Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
yrBA01LVo2.exe

Overview

General Information

Sample name:yrBA01LVo2.exe
renamed because original name is a hash value
Original sample name:2a62c57ba98308fe2316508f077186b76e5ad55a1e367e58d19e5a9b08900eec.exe
Analysis ID:1472027
MD5:da8dde3005365992711946c4622a3c74
SHA1:d04042cd11cd11f3b6386a5e2275f14b92048fc6
SHA256:2a62c57ba98308fe2316508f077186b76e5ad55a1e367e58d19e5a9b08900eec
Tags:64-112-85-3exe
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected Wannacry ransomware
AI detected suspicious sample
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains long sleeps (>= 3 min)
Creates files inside the system directory
Detected non-DNS traffic on DNS port
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file does not import any functions
Uses 32bit PE files
Yara signature match

Classification

  • System is w10x64
  • yrBA01LVo2.exe (PID: 7108 cmdline: "C:\Users\user\Desktop\yrBA01LVo2.exe" MD5: DA8DDE3005365992711946C4622A3C74)
  • yrBA01LVo2.exe (PID: 5508 cmdline: C:\Users\user\Desktop\yrBA01LVo2.exe -m security MD5: DA8DDE3005365992711946C4622A3C74)
  • svchost.exe (PID: 6504 cmdline: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
yrBA01LVo2.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    yrBA01LVo2.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x3136c:$x3: tasksche.exe
    • 0x31344:$x8: C:\%s\qeriuwjhrf
    • 0xe034:$s1: C:\%s\%s
    • 0x17338:$s1: C:\%s\%s
    • 0x31358:$s1: C:\%s\%s
    • 0x73a24:$s4: msg/m_portuguese.wnry
    • 0x2e68c:$s5: \\192.168.56.20\IPC$
    • 0x1ba81:$s6: \\172.16.99.5\IPC$
    • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    yrBA01LVo2.exeWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
    • 0x1bacc:$s1: __TREEID__PLACEHOLDER__
    • 0x1bb68:$s1: __TREEID__PLACEHOLDER__
    • 0x1c3d4:$s1: __TREEID__PLACEHOLDER__
    • 0x1d439:$s1: __TREEID__PLACEHOLDER__
    • 0x1e4a0:$s1: __TREEID__PLACEHOLDER__
    • 0x1f508:$s1: __TREEID__PLACEHOLDER__
    • 0x20570:$s1: __TREEID__PLACEHOLDER__
    • 0x215d8:$s1: __TREEID__PLACEHOLDER__
    • 0x22640:$s1: __TREEID__PLACEHOLDER__
    • 0x236a8:$s1: __TREEID__PLACEHOLDER__
    • 0x24710:$s1: __TREEID__PLACEHOLDER__
    • 0x25778:$s1: __TREEID__PLACEHOLDER__
    • 0x267e0:$s1: __TREEID__PLACEHOLDER__
    • 0x27848:$s1: __TREEID__PLACEHOLDER__
    • 0x288b0:$s1: __TREEID__PLACEHOLDER__
    • 0x29918:$s1: __TREEID__PLACEHOLDER__
    • 0x2a980:$s1: __TREEID__PLACEHOLDER__
    • 0x2ab94:$s1: __TREEID__PLACEHOLDER__
    • 0x2abf4:$s1: __TREEID__PLACEHOLDER__
    • 0x2e2c4:$s1: __TREEID__PLACEHOLDER__
    • 0x2e340:$s1: __TREEID__PLACEHOLDER__
    SourceRuleDescriptionAuthorStrings
    00000000.00000000.1999381187.000000000040F000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000002.00000000.2018076872.000000000040F000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            00000002.00000002.2671560893.0000000002289000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              Click to see the 3 entries
              SourceRuleDescriptionAuthorStrings
              2.2.yrBA01LVo2.exe.227a8c8.8.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
              • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
              • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
              2.2.yrBA01LVo2.exe.1d52084.4.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
              • 0x9131:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
              • 0x3876:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
              • 0x13e5:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
              2.2.yrBA01LVo2.exe.1d61104.3.raw.unpackJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                2.2.yrBA01LVo2.exe.1d61104.3.raw.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0x222ec:$x3: tasksche.exe
                • 0x222c4:$x8: C:\%s\qeriuwjhrf
                • 0x82b8:$s1: C:\%s\%s
                • 0x222d8:$s1: C:\%s\%s
                • 0x649a4:$s4: msg/m_portuguese.wnry
                • 0x1f60c:$s5: \\192.168.56.20\IPC$
                • 0xca01:$s6: \\172.16.99.5\IPC$
                2.2.yrBA01LVo2.exe.1d61104.3.raw.unpackWannaCry_Ransomware_GenDetects WannaCry RansomwareFlorian Roth (based on rule by US CERT)
                • 0xca4c:$s1: __TREEID__PLACEHOLDER__
                • 0xcae8:$s1: __TREEID__PLACEHOLDER__
                • 0xd354:$s1: __TREEID__PLACEHOLDER__
                • 0xe3b9:$s1: __TREEID__PLACEHOLDER__
                • 0xf420:$s1: __TREEID__PLACEHOLDER__
                • 0x10488:$s1: __TREEID__PLACEHOLDER__
                • 0x114f0:$s1: __TREEID__PLACEHOLDER__
                • 0x12558:$s1: __TREEID__PLACEHOLDER__
                • 0x135c0:$s1: __TREEID__PLACEHOLDER__
                • 0x14628:$s1: __TREEID__PLACEHOLDER__
                • 0x15690:$s1: __TREEID__PLACEHOLDER__
                • 0x166f8:$s1: __TREEID__PLACEHOLDER__
                • 0x17760:$s1: __TREEID__PLACEHOLDER__
                • 0x187c8:$s1: __TREEID__PLACEHOLDER__
                • 0x19830:$s1: __TREEID__PLACEHOLDER__
                • 0x1a898:$s1: __TREEID__PLACEHOLDER__
                • 0x1b900:$s1: __TREEID__PLACEHOLDER__
                • 0x1bb14:$s1: __TREEID__PLACEHOLDER__
                • 0x1bb74:$s1: __TREEID__PLACEHOLDER__
                • 0x1f244:$s1: __TREEID__PLACEHOLDER__
                • 0x1f2c0:$s1: __TREEID__PLACEHOLDER__
                Click to see the 29 entries

                System Summary

                barindex
                Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager, CommandLine: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 632, ProcessCommandLine: C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager, ProcessId: 6504, ProcessName: svchost.exe
                Timestamp:07/12/24-08:11:55.324048
                SID:2830018
                Source Port:57367
                Destination Port:53
                Protocol:UDP
                Classtype:A Network Trojan was detected

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: yrBA01LVo2.exeAvira: detected
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd736Avira URL Cloud: Label: malware
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f015Avira URL Cloud: Label: malware
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/I.Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd7Avira URL Cloud: Label: malware
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/9-Avira URL Cloud: Label: malware
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/3Avira URL Cloud: Label: malware
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f01544Avira URL Cloud: Label: malware
                Source: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comVirustotal: Detection: 9%Perma Link
                Source: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comVirustotal: Detection: 12%Perma Link
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Virustotal: Detection: 12%Perma Link
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comVirustotal: Detection: 9%Perma Link
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/3Virustotal: Detection: 8%Perma Link
                Source: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Virustotal: Detection: 9%Perma Link
                Source: C:\Windows\tasksche.exeReversingLabs: Detection: 86%
                Source: C:\Windows\tasksche.exeVirustotal: Detection: 82%Perma Link
                Source: yrBA01LVo2.exeReversingLabs: Detection: 100%
                Source: yrBA01LVo2.exeVirustotal: Detection: 93%Perma Link
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                Source: C:\Windows\tasksche.exeJoe Sandbox ML: detected
                Source: yrBA01LVo2.exeJoe Sandbox ML: detected

                Exploits

                barindex
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: yrBA01LVo2.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.5:49887 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.5:57034 version: TLS 1.2

                Networking

                barindex
                Source: TrafficSnort IDS: 2830018 ETPRO TROJAN Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup) 192.168.2.5:57367 -> 1.1.1.1:53
                Source: global trafficTCP traffic: 192.168.2.5:56867 -> 1.1.1.1:53
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20240712-1611-56c7-8cb1-aab7e5f01544 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20240712-1611-575d-a069-1da1339fd736 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.4
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.4
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.4
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.4
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 204.59.96.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.97
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.97
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.97
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.97
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 89.248.166.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.47
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.47
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.47
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.47
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 50.247.21.1
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.22
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.22
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.22
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.22
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: unknownTCP traffic detected without corresponding DNS query: 203.155.53.1
                Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=1BSddhgcBDph9M7&MD=UAFFSYcE HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
                Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=1BSddhgcBDph9M7&MD=UAFFSYcE HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20240712-1611-56c7-8cb1-aab7e5f01544 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20240712-1611-575d-a069-1da1339fd736 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficDNS traffic detected: DNS query: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: global trafficDNS traffic detected: DNS query: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B4A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B2E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f015
                Source: yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000C8A000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CA5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd7
                Source: yrBA01LVo2.exeString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000AEE000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B2E000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CA5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CA5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/3
                Source: yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000AEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/9-
                Source: yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000AEE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/I.
                Source: yrBA01LVo2.exe, 00000002.00000002.2667450829.000000000019D000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49887
                Source: unknownNetwork traffic detected: HTTP traffic on port 57034 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57034
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
                Source: unknownNetwork traffic detected: HTTP traffic on port 49887 -> 443
                Source: unknownHTTPS traffic detected: 52.165.165.26:443 -> 192.168.2.5:49887 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.5:57034 version: TLS 1.2

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: Yara matchFile source: yrBA01LVo2.exe, type: SAMPLE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.1d61104.3.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.2289948.6.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.227a8c8.8.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 0.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.1d52084.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.1d5d0a4.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.1d61104.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.2289948.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.2.yrBA01LVo2.exe.22858e8.7.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000000.00000000.1999381187.000000000040F000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000000.2018076872.000000000040F000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.2671560893.0000000002289000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000002.2671276992.0000000001D61000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: yrBA01LVo2.exe PID: 7108, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: yrBA01LVo2.exe PID: 5508, type: MEMORYSTR

