET19354499683.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.368850946 CET4996819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.372313023 CET4996819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.609276056 CET19354499683.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.609303951 CET19354499683.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.609467030 CET4996819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.609925032 CET4996819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.611018896 CET4996919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.612298965 CET19354499683.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.849560976 CET19354499683.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.852940083 CET19354499693.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:57.853041887 CET4996919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:57.853565931 CET4996919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.095192909 CET19354499693.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.095211029 CET19354499693.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.095277071 CET4996919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.095313072 CET4996919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.095386028 CET19354499693.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.096364021 CET4996919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.097332954 CET4997019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.336929083 CET19354499703.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.337054968 CET4997019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.337253094 CET19354499693.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.337264061 CET19354499693.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.337721109 CET4997019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.576673985 CET19354499703.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.576687098 CET19354499703.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.576786995 CET4997019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.577111959 CET4997019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.577164888 CET19354499703.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.578186035 CET4997119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.817092896 CET19354499703.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.823817968 CET19354499713.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:58.823887110 CET4997119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:58.824501038 CET4997119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.069135904 CET19354499713.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.069165945 CET19354499713.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.069361925 CET4997119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.069392920 CET19354499713.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.069981098 CET4997119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.071018934 CET4997219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.313558102 CET19354499723.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.313667059 CET4997219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.314289093 CET4997219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.314460039 CET19354499713.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.556859970 CET19354499723.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.556917906 CET4997219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.562789917 CET19354499723.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.562829018 CET19354499723.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.576169014 CET4997319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.799607992 CET19354499723.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.822484970 CET19354499733.126.37.18192.168.2.4
                                                    Dec 30, 2023 06:59:59.822788954 CET4997319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 06:59:59.823164940 CET4997319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.069133997 CET19354499733.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.069145918 CET19354499733.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.069156885 CET19354499733.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.069190025 CET4997319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.069220066 CET4997319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.069484949 CET4997319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.070622921 CET4997419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.315565109 CET19354499733.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.315594912 CET19354499733.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.316356897 CET19354499743.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.316452980 CET4997419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.317197084 CET4997419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.562249899 CET19354499743.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.562263966 CET19354499743.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.562308073 CET4997419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.562323093 CET4997419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.562774897 CET19354499743.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.605292082 CET4997419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.606206894 CET4997519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.808042049 CET19354499743.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.808073044 CET19354499743.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.846061945 CET19354499753.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:00.846421003 CET4997519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:00.846777916 CET4997519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.086410999 CET19354499753.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.086426020 CET19354499753.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.086539984 CET4997519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.086600065 CET19354499753.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.089334011 CET4997519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.091253042 CET4997619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.326582909 CET19354499753.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.332062006 CET19354499763.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.332159042 CET4997619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.334423065 CET4997619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.572926044 CET19354499763.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.572943926 CET19354499763.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.573004007 CET4997619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.573029041 CET4997619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.574796915 CET19354499763.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.580219984 CET4997619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.584264040 CET4997719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.814105988 CET19354499763.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.814117908 CET19354499763.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.826865911 CET19354499773.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:01.826992035 CET4997719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:01.827517986 CET4997719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.069555998 CET19354499773.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.069592953 CET19354499773.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.069880009 CET4997719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.070014000 CET19354499773.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.085035086 CET4997719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.085974932 CET4997819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.312299967 CET19354499773.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.330743074 CET19354499783.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.330872059 CET4997819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.331532001 CET4997819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.575797081 CET19354499783.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.575834990 CET19354499783.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.576014042 CET4997819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.576014042 CET4997819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.576148987 CET19354499783.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.593498945 CET4997819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.595742941 CET4997919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.820727110 CET19354499783.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.820741892 CET19354499783.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.832957983 CET19354499793.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:02.833129883 CET4997919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:02.833960056 CET4997919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:03.071136951 CET19354499793.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:03.071151018 CET19354499793.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:03.071228027 CET4997919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:03.071295977 CET19354499793.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:03.308660984 CET19354499793.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:03.524169922 CET4998019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:03.767959118 CET19354499803.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:03.768275023 CET4998019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:03.827429056 CET4998019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.012288094 CET19354499803.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.012469053 CET19354499803.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.012515068 CET4998019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.012547016 CET4998019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.013031006 CET4998019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.014092922 CET4998119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.071188927 CET19354499803.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.256350994 CET19354499803.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.256362915 CET19354499803.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.257035017 CET19354499813.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.257217884 CET4998119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.257675886 CET4998119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.500144958 CET19354499813.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.500164032 CET19354499813.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.500207901 CET4998119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.500247002 CET4998119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.500370026 CET19354499813.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.506705046 CET4998119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.507747889 CET4998219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.742994070 CET19354499813.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.743026972 CET19354499813.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.747471094 CET19354499823.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.747674942 CET4998219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.772515059 CET4998219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.987541914 CET19354499823.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.987659931 CET4998219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.987714052 CET19354499823.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:04.987762928 CET4998219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.988151073 CET4998219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:04.989115000 CET4998319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.012424946 CET19354499823.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.227397919 CET19354499823.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.227432013 CET19354499823.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.233597040 CET19354499833.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.233694077 CET4998319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.234339952 CET4998319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.478694916 CET19354499833.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.478709936 CET19354499833.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.478720903 CET19354499833.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.478751898 CET4998319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.478780985 CET4998319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.491362095 CET4998319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.492810965 CET4998419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.723115921 CET19354499833.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.723157883 CET19354499833.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.731527090 CET19354499843.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.731734991 CET4998419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.732244968 CET4998419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.970717907 CET19354499843.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.970737934 CET19354499843.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.970953941 CET4998419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.970982075 CET19354499843.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:05.973701954 CET4998419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:05.974698067 CET4998519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.209909916 CET19354499843.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.216156006 CET19354499853.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.216269970 CET4998519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.216831923 CET4998519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.457849979 CET19354499853.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.457863092 CET19354499853.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.458086014 CET4998519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.458215952 CET19354499853.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.473659992 CET4998519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.474736929 CET4998619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.699574947 CET19354499853.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.716228962 CET19354499863.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.716415882 CET4998619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.716981888 CET4998619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.958065987 CET19354499863.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.958080053 CET19354499863.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.958268881 CET4998619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.958415031 CET19354499863.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:06.959407091 CET4998619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:06.960490942 CET4998719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.200124025 CET19354499863.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.205202103 CET19354499873.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.205410957 CET4998719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.206315041 CET4998719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.450501919 CET19354499873.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.450521946 CET19354499873.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.450556040 CET4998719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.450587034 CET4998719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.450937033 CET19354499873.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.452820063 CET4998719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.453963995 CET4998819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.695204020 CET19354499873.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.695236921 CET19354499873.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.700108051 CET19354499883.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.700311899 CET4998819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.700870037 CET4998819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.946589947 CET19354499883.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.946603060 CET19354499883.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.946788073 CET4998819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.947009087 CET19354499883.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:07.949224949 CET4998819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:07.953690052 CET4998919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.193142891 CET19354499883.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.194924116 CET19354499893.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.195044041 CET4998919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.205585003 CET4998919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.436180115 CET19354499893.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.436203003 CET19354499893.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.436279058 CET4998919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.436655045 CET4998919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.437726974 CET4999019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.446456909 CET19354499893.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.677653074 CET19354499893.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.678944111 CET19354499903.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.679038048 CET4999019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.679646015 CET4999019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.920506001 CET19354499903.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.920538902 CET19354499903.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.920614004 CET4999019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.920744896 CET19354499903.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:08.920778036 CET4999019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.920909882 CET4999019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:08.921916962 CET4999119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.161843061 CET19354499903.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.161855936 CET19354499903.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.163105965 CET19354499913.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.163177967 CET4999119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.163786888 CET4999119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.404839993 CET19354499913.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.404872894 CET19354499913.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.404968977 CET4999119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.405119896 CET19354499913.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.405461073 CET4999119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.406491995 CET4999219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.646545887 CET19354499913.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.651642084 CET19354499923.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.651751041 CET4999219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.652740002 CET4999219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.897053957 CET19354499923.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.897068977 CET19354499923.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.897175074 CET4999219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.897175074 CET4999219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.897819996 CET19354499923.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:09.898154974 CET4999219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:09.899187088 CET4999319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.138988018 CET19354499933.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.139101982 CET4999319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.142623901 CET19354499923.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.142636061 CET19354499923.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.142760038 CET4999319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.379029989 CET19354499933.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.379045963 CET19354499933.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.379084110 CET4999319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.379103899 CET4999319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.379956007 CET4999319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.382167101 CET19354499933.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.382787943 CET4999419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.618670940 CET19354499933.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.618685961 CET19354499933.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.624070883 CET19354499943.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.624170065 CET4999419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.626827002 CET4999419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.865657091 CET19354499943.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.865675926 CET19354499943.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:10.865712881 CET4999419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.865735054 CET4999419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.865999937 CET4999419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.867156982 CET4999519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:10.868136883 CET19354499943.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.106925011 CET19354499943.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.106939077 CET19354499943.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.109677076 CET19354499953.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.109781981 CET4999519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.110411882 CET4999519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.352372885 CET19354499953.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.352386951 CET19354499953.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.352582932 CET4999519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.352670908 CET19354499953.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.357331038 CET4999519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.358376026 CET4999619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.595017910 CET19354499953.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.604732990 CET19354499963.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.604840994 CET4999619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.636030912 CET4999619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.851363897 CET19354499963.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.851411104 CET19354499963.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:11.851716042 CET4999619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.856678009 CET4999619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.857736111 CET4999719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:11.882119894 CET19354499963.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.098004103 CET19354499963.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.103668928 CET19354499973.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.103887081 CET4999719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.105094910 CET4999719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.349893093 CET19354499973.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.349930048 CET19354499973.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.349997997 CET4999719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.350039959 CET4999719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.350430965 CET4999719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.350704908 CET19354499973.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.351500034 CET4999819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.594223976 CET19354499983.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.594305992 CET4999819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.595313072 CET4999819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.595896006 CET19354499973.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.595906019 CET19354499973.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.837162971 CET19354499983.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.837177038 CET19354499983.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.837253094 CET4999819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.837873936 CET19354499983.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:12.840643883 CET4999819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:12.844151020 CET4999919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.080099106 CET19354499983.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.087552071 CET19354499993.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.087748051 CET4999919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.088344097 CET4999919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.331613064 CET19354499993.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.331657887 CET19354499993.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.331949949 CET4999919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.332026005 CET19354499993.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.347501993 CET4999919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.348644972 CET5000019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.575334072 CET19354499993.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.594520092 CET19354500003.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.594809055 CET5000019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.595230103 CET5000019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.840796947 CET19354500003.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.840837955 CET19354500003.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.840979099 CET19354500003.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:13.841135025 CET5000019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.841358900 CET5000019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:13.842478037 CET5000119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.085036993 CET19354500013.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.085119963 CET5000119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.087037086 CET19354500003.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.107817888 CET5000119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.327997923 CET19354500013.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.328010082 CET19354500013.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.328186989 CET5000119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.329201937 CET5000119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.330384970 CET5000219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.350302935 CET19354500013.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.571037054 CET19354500013.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.573976040 CET19354500023.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.574141026 CET5000219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.574938059 CET5000219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.817866087 CET19354500023.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.817889929 CET19354500023.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.817994118 CET5000219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.818501949 CET5000219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:14.818566084 CET19354500023.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:14.820354939 CET5000319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.062161922 CET19354500023.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.062176943 CET19354500033.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.062251091 CET5000319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.062947989 CET5000319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.304387093 CET19354500033.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.304449081 CET5000319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.304694891 CET19354500033.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.304804087 CET19354500033.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.306823015 CET5000419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.546217918 CET19354500033.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.546643972 CET19354500043.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.546807051 CET5000419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.549434900 CET5000419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.786933899 CET19354500043.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.786967993 CET19354500043.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.787254095 CET5000419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.788094044 CET5000419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:15.789165974 CET19354500043.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:15.789288998 CET5000519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.027282000 CET19354500043.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.031347990 CET19354500053.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.031434059 CET5000519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.032843113 CET5000519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.273658037 CET19354500053.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.273674965 CET19354500053.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.273722887 CET5000519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.273765087 CET5000519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.274876118 CET19354500053.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.275381088 CET5000519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.279021025 CET5000619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.515851021 CET19354500053.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.515875101 CET19354500053.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.519469023 CET19354500063.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.519551992 CET5000619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.520243883 CET5000619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.760303974 CET19354500063.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.760596037 CET19354500063.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.760606050 CET19354500063.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:16.760623932 CET5000619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.760798931 CET5000619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.761670113 CET5000619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:16.763000011 CET5000719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.001051903 CET19354500063.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.001132011 CET19354500063.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.002371073 CET19354500073.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.002559900 CET5000719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.003331900 CET5000719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.241960049 CET19354500073.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.241980076 CET19354500073.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.242017984 CET5000719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.242049932 CET5000719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.242964983 CET19354500073.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.252898932 CET5000719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.253923893 CET5000819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.481240988 CET19354500073.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.481280088 CET19354500073.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.496656895 CET19354500083.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.496790886 CET5000819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.503664970 CET5000819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.739880085 CET19354500083.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.739903927 CET19354500083.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.739937067 CET5000819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.739965916 CET5000819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.746391058 CET19354500083.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.750790119 CET5000819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.751976013 CET5000919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.982930899 CET19354500083.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.982968092 CET19354500083.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.991729021 CET19354500093.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:17.991921902 CET5000919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:17.992635012 CET5000919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.231786966 CET19354500093.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.231806993 CET19354500093.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.231992960 CET5000919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.232268095 CET19354500093.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.233133078 CET5000919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.234352112 CET5001019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.471982002 CET19354500093.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.475914001 CET19354500103.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.476104021 CET5001019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.477025986 CET5001019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.717340946 CET19354500103.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.717381954 CET19354500103.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.717437029 CET5001019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.717459917 CET5001019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.718087912 CET19354500103.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.718426943 CET5001019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.719422102 CET5001119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.958651066 CET19354500103.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.958669901 CET19354500103.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.961050987 CET19354500113.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:18.961128950 CET5001119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:18.962037086 CET5001119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.202899933 CET19354500113.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.202919006 CET19354500113.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.203057051 CET5001119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.203582048 CET19354500113.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.205636024 CET5001119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.207076073 CET5001219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.444885015 CET19354500113.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.450769901 CET19354500123.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.450942993 CET5001219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.451839924 CET5001219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.694926977 CET19354500123.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.694951057 CET19354500123.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.695000887 CET5001219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.695019960 CET5001219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.695374012 CET19354500123.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.695564032 CET5001219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.696768999 CET5001319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.938194990 CET19354500133.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.938410997 CET5001319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:19.938607931 CET19354500123.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.938673973 CET19354500123.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:19.939024925 CET5001319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.180006981 CET19354500133.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.180043936 CET19354500133.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.180217981 CET5001319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.180217981 CET5001319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.180509090 CET19354500133.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.194330931 CET5001319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.195483923 CET5001419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.421680927 CET19354500133.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.421698093 CET19354500133.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.439232111 CET19354500143.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.439587116 CET5001419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.575512886 CET5001419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.683475018 CET19354500143.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.683516026 CET19354500143.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.683831930 CET5001419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.684056044 CET5001419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.685051918 CET5001519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.819395065 CET19354500143.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.926055908 CET19354500153.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:20.926279068 CET5001519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:20.927345037 CET19354500143.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:21.167301893 CET19354500153.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:21.167321920 CET19354500153.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:21.167588949 CET5001519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:21.543091059 CET5001519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:21.566922903 CET5001519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:21.568120956 CET5001619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:21.783951044 CET19354500153.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:21.807451010 CET19354500163.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:21.807573080 CET5001619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:21.897628069 CET5001619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.047341108 CET19354500163.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.047362089 CET19354500163.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.047418118 CET5001619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.051028967 CET5001619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.053659916 CET5001619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.054735899 CET5001719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.136878014 CET19354500163.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.286701918 CET19354500163.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.290241003 CET19354500163.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.295077085 CET19354500173.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.295286894 CET5001719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.313219070 CET5001719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.536005020 CET19354500173.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.536026001 CET19354500173.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.536264896 CET5001719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.537971973 CET5001719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.539247036 CET5001819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.553586960 CET19354500173.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.776635885 CET19354500173.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.783123016 CET19354500183.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:22.783212900 CET5001819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:22.786928892 CET5001819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.027100086 CET19354500183.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.027134895 CET19354500183.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.027394056 CET5001819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.028440952 CET5001819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.029721022 CET5001919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.030771017 CET19354500183.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.271073103 CET19354500183.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.272975922 CET19354500193.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.273180962 CET5001919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.274007082 CET5001919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.516314983 CET19354500193.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.516359091 CET19354500193.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.516431093 CET5001919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.516463041 CET5001919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.516823053 CET19354500193.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.520661116 CET5001919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.521886110 CET5002019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.759331942 CET19354500193.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.759390116 CET19354500193.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.761115074 CET19354500203.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:23.761322021 CET5002019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:23.762339115 CET5002019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.000900030 CET19354500203.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.000912905 CET19354500203.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.001116991 CET5002019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.001421928 CET19354500203.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.005122900 CET5002019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.006412983 CET5002119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.240314960 CET19354500203.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.245888948 CET19354500213.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.245982885 CET5002119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.247127056 CET5002119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.485866070 CET19354500213.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.485878944 CET19354500213.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.486098051 CET5002119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.486582041 CET19354500213.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.486654043 CET5002119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.487775087 CET5002219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.725589037 CET19354500213.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.730554104 CET19354500223.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.730626106 CET5002219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.731564045 CET5002219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.973577976 CET19354500223.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.973593950 CET19354500223.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:24.973825932 CET5002219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:24.974219084 CET19354500223.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.016724110 CET5002219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.018035889 CET5002319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.216590881 CET19354500223.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.260946035 CET19354500233.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.261152029 CET5002319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.261895895 CET5002319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.504388094 CET19354500233.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.504400969 CET19354500233.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.504622936 CET5002319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.504878998 CET19354500233.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.506099939 CET5002319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.507339001 CET5002419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.747725010 CET19354500233.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.747740030 CET19354500243.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.747927904 CET5002419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.751102924 CET5002419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.988437891 CET19354500243.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.988451958 CET19354500243.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:25.988528967 CET5002419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.988857985 CET5002419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.989867926 CET5002519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:25.993174076 CET19354500243.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.228878021 CET19354500243.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.229948997 CET19354500253.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.230043888 CET5002519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.230593920 CET5002519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.469926119 CET19354500253.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.469940901 CET19354500253.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.469978094 CET5002519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.470020056 CET5002519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.470155954 CET19354500253.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.470371008 CET5002519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.471421003 CET5002619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.709770918 CET19354500253.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.709800959 CET19354500253.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.715791941 CET19354500263.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.715975046 CET5002619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.716615915 CET5002619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.960489035 CET19354500263.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.960517883 CET19354500263.