                System Summary

                barindex
                Source: yrBA01LVo2.exe, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: yrBA01LVo2.exe, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.2.yrBA01LVo2.exe.227a8c8.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.1d52084.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.1d61104.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.1d61104.3.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.2.yrBA01LVo2.exe.2289948.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.2289948.6.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 0.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 0.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.2.yrBA01LVo2.exe.227a8c8.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.227a8c8.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 0.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 0.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.2.yrBA01LVo2.exe.1d52084.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.1d52084.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 2.2.yrBA01LVo2.exe.1d5d0a4.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.1d61104.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.2289948.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 2.2.yrBA01LVo2.exe.22858e8.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: yrBA01LVo2.exeStatic PE information: Resource name: R type: PE32 executable (GUI) Intel 80386, for MS Windows
                Source: tasksche.exe.0.drStatic PE information: No import functions for PE file found
                Source: yrBA01LVo2.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                Source: yrBA01LVo2.exe, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: yrBA01LVo2.exe, type: SAMPLEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.2.yrBA01LVo2.exe.227a8c8.8.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.1d52084.4.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.1d61104.3.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.1d61104.3.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.2.yrBA01LVo2.exe.2289948.6.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.2289948.6.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 0.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 0.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.2.yrBA01LVo2.exe.227a8c8.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.227a8c8.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.0.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 0.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 0.2.yrBA01LVo2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.2.yrBA01LVo2.exe.1d52084.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.1d52084.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 2.2.yrBA01LVo2.exe.1d5d0a4.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.1d61104.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.2289948.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 2.2.yrBA01LVo2.exe.22858e8.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: tasksche.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: tasksche.exe.0.drStatic PE information: Section: .rdata ZLIB complexity 1.0007621951219512
                Source: tasksche.exe.0.drStatic PE information: Section: .data ZLIB complexity 1.001953125
                Source: tasksche.exe.0.drStatic PE information: Section: .rsrc ZLIB complexity 1.0007408405172413
                Source: classification engineClassification label: mal100.rans.expl.winEXE@4/1@2/100
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,0_2_00407C40
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,2_2_00407C40
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: 0_2_00407CE0 InternetCloseHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,FindResourceA,LoadResource,LockResource,SizeofResource,sprintf,sprintf,sprintf,MoveFileExA,CreateFileA,WriteFile,FindCloseChangeNotification,CreateProcessA,CloseHandle,CloseHandle,0_2_00407CE0
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: 0_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,0_2_00407C40
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: 0_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,0_2_00408090
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: 2_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,2_2_00408090
                Source: yrBA01LVo2.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: yrBA01LVo2.exeReversingLabs: Detection: 100%
                Source: yrBA01LVo2.exeVirustotal: Detection: 93%
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeFile read: C:\Users\user\Desktop\yrBA01LVo2.exeJump to behavior
                Source: unknownProcess created: C:\Users\user\Desktop\yrBA01LVo2.exe "C:\Users\user\Desktop\yrBA01LVo2.exe"
                Source: unknownProcess created: C:\Users\user\Desktop\yrBA01LVo2.exe C:\Users\user\Desktop\yrBA01LVo2.exe -m security
                Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: licensemanagersvc.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: licensemanager.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: clipc.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
                Source: yrBA01LVo2.exeStatic file information: File size 2281472 > 1048576
                Source: yrBA01LVo2.exeStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x1f8000
                Source: tasksche.exe.0.drStatic PE information: section name: .text entropy: 7.626957870221103
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeCode function: 0_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,0_2_00407C40
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeThread delayed: delay time: 86400000Jump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeDropped PE file which has not been started: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Users\user\Desktop\yrBA01LVo2.exe TID: 5672Thread sleep count: 97 > 30Jump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exe TID: 5672Thread sleep time: -194000s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exe TID: 5284Thread sleep count: 124 > 30Jump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exe TID: 5284Thread sleep count: 46 > 30Jump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exe TID: 5672Thread sleep time: -86400000s >= -30000sJump to behavior
                Source: C:\Users\user\Desktop\yrBA01LVo2.exeThread delayed: delay time: 86400000Jump to behavior
                Source: yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CBB000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp
                Source: yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B19000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CBB000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000C68000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                Service Execution
                4
                Windows Service
                4
                Windows Service
                2
                Masquerading
                OS Credential Dumping1
                Network Share Discovery
                Remote ServicesData from Local System1
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/Job1
                DLL Side-Loading
                1
                Process Injection
                21
                Virtualization/Sandbox Evasion
                LSASS Memory11
                Security Software Discovery
                Remote Desktop ProtocolData from Removable Media1
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                1
                Process Injection
                Security Account Manager21
                Virtualization/Sandbox Evasion
                SMB/Windows Admin SharesData from Network Shared Drive2
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                Obfuscated Files or Information
                NTDS1
                System Information Discovery
                Distributed Component Object ModelInput Capture3
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script3
                Software Packing
                LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                DLL Side-Loading
                Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                yrBA01LVo2.exe100%ReversingLabsWin32.Ransomware.WannaCry
                yrBA01LVo2.exe93%VirustotalBrowse
                yrBA01LVo2.exe100%AviraTR/Ransom.Gen
                yrBA01LVo2.exe100%Joe Sandbox ML
                SourceDetectionScannerLabelLink
                C:\Windows\tasksche.exe100%Joe Sandbox ML
                C:\Windows\tasksche.exe87%ReversingLabsWin32.Ransomware.WannaCry
                C:\Windows\tasksche.exe83%VirustotalBrowse
                No Antivirus matches
                SourceDetectionScannerLabelLink
                77026.bodis.com0%VirustotalBrowse
                www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com9%VirustotalBrowse
                ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com13%VirustotalBrowse
                SourceDetectionScannerLabelLink
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ0%Avira URL Cloudsafe
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd736100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f015100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/I.100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd7100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/13%VirustotalBrowse
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/9-100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/3100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com9%VirustotalBrowse
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f01544100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/39%VirustotalBrowse
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/9%VirustotalBrowse
                NameIPActiveMaliciousAntivirus DetectionReputation
                77026.bodis.com
                199.59.243.226
                truefalseunknown
                www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                103.224.212.215
                truefalseunknown
                ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                unknown
                unknownfalseunknown
                NameMaliciousAntivirus DetectionReputation
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd736false
                • Avira URL Cloud: malware
                unknown
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/true
                • 9%, Virustotal, Browse
                • Avira URL Cloud: malware
                unknown
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f01544false
                • Avira URL Cloud: malware
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f015yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B2E000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: malware
                unknown
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJyrBA01LVo2.exe, 00000002.00000002.2667450829.000000000019D000.00000004.00000010.00020000.00000000.sdmptrue
                • Avira URL Cloud: safe
                unknown
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000B4A000.00000004.00000020.00020000.00000000.sdmpfalse
                • 13%, Virustotal, Browse
                • Avira URL Cloud: malware
                unknown
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comyrBA01LVo2.exetrue
                • 9%, Virustotal, Browse
                • Avira URL Cloud: malware
                unknown
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/I.yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000AEE000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: malware
                unknown
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd7yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000C8A000.00000004.00000020.00020000.00000000.sdmp, yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CA5000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: malware
                unknown
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/9-yrBA01LVo2.exe, 00000000.00000002.2032154935.0000000000AEE000.00000004.00000020.00020000.00000000.sdmptrue
                • Avira URL Cloud: malware
                unknown
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/3yrBA01LVo2.exe, 00000002.00000002.2669265024.0000000000CA5000.00000004.00000020.00020000.00000000.sdmptrue
                • 9%, Virustotal, Browse
                • Avira URL Cloud: malware
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.148.241.91
                unknownTurkey
                208485EKSENBILISIMTRfalse
                170.120.108.114
                unknownUnited States
                22347DORSEY-WHITNEYUSfalse
                133.184.83.1
                unknownJapan385AFCONC-BLOCK1-ASUSfalse
                217.123.9.234
                unknownNetherlands
                33915TNF-ASNLfalse
                161.45.66.2
                unknownUnited States
                26335MTSUUSfalse
                161.45.66.1
                unknownUnited States
                26335MTSUUSfalse
                204.59.96.4
                unknownUnited States
                51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
                204.59.96.1
                unknownUnited States
                51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
                204.59.96.2
                unknownUnited States
                51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
                183.227.189.2
                unknownChina
                9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
                183.227.189.1
                unknownChina
                9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
                192.99.167.126
                unknownCanada
                16276OVHFRfalse
                192.99.167.1
                unknownCanada
                16276OVHFRfalse
                146.166.199.1
                unknownUnited States
                14977STATE-OF-WYOMING-ASNUSfalse
                96.158.114.43
                unknownUnited States
                7922COMCAST-7922USfalse
                45.205.206.1
                unknownSeychelles
                26484IKGUL-26484USfalse
                11.223.200.1
                unknownUnited States
                3356LEVEL3USfalse
                63.194.252.1
                unknownUnited States
                7018ATT-INTERNET4USfalse
                89.248.166.2
                unknownNetherlands
                202425INT-NETWORKSCfalse
                58.98.198.169
                unknownJapan9595XEPHIONNTT-MECorporationJPfalse
                63.194.252.161
                unknownUnited States
                7018ATT-INTERNET4USfalse
                89.248.166.1
                unknownNetherlands
                202425INT-NETWORKSCfalse
                161.45.66.107
                unknownUnited States
                26335MTSUUSfalse
                159.4.73.1
                unknownUnited States
                1906NORTHROP-GRUMMANUSfalse
                183.227.189.235
                unknownChina
                9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
                IP
                192.168.2.148
                192.168.2.149
                192.168.2.146
                192.168.2.147
                192.168.2.140
                192.168.2.141
                192.168.2.144
                192.168.2.145
                192.168.2.142
                192.168.2.143
                192.168.2.159
                192.168.2.157
                192.168.2.158
                10.50.70.81
                192.168.2.151
                192.168.2.152
                192.168.2.150
                192.168.2.155
                192.168.2.156
                192.168.2.153
                192.168.2.154
                192.168.2.126
                192.168.2.247
                192.168.2.127
                192.168.2.248
                192.168.2.124
                192.168.2.245
                192.168.2.125
                192.168.2.246
                192.168.2.128
                192.168.2.249
                192.168.2.129
                192.168.2.240
                192.168.2.122
                192.168.2.243
                192.168.2.123
                192.168.2.244
                192.168.2.120
                192.168.2.241
                192.168.2.121
                192.168.2.242
                192.168.2.97
                192.168.2.137
                192.168.2.96
                192.168.2.138
                192.168.2.99
                192.168.2.135
                192.168.2.98
                192.168.2.136
                192.168.2.139
                192.168.2.250
                192.168.2.130
                192.168.2.251
                192.168.2.91
                192.168.2.90
                192.168.2.93
                192.168.2.133
                192.168.2.254
                192.168.2.92
                192.168.2.134
                192.168.2.95
                192.168.2.131
                192.168.2.252
                192.168.2.94
                192.168.2.132
                192.168.2.253
                10.50.70.1
                192.168.2.104
                192.168.2.225
                192.168.2.105
                192.168.2.226
                192.168.2.102
                192.168.2.223
                192.168.2.103
                192.168.2.224
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1472027
                Start date and time:2024-07-12 08:11:08 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 5m 9s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:6
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:yrBA01LVo2.exe
                renamed because original name is a hash value
                Original Sample Name:2a62c57ba98308fe2316508f077186b76e5ad55a1e367e58d19e5a9b08900eec.exe
                Detection:MAL
                Classification:mal100.rans.expl.winEXE@4/1@2/100
                EGA Information:
                • Successful, ratio: 100%
                HCA Information:Failed
                Cookbook Comments:
                • Found application associated with file extension: .exe
                • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                • Excluded IPs from analysis (whitelisted): 199.232.214.172, 192.229.221.95
                • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com
                • Report size getting too big, too many NtQueryValueKey calls found.
                TimeTypeDescription
                02:12:31API Interceptor112x Sleep call for process: yrBA01LVo2.exe modified
                No context
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                77026.bodis.comhttp://sectocarewl.online/mona-michelle/Get hashmaliciousUnknownBrowse
                • 199.59.243.226
                file.exeGet hashmaliciousCMSBruteBrowse
                • 199.59.243.225
                SlHgSOYcMY.exeGet hashmaliciousUnknownBrowse
                • 199.59.243.225
                https://upsmychoicedeals.comGet hashmaliciousUnknownBrowse
                • 199.59.243.225
                http://free.filesearch.club/?q=grade+9+core+french+textbookGet hashmaliciousUnknownBrowse
                • 199.59.243.225
                PaDQmSw2ud.dllGet hashmaliciousLaplas ClipperBrowse
                • 199.59.243.225
                PaDQmSw2ud.dllGet hashmaliciousLaplas ClipperBrowse
                • 199.59.243.225
                ccQGH1mKws.exeGet hashmaliciousGlupteba, SmokeLoader, StealcBrowse
                • 199.59.243.225
                file.exeGet hashmaliciousLummaC, Glupteba, SmokeLoader, Stealc, XmrigBrowse
                • 199.59.243.225
                7abf5ad882fd72332b0b7fb530c8c6505852d4f7ea39edfe444218bdcd9c7f0e_dump.exeGet hashmaliciousGlupteba, SmokeLoader, StealcBrowse
                • 199.59.243.225
                www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comlJt3mQqCQl.dllGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                xIwkOnjSIa.dllGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                IU28r0EZFA.dllGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                ViNIRfmQmE.dllGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                Ee3RWj3ID9.exeGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                YB7v7UFV3j.exeGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                B0U3oOhQJu.exeGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                1WImqfBvqH.dllGet hashmaliciousWannacryBrowse
                • 103.224.212.220
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                DORSEY-WHITNEYUShttps://us02web.zoom.us/webinar/register/WN_7CDol1QPS2eD_bT1ntjWmgGet hashmaliciousUnknownBrowse
                • 170.114.52.2
                https://us02web.zoom.us/webinar/register/6317193087387/WN_wbycs5lISL2eo8rEP6qUDg#/registrationGet hashmaliciousUnknownBrowse
                • 170.114.45.6
                Doc3.docxGet hashmaliciousUnknownBrowse
                • 170.114.52.2
                https://us02web.zoom.us/webinar/register/WN_7CDol1QPS2eD_bT1ntjWmgGet hashmaliciousUnknownBrowse
                • 170.114.45.6
                C7QZHqCV7n.elfGet hashmaliciousUnknownBrowse
                • 170.118.48.78
                i6bCVSCWc1.elfGet hashmaliciousMiraiBrowse
                • 170.113.24.254
                https://zoom.us/downloadGet hashmaliciousUnknownBrowse
                • 170.114.65.138
                TxXQ106ErI.elfGet hashmaliciousMiraiBrowse
                • 170.113.127.1
                4ZgjosOSkq.elfGet hashmaliciousMiraiBrowse
                • 170.118.73.39
                https://us06web.zoom.us/webinar/register/WN_ozauON07SWuCo9QWQ_DMsgGet hashmaliciousUnknownBrowse
                • 170.114.52.6
                TNF-ASNLX2Yb9u8Ntz.elfGet hashmaliciousMiraiBrowse
                • 84.27.17.112
                ahN4x3ahps.elfGet hashmaliciousMiraiBrowse
                • 89.220.176.250
                3jI8pe3luL.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                • 84.31.74.137
                205.185.124.50-mips-2024-07-03T23_47_54.elfGet hashmaliciousMirai, MoobotBrowse
                • 82.72.81.13
                DVh7O0cBNN.elfGet hashmaliciousUnknownBrowse
                • 94.211.242.89
                ztGOiA742S.elfGet hashmaliciousUnknownBrowse
                • 84.26.86.38
                vGUfP1M4Q6.elfGet hashmaliciousUnknownBrowse
                • 94.208.45.195
                eW8ah5TCen.elfGet hashmaliciousUnknownBrowse
                • 217.121.211.66
                mirai.x86.elfGet hashmaliciousMiraiBrowse
                • 217.122.27.143
                mfQABKHhh1.elfGet hashmaliciousMiraiBrowse
                • 195.35.225.234
                EKSENBILISIMTRcbIcBAgY5W.exeGet hashmaliciousSystemBCBrowse
                • 193.57.27.27
                ChromeUpdate.msiGet hashmaliciousDarkGate, MailPassViewBrowse
                • 94.232.245.250
                odB2NhqqLn.exeGet hashmaliciousUnknownBrowse
                • 94.232.247.248
                jhwTchfZRO.exeGet hashmaliciousUnknownBrowse
                • 94.232.247.248
                bUWKfj04aU.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, PureLog Stealer, RedLineBrowse
                • 94.232.247.248
                Zo5nx6nbWO.elfGet hashmaliciousGafgytBrowse
                • 147.79.142.145
                https://esincecocuk.com/833002.htmlGet hashmaliciousHTMLPhisherBrowse
                • 45.143.99.2
                skid.mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                • 194.29.80.216
                file.exeGet hashmaliciousAmadey, XmrigBrowse
                • 185.154.192.128
                QbQ0spd3GB.elfGet hashmaliciousMiraiBrowse
                • 194.29.80.213
                AFCONC-BLOCK1-ASUSgw3yTM2uiZ.elfGet hashmaliciousMiraiBrowse
                • 132.37.39.147
                5Ghgetzec2.elfGet hashmaliciousMiraiBrowse
                • 147.74.215.63
                qgtfQPgL23.elfGet hashmaliciousUnknownBrowse
                • 132.4.144.101
                y7cm9CKSN9.elfGet hashmaliciousMiraiBrowse
                • 131.36.72.80
                b3lcTjArym.elfGet hashmaliciousMiraiBrowse
                • 133.176.84.21
                arm7.elfGet hashmaliciousMiraiBrowse
                • 143.144.150.34
                arm5.elfGet hashmaliciousMiraiBrowse
                • 132.16.254.93
                arm4.elfGet hashmaliciousMiraiBrowse
                • 131.28.30.51
                45.128.232.240-mips-2024-07-06T07_07_43.elfGet hashmaliciousMiraiBrowse
                • 132.51.38.171
                arm5-20240706-0316.elfGet hashmaliciousMiraiBrowse
                • 129.239.85.104
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                28a2c9bd18a11de089ef85a160da29e4https://inodive.us/css/ZC5zYXV0aWVyQHNibS5tYw==Get hashmaliciousHTMLPhisherBrowse
                • 52.165.165.26
                • 20.114.59.183
                V-Mail_maryland.gov.htmlGet hashmaliciousHTMLPhisher, Tycoon2FABrowse
                • 52.165.165.26
                • 20.114.59.183
                V-Mail_maryland.gov.htmlGet hashmaliciousHTMLPhisher, Tycoon2FABrowse
                • 52.165.165.26
                • 20.114.59.183
                https://www.searchvity.comGet hashmaliciousUnknownBrowse
                • 52.165.165.26
                • 20.114.59.183
                https://www.cognitoforms.com/Bellis2/BELLISAUSTRALIAPTYLTDGet hashmaliciousHTMLPhisherBrowse
                • 52.165.165.26
                • 20.114.59.183
                https://mail.pfl.fyi/v1/messages/01909fdd-253c-74e4-a4d4-2d3080c42178/click?link_id=01909fdd-2577-78fa-9aa1-1363f665f21c&signature=ec89d906ae45cddf78ff2ac5ff90a7b4fb4098deGet hashmaliciousUnknownBrowse
                • 52.165.165.26
                • 20.114.59.183
                SecuriteInfo.com.not-a-virus.HEUR.RemoteAdmin.Win32.Conne.gen.1416.17840.exeGet hashmaliciousUnknownBrowse
                • 52.165.165.26
                • 20.114.59.183
                tmp3A62.htmGet hashmaliciousUnknownBrowse
                • 52.165.165.26
                • 20.114.59.183
                https://zzmc.tatateri.com/lPY0TK6A/#Mandrew.lapkin@innocap.comGet hashmaliciousHTMLPhisher, Tycoon2FABrowse
                • 52.165.165.26
                • 20.114.59.183
                terence.tinnelly-TT SLIP-PDF.shtmlGet hashmaliciousHTMLPhisherBrowse
                • 52.165.165.26
                • 20.114.59.183
                No context
                Process:C:\Users\user\Desktop\yrBA01LVo2.exe
                File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):2061938
                Entropy (8bit):7.644344821595419
                Encrypted:false
                SSDEEP:49152:kMSPbcBVQej/1INMx+TSqTdX1H76SAARdhn:kPoBhz1aMxcSUD76SAEdh
                MD5:67A9A3C2AFEFCD2471C4405E7C75DA52
                SHA1:74DA4F8247EA27133F8EDCDA3EA68125E8117ACD
                SHA-256:6DD4D141569239F6B8A5D283DEAE75862E75B3243F7AB7A8016DA476C3753506
                SHA-512:C65385BB3A4C3ACF5AEF6C2C32791EBD3BAA784807066396A056129B10A04E8D8A644975405A96A937835BDAD06262B40BEF8550C1075BCDA34736BC8A6737A4
                Malicious:true
                Antivirus:
                • Antivirus: Joe Sandbox ML, Detection: 100%
                • Antivirus: ReversingLabs, Detection: 87%
                • Antivirus: Virustotal, Detection: 83%, Browse
                Reputation:low
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                File type:PE32 executable (GUI) Intel 80386, for MS Windows
                Entropy (8bit):7.536718359358342
                TrID:
                • Win32 Executable (generic) a (10002005/4) 99.96%
                • Generic Win/DOS Executable (2004/3) 0.02%
                • DOS Executable Generic (2002/1) 0.02%
                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                File name:yrBA01LVo2.exe
                File size:2'281'472 bytes
                MD5:da8dde3005365992711946c4622a3c74
                SHA1:d04042cd11cd11f3b6386a5e2275f14b92048fc6
                SHA256:2a62c57ba98308fe2316508f077186b76e5ad55a1e367e58d19e5a9b08900eec
                SHA512:a06f8a53e5cd7e80429c2d7339f0c7d78a1d384da2fccb23a0cee5c7e9f39dbe3e73bac0ee271b84f3cfa8a545a57bcf592446666b6381397df20beb644a77e7
                SSDEEP:49152:QnaMSPbcBVQej/1INMx+TSqTdX1H76SAARdhn:QaPoBhz1aMxcSUD76SAEdh
                TLSH:E1B5239A716C90F4C2092A7494BB8E12F6B67C3E21FA690BEF4089762C53F56F750743
                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......U<S..]=..]=..]=.jA1..]=..A3..]=.~B7..]=.~B6..]=.~B9..]=..R`..]=..]<.J]=.'{6..]=..[;..]=.Rich.]=.........................PE..L..
                Icon Hash:00928e8e8686b000
                Entrypoint:0x409a16
                Entrypoint Section:.text
                Digitally signed:false
                Imagebase:0x400000
                Subsystem:windows gui
                Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                DLL Characteristics:
                Time Stamp:0x4CE78ECC [Sat Nov 20 09:03:08 2010 UTC]
                TLS Callbacks:
                CLR (.Net) Version:
                OS Version Major:4
                OS Version Minor:0
                File Version Major:4
                File Version Minor:0
                Subsystem Version Major:4
                Subsystem Version Minor:0
                Import Hash:9ecee117164e0b870a53dd187cdd7174
                Instruction
                push ebp
                mov ebp, esp
                push FFFFFFFFh
                push 0040A1A0h
                push 00409BA2h
                mov eax, dword ptr fs:[00000000h]
                push eax
                mov dword ptr fs:[00000000h], esp
                sub esp, 68h
                push ebx
                push esi
                push edi
                mov dword ptr [ebp-18h], esp
                xor ebx, ebx
                mov dword ptr [ebp-04h], ebx
                push 00000002h
                call dword ptr [0040A0C0h]
                pop ecx
                or dword ptr [0070F894h], FFFFFFFFh
                or dword ptr [0070F898h], FFFFFFFFh
                call dword ptr [0040A0C8h]
                mov ecx, dword ptr [0070F88Ch]
                mov dword ptr [eax], ecx
                call dword ptr [0040A0CCh]
                mov ecx, dword ptr [0070F888h]
                mov dword ptr [eax], ecx
                mov eax, dword ptr [0040A0E4h]
                mov eax, dword ptr [eax]
                mov dword ptr [0070F890h], eax
                call 00007F9CB0CAFEC1h
                cmp dword ptr [00431410h], ebx
                jne 00007F9CB0CAFDAEh
                push 00409B9Eh
                call dword ptr [0040A0D4h]
                pop ecx
                call 00007F9CB0CAFE93h
                push 0040B010h
                push 0040B00Ch
                call 00007F9CB0CAFE7Eh
                mov eax, dword ptr [0070F884h]
                mov dword ptr [ebp-6Ch], eax
                lea eax, dword ptr [ebp-6Ch]
                push eax
                push dword ptr [0070F880h]
                lea eax, dword ptr [ebp-64h]
                push eax
                lea eax, dword ptr [ebp-70h]
                push eax
                lea eax, dword ptr [ebp-60h]
                push eax
                call dword ptr [0040A0DCh]
                push 0040B008h
                push 0040B000h
                call 00007F9CB0CAFE4Bh
                Programming Language:
                • [C++] VS98 (6.0) SP6 build 8804
                • [EXP] VC++ 6.0 SP5 build 8804
                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IMPORT0xa1e00xa0.rdata
                IMAGE_DIRECTORY_ENTRY_RESOURCE0x3100000x1f7ac8.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0xa0000x188.rdata
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x10000x8bca0x90002553ad9eb2f493e7b1b370f52918de23False0.5344509548611112data6.1344811887775705IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .rdata0xa0000x9980x1000d8037d744b539326c06e897625751cc9False0.29345703125data3.503615586181224IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .data0xb0000x30489c0x27000d7a08f7da8df3f627ed4820cda4fb8e2unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .rsrc0x3100000x1f80000x1f80005e002891cdcce84d9f8201f8de5ca41funknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                NameRVASizeTypeLanguageCountryZLIB Complexity
                R0x3100a40x1f7672PE32 executable (GUI) Intel 80386, for MS WindowsEnglishUnited States0.971949577331543
                RT_VERSION0x5077180x3b0dataEnglishUnited States0.018008474576271187
                DLLImport
                KERNEL32.dllWaitForSingleObject, InterlockedIncrement, GetCurrentThreadId, GetCurrentThread, ReadFile, GetFileSize, CreateFileA, MoveFileExA, SizeofResource, TerminateThread, LoadResource, FindResourceA, GetProcAddress, GetModuleHandleW, ExitProcess, GetModuleFileNameA, LocalFree, LocalAlloc, CloseHandle, InterlockedDecrement, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, GlobalAlloc, GlobalFree, QueryPerformanceFrequency, QueryPerformanceCounter, GetTickCount, LockResource, Sleep, GetStartupInfoA, GetModuleHandleA
                ADVAPI32.dllStartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, ChangeServiceConfig2A, SetServiceStatus, OpenSCManagerA, CreateServiceA, CloseServiceHandle, StartServiceA, CryptGenRandom, CryptAcquireContextA, OpenServiceA
                WS2_32.dllclosesocket, recv, send, htonl, ntohl, WSAStartup, inet_ntoa, ioctlsocket, select, htons, socket, connect, inet_addr
                MSVCP60.dll??1_Lockit@std@@QAE@XZ, ??0_Lockit@std@@QAE@XZ
                iphlpapi.dllGetAdaptersInfo, GetPerAdapterInfo
                WININET.dllInternetOpenA, InternetOpenUrlA, InternetCloseHandle
                MSVCRT.dll__set_app_type, _stricmp, __p__fmode, __p__commode, _except_handler3, __setusermatherr, _initterm, __getmainargs, _acmdln, _adjust_fdiv, _controlfp, exit, _XcptFilter, _exit, _onexit, __dllonexit, free, ??2@YAPAXI@Z, _ftol, sprintf, _endthreadex, strncpy, rand, _beginthreadex, __CxxFrameHandler, srand, time, __p___argc
                Language of compilation systemCountry where language is spokenMap
                EnglishUnited States
                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                07/12/24-08:11:55.324048UDP2830018ETPRO TROJAN Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)5736753192.168.2.51.1.1.1
                TimestampSource PortDest PortSource IPDest IP
                Jul 12, 2024 08:11:53.263302088 CEST49674443192.168.2.523.1.237.91
                Jul 12, 2024 08:11:53.263577938 CEST49675443192.168.2.523.1.237.91
                Jul 12, 2024 08:11:53.372781038 CEST49673443192.168.2.523.1.237.91
                Jul 12, 2024 08:11:55.490084887 CEST4970480192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:55.495085955 CEST8049704103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:55.495177984 CEST4970480192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:55.495357037 CEST4970480192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:55.500293970 CEST8049704103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:56.187971115 CEST8049704103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:56.188028097 CEST8049704103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:56.188086987 CEST4970480192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:56.188087940 CEST4970480192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:56.193460941 CEST4970480192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:56.198339939 CEST8049704103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:56.440412045 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:56.445314884 CEST8049705199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:56.445528984 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:56.445528984 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:56.452194929 CEST8049705199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:56.907282114 CEST8049705199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:56.907345057 CEST8049705199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:56.907423019 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:56.907423019 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:56.986206055 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:56.986206055 CEST4970580192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:57.243500948 CEST4970680192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:57.248625994 CEST8049706103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:57.248749971 CEST4970680192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:57.248883009 CEST4970680192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:57.253648996 CEST8049706103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:57.877907991 CEST8049706103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:57.877940893 CEST8049706103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:57.878020048 CEST4970680192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:57.881385088 CEST4970680192.168.2.5103.224.212.215
                Jul 12, 2024 08:11:57.883378029 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:57.886296034 CEST8049706103.224.212.215192.168.2.5
                Jul 12, 2024 08:11:57.888436079 CEST8049707199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:57.888520956 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:57.888644934 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:57.893409014 CEST8049707199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:58.364789009 CEST8049707199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:58.364880085 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:58.364913940 CEST8049707199.59.243.226192.168.2.5
                Jul 12, 2024 08:11:58.364954948 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:58.371155977 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:58.371207952 CEST4970780192.168.2.5199.59.243.226
                Jul 12, 2024 08:11:58.401921034 CEST49708445192.168.2.5204.59.96.4
                Jul 12, 2024 08:11:58.407017946 CEST44549708204.59.96.4192.168.2.5
                Jul 12, 2024 08:11:58.407097101 CEST49708445192.168.2.5204.59.96.4
                Jul 12, 2024 08:11:58.407711029 CEST49708445192.168.2.5204.59.96.4
                Jul 12, 2024 08:11:58.407877922 CEST49709445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.412619114 CEST44549708204.59.96.4192.168.2.5
                Jul 12, 2024 08:11:58.412946939 CEST44549709204.59.96.1192.168.2.5
                Jul 12, 2024 08:11:58.414190054 CEST49708445192.168.2.5204.59.96.4
                Jul 12, 2024 08:11:58.414206982 CEST49709445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.414267063 CEST49709445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.417023897 CEST49710445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.419600964 CEST44549709204.59.96.1192.168.2.5
                Jul 12, 2024 08:11:58.419645071 CEST49709445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.421920061 CEST44549710204.59.96.1192.168.2.5
                Jul 12, 2024 08:11:58.421969891 CEST49710445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.422027111 CEST49710445192.168.2.5204.59.96.1
                Jul 12, 2024 08:11:58.426852942 CEST44549710204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:00.405356884 CEST49733445192.168.2.589.248.166.97
                Jul 12, 2024 08:12:00.410665035 CEST4454973389.248.166.97192.168.2.5
                Jul 12, 2024 08:12:00.413393021 CEST49733445192.168.2.589.248.166.97
                Jul 12, 2024 08:12:00.413434982 CEST49733445192.168.2.589.248.166.97
                Jul 12, 2024 08:12:00.413866997 CEST49734445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.418833017 CEST4454973489.248.166.1192.168.2.5
                Jul 12, 2024 08:12:00.418914080 CEST49734445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.418955088 CEST49734445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.419097900 CEST4454973389.248.166.97192.168.2.5
                Jul 12, 2024 08:12:00.419143915 CEST49733445192.168.2.589.248.166.97
                Jul 12, 2024 08:12:00.420291901 CEST49735445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.427531958 CEST4454973489.248.166.1192.168.2.5
                Jul 12, 2024 08:12:00.427576065 CEST4454973589.248.166.1192.168.2.5
                Jul 12, 2024 08:12:00.427769899 CEST49735445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.427769899 CEST49735445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.428584099 CEST4454973489.248.166.1192.168.2.5
                Jul 12, 2024 08:12:00.428636074 CEST49734445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:00.432831049 CEST4454973589.248.166.1192.168.2.5
                Jul 12, 2024 08:12:02.422385931 CEST49758445192.168.2.550.247.21.47
                Jul 12, 2024 08:12:02.427690029 CEST4454975850.247.21.47192.168.2.5
                Jul 12, 2024 08:12:02.427802086 CEST49758445192.168.2.550.247.21.47
                Jul 12, 2024 08:12:02.427803040 CEST49758445192.168.2.550.247.21.47
                Jul 12, 2024 08:12:02.428133011 CEST49759445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.433077097 CEST4454975950.247.21.1192.168.2.5
                Jul 12, 2024 08:12:02.433159113 CEST49759445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.433214903 CEST49759445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.433387995 CEST4454975850.247.21.47192.168.2.5
                Jul 12, 2024 08:12:02.433444023 CEST49758445192.168.2.550.247.21.47
                Jul 12, 2024 08:12:02.434299946 CEST49760445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.438780069 CEST4454975950.247.21.1192.168.2.5
                Jul 12, 2024 08:12:02.438853025 CEST49759445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.439157009 CEST4454976050.247.21.1192.168.2.5
                Jul 12, 2024 08:12:02.439212084 CEST49760445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.439245939 CEST49760445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:02.444072008 CEST4454976050.247.21.1192.168.2.5
                Jul 12, 2024 08:12:02.872777939 CEST49674443192.168.2.523.1.237.91
                Jul 12, 2024 08:12:02.872826099 CEST49675443192.168.2.523.1.237.91
                Jul 12, 2024 08:12:02.982063055 CEST49673443192.168.2.523.1.237.91
                Jul 12, 2024 08:12:04.437799931 CEST49781445192.168.2.5203.155.53.22
                Jul 12, 2024 08:12:04.442893028 CEST44549781203.155.53.22192.168.2.5
                Jul 12, 2024 08:12:04.443012953 CEST49781445192.168.2.5203.155.53.22
                Jul 12, 2024 08:12:04.443062067 CEST49781445192.168.2.5203.155.53.22
                Jul 12, 2024 08:12:04.443253994 CEST49782445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.448102951 CEST44549782203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:04.448194027 CEST49782445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.448225975 CEST49782445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.448540926 CEST44549781203.155.53.22192.168.2.5
                Jul 12, 2024 08:12:04.448616028 CEST49781445192.168.2.5203.155.53.22
                Jul 12, 2024 08:12:04.449423075 CEST49783445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.453717947 CEST44549782203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:04.453769922 CEST49782445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.454293966 CEST44549783203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:04.454379082 CEST49783445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.454408884 CEST49783445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:04.459273100 CEST44549783203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:04.661717892 CEST4434970323.1.237.91192.168.2.5
                Jul 12, 2024 08:12:04.661859035 CEST49703443192.168.2.523.1.237.91
                Jul 12, 2024 08:12:06.457360029 CEST49804445192.168.2.5160.232.165.7
                Jul 12, 2024 08:12:06.463798046 CEST44549804160.232.165.7192.168.2.5
                Jul 12, 2024 08:12:06.463886023 CEST49804445192.168.2.5160.232.165.7
                Jul 12, 2024 08:12:06.463970900 CEST49804445192.168.2.5160.232.165.7
                Jul 12, 2024 08:12:06.464212894 CEST49805445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.469290018 CEST44549805160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:06.469376087 CEST49805445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.469448090 CEST49805445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.470849037 CEST44549804160.232.165.7192.168.2.5
                Jul 12, 2024 08:12:06.471911907 CEST44549804160.232.165.7192.168.2.5
                Jul 12, 2024 08:12:06.472059965 CEST49804445192.168.2.5160.232.165.7
                Jul 12, 2024 08:12:06.480350018 CEST44549805160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:06.480621099 CEST44549805160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:06.480678082 CEST49805445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.507258892 CEST49806445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.512320042 CEST44549806160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:06.512388945 CEST49806445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.512437105 CEST49806445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:06.517277956 CEST44549806160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:08.467606068 CEST49829445192.168.2.5183.227.189.235
                Jul 12, 2024 08:12:08.472903967 CEST44549829183.227.189.235192.168.2.5
                Jul 12, 2024 08:12:08.472992897 CEST49829445192.168.2.5183.227.189.235
                Jul 12, 2024 08:12:08.473135948 CEST49829445192.168.2.5183.227.189.235
                Jul 12, 2024 08:12:08.473364115 CEST49830445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.478282928 CEST44549830183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:08.478354931 CEST49830445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.478394032 CEST49830445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.478566885 CEST44549829183.227.189.235192.168.2.5
                Jul 12, 2024 08:12:08.478627920 CEST49829445192.168.2.5183.227.189.235
                Jul 12, 2024 08:12:08.479590893 CEST49831445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.484318972 CEST44549830183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:08.484390020 CEST49830445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.484571934 CEST44549831183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:08.484635115 CEST49831445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.484673977 CEST49831445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:08.490684986 CEST44549831183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:10.482675076 CEST49853445192.168.2.596.158.114.43
                Jul 12, 2024 08:12:10.489209890 CEST4454985396.158.114.43192.168.2.5
                Jul 12, 2024 08:12:10.489321947 CEST49853445192.168.2.596.158.114.43
                Jul 12, 2024 08:12:10.489388943 CEST49853445192.168.2.596.158.114.43
                Jul 12, 2024 08:12:10.489689112 CEST49854445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.494617939 CEST4454985396.158.114.43192.168.2.5
                Jul 12, 2024 08:12:10.494669914 CEST4454985496.158.114.1192.168.2.5
                Jul 12, 2024 08:12:10.494685888 CEST49853445192.168.2.596.158.114.43
                Jul 12, 2024 08:12:10.494745970 CEST49854445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.494795084 CEST49854445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.495095015 CEST49855445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.500228882 CEST4454985496.158.114.1192.168.2.5
                Jul 12, 2024 08:12:10.500253916 CEST4454985596.158.114.1192.168.2.5
                Jul 12, 2024 08:12:10.500313997 CEST49854445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.500365973 CEST49855445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.500418901 CEST49855445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:10.505248070 CEST4454985596.158.114.1192.168.2.5
                Jul 12, 2024 08:12:12.498363018 CEST49878445192.168.2.5161.45.66.107
                Jul 12, 2024 08:12:12.503329039 CEST44549878161.45.66.107192.168.2.5
                Jul 12, 2024 08:12:12.503412962 CEST49878445192.168.2.5161.45.66.107
                Jul 12, 2024 08:12:12.503556967 CEST49878445192.168.2.5161.45.66.107
                Jul 12, 2024 08:12:12.503570080 CEST49879445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.508423090 CEST44549879161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:12.508506060 CEST49879445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.508759975 CEST49880445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.508759975 CEST49879445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.509474039 CEST44549878161.45.66.107192.168.2.5
                Jul 12, 2024 08:12:12.509520054 CEST49878445192.168.2.5161.45.66.107
                Jul 12, 2024 08:12:12.513659954 CEST44549880161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:12.513730049 CEST49880445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.513765097 CEST49880445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.513914108 CEST44549879161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:12.513957977 CEST49879445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:12.518513918 CEST44549880161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:13.199069023 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:13.199100018 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:13.199167013 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:13.200540066 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:13.200547934 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:13.890430927 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:13.890642881 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:13.894138098 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:13.894149065 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:13.894401073 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:13.935153008 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:14.465157032 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:14.508497000 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:14.513660908 CEST49905445192.168.2.5149.78.23.8
                Jul 12, 2024 08:12:14.518677950 CEST44549905149.78.23.8192.168.2.5
                Jul 12, 2024 08:12:14.518745899 CEST49905445192.168.2.5149.78.23.8
                Jul 12, 2024 08:12:14.518786907 CEST49905445192.168.2.5149.78.23.8
                Jul 12, 2024 08:12:14.518850088 CEST49906445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.523642063 CEST44549906149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:14.523699999 CEST49906445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.523725033 CEST49906445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.524051905 CEST49907445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.524518013 CEST44549905149.78.23.8192.168.2.5
                Jul 12, 2024 08:12:14.524580956 CEST49905445192.168.2.5149.78.23.8
                Jul 12, 2024 08:12:14.528898001 CEST44549907149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:14.528959990 CEST49907445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.529000044 CEST49907445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.529064894 CEST44549906149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:14.529123068 CEST49906445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:14.533786058 CEST44549907149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:15.700793028 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.700812101 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.700834990 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.700882912 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.700958967 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:15.700968981 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.700974941 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.700998068 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:15.701040983 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:15.701083899 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.701174974 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:15.701179028 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.701195955 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:15.701361895 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:16.217016935 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:16.217016935 CEST49887443192.168.2.552.165.165.26
                Jul 12, 2024 08:12:16.217032909 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:16.217040062 CEST4434988752.165.165.26192.168.2.5
                Jul 12, 2024 08:12:16.529568911 CEST49933445192.168.2.5192.12.185.53
                Jul 12, 2024 08:12:16.534626961 CEST44549933192.12.185.53192.168.2.5
                Jul 12, 2024 08:12:16.534845114 CEST49933445192.168.2.5192.12.185.53
                Jul 12, 2024 08:12:16.534954071 CEST49933445192.168.2.5192.12.185.53
                Jul 12, 2024 08:12:16.535176992 CEST49934445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.540025949 CEST44549934192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:16.540096045 CEST49934445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.540169001 CEST49934445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.540262938 CEST44549933192.12.185.53192.168.2.5
                Jul 12, 2024 08:12:16.540524006 CEST49935445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.540847063 CEST49933445192.168.2.5192.12.185.53
                Jul 12, 2024 08:12:16.545433998 CEST44549935192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:16.545591116 CEST49935445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.545591116 CEST49935445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.545763016 CEST44549934192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:16.545840979 CEST49934445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:16.550687075 CEST44549935192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:17.445148945 CEST5686753192.168.2.51.1.1.1
                Jul 12, 2024 08:12:17.450381041 CEST53568671.1.1.1192.168.2.5
                Jul 12, 2024 08:12:17.450474024 CEST5686753192.168.2.51.1.1.1
                Jul 12, 2024 08:12:17.455471039 CEST53568671.1.1.1192.168.2.5
                Jul 12, 2024 08:12:17.902652979 CEST5686753192.168.2.51.1.1.1
                Jul 12, 2024 08:12:17.907849073 CEST53568671.1.1.1192.168.2.5
                Jul 12, 2024 08:12:17.908348083 CEST5686753192.168.2.51.1.1.1
                Jul 12, 2024 08:12:18.545186043 CEST56881445192.168.2.527.249.74.141
                Jul 12, 2024 08:12:18.550277948 CEST4455688127.249.74.141192.168.2.5
                Jul 12, 2024 08:12:18.550374031 CEST56881445192.168.2.527.249.74.141
                Jul 12, 2024 08:12:18.550414085 CEST56881445192.168.2.527.249.74.141
                Jul 12, 2024 08:12:18.550519943 CEST56882445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.555247068 CEST4455688227.249.74.1192.168.2.5
                Jul 12, 2024 08:12:18.555299044 CEST56882445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.555311918 CEST56882445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.555604935 CEST56883445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.555671930 CEST4455688127.249.74.141192.168.2.5
                Jul 12, 2024 08:12:18.555727959 CEST56881445192.168.2.527.249.74.141
                Jul 12, 2024 08:12:18.560393095 CEST4455688327.249.74.1192.168.2.5
                Jul 12, 2024 08:12:18.560760021 CEST4455688227.249.74.1192.168.2.5
                Jul 12, 2024 08:12:18.564342976 CEST56882445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.564393044 CEST56883445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.564393044 CEST56883445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:18.569477081 CEST4455688327.249.74.1192.168.2.5
                Jul 12, 2024 08:12:19.809998989 CEST44549710204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:19.810131073 CEST49710445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:19.810528040 CEST49710445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:19.810651064 CEST49710445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:19.815376043 CEST44549710204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:19.815385103 CEST44549710204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:20.560558081 CEST56905445192.168.2.5124.175.46.127
                Jul 12, 2024 08:12:21.591942072 CEST44556905124.175.46.127192.168.2.5
                Jul 12, 2024 08:12:21.592051983 CEST56905445192.168.2.5124.175.46.127
                Jul 12, 2024 08:12:21.670949936 CEST56917445192.168.2.56.119.83.71
                Jul 12, 2024 08:12:21.676191092 CEST445569176.119.83.71192.168.2.5
                Jul 12, 2024 08:12:21.676285982 CEST56917445192.168.2.56.119.83.71
                Jul 12, 2024 08:12:21.679920912 CEST56917445192.168.2.56.119.83.71
                Jul 12, 2024 08:12:21.680337906 CEST56918445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.684956074 CEST445569176.119.83.71192.168.2.5
                Jul 12, 2024 08:12:21.685013056 CEST56917445192.168.2.56.119.83.71
                Jul 12, 2024 08:12:21.685302973 CEST445569186.119.83.1192.168.2.5
                Jul 12, 2024 08:12:21.685445070 CEST56918445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.685445070 CEST56918445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.685863972 CEST56919445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.691215038 CEST445569186.119.83.1192.168.2.5
                Jul 12, 2024 08:12:21.691257000 CEST445569186.119.83.1192.168.2.5
                Jul 12, 2024 08:12:21.691296101 CEST445569196.119.83.1192.168.2.5
                Jul 12, 2024 08:12:21.691348076 CEST56919445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.691375017 CEST56919445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.691392899 CEST56918445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:21.696326971 CEST445569196.119.83.1192.168.2.5
                Jul 12, 2024 08:12:21.920176029 CEST4454973589.248.166.1192.168.2.5
                Jul 12, 2024 08:12:21.920289040 CEST49735445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:21.920393944 CEST49735445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:21.920393944 CEST49735445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:21.925291061 CEST4454973589.248.166.1192.168.2.5
                Jul 12, 2024 08:12:21.925335884 CEST4454973589.248.166.1192.168.2.5
                Jul 12, 2024 08:12:22.576272011 CEST56930445192.168.2.519.193.250.173
                Jul 12, 2024 08:12:22.581239939 CEST4455693019.193.250.173192.168.2.5
                Jul 12, 2024 08:12:22.581353903 CEST56930445192.168.2.519.193.250.173
                Jul 12, 2024 08:12:22.581417084 CEST56930445192.168.2.519.193.250.173
                Jul 12, 2024 08:12:22.581659079 CEST56931445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.586551905 CEST4455693119.193.250.1192.168.2.5
                Jul 12, 2024 08:12:22.586632967 CEST56931445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.586658955 CEST4455693019.193.250.173192.168.2.5
                Jul 12, 2024 08:12:22.586708069 CEST56930445192.168.2.519.193.250.173
                Jul 12, 2024 08:12:22.586817980 CEST56931445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.587122917 CEST56932445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.591967106 CEST4455693219.193.250.1192.168.2.5
                Jul 12, 2024 08:12:22.592034101 CEST4455693119.193.250.1192.168.2.5
                Jul 12, 2024 08:12:22.592041016 CEST56932445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.592051029 CEST56932445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.592077971 CEST56931445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:22.596987963 CEST4455693219.193.250.1192.168.2.5
                Jul 12, 2024 08:12:22.826757908 CEST56936445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:22.831902027 CEST44556936204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:22.831981897 CEST56936445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:22.832035065 CEST56936445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:22.836961031 CEST44556936204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:23.810003042 CEST4454976050.247.21.1192.168.2.5
                Jul 12, 2024 08:12:23.810170889 CEST49760445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:23.810265064 CEST49760445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:23.810317993 CEST49760445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:23.815198898 CEST4454976050.247.21.1192.168.2.5
                Jul 12, 2024 08:12:23.815350056 CEST4454976050.247.21.1192.168.2.5
                Jul 12, 2024 08:12:24.592015028 CEST56937445192.168.2.545.205.206.163
                Jul 12, 2024 08:12:24.597527981 CEST4455693745.205.206.163192.168.2.5
                Jul 12, 2024 08:12:24.597668886 CEST56937445192.168.2.545.205.206.163
                Jul 12, 2024 08:12:24.597733021 CEST56937445192.168.2.545.205.206.163
                Jul 12, 2024 08:12:24.597927094 CEST56938445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.602888107 CEST4455693845.205.206.1192.168.2.5
                Jul 12, 2024 08:12:24.602935076 CEST4455693745.205.206.163192.168.2.5
                Jul 12, 2024 08:12:24.602968931 CEST56938445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.602993011 CEST56938445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.603058100 CEST4455693745.205.206.163192.168.2.5
                Jul 12, 2024 08:12:24.603118896 CEST56937445192.168.2.545.205.206.163
                Jul 12, 2024 08:12:24.603302002 CEST56939445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.608167887 CEST4455693945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:24.608237982 CEST56939445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.608273029 CEST56939445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.608309984 CEST4455693845.205.206.1192.168.2.5
                Jul 12, 2024 08:12:24.608371973 CEST56938445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:24.613209963 CEST4455693945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:24.935672998 CEST56940445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:24.940774918 CEST4455694089.248.166.1192.168.2.5
                Jul 12, 2024 08:12:24.940924883 CEST56940445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:24.940983057 CEST56940445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:24.945766926 CEST4455694089.248.166.1192.168.2.5
                Jul 12, 2024 08:12:25.853007078 CEST44549783203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:25.853092909 CEST49783445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:25.853173018 CEST49783445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:25.853240967 CEST49783445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:25.858086109 CEST44549783203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:25.858155012 CEST44549783203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:26.607845068 CEST56941445192.168.2.5192.99.167.126