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:26.960594893 CET5002619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:26.960887909 CET19354500263.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.011981964 CET5002619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.013089895 CET5002719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.204920053 CET19354500263.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.254409075 CET19354500273.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.254498005 CET5002719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.255012989 CET5002719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.496125937 CET19354500273.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.496141911 CET19354500273.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.496151924 CET19354500273.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.496244907 CET5002719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.498456955 CET5002719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.499558926 CET5002819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.737503052 CET19354500273.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.744673967 CET19354500283.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.744741917 CET5002819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.745382071 CET5002819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.990180969 CET19354500283.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.990192890 CET19354500283.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.990272999 CET5002819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.990376949 CET19354500283.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:27.990714073 CET5002819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:27.991869926 CET5002919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.229022026 CET19354500293.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.229139090 CET5002919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.229768991 CET5002919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.235378027 CET19354500283.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.466579914 CET19354500293.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.466747999 CET19354500293.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.466774940 CET19354500293.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.466902018 CET5002919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.467015982 CET5002919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.467737913 CET5002919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.468707085 CET5003019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.704174995 CET19354500293.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.704205990 CET19354500293.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.711337090 CET19354500303.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.711433887 CET5003019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.712066889 CET5003019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.954350948 CET19354500303.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.954364061 CET19354500303.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.954437017 CET5003019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.954626083 CET19354500303.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:28.959455013 CET5003019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:28.962723017 CET5003119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.197207928 CET19354500303.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.203916073 CET19354500313.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.203991890 CET5003119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.206057072 CET5003119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.445458889 CET19354500313.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.445488930 CET19354500313.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.445786953 CET5003119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.446018934 CET5003119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.447037935 CET5003219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.447227955 CET19354500313.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.687110901 CET19354500313.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.687618971 CET19354500323.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.687700033 CET5003219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.691730022 CET5003219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.928647995 CET19354500323.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.928659916 CET19354500323.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.928847075 CET5003219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.930002928 CET5003219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:29.932334900 CET19354500323.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:29.932715893 CET5003319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.169457912 CET19354500323.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.174479008 CET19354500333.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.174669981 CET5003319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.175204039 CET5003319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.416543007 CET19354500333.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.416573048 CET19354500333.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.416671991 CET5003319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.417000055 CET19354500333.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.419337034 CET5003319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.420427084 CET5003419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.658524990 CET19354500343.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.658545017 CET19354500333.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.658742905 CET5003419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.660871983 CET5003419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.896943092 CET19354500343.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.897052050 CET5003419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.897180080 CET19354500343.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.897233009 CET5003419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.898144007 CET5003419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:30.898829937 CET19354500343.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:30.899431944 CET5003519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.135237932 CET19354500343.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.135251045 CET19354500343.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.139434099 CET19354500353.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.139520884 CET5003519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.140225887 CET5003519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.379751921 CET19354500353.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.379780054 CET19354500353.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.380007982 CET5003519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.380143881 CET19354500353.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.383220911 CET5003519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.384213924 CET5003619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.619925976 CET19354500353.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.626189947 CET19354500363.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.626307964 CET5003619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.626775980 CET5003619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.868668079 CET19354500363.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.868696928 CET19354500363.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.868701935 CET19354500363.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:31.869023085 CET5003619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.872458935 CET5003619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:31.873488903 CET5003719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.110987902 CET19354500363.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.115356922 CET19354500373.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.115434885 CET5003719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.119236946 CET5003719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.357554913 CET19354500373.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.357584953 CET19354500373.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.357774019 CET5003719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.358778954 CET5003719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.359852076 CET5003819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.361121893 CET19354500373.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.599737883 CET19354500373.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.603220940 CET19354500383.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.603543043 CET5003819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.609416008 CET5003819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.847050905 CET19354500383.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.847083092 CET19354500383.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:32.847377062 CET5003819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.847573996 CET5003819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.848536968 CET5003919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:32.852633953 CET19354500383.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.090539932 CET19354500383.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.092848063 CET19354500393.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.092930079 CET5003919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.093585014 CET5003919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.338419914 CET19354500393.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.338454008 CET19354500393.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.338541031 CET5003919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.338659048 CET19354500393.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.340903997 CET5003919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.342021942 CET5004019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.582915068 CET19354500393.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.584666967 CET19354500403.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.584745884 CET5004019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.587063074 CET5004019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.829860926 CET19354500403.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.829919100 CET5004019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:33.837867022 CET19354500403.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.837907076 CET19354500403.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:33.842541933 CET5004119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.072746992 CET19354500403.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.082686901 CET19354500413.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.082786083 CET5004119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.083405018 CET5004119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.322935104 CET19354500413.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.322969913 CET19354500413.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.323024988 CET5004119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.323070049 CET5004119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.323227882 CET19354500413.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.327898026 CET5004119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.329024076 CET5004219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.563028097 CET19354500413.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.563062906 CET19354500413.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.573520899 CET19354500423.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.573622942 CET5004219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.574204922 CET5004219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.817933083 CET19354500423.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.817948103 CET19354500423.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.818032980 CET5004219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.818269968 CET19354500423.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:34.819255114 CET5004219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:34.820271015 CET5004319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.063570023 CET19354500423.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.064320087 CET19354500433.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.064394951 CET5004319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.064965010 CET5004319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.307832956 CET19354500433.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.307861090 CET19354500433.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.308067083 CET5004319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.308115959 CET19354500433.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.308315039 CET5004319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.309372902 CET5004419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.550095081 CET19354500443.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.550173998 CET5004419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.550765038 CET5004419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.551078081 CET19354500433.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.791171074 CET19354500443.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.791202068 CET19354500443.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.791284084 CET5004419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.791305065 CET19354500443.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:35.794240952 CET5004419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:35.795665979 CET5004519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.031910896 CET19354500443.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.038702011 CET19354500453.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.038824081 CET5004519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.039233923 CET5004519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.282222033 CET19354500453.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.282234907 CET19354500453.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.282247066 CET19354500453.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.282305956 CET5004519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.282306910 CET5004519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.282598019 CET5004519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.284041882 CET5004619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.523799896 CET19354500463.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.524002075 CET5004619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.524653912 CET5004619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.525278091 CET19354500453.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.525321007 CET19354500453.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.763823032 CET19354500463.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.763854980 CET19354500463.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.764055967 CET5004619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.764231920 CET19354500463.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:36.765279055 CET5004619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:36.766360998 CET5004719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.003846884 CET19354500463.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.009897947 CET19354500473.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.009994030 CET5004719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.016103029 CET5004719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.254045010 CET19354500473.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.254080057 CET19354500473.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.254318953 CET5004719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.254728079 CET5004719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.255780935 CET5004819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.259634972 CET19354500473.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.496006966 CET19354500483.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.496090889 CET5004819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.496686935 CET5004819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.497912884 CET19354500473.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.736502886 CET19354500483.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.736515999 CET19354500483.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.736712933 CET5004819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.737036943 CET19354500483.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.739377975 CET5004819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.740266085 CET5004919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:37.977365017 CET19354500483.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.981758118 CET19354500493.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:37.981853008 CET5004919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.002839088 CET5004919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.223490953 CET19354500493.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.223516941 CET19354500493.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.223716021 CET5004919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.223716021 CET5004919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.225457907 CET5004919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.226466894 CET5005019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.244304895 CET19354500493.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.465434074 CET19354500493.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.465450048 CET19354500493.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.467881918 CET19354500503.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.467971087 CET5005019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.576097965 CET5005019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.709867001 CET19354500503.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.709881067 CET19354500503.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.709976912 CET5005019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.725617886 CET5005019354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.726550102 CET5005119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:38.817673922 CET19354500503.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.951389074 CET19354500503.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.972310066 CET19354500513.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:38.972498894 CET5005119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:39.218055010 CET19354500513.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:39.218069077 CET19354500513.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:39.218220949 CET5005119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:39.525799990 CET5005119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:39.532953024 CET5005119354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:39.533988953 CET5005219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:39.771447897 CET19354500513.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:39.773436069 CET19354500523.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:39.773627043 CET5005219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:39.896763086 CET5005219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.013298988 CET19354500523.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.013329983 CET19354500523.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.013511896 CET5005219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.022378922 CET5005219354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.023462057 CET5005319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.136115074 CET19354500523.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.252947092 CET19354500523.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.266055107 CET19354500533.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.266288042 CET5005319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.266642094 CET5005319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.508789062 CET19354500533.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.508817911 CET19354500533.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.508888960 CET19354500533.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.509000063 CET5005319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.518631935 CET5005319354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.532942057 CET5005419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.751420021 CET19354500533.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.774456024 CET19354500543.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:40.774564981 CET5005419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:40.775183916 CET5005419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.016328096 CET19354500543.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.016340017 CET19354500543.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.016431093 CET5005419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.016474962 CET19354500543.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.017429113 CET5005419354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.018342972 CET5005519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.258151054 CET19354500543.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.260942936 CET19354500553.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.261055946 CET5005519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.261759996 CET5005519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.503875017 CET19354500553.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.503907919 CET19354500553.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.504089117 CET5005519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.504089117 CET5005519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.504304886 CET5005519354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.504312992 CET19354500553.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.505315065 CET5005619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.746543884 CET19354500553.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.746592045 CET19354500553.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.747750044 CET19354500563.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.747823954 CET5005619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.748672009 CET5005619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.990781069 CET19354500563.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.990808010 CET19354500563.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.990890980 CET5005619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.991089106 CET19354500563.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:41.992356062 CET5005619354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:41.994766951 CET5005719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.233360052 CET19354500563.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.240442991 CET19354500573.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.240590096 CET5005719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.242902040 CET5005719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.486644983 CET19354500573.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.486676931 CET19354500573.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.486869097 CET5005719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.487349987 CET5005719354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.488281012 CET5005819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.488488913 CET19354500573.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.730798960 CET19354500583.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.730882883 CET5005819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.731333971 CET5005819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.732608080 CET19354500573.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.973568916 CET19354500583.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.973582029 CET19354500583.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.973648071 CET5005819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.973721981 CET19354500583.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:42.975178957 CET5005819354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:42.976217031 CET5005919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:43.216206074 CET19354500583.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:43.221071959 CET19354500593.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:43.221143007 CET5005919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:43.221744061 CET5005919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:43.466169119 CET19354500593.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:43.466197014 CET19354500593.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:43.466411114 CET5005919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:43.466438055 CET19354500593.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:43.468209982 CET5005919354192.168.2.43.126.37.18
                                                    Dec 30, 2023 07:00:43.593972921 CET5006019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:43.711163998 CET19354500593.126.37.18192.168.2.4
                                                    Dec 30, 2023 07:00:43.833431005 CET193545006018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:43.833554983 CET5006019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:43.834105968 CET5006019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.073302031 CET193545006018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.073331118 CET193545006018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.073502064 CET193545006018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.073545933 CET5006019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.074990034 CET5006019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.075923920 CET5006119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.313014984 CET193545006018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.319701910 CET193545006118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.319777012 CET5006119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.320331097 CET5006119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.563719034 CET193545006118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.563750982 CET193545006118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.563844919 CET5006119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.564038038 CET193545006118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.567394018 CET5006119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.568399906 CET5006219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.807595015 CET193545006118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.811083078 CET193545006218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:44.811167002 CET5006219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:44.811641932 CET5006219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.053920984 CET193545006218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.053932905 CET193545006218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.053977013 CET5006219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.053997993 CET5006219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.054059029 CET193545006218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.056648970 CET5006219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.057857037 CET5006319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.296559095 CET193545006218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.296744108 CET193545006218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.298913002 CET193545006318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.298985958 CET5006319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.301340103 CET5006319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.540329933 CET193545006318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.540358067 CET193545006318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.540599108 CET5006319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.541831970 CET5006319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.542346001 CET193545006318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.548405886 CET5006419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.781703949 CET193545006318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.792049885 CET193545006418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:45.792239904 CET5006419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:45.792624950 CET5006419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.036096096 CET193545006418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.036109924 CET193545006418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.036122084 CET193545006418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.036166906 CET5006419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.036186934 CET5006419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.036969900 CET5006419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.044394016 CET5006519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.279750109 CET193545006418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.279764891 CET193545006418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.283649921 CET193545006518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.283720970 CET5006519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.284271002 CET5006519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.523190975 CET193545006518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.523250103 CET193545006518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.523305893 CET5006519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.523329973 CET5006519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.523529053 CET193545006518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.524523973 CET5006519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.525566101 CET5006619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.762700081 CET193545006518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.762716055 CET193545006518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.770261049 CET193545006618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:46.770337105 CET5006619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:46.770843029 CET5006619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.015429020 CET193545006618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.015458107 CET193545006618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.015517950 CET193545006618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.015522957 CET5006619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.015826941 CET5006619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.016736031 CET5006719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.256055117 CET193545006718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.256136894 CET5006719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.256829023 CET5006719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.260221004 CET193545006618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.495579958 CET193545006718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.495593071 CET193545006718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.495786905 CET5006719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.496082067 CET193545006718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.496561050 CET5006719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.497658968 CET5006819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.735040903 CET193545006718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.739947081 CET193545006818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.740014076 CET5006819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.740606070 CET5006819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.982510090 CET193545006818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.982534885 CET193545006818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.982577085 CET5006819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.982605934 CET5006819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.982820034 CET193545006818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:47.983409882 CET5006819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:47.984386921 CET5006919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.224937916 CET193545006818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.224948883 CET193545006818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.226831913 CET193545006918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.227025986 CET5006919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.227391958 CET5006919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.469744921 CET193545006918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.469757080 CET193545006918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.469820976 CET5006919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.469861031 CET193545006918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.473902941 CET5006919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.474955082 CET5007019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.712455034 CET193545006918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.714590073 CET193545007018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.714659929 CET5007019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.719327927 CET5007019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.954694986 CET193545007018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.954838037 CET193545007018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:48.954922915 CET5007019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.954922915 CET5007019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.956615925 CET5007019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.957659960 CET5007119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:48.958935976 CET193545007018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.194788933 CET193545007018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.194818020 CET193545007018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.200376034 CET193545007118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.200592995 CET5007119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.200939894 CET5007119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.443455935 CET193545007118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.443471909 CET193545007118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.443559885 CET193545007118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.443578005 CET5007119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.446157932 CET5007119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.451450109 CET5007219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.686383963 CET193545007118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.694107056 CET193545007218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.694324017 CET5007219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.694788933 CET5007219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.937191010 CET193545007218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.937221050 CET193545007218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.937293053 CET5007219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.937294006 CET5007219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.937433958 CET193545007218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:49.937894106 CET5007219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:49.941781044 CET5007319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.180159092 CET193545007218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.180172920 CET193545007218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.186105013 CET193545007318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.186193943 CET5007319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.186981916 CET5007319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.430707932 CET193545007318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.430737019 CET193545007318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.430939913 CET5007319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.431236982 CET193545007318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.434045076 CET5007319354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.435023069 CET5007419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.675470114 CET193545007318.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.681616068 CET193545007418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.681804895 CET5007419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.682276964 CET5007419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.928491116 CET193545007418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.928507090 CET193545007418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.928579092 CET193545007418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:50.928621054 CET5007419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.929243088 CET5007419354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:50.930138111 CET5007519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.175182104 CET193545007418.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.176445007 CET193545007518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.176513910 CET5007519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.177057028 CET5007519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.423062086 CET193545007518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.423079967 CET193545007518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.423156023 CET5007519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.423249960 CET193545007518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.424501896 CET5007519354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.425518036 CET5007619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.669677019 CET193545007518.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.669709921 CET193545007618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.669800043 CET5007619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.670270920 CET5007619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.914130926 CET193545007618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.914143085 CET193545007618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.914151907 CET193545007618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:51.914233923 CET5007619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.920305967 CET5007619354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:51.942915916 CET5007719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.158199072 CET193545007618.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.186157942 CET193545007718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.186228037 CET5007719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.186665058 CET5007719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.429701090 CET193545007718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.429714918 CET193545007718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.429765940 CET5007719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.429927111 CET193545007718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.444221020 CET5007719354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.445276976 CET5007819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.672988892 CET193545007718.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.683437109 CET193545007818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.683535099 CET5007819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.683986902 CET5007819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.921837091 CET193545007818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.921852112 CET193545007818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.921914101 CET5007819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.922178984 CET193545007818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:52.935414076 CET5007819354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:52.936475039 CET5007919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.159993887 CET193545007818.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.176635027 CET193545007918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.176732063 CET5007919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.177189112 CET5007919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.417042971 CET193545007918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.417072058 CET193545007918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.417118073 CET5007919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.417157888 CET5007919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.417332888 CET193545007918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.417572021 CET5007919354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.418536901 CET5008019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.657073021 CET193545007918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.657105923 CET193545007918.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.664498091 CET193545008018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.664589882 CET5008019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.665143967 CET5008019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.911096096 CET193545008018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.911128044 CET193545008018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.911138058 CET193545008018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:53.911195040 CET5008019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.911626101 CET5008019354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:53.912499905 CET5008119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:54.153690100 CET193545008118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:54.153788090 CET5008119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:54.154301882 CET5008119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:54.157248020 CET193545008018.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:54.395221949 CET193545008118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:54.395256042 CET193545008118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:54.395315886 CET5008119354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:54.395318985 CET193545008118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:54.636502028 CET193545008118.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:57.751872063 CET5008219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:57.990318060 CET193545008218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:57.990466118 CET5008219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:57.990896940 CET5008219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:58.229007959 CET193545008218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:58.229074001 CET5008219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:58.229155064 CET193545008218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:58.229166985 CET193545008218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:58.229212046 CET5008219354192.168.2.418.197.239.5
                                                    Dec 30, 2023 07:00:58.467374086 CET193545008218.197.239.5192.168.2.4
                                                    Dec 30, 2023 07:00:58.467422962 CET193545008218.197.239.5192.168.2.4
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Dec 30, 2023 06:56:55.315988064 CET5941653192.168.2.41.1.1.1
                                                    Dec 30, 2023 06:56:55.461504936 CET53594161.1.1.1192.168.2.4
                                                    Dec 30, 2023 06:57:56.152983904 CET5811553192.168.2.41.1.1.1
                                                    Dec 30, 2023 06:57:56.297986031 CET53581151.1.1.1192.168.2.4
                                                    Dec 30, 2023 06:58:55.476154089 CET6126253192.168.2.41.1.1.1
                                                    Dec 30, 2023 06:58:55.600205898 CET53612621.1.1.1192.168.2.4
                                                    Dec 30, 2023 06:59:55.515933990 CET5181753192.168.2.41.1.1.1
                                                    Dec 30, 2023 06:59:55.638200045 CET53518171.1.1.1192.168.2.4
                                                    Dec 30, 2023 07:00:43.468978882 CET5258053192.168.2.41.1.1.1
                                                    Dec 30, 2023 07:00:43.593019962 CET53525801.1.1.1192.168.2.4
                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                    Dec 30, 2023 06:56:55.315988064 CET192.168.2.41.1.1.10x178bStandard query (0)2.tcp.eu.ngrok.ioA (IP address)IN (0x0001)false
                                                    Dec 30, 2023 06:57:56.152983904 CET192.168.2.41.1.1.10x9da4Standard query (0)2.tcp.eu.ngrok.ioA (IP address)IN (0x0001)false
                                                    Dec 30, 2023 06:58:55.476154089 CET192.168.2.41.1.1.10x1a93Standard query (0)2.tcp.eu.ngrok.ioA (IP address)IN (0x0001)false
                                                    Dec 30, 2023 06:59:55.515933990 CET192.168.2.41.1.1.10x6a5eStandard query (0)2.tcp.eu.ngrok.ioA (IP address)IN (0x0001)false
                                                    Dec 30, 2023 07:00:43.468978882 CET192.168.2.41.1.1.10x1e57Standard query (0)2.tcp.eu.ngrok.ioA (IP address)IN (0x0001)false
                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                    Dec 30, 2023 06:56:55.461504936 CET1.1.1.1192.168.2.40x178bNo error (0)2.tcp.eu.ngrok.io3.127.138.57A (IP address)IN (0x0001)false
                                                    Dec 30, 2023 06:57:56.297986031 CET1.1.1.1192.168.2.40x9da4No error (0)2.tcp.eu.ngrok.io18.156.13.209A (IP address)IN (0x0001)false
                                                    Dec 30, 2023 06:58:55.600205898 CET1.1.1.1192.168.2.40x1a93No error (0)2.tcp.eu.ngrok.io3.127.138.57A (IP address)IN (0x0001)false
                                                    Dec 30, 2023 06:59:55.638200045 CET1.1.1.1192.168.2.40x6a5eNo error (0)2.tcp.eu.ngrok.io3.126.37.18A (IP address)IN (0x0001)false
                                                    Dec 30, 2023 07:00:43.593019962 CET1.1.1.1192.168.2.40x1e57No error (0)2.tcp.eu.ngrok.io18.197.239.5A (IP address)IN (0x0001)false