                Jul 12, 2024 08:12:26.613033056 CEST44556941192.99.167.126192.168.2.5
                Jul 12, 2024 08:12:26.613156080 CEST56941445192.168.2.5192.99.167.126
                Jul 12, 2024 08:12:26.613265991 CEST56941445192.168.2.5192.99.167.126
                Jul 12, 2024 08:12:26.613576889 CEST56942445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.618424892 CEST44556942192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:26.618503094 CEST44556941192.99.167.126192.168.2.5
                Jul 12, 2024 08:12:26.618503094 CEST56942445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.618573904 CEST56941445192.168.2.5192.99.167.126
                Jul 12, 2024 08:12:26.618649006 CEST56942445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.618956089 CEST56943445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.624238968 CEST44556943192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:26.624288082 CEST44556942192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:26.624311924 CEST56943445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.624336004 CEST56942445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.624392986 CEST56943445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:26.629148006 CEST44556943192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:26.827650070 CEST56944445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:26.832968950 CEST4455694450.247.21.1192.168.2.5
                Jul 12, 2024 08:12:26.833101034 CEST56944445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:26.833192110 CEST56944445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:26.838176012 CEST4455694450.247.21.1192.168.2.5
                Jul 12, 2024 08:12:27.905760050 CEST44549806160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:27.906064034 CEST49806445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:27.906064034 CEST49806445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:27.906120062 CEST49806445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:27.911113024 CEST44549806160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:27.911156893 CEST44549806160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:28.651108027 CEST56945445192.168.2.5159.4.73.230
                Jul 12, 2024 08:12:28.656229019 CEST44556945159.4.73.230192.168.2.5
                Jul 12, 2024 08:12:28.656325102 CEST56945445192.168.2.5159.4.73.230
                Jul 12, 2024 08:12:28.658348083 CEST56945445192.168.2.5159.4.73.230
                Jul 12, 2024 08:12:28.658550024 CEST56946445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.663399935 CEST44556945159.4.73.230192.168.2.5
                Jul 12, 2024 08:12:28.663480043 CEST56945445192.168.2.5159.4.73.230
                Jul 12, 2024 08:12:28.663508892 CEST44556946159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:28.663575888 CEST56946445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.663775921 CEST56946445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.666552067 CEST56947445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.673712015 CEST44556947159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:28.673788071 CEST56947445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.675260067 CEST44556946159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:28.675313950 CEST56946445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.679538965 CEST56947445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:28.684470892 CEST44556947159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:28.861778975 CEST56948445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:28.866960049 CEST44556948203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:28.867047071 CEST56948445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:28.867089033 CEST56948445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:28.872010946 CEST44556948203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:29.884303093 CEST44549831183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:29.884440899 CEST49831445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:29.884546041 CEST49831445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:29.884643078 CEST49831445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:29.890018940 CEST44549831183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:29.890031099 CEST44549831183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:30.654367924 CEST56949445192.168.2.5185.148.241.91
                Jul 12, 2024 08:12:30.659343958 CEST44556949185.148.241.91192.168.2.5
                Jul 12, 2024 08:12:30.659414053 CEST56949445192.168.2.5185.148.241.91
                Jul 12, 2024 08:12:30.659590006 CEST56949445192.168.2.5185.148.241.91
                Jul 12, 2024 08:12:30.659789085 CEST56950445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.664540052 CEST44556950185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:30.664597034 CEST56950445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.664638996 CEST56950445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.664817095 CEST44556949185.148.241.91192.168.2.5
                Jul 12, 2024 08:12:30.664859056 CEST56949445192.168.2.5185.148.241.91
                Jul 12, 2024 08:12:30.664998055 CEST56951445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.669867039 CEST44556950185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:30.669887066 CEST44556951185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:30.669914007 CEST56950445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.669955969 CEST56951445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.670028925 CEST56951445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:30.675108910 CEST44556951185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:30.924211979 CEST56952445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:30.929718971 CEST44556952160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:30.929896116 CEST56952445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:30.930006981 CEST56952445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:30.935189009 CEST44556952160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:31.884322882 CEST4454985596.158.114.1192.168.2.5
                Jul 12, 2024 08:12:31.884428978 CEST49855445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:31.884463072 CEST49855445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:31.884499073 CEST49855445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:31.889491081 CEST4454985596.158.114.1192.168.2.5
                Jul 12, 2024 08:12:31.889534950 CEST4454985596.158.114.1192.168.2.5
                Jul 12, 2024 08:12:32.434648037 CEST44556951185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:32.434976101 CEST56951445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:32.435209990 CEST56951445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:32.435210943 CEST56951445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:32.442356110 CEST44556951185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:32.442383051 CEST44556951185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:32.670120001 CEST56953445192.168.2.5105.57.122.136
                Jul 12, 2024 08:12:32.675517082 CEST44556953105.57.122.136192.168.2.5
                Jul 12, 2024 08:12:32.675635099 CEST56953445192.168.2.5105.57.122.136
                Jul 12, 2024 08:12:32.678026915 CEST56953445192.168.2.5105.57.122.136
                Jul 12, 2024 08:12:32.678205967 CEST56954445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.683181047 CEST44556953105.57.122.136192.168.2.5
                Jul 12, 2024 08:12:32.683229923 CEST44556954105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:32.683269978 CEST56953445192.168.2.5105.57.122.136
                Jul 12, 2024 08:12:32.683340073 CEST56954445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.683387995 CEST56954445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.683815002 CEST56955445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.688649893 CEST44556954105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:32.688671112 CEST44556955105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:32.688704967 CEST56954445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.688874960 CEST56955445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.688875914 CEST56955445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:32.693892002 CEST44556955105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:32.888696909 CEST56956445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:32.893755913 CEST44556956183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:32.893857956 CEST56956445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:32.893897057 CEST56956445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:32.898785114 CEST44556956183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:33.903837919 CEST44549880161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:33.904103994 CEST49880445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:33.904104948 CEST49880445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:33.904104948 CEST49880445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:33.909394979 CEST44549880161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:33.909440041 CEST44549880161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:34.545335054 CEST56957445192.168.2.5217.123.9.234
                Jul 12, 2024 08:12:34.550539970 CEST44556957217.123.9.234192.168.2.5
                Jul 12, 2024 08:12:34.550642967 CEST56957445192.168.2.5217.123.9.234
                Jul 12, 2024 08:12:34.550731897 CEST56957445192.168.2.5217.123.9.234
                Jul 12, 2024 08:12:34.550930023 CEST56958445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.555891037 CEST44556958217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:34.555965900 CEST56958445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.556005955 CEST56958445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.556153059 CEST44556957217.123.9.234192.168.2.5
                Jul 12, 2024 08:12:34.556322098 CEST56957445192.168.2.5217.123.9.234
                Jul 12, 2024 08:12:34.556360960 CEST56959445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.561829090 CEST44556958217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:34.561873913 CEST44556959217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:34.561898947 CEST56958445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.561927080 CEST56959445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.561959028 CEST56959445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:34.566832066 CEST44556959217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:34.888612986 CEST56960445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:34.894140005 CEST4455696096.158.114.1192.168.2.5
                Jul 12, 2024 08:12:34.894273996 CEST56960445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:34.894315958 CEST56960445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:34.899709940 CEST4455696096.158.114.1192.168.2.5
                Jul 12, 2024 08:12:35.436013937 CEST56961445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:35.442847013 CEST44556961185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:35.443111897 CEST56961445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:35.443111897 CEST56961445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:35.450242996 CEST44556961185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:35.916590929 CEST44549907149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:35.916753054 CEST49907445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:35.916862965 CEST49907445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:35.916862965 CEST49907445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:35.921909094 CEST44549907149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:35.921952963 CEST44549907149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:36.295643091 CEST56962445192.168.2.510.50.70.81
                Jul 12, 2024 08:12:36.300717115 CEST4455696210.50.70.81192.168.2.5
                Jul 12, 2024 08:12:36.300966024 CEST56962445192.168.2.510.50.70.81
                Jul 12, 2024 08:12:36.300966978 CEST56962445192.168.2.510.50.70.81
                Jul 12, 2024 08:12:36.301067114 CEST56963445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.305902004 CEST4455696310.50.70.1192.168.2.5
                Jul 12, 2024 08:12:36.305994987 CEST56963445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.306087971 CEST56963445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.306453943 CEST56964445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.306566954 CEST4455696210.50.70.81192.168.2.5
                Jul 12, 2024 08:12:36.306644917 CEST56962445192.168.2.510.50.70.81
                Jul 12, 2024 08:12:36.311449051 CEST4455696310.50.70.1192.168.2.5
                Jul 12, 2024 08:12:36.311465979 CEST4455696410.50.70.1192.168.2.5
                Jul 12, 2024 08:12:36.311544895 CEST56963445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.311582088 CEST56964445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.311639071 CEST56964445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:36.316797972 CEST4455696410.50.70.1192.168.2.5
                Jul 12, 2024 08:12:36.919892073 CEST56965445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:36.925002098 CEST44556965161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:36.925110102 CEST56965445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:36.925158024 CEST56965445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:36.930073977 CEST44556965161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:37.221133947 CEST44556961185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:37.221414089 CEST56961445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:37.221518040 CEST56961445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:37.221518040 CEST56961445192.168.2.5185.148.241.1
                Jul 12, 2024 08:12:37.226700068 CEST44556961185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:37.226746082 CEST44556961185.148.241.1192.168.2.5
                Jul 12, 2024 08:12:37.295105934 CEST56966445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.300059080 CEST44556966185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:37.300196886 CEST56966445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.303798914 CEST56966445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.304225922 CEST56967445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.308716059 CEST44556966185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:37.308794975 CEST56966445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.308989048 CEST44556967185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:37.309050083 CEST56967445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.309211016 CEST56967445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:37.314047098 CEST44556967185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:37.936079979 CEST56968445192.168.2.563.194.252.161
                Jul 12, 2024 08:12:37.937338114 CEST44549935192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:37.937800884 CEST49935445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:37.937918901 CEST49935445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:37.937918901 CEST49935445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:37.941600084 CEST4455696863.194.252.161192.168.2.5
                Jul 12, 2024 08:12:37.941911936 CEST56968445192.168.2.563.194.252.161
                Jul 12, 2024 08:12:37.941911936 CEST56968445192.168.2.563.194.252.161
                Jul 12, 2024 08:12:37.942152023 CEST56969445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.942861080 CEST44549935192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:37.942953110 CEST44549935192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:37.946980000 CEST4455696963.194.252.1192.168.2.5
                Jul 12, 2024 08:12:37.947047949 CEST56969445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.947069883 CEST56969445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.947365999 CEST4455696863.194.252.161192.168.2.5
                Jul 12, 2024 08:12:37.947429895 CEST56970445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.947508097 CEST56968445192.168.2.563.194.252.161
                Jul 12, 2024 08:12:37.952229977 CEST4455697063.194.252.1192.168.2.5
                Jul 12, 2024 08:12:37.952323914 CEST56970445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.952323914 CEST56970445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.952358007 CEST4455696963.194.252.1192.168.2.5
                Jul 12, 2024 08:12:37.952419996 CEST56969445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:37.957257032 CEST4455697063.194.252.1192.168.2.5
                Jul 12, 2024 08:12:38.919666052 CEST56971445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:38.924731016 CEST44556971149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:38.924793005 CEST56971445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:38.924818039 CEST56971445192.168.2.5149.78.23.1
                Jul 12, 2024 08:12:38.929687977 CEST44556971149.78.23.1192.168.2.5
                Jul 12, 2024 08:12:39.467099905 CEST56972445192.168.2.5133.184.83.24
                Jul 12, 2024 08:12:39.472099066 CEST44556972133.184.83.24192.168.2.5
                Jul 12, 2024 08:12:39.472193956 CEST56972445192.168.2.5133.184.83.24
                Jul 12, 2024 08:12:39.472233057 CEST56972445192.168.2.5133.184.83.24
                Jul 12, 2024 08:12:39.472413063 CEST56973445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.477159977 CEST44556973133.184.83.1192.168.2.5
                Jul 12, 2024 08:12:39.477209091 CEST56973445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.477233887 CEST56973445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.477397919 CEST44556972133.184.83.24192.168.2.5
                Jul 12, 2024 08:12:39.477452040 CEST56972445192.168.2.5133.184.83.24
                Jul 12, 2024 08:12:39.477514982 CEST56974445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.482420921 CEST44556974133.184.83.1192.168.2.5
                Jul 12, 2024 08:12:39.482434034 CEST44556973133.184.83.1192.168.2.5
                Jul 12, 2024 08:12:39.482491016 CEST56974445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.482516050 CEST56973445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.482516050 CEST56974445192.168.2.5133.184.83.1
                Jul 12, 2024 08:12:39.487341881 CEST44556974133.184.83.1192.168.2.5
                Jul 12, 2024 08:12:39.931308031 CEST4455688327.249.74.1192.168.2.5
                Jul 12, 2024 08:12:39.931468964 CEST56883445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:39.947572947 CEST56883445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:39.947648048 CEST56883445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:39.952420950 CEST4455688327.249.74.1192.168.2.5
                Jul 12, 2024 08:12:39.952435017 CEST4455688327.249.74.1192.168.2.5
                Jul 12, 2024 08:12:40.889363050 CEST56975445192.168.2.5149.178.165.169
                Jul 12, 2024 08:12:40.894532919 CEST44556975149.178.165.169192.168.2.5
                Jul 12, 2024 08:12:40.894635916 CEST56975445192.168.2.5149.178.165.169
                Jul 12, 2024 08:12:40.894635916 CEST56975445192.168.2.5149.178.165.169
                Jul 12, 2024 08:12:40.894781113 CEST56976445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.900300980 CEST44556976149.178.165.1192.168.2.5
                Jul 12, 2024 08:12:40.900353909 CEST44556975149.178.165.169192.168.2.5
                Jul 12, 2024 08:12:40.900367022 CEST56976445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.900382042 CEST56976445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.900417089 CEST56975445192.168.2.5149.178.165.169
                Jul 12, 2024 08:12:40.900635958 CEST56977445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.905456066 CEST44556977149.178.165.1192.168.2.5
                Jul 12, 2024 08:12:40.905514002 CEST56977445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.905553102 CEST56977445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.905602932 CEST44556976149.178.165.1192.168.2.5
                Jul 12, 2024 08:12:40.905642033 CEST56976445192.168.2.5149.178.165.1
                Jul 12, 2024 08:12:40.910470009 CEST44556977149.178.165.1192.168.2.5
                Jul 12, 2024 08:12:40.951086044 CEST56978445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:40.956316948 CEST44556978192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:40.956444025 CEST56978445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:40.956521988 CEST56978445192.168.2.5192.12.185.1
                Jul 12, 2024 08:12:40.961441040 CEST44556978192.12.185.1192.168.2.5
                Jul 12, 2024 08:12:42.217015028 CEST56979445192.168.2.5199.9.102.164
                Jul 12, 2024 08:12:42.224246025 CEST44556979199.9.102.164192.168.2.5
                Jul 12, 2024 08:12:42.224380970 CEST56979445192.168.2.5199.9.102.164
                Jul 12, 2024 08:12:42.224473953 CEST56979445192.168.2.5199.9.102.164
                Jul 12, 2024 08:12:42.224526882 CEST56980445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.231756926 CEST44556980199.9.102.1192.168.2.5
                Jul 12, 2024 08:12:42.231878996 CEST56980445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.232211113 CEST56980445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.232213020 CEST56981445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.232263088 CEST44556979199.9.102.164192.168.2.5
                Jul 12, 2024 08:12:42.232315063 CEST56979445192.168.2.5199.9.102.164
                Jul 12, 2024 08:12:42.239398003 CEST44556981199.9.102.1192.168.2.5
                Jul 12, 2024 08:12:42.239494085 CEST56981445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.239531040 CEST56981445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.239866972 CEST44556980199.9.102.1192.168.2.5
                Jul 12, 2024 08:12:42.240019083 CEST56980445192.168.2.5199.9.102.1
                Jul 12, 2024 08:12:42.246562004 CEST44556981199.9.102.1192.168.2.5
                Jul 12, 2024 08:12:42.951248884 CEST56982445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:43.072417974 CEST4455698227.249.74.1192.168.2.5
                Jul 12, 2024 08:12:43.072524071 CEST56982445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:43.072582006 CEST56982445192.168.2.527.249.74.1
                Jul 12, 2024 08:12:43.079873085 CEST4455698227.249.74.1192.168.2.5
                Jul 12, 2024 08:12:43.094089985 CEST445569196.119.83.1192.168.2.5
                Jul 12, 2024 08:12:43.094191074 CEST56919445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:43.094227076 CEST56919445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:43.094252110 CEST56919445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:43.099121094 CEST445569196.119.83.1192.168.2.5
                Jul 12, 2024 08:12:43.099152088 CEST445569196.119.83.1192.168.2.5
                Jul 12, 2024 08:12:43.451443911 CEST56983445192.168.2.5170.120.108.114
                Jul 12, 2024 08:12:43.459383965 CEST44556983170.120.108.114192.168.2.5
                Jul 12, 2024 08:12:43.459588051 CEST56983445192.168.2.5170.120.108.114
                Jul 12, 2024 08:12:43.459588051 CEST56983445192.168.2.5170.120.108.114
                Jul 12, 2024 08:12:43.459588051 CEST56984445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.467294931 CEST44556984170.120.108.1192.168.2.5
                Jul 12, 2024 08:12:43.467396021 CEST56984445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.467396021 CEST56984445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.467684031 CEST56985445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.467897892 CEST44556983170.120.108.114192.168.2.5
                Jul 12, 2024 08:12:43.468065023 CEST56983445192.168.2.5170.120.108.114
                Jul 12, 2024 08:12:43.472564936 CEST44556985170.120.108.1192.168.2.5
                Jul 12, 2024 08:12:43.472640991 CEST56985445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.472682953 CEST56985445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.473047972 CEST44556984170.120.108.1192.168.2.5
                Jul 12, 2024 08:12:43.473218918 CEST56984445192.168.2.5170.120.108.1
                Jul 12, 2024 08:12:43.478622913 CEST44556985170.120.108.1192.168.2.5
                Jul 12, 2024 08:12:43.963052034 CEST4455693219.193.250.1192.168.2.5
                Jul 12, 2024 08:12:43.963221073 CEST56932445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:43.963221073 CEST56932445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:43.963221073 CEST56932445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:43.968225002 CEST4455693219.193.250.1192.168.2.5
                Jul 12, 2024 08:12:43.968255997 CEST4455693219.193.250.1192.168.2.5
                Jul 12, 2024 08:12:44.216911077 CEST44556936204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:44.216993093 CEST56936445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:44.217053890 CEST56936445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:44.217113018 CEST56936445192.168.2.5204.59.96.1
                Jul 12, 2024 08:12:44.222979069 CEST44556936204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:44.223011017 CEST44556936204.59.96.1192.168.2.5
                Jul 12, 2024 08:12:44.279170990 CEST56986445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.284622908 CEST44556986204.59.96.2192.168.2.5
                Jul 12, 2024 08:12:44.284703970 CEST56986445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.284740925 CEST56986445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.285069942 CEST56987445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.290076017 CEST44556987204.59.96.2192.168.2.5
                Jul 12, 2024 08:12:44.290139914 CEST56987445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.290163994 CEST56987445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.290180922 CEST44556986204.59.96.2192.168.2.5
                Jul 12, 2024 08:12:44.290241003 CEST56986445192.168.2.5204.59.96.2
                Jul 12, 2024 08:12:44.295118093 CEST44556987204.59.96.2192.168.2.5
                Jul 12, 2024 08:12:44.607652903 CEST56988445192.168.2.511.223.200.38
                Jul 12, 2024 08:12:44.612917900 CEST4455698811.223.200.38192.168.2.5
                Jul 12, 2024 08:12:44.613137960 CEST56988445192.168.2.511.223.200.38
                Jul 12, 2024 08:12:44.613138914 CEST56988445192.168.2.511.223.200.38
                Jul 12, 2024 08:12:44.613229990 CEST56989445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.618489027 CEST4455698911.223.200.1192.168.2.5
                Jul 12, 2024 08:12:44.618560076 CEST56989445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.618659019 CEST56989445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.618767977 CEST4455698811.223.200.38192.168.2.5
                Jul 12, 2024 08:12:44.619050026 CEST56990445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.619124889 CEST4455698811.223.200.38192.168.2.5
                Jul 12, 2024 08:12:44.619312048 CEST56988445192.168.2.511.223.200.38
                Jul 12, 2024 08:12:44.623894930 CEST4455699011.223.200.1192.168.2.5
                Jul 12, 2024 08:12:44.623972893 CEST56990445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.624021053 CEST56990445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.624598026 CEST4455698911.223.200.1192.168.2.5
                Jul 12, 2024 08:12:44.624655962 CEST56989445192.168.2.511.223.200.1
                Jul 12, 2024 08:12:44.629057884 CEST4455699011.223.200.1192.168.2.5
                Jul 12, 2024 08:12:45.685698032 CEST56991445192.168.2.5144.131.63.187
                Jul 12, 2024 08:12:45.690639019 CEST44556991144.131.63.187192.168.2.5
                Jul 12, 2024 08:12:45.690762997 CEST56991445192.168.2.5144.131.63.187
                Jul 12, 2024 08:12:45.690793991 CEST56991445192.168.2.5144.131.63.187
                Jul 12, 2024 08:12:45.691034079 CEST56992445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.697877884 CEST44556991144.131.63.187192.168.2.5
                Jul 12, 2024 08:12:45.697948933 CEST56991445192.168.2.5144.131.63.187
                Jul 12, 2024 08:12:45.697984934 CEST44556992144.131.63.1192.168.2.5
                Jul 12, 2024 08:12:45.698057890 CEST56992445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.698077917 CEST56992445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.698398113 CEST56993445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.703224897 CEST44556993144.131.63.1192.168.2.5
                Jul 12, 2024 08:12:45.703318119 CEST56993445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.703345060 CEST56993445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.704139948 CEST44556992144.131.63.1192.168.2.5
                Jul 12, 2024 08:12:45.704200983 CEST56992445192.168.2.5144.131.63.1
                Jul 12, 2024 08:12:45.708194971 CEST44556993144.131.63.1192.168.2.5
                Jul 12, 2024 08:12:45.995764017 CEST4455693945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:45.996073008 CEST56939445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:45.996073008 CEST56939445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:45.996124029 CEST56939445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:46.000921011 CEST4455693945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:46.000960112 CEST4455693945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:46.107276917 CEST56994445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:46.112457037 CEST445569946.119.83.1192.168.2.5
                Jul 12, 2024 08:12:46.112565994 CEST56994445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:46.112577915 CEST56994445192.168.2.56.119.83.1
                Jul 12, 2024 08:12:46.117423058 CEST445569946.119.83.1192.168.2.5
                Jul 12, 2024 08:12:46.341962099 CEST4455694089.248.166.1192.168.2.5
                Jul 12, 2024 08:12:46.342200994 CEST56940445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:46.342200994 CEST56940445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:46.342200994 CEST56940445192.168.2.589.248.166.1
                Jul 12, 2024 08:12:46.350481033 CEST4455694089.248.166.1192.168.2.5
                Jul 12, 2024 08:12:46.350513935 CEST4455694089.248.166.1192.168.2.5
                Jul 12, 2024 08:12:46.404443026 CEST56995445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.409815073 CEST4455699589.248.166.2192.168.2.5
                Jul 12, 2024 08:12:46.409924030 CEST56995445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.409961939 CEST56995445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.415513039 CEST56996445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.415541887 CEST4455699589.248.166.2192.168.2.5
                Jul 12, 2024 08:12:46.415611982 CEST56995445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.420722961 CEST4455699689.248.166.2192.168.2.5
                Jul 12, 2024 08:12:46.420816898 CEST56996445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.422894001 CEST56996445192.168.2.589.248.166.2
                Jul 12, 2024 08:12:46.430551052 CEST4455699689.248.166.2192.168.2.5
                Jul 12, 2024 08:12:46.735378027 CEST56997445192.168.2.558.98.198.169
                Jul 12, 2024 08:12:46.740391016 CEST4455699758.98.198.169192.168.2.5
                Jul 12, 2024 08:12:46.740462065 CEST56997445192.168.2.558.98.198.169
                Jul 12, 2024 08:12:46.740523100 CEST56997445192.168.2.558.98.198.169
                Jul 12, 2024 08:12:46.740654945 CEST56998445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.745584011 CEST4455699858.98.198.1192.168.2.5