                                                    Click to jump to process

                                                    Click to jump to process

                                                    Click to dive into process behavior distribution

                                                    Click to jump to process

                                                    Target ID:0
                                                    Start time:06:56:48
                                                    Start date:30/12/2023
                                                    Path:C:\Users\user\Desktop\tiodtk2cfy.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:C:\Users\user\Desktop\tiodtk2cfy.exe
                                                    Imagebase:0x470000
                                                    File size:95'232 bytes
                                                    MD5 hash:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:.Net C# or VB.NET
                                                    Yara matches:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000002.1630097952.0000000003A68000.00000004.00000800.00020000.00000000.sdmp, Author: JPCERT/CC Incident Response Group
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, Author: unknown
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: 00000000.00000000.1609537761.0000000000472000.00000002.00000001.01000000.00000003.sdmp, Author: JPCERT/CC Incident Response Group
                                                    Reputation:low
                                                    Has exited:true

                                                    Target ID:1
                                                    Start time:06:56:50
                                                    Start date:30/12/2023
                                                    Path:C:\Users\user\AppData\Roaming\server.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\AppData\Roaming\server.exe"
                                                    Imagebase:0x60000
                                                    File size:95'232 bytes
                                                    MD5 hash:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:.Net C# or VB.NET
                                                    Yara matches:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000001.00000002.4063644018.00000000026E1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\server.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\server.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\server.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\server.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\server.exe, Author: ditekSHen
                                                    Antivirus matches:
                                                    • Detection: 100%, Avira
                                                    • Detection: 100%, Joe Sandbox ML
                                                    • Detection: 84%, ReversingLabs
                                                    • Detection: 82%, Virustotal, Browse
                                                    Reputation:low
                                                    Has exited:false

                                                    Target ID:2
                                                    Start time:06:56:51
                                                    Start date:30/12/2023
                                                    Path:C:\Windows\SysWOW64\netsh.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:netsh firewall add allowedprogram "C:\Users\user\AppData\Roaming\server.exe" "server.exe" ENABLE
                                                    Imagebase:0x1560000
                                                    File size:82'432 bytes
                                                    MD5 hash:4E89A1A088BE715D6C946E55AB07C7DF
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:moderate
                                                    Has exited:true

                                                    Target ID:3
                                                    Start time:06:56:51
                                                    Start date:30/12/2023
                                                    Path:C:\Windows\System32\conhost.exe
                                                    Wow64 process (32bit):false
                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                    Imagebase:0x7ff7699e0000
                                                    File size:862'208 bytes
                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:C, C++ or other language
                                                    Reputation:high
                                                    Has exited:true

                                                    Target ID:5
                                                    Start time:06:57:14
                                                    Start date:30/12/2023
                                                    Path:C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe"
                                                    Imagebase:0x350000
                                                    File size:95'232 bytes
                                                    MD5 hash:B56BE916B1CA250CD9FE04B283E0C3EE
                                                    Has elevated privileges:false
                                                    Has administrator privileges:false
                                                    Programmed in:.Net C# or VB.NET
                                                    Yara matches:
                                                    • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: Joe Security
                                                    • Rule: Windows_Trojan_Njrat_30f3c220, Description: unknown, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: unknown
                                                    • Rule: CN_disclosed_20180208_c, Description: Detects malware from disclosed CN malware set, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: Florian Roth
                                                    • Rule: Njrat, Description: detect njRAT in memory, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: JPCERT/CC Incident Response Group
                                                    • Rule: MALWARE_Win_NjRAT, Description: Detects NjRAT / Bladabindi, Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe, Author: ditekSHen
                                                    Antivirus matches:
                                                    • Detection: 100%, Avira
                                                    • Detection: 100%, Joe Sandbox ML
                                                    • Detection: 84%, ReversingLabs
                                                    • Detection: 82%, Virustotal, Browse
                                                    Reputation:low
                                                    Has exited:true

                                                    Reset < >

                                                      Execution Graph

                                                      Execution Coverage:2.6%
                                                      Dynamic/Decrypted Code Coverage:100%
                                                      Signature Coverage:0%
                                                      Total number of Nodes:58
                                                      Total number of Limit Nodes:4
                                                      execution_graph 14191 a5b424 14193 a5b446 ShellExecuteExW 14191->14193 14194 a5b488 14193->14194 14144 a5aaa6 14145 a5aade CreateFileW 14144->14145 14147 a5ab2d 14145->14147 14148 a5b446 14150 a5b46c ShellExecuteExW 14148->14150 14151 a5b488 14150->14151 14152 a5aeae 14155 a5aee3 WriteFile 14152->14155 14154 a5af15 14155->14154 14187 a5a6ce 14188 a5a72e OleGetClipboard 14187->14188 14190 a5a78c 14188->14190 14163 a5b06a 14164 a5b0a2 CreateMutexW 14163->14164 14166 a5b0e5 14164->14166 14207 a5aa75 14208 a5aaa6 CreateFileW 14207->14208 14210 a5ab2d 14208->14210 14195 a5ac37 14197 a5ac6a GetFileType 14195->14197 14198 a5accc 14197->14198 14211 a5ae77 14213 a5aeae WriteFile 14211->14213 14214 a5af15 14213->14214 14199 a5b036 14201 a5b06a CreateMutexW 14199->14201 14202 a5b0e5 14201->14202 14215 a5a573 14216 a5a59a DuplicateHandle 14215->14216 14218 a5a5e6 14216->14218 14167 a5aa12 14168 a5aa3e SetErrorMode 14167->14168 14170 a5aa67 14167->14170 14169 a5aa53 14168->14169 14170->14168 14219 a5ab7c 14220 a5abbe FindCloseChangeNotification 14219->14220 14222 a5abf8 14220->14222 14183 a5a9bf 14184 a5a9c9 SetErrorMode 14183->14184 14186 a5aa53 14184->14186 14171 a5abbe 14172 a5ac29 14171->14172 14173 a5abea FindCloseChangeNotification 14171->14173 14172->14173 14174 a5abf8 14173->14174 14175 a5a65e 14176 a5a6c0 14175->14176 14177 a5a68a OleInitialize 14175->14177 14176->14177 14178 a5a698 14177->14178 14203 a5a61e 14204 a5a65e OleInitialize 14203->14204 14206 a5a698 14204->14206 14179 a5a59a 14180 a5a5d8 DuplicateHandle 14179->14180 14182 a5a610 14179->14182 14181 a5a5e6 14180->14181 14182->14180

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 0 4c44298-4c442c9 3 4c44352-4c4435a 0->3 4 4c442cf-4c44350 0->4 5 4c44366-4c4437a 3->5 4->3 32 4c4435c 4->32 6 4c44380-4c443bc 5->6 7 4c4452f-4c4467d 5->7 19 4c443ed-4c444ea 6->19 20 4c443be-4c443e6 6->20 44 4c44683-4c447d2 7->44 45 4c4480d-4c44821 7->45 138 4c444ef 19->138 20->19 32->5 44->45 47 4c44827-4c44934 45->47 48 4c4496f-4c44983 45->48 47->48 50 4c44985-4c4499b call 4c44210 48->50 51 4c449d6-4c449ea 48->51 50->51 55 4c44a32-4c44a46 51->55 56 4c449ec-4c449f7 51->56 60 4c44b94-4c44ba8 55->60 61 4c44a4c-4c44b59 55->61 56->55 63 4c44cd4-4c44ce8 60->63 64 4c44bae-4c44bc2 60->64 61->60 67 4c44f74-4c44f88 63->67 68 4c44cee-4c44f2d 63->68 72 4c44bc4-4c44bcb 64->72 73 4c44bd0-4c44be4 64->73 76 4c44fe2-4c44ff6 67->76 77 4c44f8a-4c44f9b 67->77 68->67 79 4c44c48-4c44c5c 72->79 74 4c44be6-4c44bed 73->74 75 4c44bef-4c44c03 73->75 74->79 81 4c44c05-4c44c0c 75->81 82 4c44c0e-4c44c22 75->82 85 4c45045-4c45059 76->85 86 4c44ff8-4c44ffe 76->86 77->76 88 4c44c76-4c44c82 79->88 89 4c44c5e-4c44c74 79->89 81->79 91 4c44c24-4c44c2b 82->91 92 4c44c2d-4c44c41 82->92 95 4c450a2-4c450b6 85->95 96 4c4505b 85->96 86->85 94 4c44c8d 88->94 89->94 91->79 92->79 105 4c44c43-4c44c45 92->105 94->63 103 4c4512d-4c45141 95->103 104 4c450b8-4c450e1 95->104 96->95 108 4c453b4-4c453c8 103->108 109 4c45147-4c45363 103->109 104->103 105->79 110 4c4549e-4c454b2 108->110 111 4c453ce-4c45457 108->111 495 4c45365 109->495 496 4c45367 109->496 117 4c4566f-4c45683 110->117 118 4c454b8-4c45628 110->118 111->110 127 4c457e6-4c457fa 117->127 128 4c45689-4c4579f 117->128 118->117 132 4c45800-4c45916 127->132 133 4c4595d-4c45971 127->133 128->127 132->133 139 4c45ad4-4c45ae8 133->139 140 4c45977-4c45a8d 133->140 138->7 144 4c45aee-4c45c04 139->144 145 4c45c4b-4c45c5f 139->145 140->139 144->145 152 4c45c65-4c45d7b 145->152 153 4c45dc2-4c45dd6 145->153 152->153 159 4c45ddc-4c45ef2 153->159 160 4c45f39-4c45f4d 153->160 159->160 166 4c460b0-4c460c4 160->166 167 4c45f53-4c46069 160->167 174 4c46227-4c4623b 166->174 175 4c460ca-4c461e0 166->175 167->166 183 4c46241-4c46357 174->183 184 4c4639e-4c463b2 174->184 175->174 183->184 198 4c46536-4c4654a 184->198 199 4c463b8-4c463fd call 4c44278 184->199 206 4c46550-4c4656f 198->206 207 4c4668d-4c466a1 198->207 324 4c464bd-4c464df 199->324 239 4c46614-4c46636 206->239 218 4c466a7-4c467a7 207->218 219 4c467ee-4c46802 207->219 218->219 225 4c4694f-4c46963 219->225 226 4c46808-4c46908 219->226 243 4c46ab0-4c46ada 225->243 244 4c46969-4c46a69 225->244 226->225 251 4c46574-4c46583 239->251 252 4c4663c 239->252 265 4c46ae0-4c46b53 243->265 266 4c46b9a-4c46bae 243->266 244->243 269 4c4663e 251->269 270 4c46589-4c465bc 251->270 252->207 265->266 272 4c46bb4-4c46c44 266->272 273 4c46c8b-4c46c9f 266->273 287 4c46643-4c4668b 269->287 348 4c46603-4c4660c 270->348 349 4c465be-4c465f8 270->349 272->273 288 4c46de5-4c46df9 273->288 289 4c46ca5-4c46d9e 273->289 287->207 300 4c4705c-4c47070 288->300 301 4c46dff-4c46e4f 288->301 289->288 311 4c47076-4c47111 call 4c44278 * 2 300->311 312 4c47158-4c4715f 300->312 412 4c46e51-4c46e77 301->412 413 4c46ebd-4c46ee8 301->413 311->312 336 4c464e5 324->336 337 4c46402-4c46411 324->337 336->198 358 4c464e7 337->358 359 4c46417-4c464b5 337->359 348->287 361 4c4660e 348->361 349->348 381 4c464ec-4c46534 358->381 359->381 493 4c464b7 359->493 361->239 381->198 487 4c46eb8 412->487 488 4c46e79-4c46e99 412->488 490 4c46fc6-4c47057 413->490 491 4c46eee-4c46fc1 413->491 487->300 488->487 490->300 491->300 493->324 498 4c4536d 495->498 496->498 498->108
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: @$Yk^
                                                      • API String ID: 0-61571821
                                                      • Opcode ID: 849768fb43dfff60c999ba1d36f30a682ef0c8df789cc6d3dac09b5ad52be94a
                                                      • Instruction ID: 14e7b086f88f8f7299c7b3a0b24d7cbbd14e791807e7b26f896dc9bd3e64e18f
                                                      • Opcode Fuzzy Hash: 849768fb43dfff60c999ba1d36f30a682ef0c8df789cc6d3dac09b5ad52be94a
                                                      • Instruction Fuzzy Hash: 31233A74A01228CFDB25EF74D954BA9B7B2FB88304F1041EAD90967395DB399E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 556 4c44269-4c44288 557 4c442b1-4c442c9 556->557 558 4c4428a-4c442af 556->558 560 4c44352-4c4435a 557->560 561 4c442cf-4c44350 557->561 558->557 562 4c44366-4c4437a 560->562 561->560 589 4c4435c 561->589 563 4c44380-4c443bc 562->563 564 4c4452f-4c4467d 562->564 576 4c443ed-4c444ea 563->576 577 4c443be-4c443e6 563->577 601 4c44683-4c447d2 564->601 602 4c4480d-4c44821 564->602 695 4c444ef 576->695 577->576 589->562 601->602 604 4c44827-4c44934 602->604 605 4c4496f-4c44983 602->605 604->605 607 4c44985-4c4499b call 4c44210 605->607 608 4c449d6-4c449ea 605->608 607->608 612 4c44a32-4c44a46 608->612 613 4c449ec-4c449f7 608->613 617 4c44b94-4c44ba8 612->617 618 4c44a4c-4c44b59 612->618 613->612 620 4c44cd4-4c44ce8 617->620 621 4c44bae-4c44bc2 617->621 618->617 624 4c44f74-4c44f88 620->624 625 4c44cee-4c44f2d 620->625 629 4c44bc4-4c44bcb 621->629 630 4c44bd0-4c44be4 621->630 633 4c44fe2-4c44ff6 624->633 634 4c44f8a-4c44f9b 624->634 625->624 636 4c44c48-4c44c5c 629->636 631 4c44be6-4c44bed 630->631 632 4c44bef-4c44c03 630->632 631->636 638 4c44c05-4c44c0c 632->638 639 4c44c0e-4c44c22 632->639 642 4c45045-4c45059 633->642 643 4c44ff8-4c44ffe 633->643 634->633 645 4c44c76-4c44c82 636->645 646 4c44c5e-4c44c74 636->646 638->636 648 4c44c24-4c44c2b 639->648 649 4c44c2d-4c44c41 639->649 652 4c450a2-4c450b6 642->652 653 4c4505b 642->653 643->642 651 4c44c8d 645->651 646->651 648->636 649->636 662 4c44c43-4c44c45 649->662 651->620 660 4c4512d-4c45141 652->660 661 4c450b8-4c450e1 652->661 653->652 665 4c453b4-4c453c8 660->665 666 4c45147-4c45363 660->666 661->660 662->636 667 4c4549e-4c454b2 665->667 668 4c453ce-4c45457 665->668 1052 4c45365 666->1052 1053 4c45367 666->1053 674 4c4566f-4c45683 667->674 675 4c454b8-4c45628 667->675 668->667 684 4c457e6-4c457fa 674->684 685 4c45689-4c4579f 674->685 675->674 689 4c45800-4c45916 684->689 690 4c4595d-4c45971 684->690 685->684 689->690 696 4c45ad4-4c45ae8 690->696 697 4c45977-4c45a8d 690->697 695->564 701 4c45aee-4c45c04 696->701 702 4c45c4b-4c45c5f 696->702 697->696 701->702 709 4c45c65-4c45d7b 702->709 710 4c45dc2-4c45dd6 702->710 709->710 716 4c45ddc-4c45ef2 710->716 717 4c45f39-4c45f4d 710->717 716->717 723 4c460b0-4c460c4 717->723 724 4c45f53-4c46069 717->724 731 4c46227-4c4623b 723->731 732 4c460ca-4c461e0 723->732 724->723 740 4c46241-4c46357 731->740 741 4c4639e-4c463b2 731->741 732->731 740->741 755 4c46536-4c4654a 741->755 756 4c463b8-4c463fd call 4c44278 741->756 763 4c46550-4c4656f 755->763 764 4c4668d-4c466a1 755->764 881 4c464bd-4c464df 756->881 796 4c46614-4c46636 763->796 775 4c466a7-4c467a7 764->775 776 4c467ee-4c46802 764->776 775->776 782 4c4694f-4c46963 776->782 783 4c46808-4c46908 776->783 800 4c46ab0-4c46ada 782->800 801 4c46969-4c46a69 782->801 783->782 808 4c46574-4c46583 796->808 809 4c4663c 796->809 822 4c46ae0-4c46b53 800->822 823 4c46b9a-4c46bae 800->823 801->800 826 4c4663e 808->826 827 4c46589-4c465bc 808->827 809->764 822->823 829 4c46bb4-4c46c44 823->829 830 4c46c8b-4c46c9f 823->830 844 4c46643-4c4668b 826->844 905 4c46603-4c4660c 827->905 906 4c465be-4c465f8 827->906 829->830 845 4c46de5-4c46df9 830->845 846 4c46ca5-4c46d9e 830->846 844->764 857 4c4705c-4c47070 845->857 858 4c46dff-4c46e4f 845->858 846->845 868 4c47076-4c47111 call 4c44278 * 2 857->868 869 4c47158-4c4715f 857->869 969 4c46e51-4c46e77 858->969 970 4c46ebd-4c46ee8 858->970 868->869 893 4c464e5 881->893 894 4c46402-4c46411 881->894 893->755 915 4c464e7 894->915 916 4c46417-4c464b5 894->916 905->844 918 4c4660e 905->918 906->905 938 4c464ec-4c46534 915->938 916->938 1050 4c464b7 916->1050 918->796 938->755 1044 4c46eb8 969->1044 1045 4c46e79-4c46e99 969->1045 1047 4c46fc6-4c47057 970->1047 1048 4c46eee-4c46fc1 970->1048 1044->857 1045->1044 1047->857 1048->857 1050->881 1055 4c4536d 1052->1055 1053->1055 1055->665
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: 5df949228deffe8dfddb48f669f8832ee3ea8761183c35a86f9446df9c8deb06
                                                      • Instruction ID: 583ae55f705f3ea53755a739a61d5815c410be6b96f28752d049e9869e753a40
                                                      • Opcode Fuzzy Hash: 5df949228deffe8dfddb48f669f8832ee3ea8761183c35a86f9446df9c8deb06
                                                      • Instruction Fuzzy Hash: A7134C74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1113 4c400b8-4c400cd 1141 4c400d0 call f70606 1113->1141 1142 4c400d0 call f705e3 1113->1142 1143 4c400d0 call a5a20c 1113->1143 1144 4c400d0 call f7026d 1113->1144 1145 4c400d0 call a5a23a 1113->1145 1115 4c400d5-4c400f7 1118 4c400f9-4c4010a 1115->1118 1119 4c4010b-4c401d5 1115->1119 1135 4c401d5 call f70606 1119->1135 1136 4c401d5 call f705e3 1119->1136 1137 4c401d5 call 4c43801 1119->1137 1138 4c401d5 call f7026d 1119->1138 1139 4c401d5 call 4c439bf 1119->1139 1140 4c401d5 call 4c43b18 1119->1140 1134 4c401db-4c401de 1135->1134 1136->1134 1137->1134 1138->1134 1139->1134 1140->1134 1141->1115 1142->1115 1143->1115 1144->1115 1145->1115
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: 5]k^$E]k^
                                                      • API String ID: 0-3693904655
                                                      • Opcode ID: e32f6a9d44ea53dfd5d7ca8d91bd38b06b4ce31e664aafbf16a8a46e512b4c93
                                                      • Instruction ID: 2721446060adaa3ec589d6119c63b8b282e4b348f49c43e210c0a1d164bb6aab
                                                      • Opcode Fuzzy Hash: e32f6a9d44ea53dfd5d7ca8d91bd38b06b4ce31e664aafbf16a8a46e512b4c93
                                                      • Instruction Fuzzy Hash: E83124326042409FCB15AB759852B6E3BB79BC2358F1584AED001CB2D2CFB95C068792
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1146 4c40118-4c40169 1151 4c40174-4c4017a 1146->1151 1152 4c40181-4c401bd 1151->1152 1157 4c401c8-4c401d5 1152->1157 1160 4c401d5 call f70606 1157->1160 1161 4c401d5 call f705e3 1157->1161 1162 4c401d5 call 4c43801 1157->1162 1163 4c401d5 call f7026d 1157->1163 1164 4c401d5 call 4c439bf 1157->1164 1165 4c401d5 call 4c43b18 1157->1165 1159 4c401db-4c401de 1160->1159 1161->1159 1162->1159 1163->1159 1164->1159 1165->1159
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: 5]k^$E]k^
                                                      • API String ID: 0-3693904655
                                                      • Opcode ID: bdc020832ed72540ace655305a208d6b56c51fd9199f2f09dd4154e3efda4ccb
                                                      • Instruction ID: 8930eb512f414461eb987b38867412b46f102702172f707da1d490bd91d7f8b6
                                                      • Opcode Fuzzy Hash: bdc020832ed72540ace655305a208d6b56c51fd9199f2f09dd4154e3efda4ccb
                                                      • Instruction Fuzzy Hash: 391129727011408FCB25E779A55177D2BABDBC2348B15447EC002CB792CFB95C0B8792
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1166 a5aa75-a5aafe 1170 a5ab00 1166->1170 1171 a5ab03-a5ab0f 1166->1171 1170->1171 1172 a5ab14-a5ab1d 1171->1172 1173 a5ab11 1171->1173 1174 a5ab1f-a5ab43 CreateFileW 1172->1174 1175 a5ab6e-a5ab73 1172->1175 1173->1172 1178 a5ab75-a5ab7a 1174->1178 1179 a5ab45-a5ab6b 1174->1179 1175->1174 1178->1179
                                                      APIs
                                                      • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 00A5AB25
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: CreateFile
                                                      • String ID:
                                                      • API String ID: 823142352-0
                                                      • Opcode ID: b38f9b9a100422a72160a2b9647f0d58df78e7ef32c28ecdd9cc849179517df0
                                                      • Instruction ID: 9a706c052e3359326fc0875e414959e5321b8557724b725ceab5aa77b3e13a6b
                                                      • Opcode Fuzzy Hash: b38f9b9a100422a72160a2b9647f0d58df78e7ef32c28ecdd9cc849179517df0
                                                      • Instruction Fuzzy Hash: 7A319071505380AFE722CF25CC44B52BBF8EF06310F08899AE9858B652D375E909CB61
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1182 a5b036-a5b0b9 1186 a5b0be-a5b0c7 1182->1186 1187 a5b0bb 1182->1187 1188 a5b0cc-a5b0d5 1186->1188 1189 a5b0c9 1186->1189 1187->1186 1190 a5b0d7-a5b0fb CreateMutexW 1188->1190 1191 a5b126-a5b12b 1188->1191 1189->1188 1194 a5b12d-a5b132 1190->1194 1195 a5b0fd-a5b123 1190->1195 1191->1190 1194->1195
                                                      APIs
                                                      • CreateMutexW.KERNELBASE(?,?), ref: 00A5B0DD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: CreateMutex
                                                      • String ID:
                                                      • API String ID: 1964310414-0
                                                      • Opcode ID: 1acdb43570f8a573ffdcfa8ced86e8cdc98b80003b12b274b763dcbeba265aff
                                                      • Instruction ID: e50264641bc7ac02efb1db7a0d2209d15d05c3d5663df7e456a6ed58f11019b9
                                                      • Opcode Fuzzy Hash: 1acdb43570f8a573ffdcfa8ced86e8cdc98b80003b12b274b763dcbeba265aff
                                                      • Instruction Fuzzy Hash: 5E31A1B15097805FE722CB25DC45B96FFF8EF06310F08849AE984CB692D375A909C772
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1198 a5a6ce-a5a72b 1199 a5a72e-a5a786 OleGetClipboard 1198->1199 1201 a5a78c-a5a7a2 1199->1201
                                                      APIs
                                                      • OleGetClipboard.OLE32(?,00000E24,?,?), ref: 00A5A77E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: Clipboard
                                                      • String ID:
                                                      • API String ID: 220874293-0
                                                      • Opcode ID: 3869b9317a3b817367c0c80b4e42399f584241b59dd7fe07e2b323782247c666
                                                      • Instruction ID: 44a325ee883ede76cb4df2c92735f4731756dae757570e64b4347822f6777ae3
                                                      • Opcode Fuzzy Hash: 3869b9317a3b817367c0c80b4e42399f584241b59dd7fe07e2b323782247c666
                                                      • Instruction Fuzzy Hash: F1317E7104E3C06FD3138B259C61B62BFB4EF47610F0A40DBE884CB6A3D2296919D772
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1202 a5ae77-a5af05 1206 a5af07-a5af27 WriteFile 1202->1206 1207 a5af49-a5af4e 1202->1207 1210 a5af50-a5af55 1206->1210 1211 a5af29-a5af46 1206->1211 1207->1206 1210->1211
                                                      APIs
                                                      • WriteFile.KERNELBASE(?,00000E24,B2C02E97,00000000,00000000,00000000,00000000), ref: 00A5AF0D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: FileWrite
                                                      • String ID:
                                                      • API String ID: 3934441357-0
                                                      • Opcode ID: f98ffcb286c9f19e3115bdd0acdde263087fec6040bc3834cf4e30681b2f42e1
                                                      • Instruction ID: 42a61a4423031ed34536bca3e6f233b6e666453bdea34053d87ba36afe31848d
                                                      • Opcode Fuzzy Hash: f98ffcb286c9f19e3115bdd0acdde263087fec6040bc3834cf4e30681b2f42e1
                                                      • Instruction Fuzzy Hash: 7421D3B2409380AFE722CF51DD44F96BFB8EF06314F08849AE9849B552D234A90DCB71
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1214 a5aaa6-a5aafe 1217 a5ab00 1214->1217 1218 a5ab03-a5ab0f 1214->1218 1217->1218 1219 a5ab14-a5ab1d 1218->1219 1220 a5ab11 1218->1220 1221 a5ab1f-a5ab27 CreateFileW 1219->1221 1222 a5ab6e-a5ab73 1219->1222 1220->1219 1224 a5ab2d-a5ab43 1221->1224 1222->1221 1225 a5ab75-a5ab7a 1224->1225 1226 a5ab45-a5ab6b 1224->1226 1225->1226
                                                      APIs
                                                      • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 00A5AB25
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: CreateFile
                                                      • String ID:
                                                      • API String ID: 823142352-0
                                                      • Opcode ID: f788872add61d2c52261bcb02f41976d72a5eec9656c83e2c4ea6321a930ae4c
                                                      • Instruction ID: 2935742ca5bf8fd4367a4e417e63252c48518f80648c8342c8f90e11e90b57cb
                                                      • Opcode Fuzzy Hash: f788872add61d2c52261bcb02f41976d72a5eec9656c83e2c4ea6321a930ae4c
                                                      • Instruction Fuzzy Hash: 7E21AE71600200AFEB21CF65DD45B66FBE8FF18314F04896AED458BA51D375E908CBB2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1240 a5ac37-a5acb5 1244 a5acb7-a5acca GetFileType 1240->1244 1245 a5acea-a5acef 1240->1245 1246 a5acf1-a5acf6 1244->1246 1247 a5accc-a5ace9 1244->1247 1245->1244 1246->1247
                                                      APIs
                                                      • GetFileType.KERNELBASE(?,00000E24,B2C02E97,00000000,00000000,00000000,00000000), ref: 00A5ACBD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: FileType
                                                      • String ID:
                                                      • API String ID: 3081899298-0
                                                      • Opcode ID: 4523c49c2e276a6c387c51922777f9194469ade96025897c1ca171bd271c752f
                                                      • Instruction ID: 769b4bfbd4039fe8fddd94fb234732c295884bf7d733d91860413f057c8e2da5
                                                      • Opcode Fuzzy Hash: 4523c49c2e276a6c387c51922777f9194469ade96025897c1ca171bd271c752f
                                                      • Instruction Fuzzy Hash: 4E21F6B54093806FE7128B51DC40BA2BFB8EF46714F0884D6E9848B653C268A909D772
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1229 a5a9bf-a5aa3c 1234 a5aa67-a5aa6c 1229->1234 1235 a5aa3e-a5aa51 SetErrorMode 1229->1235 1234->1235 1236 a5aa53-a5aa66 1235->1236 1237 a5aa6e-a5aa73 1235->1237 1237->1236
                                                      APIs
                                                      • SetErrorMode.KERNELBASE(?), ref: 00A5AA44
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode
                                                      • String ID:
                                                      • API String ID: 2340568224-0
                                                      • Opcode ID: e6a756278d0007e173744e5bc5c87a4e2c8c7ae7392da6670fb54f21ec22cae8
                                                      • Instruction ID: feeca3c81035c349cd09a52acc150cbda894179639a33f55405fa19b6bd17369
                                                      • Opcode Fuzzy Hash: e6a756278d0007e173744e5bc5c87a4e2c8c7ae7392da6670fb54f21ec22cae8
                                                      • Instruction Fuzzy Hash: 8121486550E3C09FD7138B259C64A52BFB4AF53624F0E81DBD9848F6A3C268580DCB73
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1251 a5b06a-a5b0b9 1254 a5b0be-a5b0c7 1251->1254 1255 a5b0bb 1251->1255 1256 a5b0cc-a5b0d5 1254->1256 1257 a5b0c9 1254->1257 1255->1254 1258 a5b0d7-a5b0df CreateMutexW 1256->1258 1259 a5b126-a5b12b 1256->1259 1257->1256 1261 a5b0e5-a5b0fb 1258->1261 1259->1258 1262 a5b12d-a5b132 1261->1262 1263 a5b0fd-a5b123 1261->1263 1262->1263
                                                      APIs
                                                      • CreateMutexW.KERNELBASE(?,?), ref: 00A5B0DD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: CreateMutex
                                                      • String ID:
                                                      • API String ID: 1964310414-0
                                                      • Opcode ID: 3eb53f825bf1d74899bb6031d4c621bc443a2b8d741f90d6366e2c5a6251ec90
                                                      • Instruction ID: b9dc8b7e87be2d5fefd85d891315b447be781158e744f6ff8654d2e066e7575f
                                                      • Opcode Fuzzy Hash: 3eb53f825bf1d74899bb6031d4c621bc443a2b8d741f90d6366e2c5a6251ec90
                                                      • Instruction Fuzzy Hash: 802192716012409FE720DF25DD45BA6FBE8EF04325F04886AED458B781D775E909CB71
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1266 a5ab7c-a5abe8 1268 a5ac29-a5ac2e 1266->1268 1269 a5abea-a5abf2 FindCloseChangeNotification 1266->1269 1268->1269 1271 a5abf8-a5ac0a 1269->1271 1272 a5ac30-a5ac35 1271->1272 1273 a5ac0c-a5ac28 1271->1273 1272->1273
                                                      APIs
                                                      • FindCloseChangeNotification.KERNELBASE(?), ref: 00A5ABF0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: ChangeCloseFindNotification
                                                      • String ID:
                                                      • API String ID: 2591292051-0
                                                      • Opcode ID: 8a3400a76ea71077c011da2a33d449928a50633b91d336d413ddf179256524ef
                                                      • Instruction ID: 7daeec18da1e3cf14a6cd1ad2a86559d115cc7e703116d7a40c07634dd25bbb1
                                                      • Opcode Fuzzy Hash: 8a3400a76ea71077c011da2a33d449928a50633b91d336d413ddf179256524ef
                                                      • Instruction Fuzzy Hash: EA21A1B55097C09FDB128B25EC95752BFB8EF16320F0984DBDC858B6A3D2359908C762
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1275 a5a61e-a5a688 1277 a5a6c0-a5a6c5 1275->1277 1278 a5a68a-a5a692 OleInitialize 1275->1278 1277->1278 1279 a5a698-a5a6aa 1278->1279 1281 a5a6c7-a5a6cc 1279->1281 1282 a5a6ac-a5a6bf 1279->1282 1281->1282
                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: Initialize
                                                      • String ID:
                                                      • API String ID: 2538663250-0
                                                      • Opcode ID: 889c488ccaf9b0881a2707ab2171cbf153417d90a3c60d90db36f987346ed15a
                                                      • Instruction ID: 6a68bfa6dc4c677b96623896222b089690380fb03be3a0556cb42255510948bf
                                                      • Opcode Fuzzy Hash: 889c488ccaf9b0881a2707ab2171cbf153417d90a3c60d90db36f987346ed15a
                                                      • Instruction Fuzzy Hash: FF21277150E3C09FDB138B25DC94652BFB4AF17224F0984DBD9848F6A3D2699908DBB2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1284 a5a573-a5a5d6 1286 a5a610-a5a615 1284->1286 1287 a5a5d8-a5a5e0 DuplicateHandle 1284->1287 1286->1287 1288 a5a5e6-a5a5f8 1287->1288 1290 a5a617-a5a61c 1288->1290 1291 a5a5fa-a5a60d 1288->1291 1290->1291
                                                      APIs
                                                      • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 00A5A5DE
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: DuplicateHandle
                                                      • String ID:
                                                      • API String ID: 3793708945-0
                                                      • Opcode ID: a7d5366cfb33e52d477d42a3e6ae3345223a48938ab4860940671136343f6472
                                                      • Instruction ID: 9aeb030f0b32657c605d35d6be3df25b7cae091bc15094369d57cf088dbdd222
                                                      • Opcode Fuzzy Hash: a7d5366cfb33e52d477d42a3e6ae3345223a48938ab4860940671136343f6472
                                                      • Instruction Fuzzy Hash: B3118471509780AFDB228F51DC44A62FFF4EF4A310F0889DAED858B562C275A918DB62
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • ShellExecuteExW.SHELL32(?), ref: 00A5B480
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: ExecuteShell
                                                      • String ID:
                                                      • API String ID: 587946157-0
                                                      • Opcode ID: 2a7985f7fc04a25e32c6cc32780e6cf1ecd147d375e75893963859ff87a89928
                                                      • Instruction ID: 37397ffbead2292382c54360dd4e858e13b3dc0277bdae64e72335d281a8a4e0