                Jul 12, 2024 08:12:46.745660067 CEST56998445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.745711088 CEST56998445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.745884895 CEST4455699758.98.198.169192.168.2.5
                Jul 12, 2024 08:12:46.745965958 CEST56997445192.168.2.558.98.198.169
                Jul 12, 2024 08:12:46.748497009 CEST56999445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.751259089 CEST4455699858.98.198.1192.168.2.5
                Jul 12, 2024 08:12:46.751316071 CEST56998445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.753773928 CEST4455699958.98.198.1192.168.2.5
                Jul 12, 2024 08:12:46.753833055 CEST56999445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.756424904 CEST56999445192.168.2.558.98.198.1
                Jul 12, 2024 08:12:46.761316061 CEST4455699958.98.198.1192.168.2.5
                Jul 12, 2024 08:12:46.966850042 CEST57000445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:46.972456932 CEST4455700019.193.250.1192.168.2.5
                Jul 12, 2024 08:12:46.972554922 CEST57000445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:46.972596884 CEST57000445192.168.2.519.193.250.1
                Jul 12, 2024 08:12:46.977642059 CEST4455700019.193.250.1192.168.2.5
                Jul 12, 2024 08:12:47.670133114 CEST57001445192.168.2.5146.166.199.132
                Jul 12, 2024 08:12:47.675446987 CEST44557001146.166.199.132192.168.2.5
                Jul 12, 2024 08:12:47.675594091 CEST57001445192.168.2.5146.166.199.132
                Jul 12, 2024 08:12:47.675712109 CEST57001445192.168.2.5146.166.199.132
                Jul 12, 2024 08:12:47.676033020 CEST57002445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.680969000 CEST44557002146.166.199.1192.168.2.5
                Jul 12, 2024 08:12:47.681080103 CEST57002445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.681231022 CEST57002445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.681291103 CEST44557001146.166.199.132192.168.2.5
                Jul 12, 2024 08:12:47.681380987 CEST57001445192.168.2.5146.166.199.132
                Jul 12, 2024 08:12:47.681865931 CEST57003445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.686496973 CEST44557002146.166.199.1192.168.2.5
                Jul 12, 2024 08:12:47.686563969 CEST57002445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.686794996 CEST44557003146.166.199.1192.168.2.5
                Jul 12, 2024 08:12:47.686868906 CEST57003445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.686913013 CEST57003445192.168.2.5146.166.199.1
                Jul 12, 2024 08:12:47.691709042 CEST44557003146.166.199.1192.168.2.5
                Jul 12, 2024 08:12:48.009408951 CEST44556943192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:48.009493113 CEST56943445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:48.009526968 CEST56943445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:48.009565115 CEST56943445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:48.014422894 CEST44556943192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:48.014451027 CEST44556943192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:48.213159084 CEST4455694450.247.21.1192.168.2.5
                Jul 12, 2024 08:12:48.213643074 CEST56944445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:48.213643074 CEST56944445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:48.216464996 CEST56944445192.168.2.550.247.21.1
                Jul 12, 2024 08:12:48.218820095 CEST4455694450.247.21.1192.168.2.5
                Jul 12, 2024 08:12:48.221395969 CEST4455694450.247.21.1192.168.2.5
                Jul 12, 2024 08:12:48.279345989 CEST57004445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.286062956 CEST4455700450.247.21.2192.168.2.5
                Jul 12, 2024 08:12:48.286153078 CEST57004445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.286175013 CEST57004445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.286580086 CEST57005445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.292932987 CEST4455700550.247.21.2192.168.2.5
                Jul 12, 2024 08:12:48.293042898 CEST57005445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.293042898 CEST57005445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.293715954 CEST4455700450.247.21.2192.168.2.5
                Jul 12, 2024 08:12:48.293771029 CEST57004445192.168.2.550.247.21.2
                Jul 12, 2024 08:12:48.298187971 CEST4455700550.247.21.2192.168.2.5
                Jul 12, 2024 08:12:48.545840979 CEST57006445192.168.2.535.216.199.11
                Jul 12, 2024 08:12:48.552103043 CEST4455700635.216.199.11192.168.2.5
                Jul 12, 2024 08:12:48.552201986 CEST57006445192.168.2.535.216.199.11
                Jul 12, 2024 08:12:48.552294970 CEST57006445192.168.2.535.216.199.11
                Jul 12, 2024 08:12:48.552495956 CEST57007445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.559967041 CEST4455700735.216.199.1192.168.2.5
                Jul 12, 2024 08:12:48.560056925 CEST57007445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.560100079 CEST57007445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.560925961 CEST4455700635.216.199.11192.168.2.5
                Jul 12, 2024 08:12:48.560983896 CEST57006445192.168.2.535.216.199.11
                Jul 12, 2024 08:12:48.561321974 CEST57008445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.565601110 CEST4455700735.216.199.1192.168.2.5
                Jul 12, 2024 08:12:48.565659046 CEST57007445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.566127062 CEST4455700835.216.199.1192.168.2.5
                Jul 12, 2024 08:12:48.566179037 CEST57008445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.566237926 CEST57008445192.168.2.535.216.199.1
                Jul 12, 2024 08:12:48.571033955 CEST4455700835.216.199.1192.168.2.5
                Jul 12, 2024 08:12:48.998016119 CEST57009445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:49.003446102 CEST4455700945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:49.003659964 CEST57009445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:49.003659964 CEST57009445192.168.2.545.205.206.1
                Jul 12, 2024 08:12:49.008795023 CEST4455700945.205.206.1192.168.2.5
                Jul 12, 2024 08:12:49.456815004 CEST57010445192.168.2.5149.72.206.63
                Jul 12, 2024 08:12:49.462018013 CEST44557010149.72.206.63192.168.2.5
                Jul 12, 2024 08:12:49.462107897 CEST57010445192.168.2.5149.72.206.63
                Jul 12, 2024 08:12:49.462393999 CEST57010445192.168.2.5149.72.206.63
                Jul 12, 2024 08:12:49.462523937 CEST57011445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.467391968 CEST44557011149.72.206.1192.168.2.5
                Jul 12, 2024 08:12:49.467463017 CEST57011445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.467705011 CEST44557010149.72.206.63192.168.2.5
                Jul 12, 2024 08:12:49.467888117 CEST57010445192.168.2.5149.72.206.63
                Jul 12, 2024 08:12:49.468633890 CEST57011445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.473769903 CEST44557011149.72.206.1192.168.2.5
                Jul 12, 2024 08:12:49.473838091 CEST57011445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.474204063 CEST57012445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.479326963 CEST44557012149.72.206.1192.168.2.5
                Jul 12, 2024 08:12:49.479422092 CEST57012445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.479453087 CEST57012445192.168.2.5149.72.206.1
                Jul 12, 2024 08:12:49.484410048 CEST44557012149.72.206.1192.168.2.5
                Jul 12, 2024 08:12:50.057267904 CEST44556947159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:50.057352066 CEST56947445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:50.057434082 CEST56947445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:50.057495117 CEST56947445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:50.062405109 CEST44556947159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:50.062532902 CEST44556947159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:50.212939978 CEST44556948203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:50.213156939 CEST56948445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:50.213215113 CEST56948445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:50.213448048 CEST56948445192.168.2.5203.155.53.1
                Jul 12, 2024 08:12:50.218096972 CEST44556948203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:50.218236923 CEST44556948203.155.53.1192.168.2.5
                Jul 12, 2024 08:12:50.232559919 CEST57013445192.168.2.5147.150.35.105
                Jul 12, 2024 08:12:50.239790916 CEST44557013147.150.35.105192.168.2.5
                Jul 12, 2024 08:12:50.240008116 CEST57013445192.168.2.5147.150.35.105
                Jul 12, 2024 08:12:50.240101099 CEST57013445192.168.2.5147.150.35.105
                Jul 12, 2024 08:12:50.240101099 CEST57014445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.245263100 CEST44557014147.150.35.1192.168.2.5
                Jul 12, 2024 08:12:50.245341063 CEST57014445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.245651960 CEST44557013147.150.35.105192.168.2.5
                Jul 12, 2024 08:12:50.245682955 CEST57014445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.245753050 CEST57013445192.168.2.5147.150.35.105
                Jul 12, 2024 08:12:50.245846033 CEST57015445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.250838995 CEST44557014147.150.35.1192.168.2.5
                Jul 12, 2024 08:12:50.250869989 CEST44557015147.150.35.1192.168.2.5
                Jul 12, 2024 08:12:50.250895977 CEST57014445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.250967026 CEST57015445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.251008034 CEST57015445192.168.2.5147.150.35.1
                Jul 12, 2024 08:12:50.255798101 CEST44557015147.150.35.1192.168.2.5
                Jul 12, 2024 08:12:50.279217005 CEST57016445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.284321070 CEST44557016203.155.53.2192.168.2.5
                Jul 12, 2024 08:12:50.284403086 CEST57016445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.284425974 CEST57016445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.284698009 CEST57017445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.289478064 CEST44557017203.155.53.2192.168.2.5
                Jul 12, 2024 08:12:50.289554119 CEST57017445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.289589882 CEST57017445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.289637089 CEST44557016203.155.53.2192.168.2.5
                Jul 12, 2024 08:12:50.289689064 CEST57016445192.168.2.5203.155.53.2
                Jul 12, 2024 08:12:50.294454098 CEST44557017203.155.53.2192.168.2.5
                Jul 12, 2024 08:12:51.013573885 CEST57019445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:51.018517971 CEST44557019192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:51.018632889 CEST57019445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:51.018652916 CEST57019445192.168.2.5192.99.167.1
                Jul 12, 2024 08:12:51.023421049 CEST44557019192.99.167.1192.168.2.5
                Jul 12, 2024 08:12:52.308984995 CEST44556952160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:52.309124947 CEST56952445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:52.309225082 CEST56952445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:52.309350014 CEST56952445192.168.2.5160.232.165.1
                Jul 12, 2024 08:12:52.314063072 CEST44556952160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:52.314713001 CEST44556952160.232.165.1192.168.2.5
                Jul 12, 2024 08:12:52.373004913 CEST57023445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.377991915 CEST44557023160.232.165.2192.168.2.5
                Jul 12, 2024 08:12:52.378088951 CEST57023445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.378125906 CEST57023445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.378488064 CEST57024445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.383285046 CEST44557024160.232.165.2192.168.2.5
                Jul 12, 2024 08:12:52.383356094 CEST57024445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.383378983 CEST57024445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.383559942 CEST44557023160.232.165.2192.168.2.5
                Jul 12, 2024 08:12:52.383618116 CEST57023445192.168.2.5160.232.165.2
                Jul 12, 2024 08:12:52.388173103 CEST44557024160.232.165.2192.168.2.5
                Jul 12, 2024 08:12:53.060349941 CEST57027445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:53.065464973 CEST44557027159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:53.065541029 CEST57027445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:53.065565109 CEST57027445192.168.2.5159.4.73.1
                Jul 12, 2024 08:12:53.070410013 CEST44557027159.4.73.1192.168.2.5
                Jul 12, 2024 08:12:54.060694933 CEST44556955105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:54.060928106 CEST56955445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:54.060928106 CEST56955445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:54.060928106 CEST56955445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:54.066257000 CEST44556955105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:54.066287041 CEST44556955105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:54.087879896 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:54.087970972 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:54.088061094 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:54.088437080 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:54.088475943 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:54.264512062 CEST44556956183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:54.264616966 CEST56956445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:54.264708996 CEST56956445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:54.264708996 CEST56956445192.168.2.5183.227.189.1
                Jul 12, 2024 08:12:54.269710064 CEST44556956183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:54.269742012 CEST44556956183.227.189.1192.168.2.5
                Jul 12, 2024 08:12:54.326502085 CEST57036445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.332546949 CEST44557036183.227.189.2192.168.2.5
                Jul 12, 2024 08:12:54.332773924 CEST57036445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.332775116 CEST57036445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.333121061 CEST57037445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.338073969 CEST44557037183.227.189.2192.168.2.5
                Jul 12, 2024 08:12:54.338129044 CEST44557036183.227.189.2192.168.2.5
                Jul 12, 2024 08:12:54.338191986 CEST57036445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.338284016 CEST57037445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.338284969 CEST57037445192.168.2.5183.227.189.2
                Jul 12, 2024 08:12:54.343189001 CEST44557037183.227.189.2192.168.2.5
                Jul 12, 2024 08:12:54.859426022 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:54.859507084 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:54.862957954 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:54.862987995 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:54.863203049 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:54.870131969 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:54.916496992 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.191601038 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.191621065 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.191766024 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.191788912 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.191838980 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.191865921 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.191889048 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.192091942 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.192152977 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.192167997 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.192229986 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.192378044 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.192420006 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.192425013 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.192466021 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.195431948 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.195467949 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.195492983 CEST57034443192.168.2.520.114.59.183
                Jul 12, 2024 08:12:55.195508003 CEST4435703420.114.59.183192.168.2.5
                Jul 12, 2024 08:12:55.935517073 CEST44556959217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:55.935592890 CEST56959445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:55.935625076 CEST56959445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:55.935658932 CEST56959445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:55.940634966 CEST44556959217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:55.940665007 CEST44556959217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:56.312473059 CEST4455696096.158.114.1192.168.2.5
                Jul 12, 2024 08:12:56.312695980 CEST56960445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:56.312737942 CEST56960445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:56.312828064 CEST56960445192.168.2.596.158.114.1
                Jul 12, 2024 08:12:56.317689896 CEST4455696096.158.114.1192.168.2.5
                Jul 12, 2024 08:12:56.317742109 CEST4455696096.158.114.1192.168.2.5
                Jul 12, 2024 08:12:56.373147964 CEST57058445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.378221989 CEST4455705896.158.114.2192.168.2.5
                Jul 12, 2024 08:12:56.380397081 CEST57058445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.380439997 CEST57058445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.380716085 CEST57059445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.385642052 CEST4455705996.158.114.2192.168.2.5
                Jul 12, 2024 08:12:56.386698961 CEST4455705896.158.114.2192.168.2.5
                Jul 12, 2024 08:12:56.386769056 CEST57058445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.386812925 CEST57059445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.386812925 CEST57059445192.168.2.596.158.114.2
                Jul 12, 2024 08:12:56.391746998 CEST4455705996.158.114.2192.168.2.5
                Jul 12, 2024 08:12:57.076703072 CEST57068445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:57.081801891 CEST44557068105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:57.081886053 CEST57068445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:57.081924915 CEST57068445192.168.2.5105.57.122.1
                Jul 12, 2024 08:12:57.086752892 CEST44557068105.57.122.1192.168.2.5
                Jul 12, 2024 08:12:57.685745955 CEST4455696410.50.70.1192.168.2.5
                Jul 12, 2024 08:12:57.685878992 CEST56964445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:57.685878992 CEST56964445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:57.685878992 CEST56964445192.168.2.510.50.70.1
                Jul 12, 2024 08:12:57.691468000 CEST4455696410.50.70.1192.168.2.5
                Jul 12, 2024 08:12:57.691497087 CEST4455696410.50.70.1192.168.2.5
                Jul 12, 2024 08:12:58.276303053 CEST44556965161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:58.276415110 CEST56965445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:58.276415110 CEST56965445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:58.276520967 CEST56965445192.168.2.5161.45.66.1
                Jul 12, 2024 08:12:58.281702995 CEST44556965161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:58.281744003 CEST44556965161.45.66.1192.168.2.5
                Jul 12, 2024 08:12:58.341864109 CEST57091445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.347246885 CEST44557091161.45.66.2192.168.2.5
                Jul 12, 2024 08:12:58.347543001 CEST57091445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.347543001 CEST57091445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.347768068 CEST57092445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.352533102 CEST44557092161.45.66.2192.168.2.5
                Jul 12, 2024 08:12:58.352703094 CEST57092445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.352866888 CEST57092445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.352907896 CEST44557091161.45.66.2192.168.2.5
                Jul 12, 2024 08:12:58.352962971 CEST57091445192.168.2.5161.45.66.2
                Jul 12, 2024 08:12:58.357712030 CEST44557092161.45.66.2192.168.2.5
                Jul 12, 2024 08:12:58.682365894 CEST44556967185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:58.682634115 CEST56967445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:58.682634115 CEST56967445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:58.682634115 CEST56967445192.168.2.5185.148.241.2
                Jul 12, 2024 08:12:58.687603951 CEST44556967185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:58.687623024 CEST44556967185.148.241.2192.168.2.5
                Jul 12, 2024 08:12:58.951052904 CEST57106445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:58.957874060 CEST44557106217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:58.958038092 CEST57106445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:58.958039045 CEST57106445192.168.2.5217.123.9.1
                Jul 12, 2024 08:12:58.966067076 CEST44557106217.123.9.1192.168.2.5
                Jul 12, 2024 08:12:59.326822996 CEST4455697063.194.252.1192.168.2.5
                Jul 12, 2024 08:12:59.327039957 CEST56970445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:59.327114105 CEST56970445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:59.327115059 CEST56970445192.168.2.563.194.252.1
                Jul 12, 2024 08:12:59.332108021 CEST4455697063.194.252.1192.168.2.5
                Jul 12, 2024 08:12:59.332133055 CEST4455697063.194.252.1192.168.2.5
                Jul 12, 2024 08:13:00.313910961 CEST44556971149.78.23.1192.168.2.5
                Jul 12, 2024 08:13:00.314007044 CEST56971445192.168.2.5149.78.23.1
                Jul 12, 2024 08:13:00.314048052 CEST56971445192.168.2.5149.78.23.1
                Jul 12, 2024 08:13:00.314057112 CEST56971445192.168.2.5149.78.23.1
                Jul 12, 2024 08:13:00.320456982 CEST44556971149.78.23.1192.168.2.5
                Jul 12, 2024 08:13:00.320601940 CEST44556971149.78.23.1192.168.2.5
                Jul 12, 2024 08:13:00.373334885 CEST57150445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.379766941 CEST44557150149.78.23.2192.168.2.5
                Jul 12, 2024 08:13:00.380099058 CEST57150445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.380192995 CEST57150445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.381180048 CEST57151445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.387145042 CEST44557150149.78.23.2192.168.2.5
                Jul 12, 2024 08:13:00.387341022 CEST57150445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.387610912 CEST44557151149.78.23.2192.168.2.5
                Jul 12, 2024 08:13:00.387676001 CEST57151445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.387722015 CEST57151445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:00.394103050 CEST44557151149.78.23.2192.168.2.5
                Jul 12, 2024 08:13:00.701055050 CEST57168445192.168.2.510.50.70.1
                Jul 12, 2024 08:13:00.706348896 CEST4455716810.50.70.1192.168.2.5
                Jul 12, 2024 08:13:00.706432104 CEST57168445192.168.2.510.50.70.1
                Jul 12, 2024 08:13:00.706454992 CEST57168445192.168.2.510.50.70.1
                Jul 12, 2024 08:13:00.712734938 CEST4455716810.50.70.1192.168.2.5
                Jul 12, 2024 08:13:00.869236946 CEST44556974133.184.83.1192.168.2.5
                Jul 12, 2024 08:13:00.869364977 CEST56974445192.168.2.5133.184.83.1
                Jul 12, 2024 08:13:00.869429111 CEST56974445192.168.2.5133.184.83.1
                Jul 12, 2024 08:13:00.869503021 CEST56974445192.168.2.5133.184.83.1
                Jul 12, 2024 08:13:00.874347925 CEST44556974133.184.83.1192.168.2.5
                Jul 12, 2024 08:13:00.874389887 CEST44556974133.184.83.1192.168.2.5
                Jul 12, 2024 08:13:01.685404062 CEST57248445192.168.2.5185.148.241.2
                Jul 12, 2024 08:13:01.690470934 CEST44557248185.148.241.2192.168.2.5
                Jul 12, 2024 08:13:01.690555096 CEST57248445192.168.2.5185.148.241.2
                Jul 12, 2024 08:13:01.690601110 CEST57248445192.168.2.5185.148.241.2
                Jul 12, 2024 08:13:01.695462942 CEST44557248185.148.241.2192.168.2.5
                Jul 12, 2024 08:13:02.276329041 CEST44556977149.178.165.1192.168.2.5
                Jul 12, 2024 08:13:02.276424885 CEST56977445192.168.2.5149.178.165.1
                Jul 12, 2024 08:13:02.337930918 CEST44556978192.12.185.1192.168.2.5
                Jul 12, 2024 08:13:02.338001013 CEST56978445192.168.2.5192.12.185.1
                Jul 12, 2024 08:13:02.973941088 CEST56982445192.168.2.527.249.74.1
                Jul 12, 2024 08:13:02.974189997 CEST56978445192.168.2.5192.12.185.1
                Jul 12, 2024 08:13:02.974204063 CEST56996445192.168.2.589.248.166.2
                Jul 12, 2024 08:13:02.974215031 CEST57092445192.168.2.5161.45.66.2
                Jul 12, 2024 08:13:02.974251986 CEST57005445192.168.2.550.247.21.2
                Jul 12, 2024 08:13:02.974271059 CEST57024445192.168.2.5160.232.165.2
                Jul 12, 2024 08:13:02.974477053 CEST56977445192.168.2.5149.178.165.1
                Jul 12, 2024 08:13:02.974498034 CEST56981445192.168.2.5199.9.102.1
                Jul 12, 2024 08:13:02.974518061 CEST56985445192.168.2.5170.120.108.1
                Jul 12, 2024 08:13:02.974535942 CEST56987445192.168.2.5204.59.96.2
                Jul 12, 2024 08:13:02.974556923 CEST56990445192.168.2.511.223.200.1
                Jul 12, 2024 08:13:02.974580050 CEST56993445192.168.2.5144.131.63.1
                Jul 12, 2024 08:13:02.974601030 CEST56994445192.168.2.56.119.83.1
                Jul 12, 2024 08:13:02.974623919 CEST56999445192.168.2.558.98.198.1
                Jul 12, 2024 08:13:02.974641085 CEST57000445192.168.2.519.193.250.1
                Jul 12, 2024 08:13:02.974730015 CEST57003445192.168.2.5146.166.199.1
                Jul 12, 2024 08:13:02.974746943 CEST57008445192.168.2.535.216.199.1
                Jul 12, 2024 08:13:02.974801064 CEST57009445192.168.2.545.205.206.1
                Jul 12, 2024 08:13:02.974843979 CEST57015445192.168.2.5147.150.35.1
                Jul 12, 2024 08:13:02.974843979 CEST57017445192.168.2.5203.155.53.2
                Jul 12, 2024 08:13:02.974864006 CEST57019445192.168.2.5192.99.167.1
                Jul 12, 2024 08:13:02.974889040 CEST57037445192.168.2.5183.227.189.2
                Jul 12, 2024 08:13:02.974917889 CEST57027445192.168.2.5159.4.73.1
                Jul 12, 2024 08:13:02.974942923 CEST57012445192.168.2.5149.72.206.1
                Jul 12, 2024 08:13:02.974942923 CEST57068445192.168.2.5105.57.122.1
                Jul 12, 2024 08:13:02.974977016 CEST57059445192.168.2.596.158.114.2
                Jul 12, 2024 08:13:02.975028992 CEST57106445192.168.2.5217.123.9.1
                Jul 12, 2024 08:13:02.975107908 CEST57168445192.168.2.510.50.70.1
                Jul 12, 2024 08:13:02.975174904 CEST57151445192.168.2.5149.78.23.2
                Jul 12, 2024 08:13:02.975816011 CEST57248445192.168.2.5185.148.241.2
                TimestampSource PortDest PortSource IPDest IP
                Jul 12, 2024 08:11:55.324048042 CEST5736753192.168.2.51.1.1.1
                Jul 12, 2024 08:11:55.484185934 CEST53573671.1.1.1192.168.2.5
                Jul 12, 2024 08:11:56.195116043 CEST5316353192.168.2.51.1.1.1
                Jul 12, 2024 08:11:56.438673973 CEST53531631.1.1.1192.168.2.5
                Jul 12, 2024 08:12:17.444612980 CEST53545121.1.1.1192.168.2.5
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Jul 12, 2024 08:11:55.324048042 CEST192.168.2.51.1.1.10x5fd5Standard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                Jul 12, 2024 08:11:56.195116043 CEST192.168.2.51.1.1.10x5b74Standard query (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Jul 12, 2024 08:11:55.484185934 CEST1.1.1.1192.168.2.50x5fd5No error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com103.224.212.215A (IP address)IN (0x0001)false
                Jul 12, 2024 08:11:56.438673973 CEST1.1.1.1192.168.2.50x5b74No error (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com77026.bodis.comCNAME (Canonical name)IN (0x0001)false
                Jul 12, 2024 08:11:56.438673973 CEST1.1.1.1192.168.2.50x5b74No error (0)77026.bodis.com199.59.243.226A (IP address)IN (0x0001)false
                • slscr.update.microsoft.com
                • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                • ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.549704103.224.212.215807108C:\Users\user\Desktop\yrBA01LVo2.exe
                TimestampBytes transferredDirectionData
                Jul 12, 2024 08:11:55.495357037 CEST100OUTGET / HTTP/1.1
                Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Cache-Control: no-cache
                Jul 12, 2024 08:11:56.187971115 CEST365INHTTP/1.1 302 Found
                date: Fri, 12 Jul 2024 06:11:56 GMT
                server: Apache
                set-cookie: __tad=1720764716.7475799; expires=Mon, 10-Jul-2034 06:11:56 GMT; Max-Age=315360000
                location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-56c7-8cb1-aab7e5f01544
                content-length: 2
                content-type: text/html; charset=UTF-8
                connection: close
                Data Raw: 0a 0a
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.549705199.59.243.226807108C:\Users\user\Desktop\yrBA01LVo2.exe
                TimestampBytes transferredDirectionData
                Jul 12, 2024 08:11:56.445528984 CEST169OUTGET /?subid1=20240712-1611-56c7-8cb1-aab7e5f01544 HTTP/1.1
                Cache-Control: no-cache
                Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Connection: Keep-Alive
                Jul 12, 2024 08:11:56.907282114 CEST1236INHTTP/1.1 200 OK
                date: Fri, 12 Jul 2024 06:11:56 GMT
                content-type: text/html; charset=utf-8
                content-length: 1258
                x-request-id: 09f54ebc-1607-4928-9eb7-1c89c752f946
                cache-control: no-store, max-age=0
                accept-ch: sec-ch-prefers-color-scheme
                critical-ch: sec-ch-prefers-color-scheme
                vary: sec-ch-prefers-color-scheme
                x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_z3+3zo1dq695acmDmqsE0o2iFkM98d09qDAxF/OSnAPh6sxb1VLjLzjWSQfAludyh2t8iiFDrNDMHrWx24jEmQ==
                set-cookie: parking_session=09f54ebc-1607-4928-9eb7-1c89c752f946; expires=Fri, 12 Jul 2024 06:26:56 GMT; path=/
                Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 7a 33 2b 33 7a 6f 31 64 71 36 39 35 61 63 6d 44 6d 71 73 45 30 6f 32 69 46 6b 4d 39 38 64 30 39 71 44 41 78 46 2f 4f 53 6e 41 50 68 36 73 78 62 31 56 4c 6a 4c 7a 6a 57 53 51 66 41 6c 75 64 79 68 32 74 38 69 69 46 44 72 4e 44 4d 48 72 57 78 32 34 6a 45 6d 51 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_z3+3zo1dq695acmDmqsE0o2iFkM98d09qDAxF/OSnAPh6sxb1VLjLzjWSQfAludyh2t8iiFDrNDMHrWx24jEmQ==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                Jul 12, 2024 08:11:56.907345057 CEST692INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiMDlmNTRlYmMtMTYwNy00OTI4LTllYjctMWM4OWM3NTJmOTQ2IiwicGFnZV90aW1lIjoxNzIwNzY0NzE2LCJwYWdlX3VybCI6I


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.549706103.224.212.215805508C:\Users\user\Desktop\yrBA01LVo2.exe
                TimestampBytes transferredDirectionData
                Jul 12, 2024 08:11:57.248883009 CEST100OUTGET / HTTP/1.1
                Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Cache-Control: no-cache
                Jul 12, 2024 08:11:57.877907991 CEST365INHTTP/1.1 302 Found
                date: Fri, 12 Jul 2024 06:11:57 GMT
                server: Apache
                set-cookie: __tad=1720764717.5636787; expires=Mon, 10-Jul-2034 06:11:57 GMT; Max-Age=315360000
                location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20240712-1611-575d-a069-1da1339fd736
                content-length: 2
                content-type: text/html; charset=UTF-8
                connection: close
                Data Raw: 0a 0a
                Data Ascii:


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.549707199.59.243.226805508C:\Users\user\Desktop\yrBA01LVo2.exe
                TimestampBytes transferredDirectionData
                Jul 12, 2024 08:11:57.888644934 CEST169OUTGET /?subid1=20240712-1611-575d-a069-1da1339fd736 HTTP/1.1
                Cache-Control: no-cache
                Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Connection: Keep-Alive
                Jul 12, 2024 08:11:58.364789009 CEST1236INHTTP/1.1 200 OK
                date: Fri, 12 Jul 2024 06:11:57 GMT
                content-type: text/html; charset=utf-8
                content-length: 1258
                x-request-id: d1b97704-9761-44e4-bc49-86973340f7fe
                cache-control: no-store, max-age=0
                accept-ch: sec-ch-prefers-color-scheme
                critical-ch: sec-ch-prefers-color-scheme
                vary: sec-ch-prefers-color-scheme
                x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_hWWVP+MHY7HLVI1wJ9uZM2dMlsfThHvdHhfQnXTLeKU9azTJoTqL+59yum9Vaujye167LXD91hTbQf5aSyYJOw==
                set-cookie: parking_session=d1b97704-9761-44e4-bc49-86973340f7fe; expires=Fri, 12 Jul 2024 06:26:58 GMT; path=/
                Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 68 57 57 56 50 2b 4d 48 59 37 48 4c 56 49 31 77 4a 39 75 5a 4d 32 64 4d 6c 73 66 54 68 48 76 64 48 68 66 51 6e 58 54 4c 65 4b 55 39 61 7a 54 4a 6f 54 71 4c 2b 35 39 79 75 6d 39 56 61 75 6a 79 65 31 36 37 4c 58 44 39 31 68 54 62 51 66 35 61 53 79 59 4a 4f 77 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_hWWVP+MHY7HLVI1wJ9uZM2dMlsfThHvdHhfQnXTLeKU9azTJoTqL+59yum9Vaujye167LXD91hTbQf5aSyYJOw==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                Jul 12, 2024 08:11:58.364913940 CEST692INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiZDFiOTc3MDQtOTc2MS00NGU0LWJjNDktODY5NzMzNDBmN2ZlIiwicGFnZV90aW1lIjoxNzIwNzY0NzE4LCJwYWdlX3VybCI6I