                                                      • Opcode Fuzzy Hash: 2a7985f7fc04a25e32c6cc32780e6cf1ecd147d375e75893963859ff87a89928
                                                      • Instruction Fuzzy Hash: DC1160715093809FDB12CF25DC94B52BFB8EF46225F0884EBED85CB653D275A908CB62
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • WriteFile.KERNELBASE(?,00000E24,B2C02E97,00000000,00000000,00000000,00000000), ref: 00A5AF0D
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: FileWrite
                                                      • String ID:
                                                      • API String ID: 3934441357-0
                                                      • Opcode ID: 0996454757bf05f8069936d62fecacab0af716c3515b75ad2e6a448609389903
                                                      • Instruction ID: a88153e71c9ed632ba338e3ec0421e17ffcee05cffef93d6faab6d240f429a6a
                                                      • Opcode Fuzzy Hash: 0996454757bf05f8069936d62fecacab0af716c3515b75ad2e6a448609389903
                                                      • Instruction Fuzzy Hash: 6F11E271600300AFEB218F55DD44BA6FBE8EF14714F04C86AED458BA41C334A50C8BB2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • GetFileType.KERNELBASE(?,00000E24,B2C02E97,00000000,00000000,00000000,00000000), ref: 00A5ACBD
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: FileType
                                                      • String ID:
                                                      • API String ID: 3081899298-0
                                                      • Opcode ID: 9136e03c5345c9f58ff5bb7c86b9feb0340aa36177520ea69e71e5c5a3ff1165
                                                      • Instruction ID: 2b8f6c24d5acaa8636b5d87d031b68c4353472443abae5be9bea7ede524abf17
                                                      • Opcode Fuzzy Hash: 9136e03c5345c9f58ff5bb7c86b9feb0340aa36177520ea69e71e5c5a3ff1165
                                                      • Instruction Fuzzy Hash: 5D010071600300AFE7208B45DD84BA6FBA8EF14725F04C4A6ED048BB41C678A80C8AA2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • ShellExecuteExW.SHELL32(?), ref: 00A5B480
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: ExecuteShell
                                                      • String ID:
                                                      • API String ID: 587946157-0
                                                      • Opcode ID: db52f8724b74b3ac44be40270330714a849bb11661e664d5bc113f2b3e8395d7
                                                      • Instruction ID: 6dd0ecec80d16563e807cadf5e166672b9056a21017f44ecd365ecd4fc50e610
                                                      • Opcode Fuzzy Hash: db52f8724b74b3ac44be40270330714a849bb11661e664d5bc113f2b3e8395d7
                                                      • Instruction Fuzzy Hash: 330180716002408FDB20CF19D984766FBE8EF04726F08C4AADD49CBA52D778E808CB61
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 00A5A5DE
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: DuplicateHandle
                                                      • String ID:
                                                      • API String ID: 3793708945-0
                                                      • Opcode ID: f15038c83580c13ddf778806a19dea71445b5102b6518d05659661d224502544
                                                      • Instruction ID: 35fb084ca288a99497c36023de96a744816ff8250daf5cdf64af2cd28b62388e
                                                      • Opcode Fuzzy Hash: f15038c83580c13ddf778806a19dea71445b5102b6518d05659661d224502544
                                                      • Instruction Fuzzy Hash: E5018B725006009FDB218F55D944B62FFE0EF08321F0889AADE894BA11D236A418DF62
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • OleGetClipboard.OLE32(?,00000E24,?,?), ref: 00A5A77E
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: Clipboard
                                                      • String ID:
                                                      • API String ID: 220874293-0
                                                      • Opcode ID: a1820f20c08128d681d055f8bc710c875f3fa172c594f50bc0854d9ed8f37d66
                                                      • Instruction ID: 0bd57ab441f0b02aa17a9f28a8e1cf853cc45a317692dcdf22c036adfe67049c
                                                      • Opcode Fuzzy Hash: a1820f20c08128d681d055f8bc710c875f3fa172c594f50bc0854d9ed8f37d66
                                                      • Instruction Fuzzy Hash: 2001D671500600ABD310DF1ACD46B66FBE8FB88A20F14815AEC089BB41D731F916CBE6
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • FindCloseChangeNotification.KERNELBASE(?), ref: 00A5ABF0
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: ChangeCloseFindNotification
                                                      • String ID:
                                                      • API String ID: 2591292051-0
                                                      • Opcode ID: c78074b97456814c51ca43f13af930c43f809a68ba3a975895b45a7e294c8806
                                                      • Instruction ID: e29354cbe836e75ec630a44144e155a3d085442bd0e9881c6ec69ac21a53d72b
                                                      • Opcode Fuzzy Hash: c78074b97456814c51ca43f13af930c43f809a68ba3a975895b45a7e294c8806
                                                      • Instruction Fuzzy Hash: 5C0184716052408FDB108F55E985766FBE4EF14321F08C4ABDD498FA55D679D808CA62
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: Initialize
                                                      • String ID:
                                                      • API String ID: 2538663250-0
                                                      • Opcode ID: 4bf5f1d7835408df3ae75b4e293c98f97c8aa89f54f99f6c3df73db8f9e66e5d
                                                      • Instruction ID: 0ad8080b7857c37fcaf851bbada004a545f402d0f8dd52091023d143f575ac37
                                                      • Opcode Fuzzy Hash: 4bf5f1d7835408df3ae75b4e293c98f97c8aa89f54f99f6c3df73db8f9e66e5d
                                                      • Instruction Fuzzy Hash: 8101AD71A012409FEB20CF15D984766FBE4EF14321F0CC8AADD488FA56D279A408CEA2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      APIs
                                                      • SetErrorMode.KERNELBASE(?), ref: 00A5AA44
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629674739.0000000000A5A000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A5A000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a5a000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID: ErrorMode
                                                      • String ID:
                                                      • API String ID: 2340568224-0
                                                      • Opcode ID: 905130a5645cc79899b503a34eacd537882de113a5699d8c0a36405f8a3746cc
                                                      • Instruction ID: 8a320d2157be844c5ffd4e14cafdabf4c3e33509fe570317d06d31b3f5ffb8e6
                                                      • Opcode Fuzzy Hash: 905130a5645cc79899b503a34eacd537882de113a5699d8c0a36405f8a3746cc
                                                      • Instruction Fuzzy Hash: 59F0A4759006409FDB208F05DA84762FBE4EF14725F08C1AADE494BB52D679A508CE62
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d7cde47b30472b8458dcbc4cc5eabd5173fc85be6bdca6c30fe8c56d13577453
                                                      • Instruction ID: a5a1f74ec94d2b0a4be1206f9d70f2b72219fb3b81363c916b1e7041d775616d
                                                      • Opcode Fuzzy Hash: d7cde47b30472b8458dcbc4cc5eabd5173fc85be6bdca6c30fe8c56d13577453
                                                      • Instruction Fuzzy Hash: F4321B30A01218CFDB14EF74D955BEDB7B2EB89304F1045A9D40AAB3A5DB799E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630037707.0000000000F70000.00000040.00000020.00020000.00000000.sdmp, Offset: 00F70000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_f70000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 197667299eb7c57d57f95af88d9c091c0befb129adbe43d41a9d3f12020674a4
                                                      • Instruction ID: b3fe8b562fcb85372df40b24eeb59855a6ad6e5b92afc1fafcecae18e4b1d41d
                                                      • Opcode Fuzzy Hash: 197667299eb7c57d57f95af88d9c091c0befb129adbe43d41a9d3f12020674a4
                                                      • Instruction Fuzzy Hash: E2219EA544E3C04FD7138B34AC25291BFB0AE43225B1E81EBC489CF5A3D22D5819D7A3
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5f7e9ad59c072d6c36dfc3c203982f933549a6006b0ebd299d54047d742f5baa
                                                      • Instruction ID: 270b00e4b2b6c09fd695bb69a6fe4e1b44221a052911f9190147378c6478a283
                                                      • Opcode Fuzzy Hash: 5f7e9ad59c072d6c36dfc3c203982f933549a6006b0ebd299d54047d742f5baa
                                                      • Instruction Fuzzy Hash: 96816C30A01258CFDB14EFB4C955BACB7B2EF89308F1045AAD40AAB3A4DB795D85CF51
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: fdfc16b7270b81a5f8bb2a2b09ae2f3f7be86b8b0b3b0ffb439da96d06803bfa
                                                      • Instruction ID: 0cc367e9ed64efc8be65ce72aa3390e1104b6fc54b21b37f3c4d8757bdecd139
                                                      • Opcode Fuzzy Hash: fdfc16b7270b81a5f8bb2a2b09ae2f3f7be86b8b0b3b0ffb439da96d06803bfa
                                                      • Instruction Fuzzy Hash: B3415C30A002588FDB14DFB9C954BACB7B2FF85308F1045AAD409AB2A5DB795E49CF52
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: bc9cf79e1c0805e5c13976679a1d69e482c57005448a4b388b9117579dd3558f
                                                      • Instruction ID: a30ddd03c6b65e2bbaa01d6986fbb9bafb8441d89efeaf6e534ae78aabef3566
                                                      • Opcode Fuzzy Hash: bc9cf79e1c0805e5c13976679a1d69e482c57005448a4b388b9117579dd3558f
                                                      • Instruction Fuzzy Hash: AD319030B012118FDB14BBB9D9117BE37ABEB88208F10443AD905977A8DF79AD179BD1
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 1c41afe93bdb13f1cfeab46019fa48d7715a4492518b3fbbf87dbe3952c66ef8
                                                      • Instruction ID: 5be8de5e46531adeb4ac37d3bdf676545794e82d5759d285ecc5d6ec6da98a65
                                                      • Opcode Fuzzy Hash: 1c41afe93bdb13f1cfeab46019fa48d7715a4492518b3fbbf87dbe3952c66ef8
                                                      • Instruction Fuzzy Hash: 1C1169A540F3C18FDB139B749CA46907FB0AF17208B5A49EBC085CA5A7E29C590FC762
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: dad126602934a20c145dfb36c2ac37f6e85c3f0b650e741cd31bcf340ebfcb9f
                                                      • Instruction ID: f885478221228484e96b8de2b6f35a3bf005a37dc4bb7153f85302b36c54e08e
                                                      • Opcode Fuzzy Hash: dad126602934a20c145dfb36c2ac37f6e85c3f0b650e741cd31bcf340ebfcb9f
                                                      • Instruction Fuzzy Hash: F50180346062428FC714EB74DA5949C7BF1FF88349B008838E4458B355EA749C0BDB82
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630037707.0000000000F70000.00000040.00000020.00020000.00000000.sdmp, Offset: 00F70000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_f70000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 44f9f54b45476fbb87190734fa6b167b7c78303cd231d672c78d94306a806a06
                                                      • Instruction ID: 86e3cef5bc610b3e36ae53f254dd37c23e890d44f17cd15cef36cd951ddd75b5
                                                      • Opcode Fuzzy Hash: 44f9f54b45476fbb87190734fa6b167b7c78303cd231d672c78d94306a806a06
                                                      • Instruction Fuzzy Hash: C6018BB55097805FD7118B159C41863FFE8EE46620709C59FEC498B652D225A908CB71
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: be43d3add15e0504eb75bf3b454934bef82ae90d60822900c508fc1677ee6390
                                                      • Instruction ID: 65ad3077d702c14872377946c76aa35c5337a39d1874fd01d6e673d6d35a9f61
                                                      • Opcode Fuzzy Hash: be43d3add15e0504eb75bf3b454934bef82ae90d60822900c508fc1677ee6390
                                                      • Instruction Fuzzy Hash: 3EF0C236A05304AFEB149BB08812BAE7B72DF81724F1185AED581DB1E2DA3558418740
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630037707.0000000000F70000.00000040.00000020.00020000.00000000.sdmp, Offset: 00F70000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_f70000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 7808fc27e79f5565e9f7cc836d4d77658170dc6ff23804d651da26a064d91cfc
                                                      • Instruction ID: 23b3165052439fe74acee967d5d62ee722ecaef0807bd2148165df85b2dcc457
                                                      • Opcode Fuzzy Hash: 7808fc27e79f5565e9f7cc836d4d77658170dc6ff23804d651da26a064d91cfc
                                                      • Instruction Fuzzy Hash: 99E092B66006404B9650CF0AFC41462FBD8EB88630B08C47FDC0D8BB11D236B508CEA6
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: bddc2261fa8232c9003b7af39a49649ba75e259b16eca62a466df378fe5ee686
                                                      • Instruction ID: 3a06924436d40c7176b40fe777743711bab28ad3a15f363b22424496de8d608a
                                                      • Opcode Fuzzy Hash: bddc2261fa8232c9003b7af39a49649ba75e259b16eca62a466df378fe5ee686
                                                      • Instruction Fuzzy Hash: 99E08630107340CFC7265B34A01491C3B71EF47309F5104FDC4468B666D7768446CB40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629663939.0000000000A52000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A52000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a52000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 058874294d3d6cfef96eb2347926d6cbb684a5074decfd03ff60cfa25200bc61
                                                      • Instruction ID: c9a5ac4a70c7f36de0bd4edc610005fab0ee2048e0d3426f9b3a36a72a30ba1d
                                                      • Opcode Fuzzy Hash: 058874294d3d6cfef96eb2347926d6cbb684a5074decfd03ff60cfa25200bc61
                                                      • Instruction Fuzzy Hash: 2AD02E79240BC04FD3228B0CC2A4B8537E4BB42704F0A04F9AC00CB763C738D984C200
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629663939.0000000000A52000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A52000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a52000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 49ad04ba5508bd658a100fd15bd2f0dbabb03900f3733c44e0288480b62b4a89
                                                      • Instruction ID: d14aee287279fb33702cd2138797e43e6d19524b080965ba7e1aee518d8265b5
                                                      • Opcode Fuzzy Hash: 49ad04ba5508bd658a100fd15bd2f0dbabb03900f3733c44e0288480b62b4a89
                                                      • Instruction Fuzzy Hash: 74D05E342002814BD725DB0CC2D4F5977D4BB41725F0644F8AC108F762C7B8D8C4DA00
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: f8eaa589c78dcd0a7e03446927fdec61ae8c383635889eb6a6fc7410192785ed
                                                      • Instruction ID: a5f5dc096b2cee24c05f3ef1f28787f1d17ef795275ad9ed870bc115a3db030d
                                                      • Opcode Fuzzy Hash: f8eaa589c78dcd0a7e03446927fdec61ae8c383635889eb6a6fc7410192785ed
                                                      • Instruction Fuzzy Hash: 0D035D74A01228CFDB25EF74D954BA9BBB2FB88304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: f7dd30cacc4619be281d20a50187325db6176bfd9ff67204f90ef83d9ffb0d46
                                                      • Instruction ID: 57a871ff7dc0641d5ca3099520283c94f38b0961be8a8f1d580b9cfe8cd4a5e0
                                                      • Opcode Fuzzy Hash: f7dd30cacc4619be281d20a50187325db6176bfd9ff67204f90ef83d9ffb0d46
                                                      • Instruction Fuzzy Hash: 64035D74A01228CFDB25EF34D954BA9BBB2FB88304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: 0b37e600a1522efbcafbf0582789907ff374de83ed1a814b8734b9b0a5d63bab
                                                      • Instruction ID: 85d76d216218f08476b1fd4a8f32c5fe1051bb698106bbb2de6812b4b0b73e90
                                                      • Opcode Fuzzy Hash: 0b37e600a1522efbcafbf0582789907ff374de83ed1a814b8734b9b0a5d63bab
                                                      • Instruction Fuzzy Hash: 96035E74A01228CFDB25EF34D954BA9BBB2FB48304F1041EAD90967395DB399E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: 29f1b1bdc06358122980efec94d4bbeed436c3005de15d40b263151181bf480c
                                                      • Instruction ID: 0f8f9b6ab528631e5372c0ad2a894e5f51355ed5a305d289d8e182a1c350ebe5
                                                      • Opcode Fuzzy Hash: 29f1b1bdc06358122980efec94d4bbeed436c3005de15d40b263151181bf480c
                                                      • Instruction Fuzzy Hash: C7F26E74A01228CFDB25EF74D954BA9BBB2FB88304F1041EAD90967395DB395E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: aedb99ff3dc93c2d2dc893d6ed2551bcafd12d58df2c9ee58c3c6041ce4e675b
                                                      • Instruction ID: 6712137d1b9035f1710c7935d833d352d784107916238a7417a55450bd3b9948
                                                      • Opcode Fuzzy Hash: aedb99ff3dc93c2d2dc893d6ed2551bcafd12d58df2c9ee58c3c6041ce4e675b
                                                      • Instruction Fuzzy Hash: BAF26D74A01228CFDB25EF34D954BA9BBB2FB88304F1041EAD90967395DB395E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: cb56467e5362bc09ce1380773f33270c9f99cdf6bafc11d17823aed8b2eff1a6
                                                      • Instruction ID: c9de26d541d47f0e18b8331e7bdc5f215259729ab2103e481c8e8f6709299b46
                                                      • Opcode Fuzzy Hash: cb56467e5362bc09ce1380773f33270c9f99cdf6bafc11d17823aed8b2eff1a6
                                                      • Instruction Fuzzy Hash: 89F25D74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: 5ca174bfd7c992efa80c24b6d7c1d494b2aedc398c8002e34745b70adfe1587b
                                                      • Instruction ID: 2a384f3c5286035483729720838df3908467fc145ddd8dceee6fdbb83d952a1b
                                                      • Opcode Fuzzy Hash: 5ca174bfd7c992efa80c24b6d7c1d494b2aedc398c8002e34745b70adfe1587b
                                                      • Instruction Fuzzy Hash: 46F25D74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: 951a5e3c0a77cf3b77a26bfb38fc856f507553d02a009a3f5eeb1ad2709cfaf2
                                                      • Instruction ID: febf9015e22ec936a4128e3a97d886f57b22b66ea312015fc9a512a0201ad341
                                                      • Opcode Fuzzy Hash: 951a5e3c0a77cf3b77a26bfb38fc856f507553d02a009a3f5eeb1ad2709cfaf2
                                                      • Instruction Fuzzy Hash: 88F26D74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: $Yk^
                                                      • API String ID: 0-737799909
                                                      • Opcode ID: a0ca799ee2454f91d02b1f084c171567b1eec545ecb048ede7b5e9e24cfeead5
                                                      • Instruction ID: 6d1683010c279de0e2863677f3ae29de6947b7aea097f27305695191675c372c
                                                      • Opcode Fuzzy Hash: a0ca799ee2454f91d02b1f084c171567b1eec545ecb048ede7b5e9e24cfeead5
                                                      • Instruction Fuzzy Hash: 22E26D74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: a54edea7b0d8b4d269a73b14b27bf162126ddf6ad6818c8731b7ce22b8adc9c7
                                                      • Instruction ID: 3655d04d04e3ef9e35ab3908963b7066e6943e66022b750532e9a4e82a32135b
                                                      • Opcode Fuzzy Hash: a54edea7b0d8b4d269a73b14b27bf162126ddf6ad6818c8731b7ce22b8adc9c7
                                                      • Instruction Fuzzy Hash: F0E25D74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: b9197e5179a3b48250d84778aabc5434e5474054f47a2a571a7b524a8fc6c119
                                                      • Instruction ID: 6a1cd3043a5b05d8229504749fb72f1e65bee83b97ff4a87ef0ac47ffc542d4b
                                                      • Opcode Fuzzy Hash: b9197e5179a3b48250d84778aabc5434e5474054f47a2a571a7b524a8fc6c119
                                                      • Instruction Fuzzy Hash: 54D25D74A01228CFDB25EF34D954BA9BBB2FB49304F1041EAD90967395DB399E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: fd865e8f99e204bf94187cbac5ff6e842d54e4d2cb428682dd4f0e134c917f4c
                                                      • Instruction ID: da4c98749fe993ec94af43391839789ab0629d6780917fb6b47cf592f0119633
                                                      • Opcode Fuzzy Hash: fd865e8f99e204bf94187cbac5ff6e842d54e4d2cb428682dd4f0e134c917f4c
                                                      • Instruction Fuzzy Hash: 88D25D74A01228CFDB25EF34D954BA9BBB2FB49304F1041EAD90967395DB399E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: dfabfcb19aed27d306977349c9d19a62a1ea139794d63f48bbb20dca70b352d1
                                                      • Instruction ID: e78cc6d2308eb2d142fd518467002d9e8bf130ebfe1ded47f6cab25282e83819
                                                      • Opcode Fuzzy Hash: dfabfcb19aed27d306977349c9d19a62a1ea139794d63f48bbb20dca70b352d1
                                                      • Instruction Fuzzy Hash: 73D24D74A01228CFDB25EF34D954BA9BBB2FB49304F1041EAD90967395DB399E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: e6baa3761b65afa72f52854104074ff8f8dbb1cfba60e09d4217fd3a291be6ef
                                                      • Instruction ID: d84261ee511978f1add250a48bb5ea49f006cae5299aa6b2bcec7628e7fe37ed
                                                      • Opcode Fuzzy Hash: e6baa3761b65afa72f52854104074ff8f8dbb1cfba60e09d4217fd3a291be6ef
                                                      • Instruction Fuzzy Hash: 74D25D74A01228CFDB25EF34D954BA9BBB2FB49304F1041EAD90967395DB399E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: 0c72fd77d149920601153c8cc7b0008bbed8870ad3c9beff2f377a868efd4051
                                                      • Instruction ID: bc919ce14a70ec8a14f869c138fb881bdb4ac80e0091783e0ceb3cef186e003e
                                                      • Opcode Fuzzy Hash: 0c72fd77d149920601153c8cc7b0008bbed8870ad3c9beff2f377a868efd4051
                                                      • Instruction Fuzzy Hash: 63D25D74A01228CFDB25EF34D954BA9BBB2FB89304F1041EAD90967395DB359E86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1630227184.0000000004C40000.00000040.00000800.00020000.00000000.sdmp, Offset: 04C40000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_4c40000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: Yk^
                                                      • API String ID: 0-2647811921
                                                      • Opcode ID: 4f665a9081db83cecdf2daa1d039a9381e130b0c0837c30080af72b5ee547215
                                                      • Instruction ID: 17918dcd48c085775aa3ace66a2718aee319627f840a0f7b93ef22ce73cb153b
                                                      • Opcode Fuzzy Hash: 4f665a9081db83cecdf2daa1d039a9381e130b0c0837c30080af72b5ee547215
                                                      • Instruction Fuzzy Hash: 17C24C74A01228CFDB25EF30D954BA9BBB6FB49304F1041EAD90967395DB35AE86CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000000.00000002.1629663939.0000000000A52000.00000040.00000800.00020000.00000000.sdmp, Offset: 00A52000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_0_2_a52000_tiodtk2cfy.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f6695509683f7e78cd6cd66599bc543d55d31486852488a36bece0255d96e607
                                                      • Instruction ID: d5c7de4526cb1e32721aa66a940f06742cfcac789edf5b02cd15dea74c62ff31
                                                      • Opcode Fuzzy Hash: f6695509683f7e78cd6cd66599bc543d55d31486852488a36bece0255d96e607
                                                      • Instruction Fuzzy Hash: 9431DE6504EBD15FD70B8B308CA2545BF71AE4351434E86CFC884CF6E7D32A990AC7A6
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Execution Graph

                                                      Execution Coverage:24.7%
                                                      Dynamic/Decrypted Code Coverage:100%
                                                      Signature Coverage:6.2%
                                                      Total number of Nodes:112
                                                      Total number of Limit Nodes:7
                                                      execution_graph 20491 509040a 20493 5090433 LookupPrivilegeValueW 20491->20493 20494 509045a 20493->20494 20495 509058a 20497 50905b9 AdjustTokenPrivileges 20495->20497 20498 50905db 20497->20498 20570 509234a 20573 5092385 LoadLibraryA 20570->20573 20572 50923c2 20573->20572 20499 94aa12 20500 94aa3e SetErrorMode 20499->20500 20502 94aa67 20499->20502 20501 94aa53 20500->20501 20502->20500 20574 94a65e 20575 94a6c0 20574->20575 20576 94a68a FindCloseChangeNotification 20574->20576 20575->20576 20577 94a698 20576->20577 20503 5091c02 20505 5091c37 shutdown 20503->20505 20506 5091c60 20505->20506 20507 5091382 20508 50913ba WSASocketW 20507->20508 20510 50913f6 20508->20510 20511 94a59a 20512 94a610 20511->20512 20513 94a5d8 DuplicateHandle 20511->20513 20512->20513 20514 94a5e6 20513->20514 20582 94b45a 20585 94b495 SendMessageTimeoutA 20582->20585 20584 94b4dd 20585->20584 20515 5090706 20516 509073b NtQuerySystemInformation 20515->20516 20517 5090766 20515->20517 20518 5090750 20516->20518 20517->20516 20519 94a186 20520 94a1bb send 20519->20520 20521 94a1f3 20519->20521 20522 94a1c9 20520->20522 20521->20520 20523 94b806 20526 94b82f CopyFileW 20523->20526 20525 94b856 20526->20525 20527 5092f1a 20530 5092f43 select 20527->20530 20529 5092f78 20530->20529 20531 94b982 20532 94b9ab SetFileAttributesW 20531->20532 20534 94b9c7 20532->20534 20535 5090e1e 20537 5090e53 GetExitCodeProcess 20535->20537 20538 5090e7c 20537->20538 20539 509209e 20541 50920d3 WSAConnect 20539->20541 20542 50920f2 20541->20542 20590 509195e 20591 5091996 MapViewOfFile 20590->20591 20593 50919e5 20591->20593 20594 94bace 20595 94bb2c 20594->20595 20596 94bafa FindClose 20594->20596 20595->20596 20597 94bb0f 20596->20597 20598 94b8ce 20600 94b8f4 DeleteFileW 20598->20600 20601 94b910 20600->20601 20602 50930d2 20605 5093107 SetProcessWorkingSetSize 20602->20605 20604 5093133 20605->20604 20606 5091dd2 20608 5091e07 GetProcessTimes 20606->20608 20609 5091e39 20608->20609 20610 4840958 20613 4840974 20610->20613 20611 4840ad5 20612 48400b8 GetLogicalDrives GetLogicalDrives 20612->20613 20613->20611 20613->20612 20614 94b176 20615 94b1ae RegOpenKeyExW 20614->20615 20617 94b204 20615->20617 20618 94b372 20621 94b3a7 RegSetValueExW 20618->20621 20620 94b3f3 20621->20620 20543 50917ae 20544 50917e6 ConvertStringSecurityDescriptorToSecurityDescriptorW 20543->20544 20546 5091827 20544->20546 20622 5092c6e 20623 5092ca6 RegCreateKeyExW 20622->20623 20625 5092d18 20623->20625 20626 5092fee 20628 5093023 GetProcessWorkingSetSize 20626->20628 20629 509304f 20628->20629 20630 94b27e 20631 94b2b3 RegQueryValueExW 20630->20631 20633 94b307 20631->20633 20551 94aaa6 20552 94aade CreateFileW 20551->20552 20554 94ab2d 20552->20554 20555 5092e3e 20557 5092e73 ioctlsocket 20555->20557 20558 5092e9f 20557->20558 20559 5091ebe 20560 5091ef9 getaddrinfo 20559->20560 20562 5091f6b 20560->20562 20563 94a72e 20564 94a77e OleGetClipboard 20563->20564 20565 94a78c 20564->20565 20637 94adee 20640 94ae23 WriteFile 20637->20640 20639 94ae55 20640->20639 20566 94afaa 20567 94afe2 CreateMutexW 20566->20567 20569 94b025 20567->20569 20641 94ac6a 20643 94ac9f GetFileType 20641->20643 20644 94accc 20643->20644
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID: @
                                                      • API String ID: 0-2766056989
                                                      • Opcode ID: e4adb59a96b9a8b8fd5843b716684a265b1f39650a2f2c00f2be9dbaa8098b47
                                                      • Instruction ID: cadb763fa8f43cb53b67bc956f1b6928a2f3074a57ab232061628ea166ea7e77
                                                      • Opcode Fuzzy Hash: e4adb59a96b9a8b8fd5843b716684a265b1f39650a2f2c00f2be9dbaa8098b47
                                                      • Instruction Fuzzy Hash: 90236B74A012288FDB25EF35D854BADB7B2FB49308F1041E9D509AB398DB395E85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1127 48444f1-484467d 1148 4844683-48447d2 1127->1148 1149 484480d-4844821 1127->1149 1148->1149 1150 4844827-4844934 1149->1150 1151 484496f-4844983 1149->1151 1150->1151 1152 4844985-484498b call 4844210 1151->1152 1153 48449d6-48449ea 1151->1153 1159 4844990-484499b 1152->1159 1157 4844a32-4844a46 1153->1157 1158 48449ec-48449f7 1153->1158 1160 4844b94-4844ba8 1157->1160 1161 4844a4c-4844b51 1157->1161 1158->1157 1159->1153 1164 4844cd4-4844ce8 1160->1164 1165 4844bae-4844bc2 1160->1165 1379 4844b59 1161->1379 1167 4844f74-4844f88 1164->1167 1168 4844cee-4844f22 1164->1168 1170 4844bc4-4844bcb 1165->1170 1171 4844bd0-4844be4 1165->1171 1174 4844fe2-4844ff6 1167->1174 1175 4844f8a-4844f91 1167->1175 1643 4844f2d 1168->1643 1179 4844c48-4844c5c 1170->1179 1176 4844be6-4844bed 1171->1176 1177 4844bef-4844c03 1171->1177 1184 4845045-4845059 1174->1184 1185 4844ff8 1174->1185 1204 4844f9b 1175->1204 1176->1179 1182 4844c05-4844c0c 1177->1182 1183 4844c0e-4844c22 1177->1183 1186 4844c76-4844c82 1179->1186 1187 4844c5e-4844c74 1179->1187 1182->1179 1190 4844c24-4844c2b 1183->1190 1191 4844c2d-4844c41 1183->1191 1194 48450a2-48450b6 1184->1194 1195 484505b 1184->1195 1653 4844ff8 call 48474b0 1185->1653 1654 4844ff8 call 4847310 1185->1654 1655 4844ff8 call 4847461 1185->1655 1656 4844ff8 call af0606 1185->1656 1657 4844ff8 call af05e1 1185->1657 1193 4844c8d 1186->1193 1187->1193 1190->1179 1191->1179 1203 4844c43-4844c45 1191->1203 1193->1164 1200 484512d-4845141 1194->1200 1201 48450b8-48450e1 1194->1201 1195->1194 1197 4844ffe 1197->1184 1205 48453b4-48453c8 1200->1205 1206 4845147-4845363 1200->1206 1201->1200 1203->1179 1204->1174 1208 484549e-48454b2 1205->1208 1209 48453ce-4845457 1205->1209 1590 4845365 1206->1590 1591 4845367 1206->1591 1215 484566f-4845683 1208->1215 1216 48454b8-4845628 1208->1216 1209->1208 1223 48457e6-48457fa 1215->1223 1224 4845689-484579f 1215->1224 1216->1215 1227 4845800-4845916 1223->1227 1228 484595d-4845971 1223->1228 1224->1223 1227->1228 1233 4845ad4-4845ae8 1228->1233 1234 4845977-4845a8d 1228->1234 1238 4845aee-4845c04 1233->1238 1239 4845c4b-4845c5f 1233->1239 1234->1233 1238->1239 1246 4845c65-4845d7b 1239->1246 1247 4845dc2-4845dd6 1239->1247 1246->1247 1253 4845ddc-4845ef2 1247->1253 1254 4845f39-4845f4d 1247->1254 1253->1254 1261 48460b0-48460c4 1254->1261 1262 4845f53-4846069 1254->1262 1269 4846227-484623b 1261->1269 1270 48460ca-48461e0 1261->1270 1262->1261 1278 4846241-4846357 1269->1278 1279 484639e-48463b2 1269->1279 1270->1269 1278->1279 1293 4846536-484654a 1279->1293 1294 48463b8-48463fd call 4844278 1279->1294 1296 4846550-484656f 1293->1296 1297 484668d-48466a1 1293->1297 1420 48464bd-48464df 1294->1420 1330 4846614-4846636 1296->1330 1310 48466a7-48467a7 1297->1310 1311 48467ee-4846802 1297->1311 1310->1311 1326 484694f-4846963 1311->1326 1327 4846808-4846908 1311->1327 1336 4846ab0-4846ada 1326->1336 1337 4846969-4846a69 1326->1337 1327->1326 1343 4846574-4846583 1330->1343 1344 484663c 1330->1344 1357 4846ae0-4846b53 1336->1357 1358 4846b9a-4846bae 1336->1358 1337->1336 1364 484663e 1343->1364 1365 4846589-484658d 1343->1365 1344->1297 1357->1358 1372 4846bb4-4846c0b 1358->1372 1373 4846c8b-4846c9f 1358->1373 1386 4846643-484668b 1364->1386 1389 4846598-48465bc 1365->1389 1497 4846c12-4846c44 1372->1497 1377 4846de5-4846df9 1373->1377 1378 4846ca5-4846d9e 1373->1378 1391 484705c-4847070 1377->1391 1392 4846dff-4846e4f 1377->1392 1378->1377 1379->1160 1386->1297 1446 4846603-484660c 1389->1446 1447 48465be-48465f8 1389->1447 1414 4847076-4847111 call 4844278 * 2 1391->1414 1415 4847158-484715f 1391->1415 1505 4846e51-4846e77 1392->1505 1506 4846ebd-4846ee8 1392->1506 1414->1415 1439 48464e5 1420->1439 1440 4846402-4846411 1420->1440 1439->1293 1443 48464e7 1440->1443 1444 4846417-48464b5 1440->1444 1472 48464ec-4846534 1443->1472 1444->1472 1589 48464b7 1444->1589 1446->1386 1464 484660e 1446->1464 1447->1446 1464->1330 1472->1293 1497->1373 1584 4846eb8 1505->1584 1585 4846e79-4846e99 1505->1585 1582 4846fc6-4847057 1506->1582 1583 4846eee-4846fc1 1506->1583 1582->1391 1583->1391 1584->1391 1585->1584 1589->1420 1596 484536d 1590->1596 1591->1596 1651 4845367 call 48474e0 1591->1651 1652 4845367 call 484758e 1591->1652 1596->1205 1643->1167 1651->1596 1652->1596 1653->1197 1654->1197 1655->1197 1656->1197 1657->1197
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: 0c46161e1de7f81ed5e5d8ea7bd67098128a2935b3e5920b7d5005ab17b53116
                                                      • Instruction ID: b0f4a6afeab05eea48fbf4999e6629310b8a06eeb9df1f8690e2d9c623aec6bd
                                                      • Opcode Fuzzy Hash: 0c46161e1de7f81ed5e5d8ea7bd67098128a2935b3e5920b7d5005ab17b53116
                                                      • Instruction Fuzzy Hash: 63035A74A012288FDB25EF35D854BACB7B2FB49308F1041E9D509AB399DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 1658 4844544-484467d 1676 4844683-48447d2 1658->1676 1677 484480d-4844821 1658->1677 1676->1677 1678 4844827-4844934 1677->1678 1679 484496f-4844983 1677->1679 1678->1679 1680 4844985-484498b call 4844210 1679->1680 1681 48449d6-48449ea 1679->1681 1687 4844990-484499b 1680->1687 1685 4844a32-4844a46 1681->1685 1686 48449ec-48449f7 1681->1686 1688 4844b94-4844ba8 1685->1688 1689 4844a4c-4844b51 1685->1689 1686->1685 1687->1681 1692 4844cd4-4844ce8 1688->1692 1693 4844bae-4844bc2 1688->1693 1907 4844b59 1689->1907 1695 4844f74-4844f88 1692->1695 1696 4844cee-4844f22 1692->1696 1698 4844bc4-4844bcb 1693->1698 1699 4844bd0-4844be4 1693->1699 1702 4844fe2-4844ff6 1695->1702 1703 4844f8a-4844f91 1695->1703 2171 4844f2d 1696->2171 1707 4844c48-4844c5c 1698->1707 1704 4844be6-4844bed 1699->1704 1705 4844bef-4844c03 1699->1705 1712 4845045-4845059 1702->1712 1713 4844ff8 1702->1713 1732 4844f9b 1703->1732 1704->1707 1710 4844c05-4844c0c 1705->1710 1711 4844c0e-4844c22 1705->1711 1714 4844c76-4844c82 1707->1714 1715 4844c5e-4844c74 1707->1715 1710->1707 1718 4844c24-4844c2b 1711->1718 1719 4844c2d-4844c41 1711->1719 1722 48450a2-48450b6 1712->1722 1723 484505b 1712->1723 2181 4844ff8 call 48474b0 1713->2181 2182 4844ff8 call 4847310 1713->2182 2183 4844ff8 call 4847461 1713->2183 2184 4844ff8 call af0606 1713->2184 2185 4844ff8 call af05e1 1713->2185 1721 4844c8d 1714->1721 1715->1721 1718->1707 1719->1707 1731 4844c43-4844c45 1719->1731 1721->1692 1728 484512d-4845141 1722->1728 1729 48450b8-48450e1 1722->1729 1723->1722 1725 4844ffe 1725->1712 1733 48453b4-48453c8 1728->1733 1734 4845147-4845363 1728->1734 1729->1728 1731->1707 1732->1702 1736 484549e-48454b2 1733->1736 1737 48453ce-4845457 1733->1737 2118 4845365 1734->2118 2119 4845367 1734->2119 1743 484566f-4845683 1736->1743 1744 48454b8-4845628 1736->1744 1737->1736 1751 48457e6-48457fa 1743->1751 1752 4845689-484579f 1743->1752 1744->1743 1755 4845800-4845916 1751->1755 1756 484595d-4845971 1751->1756 1752->1751 1755->1756 1761 4845ad4-4845ae8 1756->1761 1762 4845977-4845a8d 1756->1762 1766 4845aee-4845c04 1761->1766 1767 4845c4b-4845c5f 1761->1767 1762->1761 1766->1767 1774 4845c65-4845d7b 1767->1774 1775 4845dc2-4845dd6 1767->1775 1774->1775 1781 4845ddc-4845ef2 1775->1781 1782 4845f39-4845f4d 1775->1782 1781->1782 1789 48460b0-48460c4 1782->1789 1790 4845f53-4846069 1782->1790 1797 4846227-484623b 1789->1797 1798 48460ca-48461e0 1789->1798 1790->1789 1806 4846241-4846357 1797->1806 1807 484639e-48463b2 1797->1807 1798->1797 1806->1807 1821 4846536-484654a 1807->1821 1822 48463b8-48463fd call 4844278 1807->1822 1824 4846550-484656f 1821->1824 1825 484668d-48466a1 1821->1825 1948 48464bd-48464df 1822->1948 1858 4846614-4846636 1824->1858 1838 48466a7-48467a7 1825->1838 1839 48467ee-4846802 1825->1839 1838->1839 1854 484694f-4846963 1839->1854 1855 4846808-4846908 1839->1855 1864 4846ab0-4846ada 1854->1864 1865 4846969-4846a69 1854->1865 1855->1854 1871 4846574-4846583 1858->1871 1872 484663c 1858->1872 1885 4846ae0-4846b53 1864->1885 1886 4846b9a-4846bae 1864->1886 1865->1864 1892 484663e 1871->1892 1893 4846589-484658d 1871->1893 1872->1825 1885->1886 1900 4846bb4-4846c0b 1886->1900 1901 4846c8b-4846c9f 1886->1901 1914 4846643-484668b 1892->1914 1917 4846598-48465bc 1893->1917 2025 4846c12-4846c44 1900->2025 1905 4846de5-4846df9 1901->1905 1906 4846ca5-4846d9e 1901->1906 1919 484705c-4847070 1905->1919 1920 4846dff-4846e4f 1905->1920 1906->1905 1907->1688 1914->1825 1974 4846603-484660c 1917->1974 1975 48465be-48465f8 1917->1975 1942 4847076-4847111 call 4844278 * 2 1919->1942 1943 4847158-484715f 1919->1943 2033 4846e51-4846e77 1920->2033 2034 4846ebd-4846ee8 1920->2034 1942->1943 1967 48464e5 1948->1967 1968 4846402-4846411 1948->1968 1967->1821 1971 48464e7 1968->1971 1972 4846417-48464b5 1968->1972 2000 48464ec-4846534 1971->2000 1972->2000 2117 48464b7 1972->2117 1974->1914 1992 484660e 1974->1992 1975->1974 1992->1858 2000->1821 2025->1901 2112 4846eb8 2033->2112 2113 4846e79-4846e99 2033->2113 2110 4846fc6-4847057 2034->2110 2111 4846eee-4846fc1 2034->2111 2110->1919 2111->1919 2112->1919 2113->2112 2117->1948 2124 484536d 2118->2124 2119->2124 2179 4845367 call 48474e0 2119->2179 2180 4845367 call 484758e 2119->2180 2124->1733 2171->1695 2179->2124 2180->2124 2181->1725 2182->1725 2183->1725 2184->1725 2185->1725
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: e4e6485ea78923ca57c49374cd6d20593ce76af1d9316686112e7f04db29334b
                                                      • Instruction ID: 25c769061480ef4816796dda36cb5ae76610a5e034920e720a9522ad69106fef
                                                      • Opcode Fuzzy Hash: e4e6485ea78923ca57c49374cd6d20593ce76af1d9316686112e7f04db29334b
                                                      • Instruction Fuzzy Hash: 28035A74A012288FDB25EF35D854BACB7B2FB49308F1041E9D509AB399DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 2186 4844630-484467d 2193 4844683-48447d2 2186->2193 2194 484480d-4844821 2186->2194 2193->2194 2195 4844827-4844934 2194->2195 2196 484496f-4844983 2194->2196 2195->2196 2197 4844985-484498b call 4844210 2196->2197 2198 48449d6-48449ea 2196->2198 2204 4844990-484499b 2197->2204 2202 4844a32-4844a46 2198->2202 2203 48449ec-48449f7 2198->2203 2205 4844b94-4844ba8 2202->2205 2206 4844a4c-4844b51 2202->2206 2203->2202 2204->2198 2209 4844cd4-4844ce8 2205->2209 2210 4844bae-4844bc2 2205->2210 2424 4844b59 2206->2424 2212 4844f74-4844f88 2209->2212 2213 4844cee-4844f22 2209->2213 2215 4844bc4-4844bcb 2210->2215 2216 4844bd0-4844be4 2210->2216 2219 4844fe2-4844ff6 2212->2219 2220 4844f8a-4844f91 2212->2220 2688 4844f2d 2213->2688 2224 4844c48-4844c5c 2215->2224 2221 4844be6-4844bed 2216->2221 2222 4844bef-4844c03 2216->2222 2229 4845045-4845059 2219->2229 2230 4844ff8 2219->2230 2249 4844f9b 2220->2249 2221->2224 2227 4844c05-4844c0c 2222->2227 2228 4844c0e-4844c22 2222->2228 2231 4844c76-4844c82 2224->2231 2232 4844c5e-4844c74 2224->2232 2227->2224 2235 4844c24-4844c2b 2228->2235 2236 4844c2d-4844c41 2228->2236 2239 48450a2-48450b6 2229->2239 2240 484505b 2229->2240 2696 4844ff8 call 48474b0 2230->2696 2697 4844ff8 call 4847310 2230->2697 2698 4844ff8 call 4847461 2230->2698 2699 4844ff8 call af0606 2230->2699 2700 4844ff8 call af05e1 2230->2700 2238 4844c8d 2231->2238 2232->2238 2235->2224 2236->2224 2248 4844c43-4844c45 2236->2248 2238->2209 2245 484512d-4845141 2239->2245 2246 48450b8-48450e1 2239->2246 2240->2239 2242 4844ffe 2242->2229 2250 48453b4-48453c8 2245->2250 2251 4845147-4845363 2245->2251 2246->2245 2248->2224 2249->2219 2253 484549e-48454b2 2250->2253 2254 48453ce-4845457 2250->2254 2635 4845365 2251->2635 2636 4845367 2251->2636 2260 484566f-4845683 2253->2260 2261 48454b8-4845628 2253->2261 2254->2253 2268 48457e6-48457fa 2260->2268 2269 4845689-484579f 2260->2269 2261->2260 2272 4845800-4845916 2268->2272 2273 484595d-4845971 2268->2273 2269->2268 2272->2273 2278 4845ad4-4845ae8 2273->2278 2279 4845977-4845a8d 2273->2279 2283 4845aee-4845c04 2278->2283 2284 4845c4b-4845c5f 2278->2284 2279->2278 2283->2284 2291 4845c65-4845d7b 2284->2291 2292 4845dc2-4845dd6 2284->2292 2291->2292 2298 4845ddc-4845ef2 2292->2298 2299 4845f39-4845f4d 2292->2299 2298->2299 2306 48460b0-48460c4 2299->2306 2307 4845f53-4846069 2299->2307 2314 4846227-484623b 2306->2314 2315 48460ca-48461e0 2306->2315 2307->2306 2323 4846241-4846357 2314->2323 2324 484639e-48463b2 2314->2324 2315->2314 2323->2324 2338 4846536-484654a 2324->2338 2339 48463b8-48463fd call 4844278 2324->2339 2341 4846550-484656f 2338->2341 2342 484668d-48466a1 2338->2342 2465 48464bd-48464df 2339->2465 2375 4846614-4846636 2341->2375 2355 48466a7-48467a7 2342->2355 2356 48467ee-4846802 2342->2356 2355->2356 2371 484694f-4846963 2356->2371 2372 4846808-4846908 2356->2372 2381 4846ab0-4846ada 2371->2381 2382 4846969-4846a69 2371->2382 2372->2371 2388 4846574-4846583 2375->2388 2389 484663c 2375->2389 2402 4846ae0-4846b53 2381->2402 2403 4846b9a-4846bae 2381->2403 2382->2381 2409 484663e 2388->2409 2410 4846589-484658d 2388->2410 2389->2342 2402->2403 2417 4846bb4-4846c0b 2403->2417 2418 4846c8b-4846c9f 2403->2418 2431 4846643-484668b 2409->2431 2434 4846598-48465bc 2410->2434 2542 4846c12-4846c44 2417->2542 2422 4846de5-4846df9 2418->2422 2423 4846ca5-4846d9e 2418->2423 2436 484705c-4847070 2422->2436 2437 4846dff-4846e4f 2422->2437 2423->2422 2424->2205 2431->2342 2491 4846603-484660c 2434->2491 2492 48465be-48465f8 2434->2492 2459 4847076-4847111 call 4844278 * 2 2436->2459 2460 4847158-484715f 2436->2460 2550 4846e51-4846e77 2437->2550 2551 4846ebd-4846ee8 2437->2551 2459->2460 2484 48464e5 2465->2484 2485 4846402-4846411 2465->2485 2484->2338 2488 48464e7 2485->2488 2489 4846417-48464b5 2485->2489 2517 48464ec-4846534 2488->2517 2489->2517 2634 48464b7 2489->2634 2491->2431 2509 484660e 2491->2509 2492->2491 2509->2375 2517->2338 2542->2418 2629 4846eb8 2550->2629 2630 4846e79-4846e99 2550->2630 2627 4846fc6-4847057 2551->2627 2628 4846eee-4846fc1 2551->2628 2627->2436 2628->2436 2629->2436 2630->2629 2634->2465 2641 484536d 2635->2641 2636->2641 2701 4845367 call 48474e0 2636->2701 2702 4845367 call 484758e 2636->2702 2641->2250 2688->2212 2696->2242 2697->2242 2698->2242 2699->2242 2700->2242 2701->2641 2702->2641
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: b4b786cec745776b5ac97a160ac92ebbb969ddf087061485e1081a39daf98da8
                                                      • Instruction ID: a273c2ff694fa589c8507e2cb439c72db5604dd62ada9373fc997bd5922bea58
                                                      • Opcode Fuzzy Hash: b4b786cec745776b5ac97a160ac92ebbb969ddf087061485e1081a39daf98da8