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.54988752.165.165.26443
                TimestampBytes transferredDirectionData
                2024-07-12 06:12:14 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=1BSddhgcBDph9M7&MD=UAFFSYcE HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2024-07-12 06:12:15 UTC560INHTTP/1.1 200 OK
                Cache-Control: no-cache
                Pragma: no-cache
                Content-Type: application/octet-stream
                Expires: -1
                Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                MS-CorrelationId: 1e0e9a66-cd26-4c98-a74a-6218b2d0fbb6
                MS-RequestId: c5308cd8-22a8-4968-acf4-9cf16913e7b3
                MS-CV: Vt2xmLiGiUayxKPV.0
                X-Microsoft-SLSClientCache: 2880
                Content-Disposition: attachment; filename=environment.cab
                X-Content-Type-Options: nosniff
                Date: Fri, 12 Jul 2024 06:12:14 GMT
                Connection: close
                Content-Length: 24490
                2024-07-12 06:12:15 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                2024-07-12 06:12:15 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.55703420.114.59.183443
                TimestampBytes transferredDirectionData
                2024-07-12 06:12:54 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=1BSddhgcBDph9M7&MD=UAFFSYcE HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                Host: slscr.update.microsoft.com
                2024-07-12 06:12:55 UTC560INHTTP/1.1 200 OK
                Cache-Control: no-cache
                Pragma: no-cache
                Content-Type: application/octet-stream
                Expires: -1
                Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                MS-CorrelationId: 4ec80965-e154-4f93-bd86-5423f9c36c08
                MS-RequestId: dcd43a2c-1d92-4fa7-8fc5-cb7d2fca52cd
                MS-CV: Re1QMJloNEGIpQZd.0
                X-Microsoft-SLSClientCache: 1440
                Content-Disposition: attachment; filename=environment.cab
                X-Content-Type-Options: nosniff
                Date: Fri, 12 Jul 2024 06:12:54 GMT
                Connection: close
                Content-Length: 30005
                2024-07-12 06:12:55 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                2024-07-12 06:12:55 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Click to jump to process