                                                      • Instruction Fuzzy Hash: AE035A74A012288FDB25EF35D854BACB7B2FB49308F1041E9D509AB399DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 2703 484470f-4844821 2717 4844827-4844934 2703->2717 2718 484496f-4844983 2703->2718 2717->2718 2719 4844985-484498b call 4844210 2718->2719 2720 48449d6-48449ea 2718->2720 2725 4844990-484499b 2719->2725 2723 4844a32-4844a46 2720->2723 2724 48449ec-48449f7 2720->2724 2726 4844b94-4844ba8 2723->2726 2727 4844a4c-4844b51 2723->2727 2724->2723 2725->2720 2729 4844cd4-4844ce8 2726->2729 2730 4844bae-4844bc2 2726->2730 2933 4844b59 2727->2933 2732 4844f74-4844f88 2729->2732 2733 4844cee-4844f22 2729->2733 2735 4844bc4-4844bcb 2730->2735 2736 4844bd0-4844be4 2730->2736 2738 4844fe2-4844ff6 2732->2738 2739 4844f8a-4844f91 2732->2739 3197 4844f2d 2733->3197 2743 4844c48-4844c5c 2735->2743 2740 4844be6-4844bed 2736->2740 2741 4844bef-4844c03 2736->2741 2747 4845045-4845059 2738->2747 2748 4844ff8 2738->2748 2768 4844f9b 2739->2768 2740->2743 2745 4844c05-4844c0c 2741->2745 2746 4844c0e-4844c22 2741->2746 2749 4844c76-4844c82 2743->2749 2750 4844c5e-4844c74 2743->2750 2745->2743 2753 4844c24-4844c2b 2746->2753 2754 4844c2d-4844c41 2746->2754 2757 48450a2-48450b6 2747->2757 2758 484505b 2747->2758 3205 4844ff8 call 48474b0 2748->3205 3206 4844ff8 call 4847310 2748->3206 3207 4844ff8 call 4847461 2748->3207 3208 4844ff8 call af0606 2748->3208 3209 4844ff8 call af05e1 2748->3209 2756 4844c8d 2749->2756 2750->2756 2753->2743 2754->2743 2763 4844c43-4844c45 2754->2763 2756->2729 2760 484512d-4845141 2757->2760 2761 48450b8-48450e1 2757->2761 2758->2757 2766 48453b4-48453c8 2760->2766 2767 4845147-4845363 2760->2767 2761->2760 2763->2743 2764 4844ffe 2764->2747 2770 484549e-48454b2 2766->2770 2771 48453ce-4845457 2766->2771 3144 4845365 2767->3144 3145 4845367 2767->3145 2768->2738 2776 484566f-4845683 2770->2776 2777 48454b8-4845628 2770->2777 2771->2770 2782 48457e6-48457fa 2776->2782 2783 4845689-484579f 2776->2783 2777->2776 2787 4845800-4845916 2782->2787 2788 484595d-4845971 2782->2788 2783->2782 2787->2788 2790 4845ad4-4845ae8 2788->2790 2791 4845977-4845a8d 2788->2791 2797 4845aee-4845c04 2790->2797 2798 4845c4b-4845c5f 2790->2798 2791->2790 2797->2798 2807 4845c65-4845d7b 2798->2807 2808 4845dc2-4845dd6 2798->2808 2807->2808 2815 4845ddc-4845ef2 2808->2815 2816 4845f39-4845f4d 2808->2816 2815->2816 2818 48460b0-48460c4 2816->2818 2819 4845f53-4846069 2816->2819 2826 4846227-484623b 2818->2826 2827 48460ca-48461e0 2818->2827 2819->2818 2834 4846241-4846357 2826->2834 2835 484639e-48463b2 2826->2835 2827->2826 2834->2835 2848 4846536-484654a 2835->2848 2849 48463b8-48463fd call 4844278 2835->2849 2851 4846550-484656f 2848->2851 2852 484668d-48466a1 2848->2852 2974 48464bd-48464df 2849->2974 2884 4846614-4846636 2851->2884 2864 48466a7-48467a7 2852->2864 2865 48467ee-4846802 2852->2865 2864->2865 2880 484694f-4846963 2865->2880 2881 4846808-4846908 2865->2881 2890 4846ab0-4846ada 2880->2890 2891 4846969-4846a69 2880->2891 2881->2880 2897 4846574-4846583 2884->2897 2898 484663c 2884->2898 2911 4846ae0-4846b53 2890->2911 2912 4846b9a-4846bae 2890->2912 2891->2890 2918 484663e 2897->2918 2919 4846589-484658d 2897->2919 2898->2852 2911->2912 2926 4846bb4-4846c0b 2912->2926 2927 4846c8b-4846c9f 2912->2927 2940 4846643-484668b 2918->2940 2943 4846598-48465bc 2919->2943 3051 4846c12-4846c44 2926->3051 2931 4846de5-4846df9 2927->2931 2932 4846ca5-4846d9e 2927->2932 2945 484705c-4847070 2931->2945 2946 4846dff-4846e4f 2931->2946 2932->2931 2933->2726 2940->2852 3000 4846603-484660c 2943->3000 3001 48465be-48465f8 2943->3001 2968 4847076-4847111 call 4844278 * 2 2945->2968 2969 4847158-484715f 2945->2969 3059 4846e51-4846e77 2946->3059 3060 4846ebd-4846ee8 2946->3060 2968->2969 2993 48464e5 2974->2993 2994 4846402-4846411 2974->2994 2993->2848 2997 48464e7 2994->2997 2998 4846417-48464b5 2994->2998 3026 48464ec-4846534 2997->3026 2998->3026 3143 48464b7 2998->3143 3000->2940 3018 484660e 3000->3018 3001->3000 3018->2884 3026->2848 3051->2927 3138 4846eb8 3059->3138 3139 4846e79-4846e99 3059->3139 3136 4846fc6-4847057 3060->3136 3137 4846eee-4846fc1 3060->3137 3136->2945 3137->2945 3138->2945 3139->3138 3143->2974 3150 484536d 3144->3150 3145->3150 3210 4845367 call 48474e0 3145->3210 3211 4845367 call 484758e 3145->3211 3150->2766 3197->2732 3205->2764 3206->2764 3207->2764 3208->2764 3209->2764 3210->3150 3211->3150
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: c5f25e824538d234d840329f20af0d43bbe71f20c31f22092f056365dfecc4b8
                                                      • Instruction ID: dd14333161a9c21cd18e6c3d0255b3e6965a5c5ce5fca61de98297343538ee76
                                                      • Opcode Fuzzy Hash: c5f25e824538d234d840329f20af0d43bbe71f20c31f22092f056365dfecc4b8
                                                      • Instruction Fuzzy Hash: 9DF25B74A012288FDB25EF35D854BADB7B2FB49308F1041E9D509AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 3212 48447d4-4844821 3219 4844827-4844934 3212->3219 3220 484496f-4844983 3212->3220 3219->3220 3221 4844985-484498b call 4844210 3220->3221 3222 48449d6-48449ea 3220->3222 3227 4844990-484499b 3221->3227 3225 4844a32-4844a46 3222->3225 3226 48449ec-48449f7 3222->3226 3228 4844b94-4844ba8 3225->3228 3229 4844a4c-4844b51 3225->3229 3226->3225 3227->3222 3231 4844cd4-4844ce8 3228->3231 3232 4844bae-4844bc2 3228->3232 3435 4844b59 3229->3435 3234 4844f74-4844f88 3231->3234 3235 4844cee-4844f22 3231->3235 3237 4844bc4-4844bcb 3232->3237 3238 4844bd0-4844be4 3232->3238 3240 4844fe2-4844ff6 3234->3240 3241 4844f8a-4844f91 3234->3241 3699 4844f2d 3235->3699 3245 4844c48-4844c5c 3237->3245 3242 4844be6-4844bed 3238->3242 3243 4844bef-4844c03 3238->3243 3249 4845045-4845059 3240->3249 3250 4844ff8 3240->3250 3270 4844f9b 3241->3270 3242->3245 3247 4844c05-4844c0c 3243->3247 3248 4844c0e-4844c22 3243->3248 3251 4844c76-4844c82 3245->3251 3252 4844c5e-4844c74 3245->3252 3247->3245 3255 4844c24-4844c2b 3248->3255 3256 4844c2d-4844c41 3248->3256 3259 48450a2-48450b6 3249->3259 3260 484505b 3249->3260 3707 4844ff8 call 48474b0 3250->3707 3708 4844ff8 call 4847310 3250->3708 3709 4844ff8 call 4847461 3250->3709 3710 4844ff8 call af0606 3250->3710 3711 4844ff8 call af05e1 3250->3711 3258 4844c8d 3251->3258 3252->3258 3255->3245 3256->3245 3265 4844c43-4844c45 3256->3265 3258->3231 3262 484512d-4845141 3259->3262 3263 48450b8-48450e1 3259->3263 3260->3259 3268 48453b4-48453c8 3262->3268 3269 4845147-4845363 3262->3269 3263->3262 3265->3245 3266 4844ffe 3266->3249 3272 484549e-48454b2 3268->3272 3273 48453ce-4845457 3268->3273 3646 4845365 3269->3646 3647 4845367 3269->3647 3270->3240 3278 484566f-4845683 3272->3278 3279 48454b8-4845628 3272->3279 3273->3272 3284 48457e6-48457fa 3278->3284 3285 4845689-484579f 3278->3285 3279->3278 3289 4845800-4845916 3284->3289 3290 484595d-4845971 3284->3290 3285->3284 3289->3290 3292 4845ad4-4845ae8 3290->3292 3293 4845977-4845a8d 3290->3293 3299 4845aee-4845c04 3292->3299 3300 4845c4b-4845c5f 3292->3300 3293->3292 3299->3300 3309 4845c65-4845d7b 3300->3309 3310 4845dc2-4845dd6 3300->3310 3309->3310 3317 4845ddc-4845ef2 3310->3317 3318 4845f39-4845f4d 3310->3318 3317->3318 3320 48460b0-48460c4 3318->3320 3321 4845f53-4846069 3318->3321 3328 4846227-484623b 3320->3328 3329 48460ca-48461e0 3320->3329 3321->3320 3336 4846241-4846357 3328->3336 3337 484639e-48463b2 3328->3337 3329->3328 3336->3337 3350 4846536-484654a 3337->3350 3351 48463b8-48463fd call 4844278 3337->3351 3353 4846550-484656f 3350->3353 3354 484668d-48466a1 3350->3354 3476 48464bd-48464df 3351->3476 3386 4846614-4846636 3353->3386 3366 48466a7-48467a7 3354->3366 3367 48467ee-4846802 3354->3367 3366->3367 3382 484694f-4846963 3367->3382 3383 4846808-4846908 3367->3383 3392 4846ab0-4846ada 3382->3392 3393 4846969-4846a69 3382->3393 3383->3382 3399 4846574-4846583 3386->3399 3400 484663c 3386->3400 3413 4846ae0-4846b53 3392->3413 3414 4846b9a-4846bae 3392->3414 3393->3392 3420 484663e 3399->3420 3421 4846589-484658d 3399->3421 3400->3354 3413->3414 3428 4846bb4-4846c0b 3414->3428 3429 4846c8b-4846c9f 3414->3429 3442 4846643-484668b 3420->3442 3445 4846598-48465bc 3421->3445 3553 4846c12-4846c44 3428->3553 3433 4846de5-4846df9 3429->3433 3434 4846ca5-4846d9e 3429->3434 3447 484705c-4847070 3433->3447 3448 4846dff-4846e4f 3433->3448 3434->3433 3435->3228 3442->3354 3502 4846603-484660c 3445->3502 3503 48465be-48465f8 3445->3503 3470 4847076-4847111 call 4844278 * 2 3447->3470 3471 4847158-484715f 3447->3471 3561 4846e51-4846e77 3448->3561 3562 4846ebd-4846ee8 3448->3562 3470->3471 3495 48464e5 3476->3495 3496 4846402-4846411 3476->3496 3495->3350 3499 48464e7 3496->3499 3500 4846417-48464b5 3496->3500 3528 48464ec-4846534 3499->3528 3500->3528 3645 48464b7 3500->3645 3502->3442 3520 484660e 3502->3520 3503->3502 3520->3386 3528->3350 3553->3429 3640 4846eb8 3561->3640 3641 4846e79-4846e99 3561->3641 3638 4846fc6-4847057 3562->3638 3639 4846eee-4846fc1 3562->3639 3638->3447 3639->3447 3640->3447 3641->3640 3645->3476 3652 484536d 3646->3652 3647->3652 3712 4845367 call 48474e0 3647->3712 3713 4845367 call 484758e 3647->3713 3652->3268 3699->3234 3707->3266 3708->3266 3709->3266 3710->3266 3711->3266 3712->3652 3713->3652
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: 6f4b7ae993ccd4babdbc2e70cc867b4b45d82408b41a287531c44e95f51053c7
                                                      • Instruction ID: 13ed2d9cf2ec15561d45db3cc15731a66328e8f06725c8fa2f4e1d0a9f525f5b
                                                      • Opcode Fuzzy Hash: 6f4b7ae993ccd4babdbc2e70cc867b4b45d82408b41a287531c44e95f51053c7
                                                      • Instruction Fuzzy Hash: 1DF25B74A012288FDB25EF35D854BADB7B2FB49308F1041E9D509AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 3714 4844936-4844983 3721 4844985-484498b call 4844210 3714->3721 3722 48449d6-48449ea 3714->3722 3726 4844990-484499b 3721->3726 3724 4844a32-4844a46 3722->3724 3725 48449ec-48449f7 3722->3725 3727 4844b94-4844ba8 3724->3727 3728 4844a4c-4844b51 3724->3728 3725->3724 3726->3722 3729 4844cd4-4844ce8 3727->3729 3730 4844bae-4844bc2 3727->3730 3921 4844b59 3728->3921 3732 4844f74-4844f88 3729->3732 3733 4844cee-4844f22 3729->3733 3735 4844bc4-4844bcb 3730->3735 3736 4844bd0-4844be4 3730->3736 3738 4844fe2-4844ff6 3732->3738 3739 4844f8a-4844f91 3732->3739 4185 4844f2d 3733->4185 3742 4844c48-4844c5c 3735->3742 3740 4844be6-4844bed 3736->3740 3741 4844bef-4844c03 3736->3741 3746 4845045-4845059 3738->3746 3747 4844ff8 3738->3747 3766 4844f9b 3739->3766 3740->3742 3744 4844c05-4844c0c 3741->3744 3745 4844c0e-4844c22 3741->3745 3748 4844c76-4844c82 3742->3748 3749 4844c5e-4844c74 3742->3749 3744->3742 3752 4844c24-4844c2b 3745->3752 3753 4844c2d-4844c41 3745->3753 3755 48450a2-48450b6 3746->3755 3756 484505b 3746->3756 4195 4844ff8 call 48474b0 3747->4195 4196 4844ff8 call 4847310 3747->4196 4197 4844ff8 call 4847461 3747->4197 4198 4844ff8 call af0606 3747->4198 4199 4844ff8 call af05e1 3747->4199 3754 4844c8d 3748->3754 3749->3754 3752->3742 3753->3742 3761 4844c43-4844c45 3753->3761 3754->3729 3758 484512d-4845141 3755->3758 3759 48450b8-48450e1 3755->3759 3756->3755 3764 48453b4-48453c8 3758->3764 3765 4845147-4845363 3758->3765 3759->3758 3761->3742 3762 4844ffe 3762->3746 3767 484549e-48454b2 3764->3767 3768 48453ce-4845457 3764->3768 4132 4845365 3765->4132 4133 4845367 3765->4133 3766->3738 3772 484566f-4845683 3767->3772 3773 48454b8-4845628 3767->3773 3768->3767 3778 48457e6-48457fa 3772->3778 3779 4845689-484579f 3772->3779 3773->3772 3782 4845800-4845916 3778->3782 3783 484595d-4845971 3778->3783 3779->3778 3782->3783 3785 4845ad4-4845ae8 3783->3785 3786 4845977-4845a8d 3783->3786 3792 4845aee-4845c04 3785->3792 3793 4845c4b-4845c5f 3785->3793 3786->3785 3792->3793 3801 4845c65-4845d7b 3793->3801 3802 4845dc2-4845dd6 3793->3802 3801->3802 3808 4845ddc-4845ef2 3802->3808 3809 4845f39-4845f4d 3802->3809 3808->3809 3814 48460b0-48460c4 3809->3814 3815 4845f53-4846069 3809->3815 3819 4846227-484623b 3814->3819 3820 48460ca-48461e0 3814->3820 3815->3814 3826 4846241-4846357 3819->3826 3827 484639e-48463b2 3819->3827 3820->3819 3826->3827 3839 4846536-484654a 3827->3839 3840 48463b8-48463fd call 4844278 3827->3840 3842 4846550-484656f 3839->3842 3843 484668d-48466a1 3839->3843 3962 48464bd-48464df 3840->3962 3873 4846614-4846636 3842->3873 3855 48466a7-48467a7 3843->3855 3856 48467ee-4846802 3843->3856 3855->3856 3870 484694f-4846963 3856->3870 3871 4846808-4846908 3856->3871 3879 4846ab0-4846ada 3870->3879 3880 4846969-4846a69 3870->3880 3871->3870 3886 4846574-4846583 3873->3886 3887 484663c 3873->3887 3899 4846ae0-4846b53 3879->3899 3900 4846b9a-4846bae 3879->3900 3880->3879 3906 484663e 3886->3906 3907 4846589-484658d 3886->3907 3887->3843 3899->3900 3914 4846bb4-4846c0b 3900->3914 3915 4846c8b-4846c9f 3900->3915 3928 4846643-484668b 3906->3928 3931 4846598-48465bc 3907->3931 4039 4846c12-4846c44 3914->4039 3919 4846de5-4846df9 3915->3919 3920 4846ca5-4846d9e 3915->3920 3933 484705c-4847070 3919->3933 3934 4846dff-4846e4f 3919->3934 3920->3919 3921->3727 3928->3843 3988 4846603-484660c 3931->3988 3989 48465be-48465f8 3931->3989 3956 4847076-4847111 call 4844278 * 2 3933->3956 3957 4847158-484715f 3933->3957 4047 4846e51-4846e77 3934->4047 4048 4846ebd-4846ee8 3934->4048 3956->3957 3981 48464e5 3962->3981 3982 4846402-4846411 3962->3982 3981->3839 3985 48464e7 3982->3985 3986 4846417-48464b5 3982->3986 4014 48464ec-4846534 3985->4014 3986->4014 4131 48464b7 3986->4131 3988->3928 4006 484660e 3988->4006 3989->3988 4006->3873 4014->3839 4039->3915 4126 4846eb8 4047->4126 4127 4846e79-4846e99 4047->4127 4124 4846fc6-4847057 4048->4124 4125 4846eee-4846fc1 4048->4125 4124->3933 4125->3933 4126->3933 4127->4126 4131->3962 4138 484536d 4132->4138 4133->4138 4193 4845367 call 48474e0 4133->4193 4194 4845367 call 484758e 4133->4194 4138->3764 4185->3732 4193->4138 4194->4138 4195->3762 4196->3762 4197->3762 4198->3762 4199->3762
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: c8be73d3524b2c18e95341ef29e34e4722e97b3edeab29ddfa2d5e6837ef8fee
                                                      • Instruction ID: 782ac4532cebfb38f5318b599465c4ad7e5da96c90641de39da10dd039fad408
                                                      • Opcode Fuzzy Hash: c8be73d3524b2c18e95341ef29e34e4722e97b3edeab29ddfa2d5e6837ef8fee
                                                      • Instruction Fuzzy Hash: 62F26A74A01228CFDB25EF35D854BADB7B2BB49308F1041E9D509AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 4200 484499d-48449ea 4207 4844a32-4844a46 4200->4207 4208 48449ec-48449f7 4200->4208 4209 4844b94-4844ba8 4207->4209 4210 4844a4c-4844b51 4207->4210 4208->4207 4211 4844cd4-4844ce8 4209->4211 4212 4844bae-4844bc2 4209->4212 4402 4844b59 4210->4402 4214 4844f74-4844f88 4211->4214 4215 4844cee-4844f22 4211->4215 4216 4844bc4-4844bcb 4212->4216 4217 4844bd0-4844be4 4212->4217 4219 4844fe2-4844ff6 4214->4219 4220 4844f8a-4844f91 4214->4220 4666 4844f2d 4215->4666 4223 4844c48-4844c5c 4216->4223 4221 4844be6-4844bed 4217->4221 4222 4844bef-4844c03 4217->4222 4227 4845045-4845059 4219->4227 4228 4844ff8 4219->4228 4247 4844f9b 4220->4247 4221->4223 4225 4844c05-4844c0c 4222->4225 4226 4844c0e-4844c22 4222->4226 4229 4844c76-4844c82 4223->4229 4230 4844c5e-4844c74 4223->4230 4225->4223 4233 4844c24-4844c2b 4226->4233 4234 4844c2d-4844c41 4226->4234 4236 48450a2-48450b6 4227->4236 4237 484505b 4227->4237 4674 4844ff8 call 48474b0 4228->4674 4675 4844ff8 call 4847310 4228->4675 4676 4844ff8 call 4847461 4228->4676 4677 4844ff8 call af0606 4228->4677 4678 4844ff8 call af05e1 4228->4678 4235 4844c8d 4229->4235 4230->4235 4233->4223 4234->4223 4242 4844c43-4844c45 4234->4242 4235->4211 4239 484512d-4845141 4236->4239 4240 48450b8-48450e1 4236->4240 4237->4236 4245 48453b4-48453c8 4239->4245 4246 4845147-4845363 4239->4246 4240->4239 4242->4223 4243 4844ffe 4243->4227 4248 484549e-48454b2 4245->4248 4249 48453ce-4845457 4245->4249 4613 4845365 4246->4613 4614 4845367 4246->4614 4247->4219 4253 484566f-4845683 4248->4253 4254 48454b8-4845628 4248->4254 4249->4248 4259 48457e6-48457fa 4253->4259 4260 4845689-484579f 4253->4260 4254->4253 4263 4845800-4845916 4259->4263 4264 484595d-4845971 4259->4264 4260->4259 4263->4264 4266 4845ad4-4845ae8 4264->4266 4267 4845977-4845a8d 4264->4267 4273 4845aee-4845c04 4266->4273 4274 4845c4b-4845c5f 4266->4274 4267->4266 4273->4274 4282 4845c65-4845d7b 4274->4282 4283 4845dc2-4845dd6 4274->4283 4282->4283 4289 4845ddc-4845ef2 4283->4289 4290 4845f39-4845f4d 4283->4290 4289->4290 4295 48460b0-48460c4 4290->4295 4296 4845f53-4846069 4290->4296 4300 4846227-484623b 4295->4300 4301 48460ca-48461e0 4295->4301 4296->4295 4307 4846241-4846357 4300->4307 4308 484639e-48463b2 4300->4308 4301->4300 4307->4308 4320 4846536-484654a 4308->4320 4321 48463b8-48463fd call 4844278 4308->4321 4323 4846550-484656f 4320->4323 4324 484668d-48466a1 4320->4324 4443 48464bd-48464df 4321->4443 4354 4846614-4846636 4323->4354 4336 48466a7-48467a7 4324->4336 4337 48467ee-4846802 4324->4337 4336->4337 4351 484694f-4846963 4337->4351 4352 4846808-4846908 4337->4352 4360 4846ab0-4846ada 4351->4360 4361 4846969-4846a69 4351->4361 4352->4351 4367 4846574-4846583 4354->4367 4368 484663c 4354->4368 4380 4846ae0-4846b53 4360->4380 4381 4846b9a-4846bae 4360->4381 4361->4360 4387 484663e 4367->4387 4388 4846589-484658d 4367->4388 4368->4324 4380->4381 4395 4846bb4-4846c0b 4381->4395 4396 4846c8b-4846c9f 4381->4396 4409 4846643-484668b 4387->4409 4412 4846598-48465bc 4388->4412 4520 4846c12-4846c44 4395->4520 4400 4846de5-4846df9 4396->4400 4401 4846ca5-4846d9e 4396->4401 4414 484705c-4847070 4400->4414 4415 4846dff-4846e4f 4400->4415 4401->4400 4402->4209 4409->4324 4469 4846603-484660c 4412->4469 4470 48465be-48465f8 4412->4470 4437 4847076-4847111 call 4844278 * 2 4414->4437 4438 4847158-484715f 4414->4438 4528 4846e51-4846e77 4415->4528 4529 4846ebd-4846ee8 4415->4529 4437->4438 4462 48464e5 4443->4462 4463 4846402-4846411 4443->4463 4462->4320 4466 48464e7 4463->4466 4467 4846417-48464b5 4463->4467 4495 48464ec-4846534 4466->4495 4467->4495 4612 48464b7 4467->4612 4469->4409 4487 484660e 4469->4487 4470->4469 4487->4354 4495->4320 4520->4396 4607 4846eb8 4528->4607 4608 4846e79-4846e99 4528->4608 4605 4846fc6-4847057 4529->4605 4606 4846eee-4846fc1 4529->4606 4605->4414 4606->4414 4607->4414 4608->4607 4612->4443 4619 484536d 4613->4619 4614->4619 4679 4845367 call 48474e0 4614->4679 4680 4845367 call 484758e 4614->4680 4619->4245 4666->4214 4674->4243 4675->4243 4676->4243 4677->4243 4678->4243 4679->4619 4680->4619
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: f4f5ecc2be7c16cfa158c2289071b22f593562876583163cb8beeadfdc359149
                                                      • Instruction ID: 0a3f78e75b4ecee285daef6a788eb589eeeba61ed814568caf49cb2d993f64fc
                                                      • Opcode Fuzzy Hash: f4f5ecc2be7c16cfa158c2289071b22f593562876583163cb8beeadfdc359149
                                                      • Instruction Fuzzy Hash: 27F25A74A01228CFDB25EF35D854BADB7B2BB49308F1041E9D509AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Control-flow Graph

                                                      • Executed
                                                      • Not Executed
                                                      control_flow_graph 4681 48449f9-4844a46 4688 4844b94-4844ba8 4681->4688 4689 4844a4c-4844b51 4681->4689 4690 4844cd4-4844ce8 4688->4690 4691 4844bae-4844bc2 4688->4691 4880 4844b59 4689->4880 4692 4844f74-4844f88 4690->4692 4693 4844cee-4844f22 4690->4693 4694 4844bc4-4844bcb 4691->4694 4695 4844bd0-4844be4 4691->4695 4697 4844fe2-4844ff6 4692->4697 4698 4844f8a-4844f91 4692->4698 5144 4844f2d 4693->5144 4701 4844c48-4844c5c 4694->4701 4699 4844be6-4844bed 4695->4699 4700 4844bef-4844c03 4695->4700 4705 4845045-4845059 4697->4705 4706 4844ff8 4697->4706 4725 4844f9b 4698->4725 4699->4701 4703 4844c05-4844c0c 4700->4703 4704 4844c0e-4844c22 4700->4704 4707 4844c76-4844c82 4701->4707 4708 4844c5e-4844c74 4701->4708 4703->4701 4711 4844c24-4844c2b 4704->4711 4712 4844c2d-4844c41 4704->4712 4714 48450a2-48450b6 4705->4714 4715 484505b 4705->4715 5154 4844ff8 call 48474b0 4706->5154 5155 4844ff8 call 4847310 4706->5155 5156 4844ff8 call 4847461 4706->5156 5157 4844ff8 call af0606 4706->5157 5158 4844ff8 call af05e1 4706->5158 4713 4844c8d 4707->4713 4708->4713 4711->4701 4712->4701 4720 4844c43-4844c45 4712->4720 4713->4690 4717 484512d-4845141 4714->4717 4718 48450b8-48450e1 4714->4718 4715->4714 4723 48453b4-48453c8 4717->4723 4724 4845147-4845363 4717->4724 4718->4717 4720->4701 4721 4844ffe 4721->4705 4726 484549e-48454b2 4723->4726 4727 48453ce-4845457 4723->4727 5091 4845365 4724->5091 5092 4845367 4724->5092 4725->4697 4731 484566f-4845683 4726->4731 4732 48454b8-4845628 4726->4732 4727->4726 4737 48457e6-48457fa 4731->4737 4738 4845689-484579f 4731->4738 4732->4731 4741 4845800-4845916 4737->4741 4742 484595d-4845971 4737->4742 4738->4737 4741->4742 4744 4845ad4-4845ae8 4742->4744 4745 4845977-4845a8d 4742->4745 4751 4845aee-4845c04 4744->4751 4752 4845c4b-4845c5f 4744->4752 4745->4744 4751->4752 4760 4845c65-4845d7b 4752->4760 4761 4845dc2-4845dd6 4752->4761 4760->4761 4767 4845ddc-4845ef2 4761->4767 4768 4845f39-4845f4d 4761->4768 4767->4768 4773 48460b0-48460c4 4768->4773 4774 4845f53-4846069 4768->4774 4778 4846227-484623b 4773->4778 4779 48460ca-48461e0 4773->4779 4774->4773 4785 4846241-4846357 4778->4785 4786 484639e-48463b2 4778->4786 4779->4778 4785->4786 4798 4846536-484654a 4786->4798 4799 48463b8-48463fd call 4844278 4786->4799 4801 4846550-484656f 4798->4801 4802 484668d-48466a1 4798->4802 4921 48464bd-48464df 4799->4921 4832 4846614-4846636 4801->4832 4814 48466a7-48467a7 4802->4814 4815 48467ee-4846802 4802->4815 4814->4815 4829 484694f-4846963 4815->4829 4830 4846808-4846908 4815->4830 4838 4846ab0-4846ada 4829->4838 4839 4846969-4846a69 4829->4839 4830->4829 4845 4846574-4846583 4832->4845 4846 484663c 4832->4846 4858 4846ae0-4846b53 4838->4858 4859 4846b9a-4846bae 4838->4859 4839->4838 4865 484663e 4845->4865 4866 4846589-484658d 4845->4866 4846->4802 4858->4859 4873 4846bb4-4846c0b 4859->4873 4874 4846c8b-4846c9f 4859->4874 4887 4846643-484668b 4865->4887 4890 4846598-48465bc 4866->4890 4998 4846c12-4846c44 4873->4998 4878 4846de5-4846df9 4874->4878 4879 4846ca5-4846d9e 4874->4879 4892 484705c-4847070 4878->4892 4893 4846dff-4846e4f 4878->4893 4879->4878 4880->4688 4887->4802 4947 4846603-484660c 4890->4947 4948 48465be-48465f8 4890->4948 4915 4847076-4847111 call 4844278 * 2 4892->4915 4916 4847158-484715f 4892->4916 5006 4846e51-4846e77 4893->5006 5007 4846ebd-4846ee8 4893->5007 4915->4916 4940 48464e5 4921->4940 4941 4846402-4846411 4921->4941 4940->4798 4944 48464e7 4941->4944 4945 4846417-48464b5 4941->4945 4973 48464ec-4846534 4944->4973 4945->4973 5090 48464b7 4945->5090 4947->4887 4965 484660e 4947->4965 4948->4947 4965->4832 4973->4798 4998->4874 5085 4846eb8 5006->5085 5086 4846e79-4846e99 5006->5086 5083 4846fc6-4847057 5007->5083 5084 4846eee-4846fc1 5007->5084 5083->4892 5084->4892 5085->4892 5086->5085 5090->4921 5097 484536d 5091->5097 5092->5097 5152 4845367 call 48474e0 5092->5152 5153 4845367 call 484758e 5092->5153 5097->4723 5144->4692 5152->5097 5153->5097 5154->4721 5155->4721 5156->4721 5157->4721 5158->4721
                                                      Strings
                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID: 0-3916222277
                                                      • Opcode ID: 5eafca959e50c9703621d237607efc10930289e407cfeebc66715b427d8adfc4
                                                      • Instruction ID: e46ed8a28d2e5bca2b2f0485cc14b3c089ddbeeb7b6b9ca68f30aee99352f8ae
                                                      • Opcode Fuzzy Hash: 5eafca959e50c9703621d237607efc10930289e407cfeebc66715b427d8adfc4
                                                      • Instruction Fuzzy Hash: 07F25A74A012288FDB25EF35D854BADB7B2BB49308F1041E9D509AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3f39f19d75d0738cbb43132854a38ba32da6e8ab227fc679d9ba30e1e7d89eca
                                                      • Instruction ID: 458bb0fb76e15ccd1d44ecb7644df23d540aa780981a61d5f432ae1568c0580a
                                                      • Opcode Fuzzy Hash: 3f39f19d75d0738cbb43132854a38ba32da6e8ab227fc679d9ba30e1e7d89eca
                                                      • Instruction Fuzzy Hash: 13E25B74A012288FDB25EF35D850BADB7B2FB49304F1041E9D509AB399DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3861bb510c758ee09a308aa5fc9abcb9cc51b58e84cc394ae27329fa44c45aa7
                                                      • Instruction ID: 8ef124dce5f87338b332435a4f84ac81efb2b4679992c2bc15289674b1c33289
                                                      • Opcode Fuzzy Hash: 3861bb510c758ee09a308aa5fc9abcb9cc51b58e84cc394ae27329fa44c45aa7
                                                      • Instruction Fuzzy Hash: 9CD26B74A01228CFDB25EF35D854BADB7B2BB49304F1041E9D909AB398DB355E85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: c53d76e1a90fa839f1d369c52c7dbfea26074bef2a42f04b2aa6e941cb99a7c5
                                                      • Instruction ID: bd19b712788c8c8e89fe916137adacde81097fd116a9a4151dbfe83413485073
                                                      • Opcode Fuzzy Hash: c53d76e1a90fa839f1d369c52c7dbfea26074bef2a42f04b2aa6e941cb99a7c5
                                                      • Instruction Fuzzy Hash: 15D25B74A01228CFDB25EF35D854BADB7B2BB49304F1041E9D909AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 281c2e4e33732f5779a9fb547969307612b637a1d57a535cb6dbab9c719fa844
                                                      • Instruction ID: 5e5d92774f94c4bed55432ef501e58ba7a3f3f12865e619e1f734736d24230c8
                                                      • Opcode Fuzzy Hash: 281c2e4e33732f5779a9fb547969307612b637a1d57a535cb6dbab9c719fa844
                                                      • Instruction Fuzzy Hash: 59D25A74A012288FDB25EF35D854BADB7B2BB49304F1041E9D909AB398DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: ef98a5f1b7556bd38d05e0a33e47cbe381c2ec7c3a94bd1f5395c70ed6788556
                                                      • Instruction ID: 1b8f927b7d72493b66d8dfb6d846cf94ea4e003a4c277d3e9f193a26731744bb
                                                      • Opcode Fuzzy Hash: ef98a5f1b7556bd38d05e0a33e47cbe381c2ec7c3a94bd1f5395c70ed6788556
                                                      • Instruction Fuzzy Hash: B0D25A74A012288FDB25EF35D850BADB7B2FB49304F1041E9D909AB399DB355E89DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 53e4e7bdc123157172fdd339e0794bbea9c53671cc97d233a83a479dd6d10901
                                                      • Instruction ID: 813301ef0fa8c67ba43ca873f0170c9624fb0be14e386f6f8ac1cd8876d9cb15
                                                      • Opcode Fuzzy Hash: 53e4e7bdc123157172fdd339e0794bbea9c53671cc97d233a83a479dd6d10901
                                                      • Instruction Fuzzy Hash: 2D0226325052669BDB2A9F329850479B3A2BFC03953458B3AD461DB3D8EF2EFC41D790
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 3e24c9a188ec5521b930e51a718103bf7a471839b8faefce9bf8fa3ae7da016f
                                                      • Instruction ID: 2501d41cdd39f649216332e1ee334a9ae0e99c9bbc4fb240e21d1c4fff7b82d8
                                                      • Opcode Fuzzy Hash: 3e24c9a188ec5521b930e51a718103bf7a471839b8faefce9bf8fa3ae7da016f
                                                      • Instruction Fuzzy Hash: 8FC13B316053A68BD722EB33A85043577A37FC01963458A77E490CF2D9EF28ED85E7A0
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: b469ca3a033b4a52359c2e38ee08386a941ed286c506a9e9e4a76f988ee2fa83
                                                      • Instruction ID: 52deec38523dcbe5ac17b590a07f1f4801de96fe932ee9ba9695b7703dbc41f8
                                                      • Opcode Fuzzy Hash: b469ca3a033b4a52359c2e38ee08386a941ed286c506a9e9e4a76f988ee2fa83
                                                      • Instruction Fuzzy Hash: 78C29074B04258CFDB21AB3AD9107AD77B2AB89304F0085679805DBB9CDF749D98EF60
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 47162514b693aa0bec52d96a4a3c615cb66b5941cbdaea1c24aff42daf5fc6bb
                                                      • Instruction ID: 08e317aaf6e7390569e6beb385c8a58435fad62bb10896719b7eff60dda62801
                                                      • Opcode Fuzzy Hash: 47162514b693aa0bec52d96a4a3c615cb66b5941cbdaea1c24aff42daf5fc6bb
                                                      • Instruction Fuzzy Hash: E692D234B042688BDF25AB3ADC107BD77A6AB88308F0049679445D7B9CDF749D98EF60
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d4fa9a6dbeda909220a7f40ed1f4437d41efd8a38b47084ffec37d0ff52dcf55
                                                      • Instruction ID: 5cee2c216a6107bda8142e855971e162d0aab42954f687395d21ad86921a8c96
                                                      • Opcode Fuzzy Hash: d4fa9a6dbeda909220a7f40ed1f4437d41efd8a38b47084ffec37d0ff52dcf55
                                                      • Instruction Fuzzy Hash: 0F92C134B042688BDF21AB3ADC107BD77A6AB88308F0048679405D7B9CDF749D98EF60
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a9bcc6733c62277d18bb806a796e8ac11a50972eb4fa735727359242e668c930
                                                      • Instruction ID: 2f8b384ecd9be0686e950a7e1c120ca19d40db3e468ac67282c1a98f9eb8e62e
                                                      • Opcode Fuzzy Hash: a9bcc6733c62277d18bb806a796e8ac11a50972eb4fa735727359242e668c930
                                                      • Instruction Fuzzy Hash: E8B21974A01228CFDB25EF34D854BA9B7B2FB49304F1051E9D909AB398DB356E85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f1963cfa7ac4786153024aed0e57475fcf0c09c0aa154c96212544757b45c00f
                                                      • Instruction ID: a1e28eccceee2408f0276a5dee3146101fe55c58e3deacf72ae39d73ddd3f846
                                                      • Opcode Fuzzy Hash: f1963cfa7ac4786153024aed0e57475fcf0c09c0aa154c96212544757b45c00f
                                                      • Instruction Fuzzy Hash: 28A22874A01228CFDB25EF34D854BA9B7B2FB49304F1051E9D909AB398DB356E85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2a1b1e54fd222f26de2d7b3656b931a97491f6a52a20251c519624a04348553f
                                                      • Instruction ID: aa6a36db307429fd8f1be031a3011a516ad391c829a52578900086cbabef0767
                                                      • Opcode Fuzzy Hash: 2a1b1e54fd222f26de2d7b3656b931a97491f6a52a20251c519624a04348553f
                                                      • Instruction Fuzzy Hash: 48922974A01228CFDB25EF34D854BA9B7B2FB49304F1051E9D909AB398DB356E85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 174cfd1a7c09164d627f9c214d41e1af4239e378368f592899044a19339efe1b
                                                      • Instruction ID: d39c68d993555c36ad702f1f0ccb1a8b0ce128dc8e07ae30aac3e3175583bf78
                                                      • Opcode Fuzzy Hash: 174cfd1a7c09164d627f9c214d41e1af4239e378368f592899044a19339efe1b
                                                      • Instruction Fuzzy Hash: C5922B74A01228CFDB25EF34D854BA8B7B2FB49304F1051E9D509AB398DB35AE85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 37a2eba7c53829ea1e63c1b03f807545dbe89f2f2dccc9e7671353b502696608
                                                      • Instruction ID: b89cf639f5003a028b4a4b0e3a3f593ac57e9923811bc0176252e307d489b885
                                                      • Opcode Fuzzy Hash: 37a2eba7c53829ea1e63c1b03f807545dbe89f2f2dccc9e7671353b502696608
                                                      • Instruction Fuzzy Hash: D3823D74A01228CFDB25EF34D854BA8B7B6FB49304F1051E9D509AB398DB35AE85DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2774ea1110b360ac592c9b2889fa479547dae5a18c0d36473e03c7661f95d9f7
                                                      • Instruction ID: 9acf3ca388fafce7059a723f4c622b73f265db28cf4be00dd4020e8c4fe69879
                                                      • Opcode Fuzzy Hash: 2774ea1110b360ac592c9b2889fa479547dae5a18c0d36473e03c7661f95d9f7
                                                      • Instruction Fuzzy Hash: 52623C74A01228CFDB25EF34D854BA8B7B6FB49304F1051E9D909AB398DB35AE85DF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: f4d1ebf8aec9bc6c4ff082e6d98c79474aaf528adced485b7b475bce1d23a8f3
                                                      • Instruction ID: 75301d545b776fe15cb45364407f9c6797a8acb8df514335cdb790a957d0429c
                                                      • Opcode Fuzzy Hash: f4d1ebf8aec9bc6c4ff082e6d98c79474aaf528adced485b7b475bce1d23a8f3
                                                      • Instruction Fuzzy Hash: 59422E74A01228CFDB25EF34D854BA8B7B5FB49304F1085E9D909AB398DB35AE85DF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: e44f121d5d724124270a6a48d798f7569770073fd5ab9eabeda5cb1632c5c576
                                                      • Instruction ID: ec10e6c8be19d2c70236fc18c1fe87161841ba60119c4f94dffecc766dcee48c
                                                      • Opcode Fuzzy Hash: e44f121d5d724124270a6a48d798f7569770073fd5ab9eabeda5cb1632c5c576
                                                      • Instruction Fuzzy Hash: 1B323B30A01218CFDB25EF74D855BEDB7B2BB89308F1045A9D409AB399DB395E85CF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 98ebac44fd191a5998c79d3474500afb48ad371d0d76a40eb3addb552a81e39e
                                                      • Instruction ID: 5000519de4f3e64dc2cd5595ebb8dd2315db96a62e1be3c716d27564213074c1
                                                      • Opcode Fuzzy Hash: 98ebac44fd191a5998c79d3474500afb48ad371d0d76a40eb3addb552a81e39e
                                                      • Instruction Fuzzy Hash: 9F223D74A01228CFDB25DF34D854BA8B7B5FB49304F1085EAD909AB398DB35AE84DF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: e9295b37eafb58504c38beda7bf80cbb701ccc38b5aa5069f9c97c8d6069ed21
                                                      • Instruction ID: a26c0eaa41e5bfb51515c17f79ea21b02ff342a4116a98e42da12952978b389e
                                                      • Opcode Fuzzy Hash: e9295b37eafb58504c38beda7bf80cbb701ccc38b5aa5069f9c97c8d6069ed21
                                                      • Instruction Fuzzy Hash: 27023C74A01218CFDB25EF34D854BACB7B6BB49304F5045EAD909AB398DB359E85CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a519db181757d921f543b264eadbdc6dd1a64fcc935f0eff3a395d4285ba3588
                                                      • Instruction ID: 231466c643482767a9241a628bbcf9bdcad7f42a5ef83210f7ba77b5ae9677da
                                                      • Opcode Fuzzy Hash: a519db181757d921f543b264eadbdc6dd1a64fcc935f0eff3a395d4285ba3588
                                                      • Instruction Fuzzy Hash: 30D13170F00208DFCB19EFB5E45156E77B6AF88248B608529E4119B3ACDF39AC49DB90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5aba7cfee41cfc1f6e8bdcc45a36d2addb9516ac766989a8c6f1fd8bb64e012b
                                                      • Instruction ID: 6290e528231c2b9b523b978c68af4846419ee770020e933ba02239e46eefec7e
                                                      • Opcode Fuzzy Hash: 5aba7cfee41cfc1f6e8bdcc45a36d2addb9516ac766989a8c6f1fd8bb64e012b
                                                      • Instruction Fuzzy Hash: 98D13E74A01228CFDB25EF34D854BADB7B1BB89308F5045EAD509AB394DB399E85CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 6f84419b1642fe7a17749fffcb73c0407319dacc9147400b1653e0eab46d5268
                                                      • Instruction ID: a8604c50dec5c2f4ada6b334072d4623157febc9d9846a2ff9bdaed23c2f2893
                                                      • Opcode Fuzzy Hash: 6f84419b1642fe7a17749fffcb73c0407319dacc9147400b1653e0eab46d5268
                                                      • Instruction Fuzzy Hash: 2EA15F70B00204DFCB19EF75E851A5E77B6AF88348B608529E4119B3ACDF39AC59DF90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 24cf70a45332404bc960f592947284f90b7f0f6154163e8622e63c72f99064d9
                                                      • Instruction ID: cb16edb40780060f400cbfeefd654a3e1e94e775b193ac91c4c96a204c368444
                                                      • Opcode Fuzzy Hash: 24cf70a45332404bc960f592947284f90b7f0f6154163e8622e63c72f99064d9
                                                      • Instruction Fuzzy Hash: 34913F34B00208DFCB19EFB5E451A6D77B2AF88348B608529E4119B7ACDF39AC55DF90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: e4dbfba677cbd6bad21f23e5c1b207fa313984aa269b9fae5195600eea4aa0e7
                                                      • Instruction ID: 38bccde7df095975882fa77f8acb42846c69e4e9f94612d177d073b30b78862e
                                                      • Opcode Fuzzy Hash: e4dbfba677cbd6bad21f23e5c1b207fa313984aa269b9fae5195600eea4aa0e7
                                                      • Instruction Fuzzy Hash: 99914E34B00204DFCB19EFB5E451A6D73B2AF88348B608529E4119B7ACDF39AC59DF90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 984f3b626185dbcdd729fdab1dd90d6a14260764946d874cb93b96d948a75419
                                                      • Instruction ID: 87c3976aa08fb1c99205195bf8fd8046673bce167b38e3c7df9bfa694fb430f0
                                                      • Opcode Fuzzy Hash: 984f3b626185dbcdd729fdab1dd90d6a14260764946d874cb93b96d948a75419
                                                      • Instruction Fuzzy Hash: D8913E70A012288FDB25EF35D855BAD73B2AF85308F5046ED9509AB394DF396E85CF40
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: df62237eacfc5c86f7c60a0f22489d3c397ee0350dbb65a5484acec1a48d998f
                                                      • Instruction ID: 10fb707e9ddc2c4f6b7038b4bdda0c8dd7e5434cf3b63d6bed3e366b2e7b8594
                                                      • Opcode Fuzzy Hash: df62237eacfc5c86f7c60a0f22489d3c397ee0350dbb65a5484acec1a48d998f
                                                      • Instruction Fuzzy Hash: 0AA1F334A01228CFCB25EF75D950BACB7B2BB49308F1045A9D809AB359DB359E85CF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: b114d3505fff0ab0e79439393bf2bd88b5bde16885c3e28a45a6b5acdaa2cc0a
                                                      • Instruction ID: 07625c5d63b3bde001ba5a3e6e2f72fa992c05dea5e5360b03d70ded8d482bcd
                                                      • Opcode Fuzzy Hash: b114d3505fff0ab0e79439393bf2bd88b5bde16885c3e28a45a6b5acdaa2cc0a
                                                      • Instruction Fuzzy Hash: D5714F34B01204DFCB19EF75E45166D73B6AF88348B608529E8119B7ACDF39AC59DF80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 78c56c5e5f528f466e25b3ae8e01508b7dbb64c4593cb38bc4e5cd149c735de9
                                                      • Instruction ID: b09ccc06fcb23dbec2cebdf2dac978e15edeb500e441ae73e17e0975c3ecf725
                                                      • Opcode Fuzzy Hash: 78c56c5e5f528f466e25b3ae8e01508b7dbb64c4593cb38bc4e5cd149c735de9
                                                      • Instruction Fuzzy Hash: 95814C30A01218CFDB24EFB4C855BADB7F2AF85308F5045A9D50AAB398DB795D88CF51
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: bf56da188a5b65441d18b702c95f7f7e737ea18ec344765847116b2ec99bc88b
                                                      • Instruction ID: 11e53c050d02d91b63a8651987b544309aa555c16c09ac9db756815925c1698a
                                                      • Opcode Fuzzy Hash: bf56da188a5b65441d18b702c95f7f7e737ea18ec344765847116b2ec99bc88b
                                                      • Instruction Fuzzy Hash: 50518430B00214DFCB19EF75E85166E73A6EF84358F208529E8119B7ACDF38AC55DB90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a0bbb86d200b6ef6993149ec1cbbfb62185eabfd9b9e2e5a49f8c14d4a6f8d49
                                                      • Instruction ID: 004c615da964836bb1fe6a6b7bfa929a6d30968725ecfbf347e10b790248902b
                                                      • Opcode Fuzzy Hash: a0bbb86d200b6ef6993149ec1cbbfb62185eabfd9b9e2e5a49f8c14d4a6f8d49
                                                      • Instruction Fuzzy Hash: 0551E2307002448FCB06EB78D454ABD7BF2AF89208B2485ADD405DF39ADF399C4ACB91
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a2701c98655b9f590c3c1744d2420decfaa9de5416d92f4a10d550fac0842ee5
                                                      • Instruction ID: 290f15588ec1cf6b9c5476728d268f2f51a99814b02dec0efedef02dcd62f24c
                                                      • Opcode Fuzzy Hash: a2701c98655b9f590c3c1744d2420decfaa9de5416d92f4a10d550fac0842ee5
                                                      • Instruction Fuzzy Hash: 7F41E7317043098FD724EF36D8017B933E2AB85355F584A69D411DB2D9EF38EA49DB60
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: bc2560622dd12dc061e682349bbab48d723059ee61b589259f67d66aa03a0f62
                                                      • Instruction ID: a59bc04d89de0462721105a587973692be18c0a00d47d1f14ad393248391d647
                                                      • Opcode Fuzzy Hash: bc2560622dd12dc061e682349bbab48d723059ee61b589259f67d66aa03a0f62
                                                      • Instruction Fuzzy Hash: 7E415A30A00218CFDB24EFB9C954BECB7F2BF85309F5045AAD409AB295DB795A48CF51
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a0a4498a6b47b45f26dff00525b27f9ee6348723aa918942eef03ec77e38faeb
                                                      • Instruction ID: 24d82343cec12f4223cca77b4b5a025155b7861bd2299a95e6a54be0cfb0276e
                                                      • Opcode Fuzzy Hash: a0a4498a6b47b45f26dff00525b27f9ee6348723aa918942eef03ec77e38faeb
                                                      • Instruction Fuzzy Hash: 2E31D574B402099FDB18DB79D854BAEBBF2AFC8244F144539E405EB3A1DF74A8088B91
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 75d92786fd855cd369aa1c0fec7edb5dca0627de6d37b70b3bc4b89eab469b48
                                                      • Instruction ID: 8a6a62efe84049e3c067fbc8fefc60a110f73db9e780f34291b629f80d12eae4
                                                      • Opcode Fuzzy Hash: 75d92786fd855cd369aa1c0fec7edb5dca0627de6d37b70b3bc4b89eab469b48
                                                      • Instruction Fuzzy Hash: E43124316083449FCB15E7769812B6E3BA7ABC2248B1488BED001CF2D6DF795C09C7D2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d7eb6b1dd61196a476ac59b6fe3db1799c6cd9ca9170d89469b68f5d4a458903
                                                      • Instruction ID: be21a5ec7fc91720e91291bf7fd46f072a8c2f0d2feeb0c0df3998a25fd8bb14
                                                      • Opcode Fuzzy Hash: d7eb6b1dd61196a476ac59b6fe3db1799c6cd9ca9170d89469b68f5d4a458903
                                                      • Instruction Fuzzy Hash: 0E319F7470124A9FEB20DB69CC80BAA77E5FFCA244F140979D941EB784DB70E9098B90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5185dfe74b84d98a712e434f023b757c9c5e50d6b9b1abb2e9362a2ccc812c3c
                                                      • Instruction ID: a97bbfd795ccd344eb2d268c35878c01139c3922965bc95a52d7505ccbbc1d65
                                                      • Opcode Fuzzy Hash: 5185dfe74b84d98a712e434f023b757c9c5e50d6b9b1abb2e9362a2ccc812c3c
                                                      • Instruction Fuzzy Hash: CC212F757002499FEB20DB6AC881BAA73E5FFC9244F140978E941EB794E770FD158790
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063584630.0000000000AF0000.00000040.00000020.00020000.00000000.sdmp, Offset: 00AF0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_af0000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 2b0859269b9f07b27167d985ede3be9853a8e2ad01e83e8a32e05a33903d635c
                                                      • Instruction ID: 62aae6143758902a9505e45f5b600a34ae53a954e9cd05daf23ece549b216f08
                                                      • Opcode Fuzzy Hash: 2b0859269b9f07b27167d985ede3be9853a8e2ad01e83e8a32e05a33903d635c
                                                      • Instruction Fuzzy Hash: F211E434204684DFC711CB64D980F26B7A5AB88708F24C9ACF5491BB43C77BD843CAD1
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5407b648b5eb10138beb9b4e226a08d933aa45949e50aca69a91fa702951cbb1
                                                      • Instruction ID: 1d19cad46f159f627dc7ffbe87f7c68c5b0d623756dc6d93d4a9cbadceb7afb7
                                                      • Opcode Fuzzy Hash: 5407b648b5eb10138beb9b4e226a08d933aa45949e50aca69a91fa702951cbb1
                                                      • Instruction Fuzzy Hash: 5A1102316097408FC725A37AA451A6D2BD7ABC328935488BDD0028F796CF799C0D97D2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 1c0b9e5891bd2e9713463a79c1dd7fc436d4e9866fc343b60d569406e69ff036
                                                      • Instruction ID: 593424902f1079c290a0c1bcc580273e91006a4c67584dbf15f6b798a32bd126
                                                      • Opcode Fuzzy Hash: 1c0b9e5891bd2e9713463a79c1dd7fc436d4e9866fc343b60d569406e69ff036
                                                      • Instruction Fuzzy Hash: DB0192342093904FC7266378A8214693BA2DBC320674545EFD8829F69BDB295C0AC392
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 21d26cf024155d222df023cfafcb5efb635eae35a6b6469e354862617a6f7963
                                                      • Instruction ID: d702e984731fa39095a8bafa25f69f1e37411da9e71f95e331c37dc7b86d8d7e
                                                      • Opcode Fuzzy Hash: 21d26cf024155d222df023cfafcb5efb635eae35a6b6469e354862617a6f7963
                                                      • Instruction Fuzzy Hash: 7211E331F002588FCB55DBB898154AEBBF6AB9A24471041BEC805EB356EB359E05CB90
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 71e497b60514a8223858d09f70c371a43fcf65d626c9dfc76d10d81f6500d743
                                                      • Instruction ID: 24412ba4dcadfab7a8c9fb4da9baa05987ea29c878a06701f40f94c8521198a0
                                                      • Opcode Fuzzy Hash: 71e497b60514a8223858d09f70c371a43fcf65d626c9dfc76d10d81f6500d743
                                                      • Instruction Fuzzy Hash: 8611AB6040F3C55FC3139734AC686947FB0AE43209B4E84DBC8D0CF2A7C6685A0EE7A2
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063584630.0000000000AF0000.00000040.00000020.00020000.00000000.sdmp, Offset: 00AF0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_af0000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 5c1b3acab3ec386dbdea6b4390e6908fe3af89a4d7a257152f6b217cae398f9b
                                                      • Instruction ID: a6246d0a4982dd512c97633c92c1f96c912238614a7b8547e0c7dcb32677d4ff
                                                      • Opcode Fuzzy Hash: 5c1b3acab3ec386dbdea6b4390e6908fe3af89a4d7a257152f6b217cae398f9b
                                                      • Instruction Fuzzy Hash: 011130315093C48FC712CB50C950B55BFB1AF4A708F19C5EEE5854B6A3C33A9C06DB91
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063584630.0000000000AF0000.00000040.00000020.00020000.00000000.sdmp, Offset: 00AF0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_af0000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 9ab612d99231f558730d5e409526e9a7de92ac850f3b72dec33328996fe4f02e
                                                      • Instruction ID: c0cc3eac3e713263feab5d85feaa284ce8afd91b7ebe533d9d1aa467db557233
                                                      • Opcode Fuzzy Hash: 9ab612d99231f558730d5e409526e9a7de92ac850f3b72dec33328996fe4f02e
                                                      • Instruction Fuzzy Hash: 1FF0A9B65093806FD7118B059C41862FFF8DF86620709C4AFED498B712D225A909C7B1
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: ffc60503c7bd2669c5d883ff037a041d00027fee30e20c3c9fdc7e3c42a5fd90
                                                      • Instruction ID: 9ae220ed7cc2a275c462d37eb89475ef16e69224227e3189cfbe6d9e7ebdee0f
                                                      • Opcode Fuzzy Hash: ffc60503c7bd2669c5d883ff037a041d00027fee30e20c3c9fdc7e3c42a5fd90
                                                      • Instruction Fuzzy Hash: 06011E30516341CFCB50EB79D55899C7BE1EF89309F40882CE8558B65AEB359948EF41
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 578c6516802aabfb1f4c50047e5426ea647d69d168474aa1636dbf89ee6efaea
                                                      • Instruction ID: 7390d01e170205a80801c132559adaa4dc9c880ccd405a7232b9eda4180af78e
                                                      • Opcode Fuzzy Hash: 578c6516802aabfb1f4c50047e5426ea647d69d168474aa1636dbf89ee6efaea
                                                      • Instruction Fuzzy Hash: 75F09672A013049FEB14DB70C852BAF7BB2EFC1724F1085BEA541DB1D1EA355841C740
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063584630.0000000000AF0000.00000040.00000020.00020000.00000000.sdmp, Offset: 00AF0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_af0000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 74b9f174851936b42c91253ba0377f3a0e724fe011995a5d7daf0febe73ee2ff
                                                      • Instruction ID: 376da87be0d1826dbd3037f3a00ddafcda0aac8ad955dbf49aad11815da919ef
                                                      • Opcode Fuzzy Hash: 74b9f174851936b42c91253ba0377f3a0e724fe011995a5d7daf0febe73ee2ff
                                                      • Instruction Fuzzy Hash: 9AF0FB35144644DFC605CB50D540F25FBA2EB89718F24CAA9E9491B652C737E812DA81
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063584630.0000000000AF0000.00000040.00000020.00020000.00000000.sdmp, Offset: 00AF0000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_af0000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 0329d58375c2bf3a5aef05cb1214bb31c1c83fac34b7be2bb8bfb6601afe7b39
                                                      • Instruction ID: 91107a811b822c226546aca3ba0eb894cfcbb3a875b5db48cda81458f2ec8bc3
                                                      • Opcode Fuzzy Hash: 0329d58375c2bf3a5aef05cb1214bb31c1c83fac34b7be2bb8bfb6601afe7b39
                                                      • Instruction Fuzzy Hash: 61E092B6A006004BD650CF0EEC41452FBD8EB88630B08C47FDD0D8BB11D235B908CAA5
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a94ffe1c2afe8dd694e909c810ba7ee64c4a4f6f654be1a5b46a1fee895191af
                                                      • Instruction ID: 994210d13d75059890f5a3e1c2704112730f489d44fb28852afb52a0b653d07b
                                                      • Opcode Fuzzy Hash: a94ffe1c2afe8dd694e909c810ba7ee64c4a4f6f654be1a5b46a1fee895191af
                                                      • Instruction Fuzzy Hash: C7E04F3091F2889FCB42CF749D215EC7FB0DB4220571442EED84ACB6A2DA251A09DB42
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 221c9f8fb466d3df10f839574dbdb051bdae6cca8b886bea367e45c7c8f4f8ff
                                                      • Instruction ID: 5234e796fb16c7e40c64115a2e3b03ce0ea4732099857208eec60f3b19966a73
                                                      • Opcode Fuzzy Hash: 221c9f8fb466d3df10f839574dbdb051bdae6cca8b886bea367e45c7c8f4f8ff
                                                      • Instruction Fuzzy Hash: B4E08C2090E2C85FCB13CBB09C658EE7F70898210131401DFC842CB2A3D9250A0D9B43
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 0a6e9e41166eb1b3b178d099606ea80f19f11883e50cfcf8fd420b31543d818a
                                                      • Instruction ID: 6508bd1f2e79194b230f27df1af5e4c6b5f283d2969292e0a4cdc18e70ea9e7a
                                                      • Opcode Fuzzy Hash: 0a6e9e41166eb1b3b178d099606ea80f19f11883e50cfcf8fd420b31543d818a
                                                      • Instruction Fuzzy Hash: 7DE0E63015B3948FC7175B34A42585C3B759A4720535404FFD446CB696D676948ADB41
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063315361.0000000000942000.00000040.00000800.00020000.00000000.sdmp, Offset: 00942000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_942000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: 7f819e1f91946dc808ebecbe818d4282f09b47d36ac3e9a6a21929928215839a
                                                      • Instruction ID: 50a27cfcd2c7a516cf59bc2d1f581acf9d248397be926f7fadc88a6e9645fde0
                                                      • Opcode Fuzzy Hash: 7f819e1f91946dc808ebecbe818d4282f09b47d36ac3e9a6a21929928215839a
                                                      • Instruction Fuzzy Hash: 55D05E79209AD14FD3269B1CC6A8FA537D8BB51714F8A44F9A800CBBB3CB68D981D600
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4063315361.0000000000942000.00000040.00000800.00020000.00000000.sdmp, Offset: 00942000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_942000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: d3c2300716345f04d26a57c375475c5d5b7fa6b11abfa59eb762c228bc090959
                                                      • Instruction ID: f1f9895e331b1ba00c097f3adbb71b7b39d612e8467e8500ddc88ad7cec311b8
                                                      • Opcode Fuzzy Hash: d3c2300716345f04d26a57c375475c5d5b7fa6b11abfa59eb762c228bc090959
                                                      • Instruction Fuzzy Hash: 06D05E342002814BC725DF0CC2D4F5977E8BB40B14F0644E8BC108B762C7B8DCC0DA00
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%

                                                      Memory Dump Source
                                                      • Source File: 00000001.00000002.4066771549.0000000004840000.00000040.00000800.00020000.00000000.sdmp, Offset: 04840000, based on PE: false
                                                      Joe Sandbox IDA Plugin
                                                      • Snapshot File: hcaresult_1_2_4840000_server.jbxd
                                                      Similarity
                                                      • API ID:
                                                      • String ID:
                                                      • API String ID:
                                                      • Opcode ID: a2907166c9a65dea99e0590db98f6f10668404968c2dbfd8643b8ea598c5cab4
                                                      • Instruction ID: 0362a7b70d0b623c356b9e2e01c3598a1431e4f8b00f1de5ee2c17b78743d90f
                                                      • Opcode Fuzzy Hash: a2907166c9a65dea99e0590db98f6f10668404968c2dbfd8643b8ea598c5cab4
                                                      • Instruction Fuzzy Hash: 5AD0A931A16208EF8B40DFA8DC008ADB7F8EB0520AB0001AAA80DC3310EE321E00EB80
                                                      Uniqueness

                                                      Uniqueness Score: -1.00%