                Target ID:0
                Start time:02:11:54
                Start date:12/07/2024
                Path:C:\Users\user\Desktop\yrBA01LVo2.exe
                Wow64 process (32bit):true
                Commandline:"C:\Users\user\Desktop\yrBA01LVo2.exe"
                Imagebase:0x400000
                File size:2'281'472 bytes
                MD5 hash:DA8DDE3005365992711946C4622A3C74
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000000.1999381187.000000000040F000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                Reputation:low
                Has exited:true

                Target ID:2
                Start time:02:11:56
                Start date:12/07/2024
                Path:C:\Users\user\Desktop\yrBA01LVo2.exe
                Wow64 process (32bit):true
                Commandline:C:\Users\user\Desktop\yrBA01LVo2.exe -m security
                Imagebase:0x400000
                File size:2'281'472 bytes
                MD5 hash:DA8DDE3005365992711946C4622A3C74
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000002.00000000.2018076872.000000000040F000.00000008.00000001.01000000.00000003.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000002.00000002.2671560893.0000000002289000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000002.00000002.2671276992.0000000001D61000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                Reputation:low
                Has exited:true

                Target ID:4
                Start time:02:12:41
                Start date:12/07/2024
                Path:C:\Windows\System32\svchost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\System32\svchost.exe -k LocalService -p -s LicenseManager
                Imagebase:0x7ff7e52b0000
                File size:55'320 bytes
                MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                Has elevated privileges:true
                Has administrator privileges:false
                Programmed in:C, C++ or other language
                Reputation:high
                Has exited:false

                Reset < >

                  Execution Graph

                  Execution Coverage:71.7%
                  Dynamic/Decrypted Code Coverage:0%
                  Signature Coverage:63.2%
                  Total number of Nodes:38
                  Total number of Limit Nodes:9
                  execution_graph 63 409a16 __set_app_type __p__fmode __p__commode 64 409a85 63->64 65 409a99 64->65 66 409a8d __setusermatherr 64->66 75 409b8c _controlfp 65->75 66->65 68 409a9e _initterm __getmainargs _initterm 69 409af2 GetStartupInfoA 68->69 71 409b26 GetModuleHandleA 69->71 76 408140 InternetOpenA InternetOpenUrlA 71->76 75->68 77 4081a7 InternetCloseHandle InternetCloseHandle 76->77 80 408090 GetModuleFileNameA __p___argc 77->80 79 4081b2 exit _XcptFilter 81 4080b0 80->81 82 4080b9 OpenSCManagerA 80->82 91 407f20 81->91 83 408101 StartServiceCtrlDispatcherA 82->83 84 4080cf OpenServiceA 82->84 83->79 86 4080fc CloseServiceHandle 84->86 87 4080ee 84->87 86->83 96 407fa0 ChangeServiceConfig2A 87->96 90 4080f6 CloseServiceHandle 90->86 108 407c40 sprintf OpenSCManagerA 91->108 93 407f25 97 407ce0 GetModuleHandleW 93->97 96->90 98 407d01 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 97->98 99 407f08 97->99 98->99 100 407d49 98->100 99->79 100->99 101 407d69 FindResourceA 100->101 101->99 102 407d84 LoadResource 101->102 102->99 103 407d94 LockResource 102->103 103->99 104 407da7 SizeofResource 103->104 104->99 105 407db9 sprintf sprintf MoveFileExA CreateFileA 104->105 105->99 106 407e54 WriteFile FindCloseChangeNotification CreateProcessA 105->106 106->99 107 407ef2 CloseHandle CloseHandle 106->107 107->99 109 407c74 CreateServiceA 108->109 110 407cca 108->110 111 407cbb CloseServiceHandle 109->111 112 407cad StartServiceA CloseServiceHandle 109->112 110->93 111->93 112->111

                  Callgraph

                  Control-flow Graph

                  APIs
                  • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F390EF0,?,00000000), ref: 00407CEF
                  • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                  • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                  • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                  • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                  • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                  • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                  • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                  • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                  • sprintf.MSVCRT ref: 00407E01
                  • sprintf.MSVCRT ref: 00407E18
                  • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                  • CreateFileA.KERNELBASE(?,40000000,00000000,00000000,00000002,00000004,00000000), ref: 00407E43
                  • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 00407E61
                  • FindCloseChangeNotification.KERNELBASE(00000000), ref: 00407E68
                  • CreateProcessA.KERNELBASE ref: 00407EE8
                  • CloseHandle.KERNEL32(00000000), ref: 00407EF7
                  • CloseHandle.KERNEL32(08000000), ref: 00407F02
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2031797583.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000000.00000002.2031770948.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031824180.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031903602.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressProcResource$CloseFileHandle$CreateFindsprintf$ChangeLoadLockModuleMoveNotificationProcessSizeofWrite
                  • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                  • API String ID: 1541710770-1507730452
                  • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                  • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                  Control-flow Graph

                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.2031797583.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000000.00000002.2031770948.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031824180.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031903602.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                  • String ID:
                  • API String ID: 801014965-0
                  • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                  • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59

                  Control-flow Graph

                  APIs
                  • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                  • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                  • InternetCloseHandle.WININET(00000000), ref: 004081A7
                  • InternetCloseHandle.WININET(00000000), ref: 004081AB
                    • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                    • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                  Strings
                  • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                  Memory Dump Source
                  • Source File: 00000000.00000002.2031797583.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000000.00000002.2031770948.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031824180.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031903602.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                  • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                  • API String ID: 774561529-2614457033
                  • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                  • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                  • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                  • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                  Control-flow Graph

                  APIs
                  • sprintf.MSVCRT ref: 00407C56
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                  • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F390EF0,00000000), ref: 00407C9B
                  • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2031797583.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000000.00000002.2031770948.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031824180.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031903602.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                  • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                  • API String ID: 3340711343-2450984573
                  • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                  • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                  Control-flow Graph

                  APIs
                  • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                  • __p___argc.MSVCRT ref: 004080A5
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                  • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F390EF0,00000000,?,004081B2), ref: 004080DC
                  • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                  • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                  • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2031797583.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000000.00000002.2031770948.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031824180.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031849170.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031903602.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000000.00000002.2031973988.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                  • String ID: mssecsvc2.1
                  • API String ID: 4274534310-2839763450
                  • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                  • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                  Execution Graph

                  Execution Coverage:34.8%
                  Dynamic/Decrypted Code Coverage:0%
                  Signature Coverage:0%
                  Total number of Nodes:36
                  Total number of Limit Nodes:2

                  Callgraph

                  Control-flow Graph

                  APIs
                  • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                  • __p___argc.MSVCRT ref: 004080A5
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                  • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F390EF0,00000000,?,004081B2), ref: 004080DC
                  • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                  • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                  • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                  Strings
                  Memory Dump Source
                  • Source File: 00000002.00000002.2667490385.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000002.00000002.2667478265.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667508008.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667637821.000000000042F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667647828.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_2_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                  • String ID: mssecsvc2.1
                  • API String ID: 4274534310-2839763450
                  • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                  • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                  • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                  Control-flow Graph

                  APIs
                  • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                  • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                  • InternetCloseHandle.WININET(00000000), ref: 004081A7
                  • InternetCloseHandle.WININET(00000000), ref: 004081AB
                    • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                    • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                  Strings
                  • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                  Memory Dump Source
                  • Source File: 00000002.00000002.2667490385.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000002.00000002.2667478265.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667508008.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667637821.000000000042F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667647828.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_2_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                  • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                  • API String ID: 774561529-2614457033
                  • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                  • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                  • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                  • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                  Control-flow Graph

                  APIs
                  • sprintf.MSVCRT ref: 00407C56
                  • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                  • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F390EF0,00000000), ref: 00407C9B
                  • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                  • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                  Strings
                  Memory Dump Source
                  • Source File: 00000002.00000002.2667490385.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000002.00000002.2667478265.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667508008.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667637821.000000000042F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667647828.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_2_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                  • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                  • API String ID: 3340711343-2450984573
                  • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                  • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                  • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 15 407ce0-407cfb GetModuleHandleW 16 407d01-407d43 GetProcAddress * 4 15->16 17 407f08-407f14 15->17 16->17 18 407d49-407d4f 16->18 18->17 19 407d55-407d5b 18->19 19->17 20 407d61-407d63 19->20 20->17 21 407d69-407d7e FindResourceA 20->21 21->17 22 407d84-407d8e LoadResource 21->22 22->17 23 407d94-407da1 LockResource 22->23 23->17 24 407da7-407db3 SizeofResource 23->24 24->17 25 407db9-407e4e sprintf * 2 MoveFileExA 24->25 25->17 27 407e54-407ef0 25->27 27->17 31 407ef2-407f01 27->31 31->17
                  APIs
                  • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F390EF0,?,00000000), ref: 00407CEF
                  • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                  • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                  • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                  • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                  • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                  • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                  • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                  • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                  • sprintf.MSVCRT ref: 00407E01
                  • sprintf.MSVCRT ref: 00407E18
                  • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                  Strings
                  Memory Dump Source
                  • Source File: 00000002.00000002.2667490385.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000002.00000002.2667478265.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667508008.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667637821.000000000042F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667647828.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_2_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressProcResource$sprintf$FileFindHandleLoadLockModuleMoveSizeof
                  • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                  • API String ID: 4072214828-1507730452
                  • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                  • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                  • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                  Control-flow Graph

                  APIs
                  Memory Dump Source
                  • Source File: 00000002.00000002.2667490385.0000000000401000.00000020.00000001.01000000.00000003.sdmp, Offset: 00400000, based on PE: true
                  • Associated: 00000002.00000002.2667478265.0000000000400000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667508008.000000000040A000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040B000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667574480.000000000040F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667627520.000000000042E000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667637821.000000000042F000.00000008.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667647828.0000000000431000.00000004.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.0000000000710000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.000000000083B000.00000002.00000001.01000000.00000003.sdmpDownload File
                  • Associated: 00000002.00000002.2667717871.00000000008A0000.00000002.00000001.01000000.00000003.sdmpDownload File
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_2_2_400000_yrBA01LVo2.jbxd
                  Yara matches
                  Similarity
                  • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                  • String ID:
                  • API String ID: 801014965-0
                  • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                  • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                  • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59